HIGHLY Recommended

http://www.newzie.com/
http://www.ziepod.com/ZiepodSetup.exe
I'll follow up later with results...
So certain stuff are written to the app folder, but a whole lot of other stuff (eg. keyboard shortcuts) are written to the registry.
----------------------------------
Keys added:6
----------------------------------
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\DBIDMap
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\IDRolls
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts
----------------------------------
Values added:50
----------------------------------
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\100: "2080"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\101: "2078"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\102: "2079"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\103: "1049"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\104: "1050"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\105: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\106: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\107: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\108: "3082"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\109: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\110: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\111: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\112: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\113: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\114: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\115: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\116: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\117: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\118: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\130: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\119: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\121: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\120: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\122: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\123: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\124: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\125: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\126: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\127: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\128: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\129: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\KeyboardShortcuts\131: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\IDRolls\LRID-7: 0x00000066
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\DBIDMap\RC_R7_G2: 0x00000000
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\DBIDMap\RC_R7_G3: 0x00000001
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\DBIDMap\RC_R7_G100: 0x00000002
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\DBIDMap\RC_R7_G101: 0x00000003
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\Username: "Newzie"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\InstallationDate: "02/19/07@22:03"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\LastDBID: 0x00000004
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\NewzieBlogAdded: "1"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\InstalledVersion: "0.99.8"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\WindowPosition: 2C 00 00 00 00 00 00 00 01 00 00 00 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 48 00 00 00 45 00 00 00 B8 03 00 00 BB 02 00 00
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\TotalRetrievedPostCount: 0x00000016
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\DailyRetrievedCounts: "19:2:2007:22|"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\NotifFile: ""
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\EnableNotifier: "0"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\User-Newzie\HideToolbarPanel: "1"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\InstallPath: "C:\Temp\NewzieSetup\{app}\Newzie.exe"
HKU\S-1-5-21-329068152-343818398-725345543-1001\Software\Newzie\Newzie\Users: "Newzie|"
----------------------------------
Files added:12
----------------------------------
C:\TEMP\NewzieSetup\{app}\Newzie\2.zdb
C:\TEMP\NewzieSetup\{app}\Newzie\3.zdb
C:\TEMP\NewzieSetup\{app}\Newzie\Bins.zdb
C:\TEMP\NewzieSetup\{app}\Newzie\BulkChannels.zdb
C:\TEMP\NewzieSetup\{app}\Newzie\C100.zdb
C:\TEMP\NewzieSetup\{app}\Newzie\C101.zdb
C:\TEMP\NewzieSetup\{app}\Newzie\ChannelInfo.zdb
C:\TEMP\NewzieSetup\{app}\Newzie\Channels.zdb
C:\TEMP\NewzieSetup\{app}\Newzie\VirtualChannels.zdb
C:\TEMP\NewzieSetup\{app}\Newzie\WebPages.zdb
C:\TEMP\NewzieSetup\{app}\Newzie\WordWatchDogs.zdb
----------------------------------
Files [attributes?] modified:6
----------------------------------
C:\TEMP\NewzieSetup\{app}\Help\HelpSections.zdb
----------------------------------
Folders added:1
----------------------------------
C:\TEMP\NewzieSetup\{app}\Newzie\Indeces
Code: Select all
[HKEY_CURRENT_USER\user\current\software\Ziepod\Ziepod]
"InstallPath"="F:\\Downloads\\ZiepodSetup\\{app}\\Ziepod.exe"
[HKEY_CURRENT_USER\user\current\software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings"=hex(3):46,00,00,00,C1,2A,00,00,01,00,00,00,00,00,00,\
...
(I truncated the above super-long value)
...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm]
"cFormatTags"=dword:00000002
"aFormatTagCache"=hex(3):01,00,00,00,10,00,00,00,11,00,00,00,14,00,00,00
"cFilterTags"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"Name"="Ziepod.exe"
"ID"=dword:4718ed11
[HKEY_CURRENT_USER\user\current\software\Ziepod\Ziepod\WindowPositions]
"FullMode"=hex(3):2C,00,00,00,00,00,00,00,01,00,00,00,58,02,00,00,64,00,00,\
00,FF,FF,FF,FF,FF,FF,FF,FF,F5,00,00,00,97,00,00,00,AB,04,00,00,21,03,00,00
Code: Select all
HKCU\Software\Ziepod
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist*