I saw the site mentioned earlier in another thread.
www.giveawayoftheday.com so I've downloaded two freebies for today and decided to run the Zsoft app Before n After running Activate.exe below is the log.
FILE ADDED! C:\WINDOWS\Prefetch\ACTIVATE.EXE-21FBCE9F.pf
REG ADDED! HKLM SOFTWARE\3Planesoft
REG ADDED! HKLM SOFTWARE\3Planesoft\Earth 3D Screensaver
REG ADDED! HKLM SOFTWARE\3Planesoft\Earth 3D Screensaver RegisteredTo "3: Registered to: Giveawayoftheday"
REG ADDED! HKLM SOFTWARE\3Planesoft\Earth 3D Screensaver RegName "3: Giveawayoftheday"
REG ADDED! HKLM SOFTWARE\3Planesoft\Earth 3D Screensaver SerNum "3: fireryone-Hid-His-Serial-Number"
REG ADDED! HKLM SOFTWARE\Microsoft\Cryptography\RNG Seed bin:YmHEjamdKVq9CoCClJrijdQ8SSu+[output cut]=
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Google\Google Desktop\HistoricalCapture
capture_component_indexer_stats bin:RgAAAFEAAAAEAAAAAA[output cut]
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Google\Google
Desktop\Status blt_count_slp int:1524174
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Google\Google
Desktop\Status dib_count_slp int:2411560
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Google\Google
Desktop\Status dib_msec_slp int:423267
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\MSNMessenger\SQM
SessionTime int:25740
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Narrator CurrentPitch
int:26935301
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows
NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlooka0d020000000000c000000000000046 0003022b bin:BgAAAA==
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging
Subsystem\Profiles\Outlooka0d020000000000c000000000000046 0003031f bin:BgAAAA==
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging
Subsystem\Profiles\Outlooka0d020000000000c000000000000046 00030398 bin:AgAAAA==
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlooka0d020000000000c000000000000046 101f031e bin:CgAAACwAAABOAAA[output cut]=
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging
Subsystem\Profiles\Outlooka0d020000000000c000000000000046 1102022a
bin:CgAAAMQAAABUAAAAxAAA[output cut]==
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows\CurrentVersion\
Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
HRZR_EHACNGU bin:rAAAAFQXAAAwyCOKm2PHAQ==
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows\CurrentVersion\
Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
HRZR_EHACNGU:G:\FperraFniref\Rnegu3QFperrafnire\Npgvingr.rkr
bin:rAAAAAYAAAAwyCOKm2PHAQ==
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows\CurrentVersion\
Internet Settings\Connections SavedLegacySettings bin:RgAAACssAAABAAAAAAAA[output cut]
REG ADDED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows\ShellNoRoam\
MUICache T:\ScreenSavers\Earth3DScreensaver\Activate.exe "Activate"
REG DELETED! HKLM SOFTWARE\Microsoft\Cryptography\RNG Seed
bin:kPagJN8FxKzxDzcfOm8S5FPL8nwPnFoczpZ3/7l[output cut]=
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Google\Google
Desktop\HistoricalCapture capture_component_indexer_stats
bin:RgAAAFEAAAAEAAAAAAAAADMAAAD[output cut]
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Google\Google Desktop\Status
blt_count_slp int:1524109
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Google\Google Desktop\Status
dib_count_slp int:2411495
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Google\Google Desktop\Status
dib_msec_slp int:423250
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\MSNMessenger\SQM
SessionTime int:25440
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Narrator CurrentPitch
int:34209797
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows
NT\CurrentVersion\Windows Messaging
Subsystem\Profiles\Outlooka0d020000000000c000000000000046 0003022b bin:BwAAAA==
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows
NT\CurrentVersion\Windows Messaging
Subsystem\Profiles\Outlooka0d020000000000c000000000000046 0003031f bin:BwAAAA==
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows
NT\CurrentVersion\Windows Messaging
Subsystem\Profiles\Outlooka0d020000000000c000000000000046 00030398 bin:AQAAAA==
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows
NT\CurrentVersion\Windows Messaging
Subsystem\Profiles\Outlooka0d020000000000c000000000000046 101f031e
bin:CgAAACwAAABOAAAAVgAAAGYA[output cut]=
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows
NT\CurrentVersion\Windows Messaging
Subsystem\Profiles\Outlooka0d020000000000c000000000000046 1102022a
bin:CgAAAMQAAABUAAAAxAAAABgBAADEAAA[output cut]==
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows\CurrentVersion\
Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
HRZR_EHACNGU bin:rAAAAFMXAABw0b/DmmPHAQ==
REG DELETED! HKU S-1-5-21-682003330-412668190-2146912999-1003\Software\Microsoft\Windows\CurrentVersion\
Internet Settings\Connections SavedLegacySettings
bin:RgAAACosAAABAAAAAAAAAAAA[output cut]
Note: The sreensaver is not installed at this point only the registration is activated.
I dont see anything nasty though I'm not yet a expert at reading thease yet, I expect all those other unrelated entries must have been added the various things I had running during the analize
The file is located on my T partition and I've cut short some some of the long strings.
If you want to see the Zsoft log of "after installing the screensaver" let me know and i'll dig it up.