Help - Search - Members - Calendar
Full Version: Seeking help with bad virus,IE redirects,file access removed,etc.
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive HijackThis Logs
Bowtie41
Hello,
I am seeking help for an apparent virus I cannot get rid of.It so far has the Google redirects,all pop ups and in window ads are for Vimaxx or something like that.When I did a search for the ads a few weeks ago,it led me to this forum,so I'm hoping you can help.Other things the virus has done is made my java not work right so my paid subscription to pogo.com is worthless(I have uninstalled/reinstalled java,and cleared cache countless times).I cannot goto certain websites,like my site for controlling my internet router(so now I can't turn wireless,etc. off/on).It has taken my folders for cookies,recent,start menu,my documents,etc. and changed them to shortcuts that when I try to open them give me the message"location not accessible,access is denied".A week or so ago,the PC got to where it wouldn't boot,as soon as the desktop showed,it would crash and try to reboot.After about 20 tries I would give up,and let it go into safe mode with networking so I could at least read my mail.In the last week it has been loading normally,until I tried installing Hijack this again tonight.I have DSL from ATT and used the AT&T Internet Security Suite powered by McAfee®.It never caught anything.I have been able to uninstall it,and installed ad-aware and am using Windows firewall,but I'd like to go back to the ATT/Yahoo suite when this is all over.Per the IMPORTANT: Before You Post Read This!, First Steps to do before posting your topic,I have so far downloaded and ran System restore point,downloaded and ran ERUNT.Every time I try to run HiJackThis,my system crashes(BSOD),and it takes about 9-10 reboots before it will come back again.I tried twice tonight to run it from the link provided,and it crashed.Both times it took about 1/4-1/2 hr before it would come back around.I finally saved the installer program to my desktop,but twice when I tried to run it,....crash,swear,walk away for awhile til it reboots,try again.One point of note,when it does crash and reboot,it gets as far as the welcome screen,then shows my desktop,and as it's loading,and starting to show icons in the taskbar,is when it crashes.However,it doesn't always crash at the same point.Sometimes,the desktop shows only for a second or to,and at other times,it will load almost all the icons(15-20 seconds),before the crash.A couple weeks ago,I tried all this before posting here,and the installer seemed to work,it put shortcut on desktop,but they do nothing and don't show up in installed program list,so today,I've been trying all evening to get it to work to no avail.As a side note,after reading lots of posts here,I took advice and uninstalled p2p software I hadn't used in awhile(limewire,utorrent,etc.).Also,after reading lots of posts,I didn't want to try to run DDS,GMER,Combofix,etc. without being told to do so because,quite frankly,I don't know what I'm doing,lol.Sorry this so long winded,but after reading all the help you have done others,I'm hoping you can do the same for me.Thank You.
P.S.
Forgot to add,I was able to run ad-aware scan and remove some cookies.The dashboard for ad-aware says Web Update Status:OK,but the date stamp for the last update is blank.Whenever I try to get the latest update,I get the error"Connection Error,check your settings"
Bowtie41
Hello,
I waited 8 days to hopefully get some help.Can somebody please recommend me a place to start?Thank You in advance for your help.Kirk
Bowtie41
I have run DDS and GMER in hopes of getting help with this malware.
Here is the DDS log:


DDS (Ver_09-07-30.01) - NTFSx86
Run by Kirk at 8:23:30.90 on Tue 09/01/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.959.375 [GMT -5:00]

SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Users\Kirk\Downloads\1695.dvb.pc.4.4.3\Zune\ZuneLauncher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\system32\IoctlSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\taskeng.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Kirk\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://att.my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Live TV Toolbar: {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - c:\program files\live_tv\tbLive.dll
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Live TV Toolbar: {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - c:\program files\live_tv\tbLive.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll
TB: Live TV Toolbar: {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - c:\program files\live_tv\tbLive.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [Zinio DLM] c:\program files\zinio\ZinioReader.exe /autostart
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Zune Launcher] "c:\users\kirk\downloads\1695.dvb.pc.4.4.3\zune\ZuneLauncher.exe"
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [AmazonGSDownloaderTray] c:\program files\amazon\amazon games & software downloader\AmazonGSDownloaderTray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\users\kirk\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\server~1.lnk - c:\program files\technisat dvb\bin\Server4PC.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: electronicarts.com
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: pogo.com
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {588031A3-94BF-4CDD-86D0-939F6F93910F} - hxxps://fixit.support.microsoft.com/ActiveX/FixItClient.CAB
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} - hxxps://offers.e-centives.com/cif/download/bin/actxcab.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game13.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
TCP: NameServer = 85.255.112.19,85.255.112.120
TCP: {2546DED6-C367-4202-9013-30245EDB0A0E} = 85.255.112.19,85.255.112.120
TCP: {58C5F947-D101-42C2-B9E6-F88196B0567A} = 85.255.112.19,85.255.112.120

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-8-3 64160]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2008-11-24 29263712]
S2 Amazon Download Agent;Amazon Download Agent;c:\program files\amazon\amazon games & software downloader\AmazonGSDownloaderService.exe [2009-2-6 317440]
S2 gupdate1c98590c9c1b434;Google Update Service (gupdate1c98590c9c1b434);c:\program files\google\update\GoogleUpdate.exe [2009-2-2 133104]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
S3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\drivers\SkyNET.sys [2008-6-9 418832]

=============== Created Last 30 ================

2009-08-11 20:18 <DIR> --d----- c:\users\kirk\appdata\roaming\TechSmith
2009-08-11 19:02 <DIR> --d----- c:\programdata\TechSmith
2009-08-11 19:00 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-08-11 10:57 <DIR> --d----- c:\users\kirk\appdata\roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-08-04 14:23 2,560 a------- c:\windows\_MSRSTRT.EXE
2009-08-04 13:57 <DIR> --d----- c:\program files\Live_TV
2009-08-04 13:57 <DIR> --d----- c:\program files\Conduit
2009-08-04 08:03 <DIR> --d----- c:\program files\Trend Micro
2009-08-04 00:19 15,688 a------- c:\windows\system32\lsdelete.exe
2009-08-03 20:37 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-08-03 20:27 <DIR> -cd-h--- c:\programdata\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-03 20:27 <DIR> -cd-h--- c:\progra~2\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-03 20:27 <DIR> --d----- c:\programdata\Lavasoft
2009-08-03 20:27 <DIR> --d----- c:\program files\Lavasoft

==================== Find3M ====================

2009-08-20 01:19 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-21 00:21 172,912 a---h--- c:\windows\system32\mlfcache.dat
2009-07-19 21:30 4,096 a------- c:\windows\d3dx.dat
2009-07-16 18:36 3,277 a------- C:\awFLEXLM.dat
2009-07-16 16:37 466,944 a------- c:\windows\system32\BSTIEPrintCtl1.dll
2009-06-17 20:43 51,200 a------- c:\windows\inf\infpub.dat
2009-06-17 20:43 86,016 a------- c:\windows\inf\infstrng.dat
2009-06-17 20:43 86,016 a------- c:\windows\inf\infstor.dat
2009-06-15 10:24 156,672 a------- c:\windows\system32\t2embed.dll
2009-06-15 10:20 72,704 a------- c:\windows\system32\fontsub.dll
2009-06-15 10:20 10,240 a------- c:\windows\system32\dciman32.dll
2009-06-15 07:52 289,792 a------- c:\windows\system32\atmfd.dll
2009-03-05 01:01 174 a--sh--- c:\program files\desktop.ini
2008-10-03 12:10 473,823 a--sh--- c:\users\kirk\css.exe
2008-10-03 12:10 100,775 a--sh--- c:\users\kirk\sccs.exe
2008-10-03 12:10 10,961 a--sh--- c:\users\kirk\MediaTubeCodec_ver1.1463.0.exe
2008-07-26 23:19 665,600 a------- c:\windows\inf\drvindex.dat
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib409\perfi.dat
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib409\perfh.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib409\perfd.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib409\perfc.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib00\perfi.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib00\perfh.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib00\perfd.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib00\perfc.dat
2009-05-21 23:26 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-05-21 23:26 32,768 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-05-21 23:26 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat

============= FINISH: 8:26:04.85 ===============


And here is the GMER log:

GMER 1.0.15.15077 [71tof4ny.exe] - http://www.gmer.net
Rootkit scan 2009-09-01 12:45:25
Windows 6.0.6001 Service Pack 1


---- System - GMER 1.0.15 ----

Code 851FC270 ZwEnumerateKey
Code 854EA190 ZwFlushInstructionCache
Code 84DCB59D IofCallDriver
Code 85134286 IofCompleteRequest
Code 84D2C355 ZwSaveKey
Code 84DCB405 ZwSaveKeyEx

---- Kernel code sections - GMER 1.0.15 ----

.text ntoskrnl.exe!IofCallDriver 81C4C169 5 Bytes JMP 84DCB5A2
.text ntoskrnl.exe!IofCompleteRequest 81C4C1D6 5 Bytes JMP 8513428B
.text ntoskrnl.exe!ZwSaveKey 81C5C5A4 5 Bytes JMP 84D2C35A
.text ntoskrnl.exe!ZwSaveKeyEx 81C5C5B8 5 Bytes JMP 84DCB40A

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Internet Explorer\iexplore.exe[5104] USER32.dll!DialogBoxIndirectParamW 75E1BD25 5 Bytes JMP 71DD5BD3 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5104] USER32.dll!DialogBoxParamW 75E31FD5 5 Bytes JMP 71DD5B5D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5104] USER32.dll!DialogBoxParamA 75E580B2 5 Bytes JMP 71DD5B98 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5104] USER32.dll!DialogBoxIndirectParamA 75E583DD 5 Bytes JMP 71DD5C0E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5104] USER32.dll!MessageBoxIndirectA 75E6D471 5 Bytes JMP 71DD5B19 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5104] USER32.dll!MessageBoxIndirectW 75E6D56B 5 Bytes JMP 71DD5AD5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5104] USER32.dll!MessageBoxExA 75E6D5D1 5 Bytes JMP 71DD5A9B C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5104] USER32.dll!MessageBoxExW 75E6D5F5 5 Bytes JMP 71DD5A61 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [744B7BA4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [744F98C5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [744BD3C8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [744AF527] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [744B7599] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [744AE43D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [744EB33D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [744BD68A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [744B012E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [744B0095] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [744A71F3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7453D802] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [744D75E1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [744ADAE1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [744A668F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [744A66BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [744B1E45] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\tdx \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Services - GMER 1.0.15 ----

Service C:\Windows\system32\drivers\ESQULinemrubsscmrshtrxoqcraxiefprptji.sys (*** hidden *** ) [SYSTEM] ESQULserv.sys <-- ROOTKIT !!!

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\ESQULserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ESQULserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ESQULserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ESQULserv.sys@imagepath \systemroot\system32\drivers\ESQULinemrubsscmrshtrxoqcraxiefprptji.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ESQULserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\ESQULserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\ESQULserv.sys\modules@ESQULserv \\?\globalroot\systemroot\system32\drivers\ESQULinemrubsscmrshtrxoqcraxiefprptji.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ESQULserv.sys\modules@ESQULl \\?\globalroot\systemroot\system32\ESQULpiqbtppqqspxxuhdvceldxtiohostngb.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ESQULserv.sys\modules@ESQULclk \\?\globalroot\systemroot\system32\ESQULennmudemmcwisyadqsoempnqnikirmbh.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ESQULserv.sys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ESQULserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\ESQULserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\ESQULserv.sys@imagepath \systemroot\system32\drivers\ESQULinemrubsscmrshtrxoqcraxiefprptji.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ESQULserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\ESQULserv.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ESQULserv.sys\modules@ESQULserv \\?\globalroot\systemroot\system32\drivers\ESQULinemrubsscmrshtrxoqcraxiefprptji.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ESQULserv.sys\modules@ESQULl \\?\globalroot\systemroot\system32\ESQULpiqbtppqqspxxuhdvceldxtiohostngb.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ESQULserv.sys\modules@ESQULclk \\?\globalroot\systemroot\system32\ESQULennmudemmcwisyadqsoempnqnikirmbh.dll

---- Files - GMER 1.0.15 ----

File C:\Windows\System32\ESQULennmudemmcwisyadqsoempnqnikirmbh.dll 57344 bytes executable
File C:\Windows\System32\ESQULpiqbtppqqspxxuhdvceldxtiohostngb.dll 23552 bytes executable
File C:\Windows\System32\ESQULzcounter 4 bytes
File C:\Windows\System32\drivers\ESQULinemrubsscmrshtrxoqcraxiefprptji.sys 83968 bytes <-- ROOTKIT !!!

---- EOF - GMER 1.0.15 ----

The attatch.txt is also attatched.


I'm still unable to run HJT,it just crashes like before.
Can someone please help me?
Blade81
Hello Kirk,


Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.

Please continue as follows:
  1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  2. Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds.txt log.


A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
Bowtie41
Blade81,
First let me say Thank You for helping me,I've seen you do good for lots of people here!
I was going to download and run the Combofix tool,and then I remembered seeing lots of people getting help in this forum being told to rename the Combofix file to "Combo-Fix" as it was downloaded,and was wondering if I should do the same before proceeding.I didn't see it in your post,or in the instruction page,and figured I better check with you.I would rather be safe than sorry.Thank You again,and i await your reply!
Kirk
Blade81
Yes, you may rename it first smile.gif
Bowtie41
Blade81,
I downloaded Combofix.When it was 99% done,a little window popped up saying it was copying a file called ZLFOID,or something similar(It closed before I could write it down).I thought maybe it was just copying the Combofix icon to the desktop,but wanted to make sure it had nothing to do with my malware,or if this was normal.I will run the Combofix in the morning,and post the logs,I have family things to do tonight.Thank You once again for all you do!
Kirk
Blade81
Yes, just let ComboFix run. I'll wait for the logs smile.gif
Bowtie41
Well,
I'm on my laptop now.I ran combofix.When it first started,it had a little popup saying it couldn't find some file,but it eventually started running anyway.Partway through,I got a popup window showing Rootkit!!,and to write them down.They are as follows:

C:\Windows\System32\ESQULpiqbtppqqspxxuhdvceldxtiohostngb.dll

C:\Windows\System32\drivers\ESQULinemrubsscmrshtrxoqcraxiefprptji.sys

C:\Windows\System32\ESQULennmudemmcwisyadqsoempnqnikirmbh.dll

C:\Windows\system32\drivers\ESQULinemrubsscmrshtrxoqcraxiefprptji.sys

C:\Windows\system32\ESQULpiqbtppqqspxxuhdvceldxtiohostngb.dll

C:\Windows\system32\ESQULennmudemmcwisyadqsoempnqnikirmbh.dll

I wrote them down and let Combofix do it's thing.When it rebooted,I got a popup saying:
"Error!! Launch ERUNT Failed".

I waited about 1/2 hr,then clicked on OK.After a while,it created the log.
When I tried to launch my web browser,I got a popup stating:
C:\Program Files\Internet Explorer\iexplore.exe
"Illegal operation attempted on a registry key that has been marked for deletion"

When I tried to rerun DDS,or anything else,I get the same type of error message.
I didn't want to manually reboot or do anything else until I get a response from you,so I'm leaving it as is.

Hope this helps and Thank You!
Kirk
Blade81
Hi,

Reboot and see if you still get that error.
Bowtie41
I'm back on my desktop now.I happened to wake up early and decided to see if it was still giving errors or if I needed to reboot,and IE and DDS opened just fine.I don't think it rebooted during the night,but it may have.
Here is the Combofix log,and the new DDS logs.Thank You!



Combofix Log:

ComboFix 09-09-05.02 - Kirk 09/05/2009 18:01.1.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.959.191 [GMT -5:00]
Running from: c:\users\Kirk\Desktop\Combo-Fix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\users\Kirk\AppData\Roaming\PCenter
c:\users\Kirk\AppData\Roaming\PCenter\dbases\cg.dat
c:\users\Kirk\AppData\Roaming\PCenter\dbases\mw.dat
c:\users\Kirk\AppData\Roaming\PCenter\dbases\rd.dat
c:\users\Kirk\AppData\Roaming\PCenter\dbases\sc.dat
c:\users\Kirk\AppData\Roaming\PCenter\dbases\sm.dat
c:\users\Kirk\AppData\Roaming\PCenter\dbases\sp.dat
c:\users\Kirk\AppData\Roaming\PCenter\keys\cg.key
c:\users\Kirk\AppData\Roaming\PCenter\keys\rd.key
c:\users\Kirk\AppData\Roaming\PCenter\keys\sc.key
c:\users\Kirk\AppData\Roaming\PCenter\keys\sp.key
c:\users\Kirk\AppData\Roaming\PCenter\temp\settings.ini
c:\users\Kirk\AppData\Roaming\PCenter\temp\spfilter
c:\windows\system32\BSTIEPrintCtl1.dll
c:\windows\system32\drivers\ESQULinemrubsscmrshtrxoqcraxiefprptji.sys
c:\windows\System32\ESQULennmudemmcwisyadqsoempnqnikirmbh.dll
c:\windows\system32\ESQULpiqbtppqqspxxuhdvceldxtiohostngb.dll
c:\windows\system32\ESQULzcounter
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_ESQULserv.sys
-------\Service_SKYNET
-------\Legacy_ESQULserv.sys
-------\Legacy_SKYNET


((((((((((((((((((((((((( Files Created from 2009-08-05 to 2009-09-05 )))))))))))))))))))))))))))))))
.

2009-09-05 23:13 . 2009-09-05 23:16 -------- d-----w- c:\users\Kirk\AppData\Local\temp
2009-09-05 23:13 . 2009-09-05 23:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-08-20 06:19 . 2009-08-20 06:19 -------- d-----w- c:\program files\Java
2009-08-18 21:34 . 2009-08-18 21:34 -------- d-----w- c:\program files\ERUNT
2009-08-17 11:05 . 2009-08-17 11:05 -------- d-----w- c:\users\Kirk\AppData\Local\Live_TV
2009-08-12 01:18 . 2009-08-12 01:18 -------- d-----w- c:\users\Kirk\AppData\Roaming\TechSmith
2009-08-12 00:02 . 2009-08-12 00:02 -------- d-----w- c:\programdata\TechSmith
2009-08-12 00:02 . 2009-08-12 00:02 -------- d-----w- c:\users\Kirk\AppData\Local\TechSmith
2009-08-12 00:02 . 2009-08-12 00:02 -------- d-----w- c:\program files\TechSmith
2009-08-12 00:00 . 2009-08-12 00:00 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-11 15:57 . 2009-08-11 15:57 -------- d-----w- c:\users\Kirk\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-08-11 15:56 . 2009-08-11 15:56 -------- d-----w- c:\program files\Common Files\Adobe AIR

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-05 23:16 . 2008-07-11 04:44 1356 ----a-w- c:\users\Kirk\AppData\Local\d3d9caps.dat
2009-09-05 20:12 . 2008-08-15 21:03 -------- d-----w- c:\users\Kirk\AppData\Roaming\ContentGuard
2009-09-05 06:15 . 2009-02-02 23:44 -------- d-----w- c:\programdata\Google Updater
2009-08-20 06:19 . 2008-12-19 10:49 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-17 11:05 . 2009-08-04 18:57 -------- d-----w- c:\program files\Live_TV
2009-08-17 11:05 . 2009-08-04 18:57 -------- d-----w- c:\program files\Conduit
2009-08-12 05:40 . 2008-10-13 16:08 -------- d-----w- c:\users\Kirk\AppData\Roaming\GetRightToGo
2009-08-12 05:19 . 2008-10-13 20:46 -------- d-----w- c:\programdata\Microsoft Help
2009-08-04 19:23 . 2009-08-04 19:23 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-08-04 13:03 . 2009-08-04 13:03 -------- d-----w- c:\program files\Trend Micro
2009-08-04 01:37 . 2009-08-04 01:27 -------- d-----w- c:\programdata\Lavasoft
2009-08-04 01:27 . 2009-08-04 01:27 -------- dc-h--w- c:\programdata\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-04 01:27 . 2009-08-04 01:27 -------- d-----w- c:\program files\Lavasoft
2009-08-03 23:12 . 2009-03-05 00:07 -------- d-----w- c:\programdata\McAfee
2009-08-03 23:12 . 2009-03-18 00:54 -------- d-----w- c:\program files\Common Files\McAfee
2009-08-03 23:11 . 2009-03-18 00:53 -------- d-----w- c:\program files\McAfee
2009-08-03 19:42 . 2008-08-08 23:12 -------- d-----w- c:\program files\Coupons
2009-07-21 05:21 . 2008-07-31 07:31 172912 ---ha-w- c:\windows\system32\mlfcache.dat
2009-07-20 02:30 . 2009-07-20 02:30 4096 ----a-w- c:\windows\d3dx.dat
2009-07-20 02:27 . 2009-07-20 02:27 552 ----a-w- c:\users\Kirk\AppData\Local\d3d8caps.dat
2009-07-20 02:26 . 2009-02-06 15:23 -------- d-----w- c:\program files\The Price Is Right
2009-07-16 23:36 . 2009-07-16 23:35 3277 ----a-w- C:\awFLEXLM.dat
2009-07-16 05:12 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-16 04:28 . 2009-07-16 04:28 -------- d-----w- c:\users\Kirk\AppData\Roaming\Autodesk
2009-07-16 03:32 . 2009-07-16 02:37 -------- d-----w- c:\program files\Autodesk
2009-07-16 03:14 . 2009-07-16 02:37 -------- d-----w- c:\program files\Common Files\Alias Shared
2009-07-16 03:12 . 2009-07-16 03:12 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2009-07-03 14:49 . 2009-08-04 01:37 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-03 14:49 . 2009-08-04 05:19 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-27 18:12 . 2008-07-11 04:45 104248 ----a-w- c:\users\Kirk\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-15 15:24 . 2009-07-15 10:49 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 15:20 . 2009-07-15 10:49 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 15:20 . 2009-07-15 10:49 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:52 . 2009-07-15 10:49 289792 ----a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zinio DLM"="c:\program files\Zinio\ZinioReader.exe" [2008-07-08 3874886]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Zune Launcher"="c:\users\Kirk\Downloads\1695.dvb.pc.4.4.3\Zune\ZuneLauncher.exe" [2008-11-10 157312]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"AmazonGSDownloaderTray"="c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-02-02 246272]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-25 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-20 149280]

c:\users\Kirk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Server4PC.lnk - c:\program files\TechniSat DVB\bin\Server4PC.exe [2008-7-11 338448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E6B77BCC-89C6-466A-9985-8446164FBFE9}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C2C61E87-73E6-4C7F-8432-813998F6F46E}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{BD42AE93-415F-4E1A-BA9E-36C363AB003A}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{6EB61C02-E80B-4035-A7DF-EF56EACB465A}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{4FAB8BC1-ADA5-4B47-A3F8-C69C6CC622AA}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{EDB07C8F-B1A2-4C7F-B34F-640B79BAAA79}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{B30CC371-7C9E-48F0-AB4A-140F20358DA4}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{CB829BD1-BC37-41A2-AB22-15718DBE33B4}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{4E6DC5CE-F86D-463D-BE06-D1CDBDE941BC}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D2D5F2E2-4D0E-4388-9BE7-E645DFE1A6A2}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{C48E482A-A1F4-43FD-95C7-4954D34F1FF6}c:\\done\\done\\tmd-recruit.5.1\\mirc.exe"= UDP:c:\done\done\tmd-recruit.5.1\mirc.exe:mIRC
"UDP Query User{70D64D7E-0509-4D9F-AF5B-9EAF022E2207}c:\\done\\done\\tmd-recruit.5.1\\mirc.exe"= TCP:c:\done\done\tmd-recruit.5.1\mirc.exe:mIRC
"TCP Query User{B6DC8950-31AF-4945-A892-0E4F0E52DEDA}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{E7200DC0-AE53-409E-94AC-2CDB8A32D32B}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [8/3/2009 8:37 PM 64160]
R2 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2/6/2009 9:10 AM 317440]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712]
S2 gupdate1c98590c9c1b434;Google Update Service (gupdate1c98590c9c1b434);c:\program files\Google\Update\GoogleUpdate.exe [2/2/2009 6:48 PM 133104]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
.
Contents of the 'Scheduled Tasks' folder

2009-09-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]

2009-09-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-02 09:12]

2009-09-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-02 23:48]

2009-09-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-02 23:48]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://att.my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: electronicarts.com
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: pogo.com
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game13.zylom.com/activex/zylomgamesplayer.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-05 18:16
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Kontiki\KService.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\System32\IoctlSvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-09-05 18:25 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-05 23:25

Pre-Run: 13,316,952,064 bytes free
Post-Run: 13,777,940,480 bytes free

208 --- E O F --- 2009-07-16 05:13


And The New DDS Log:



DDS (Ver_09-07-30.01) - NTFSx86
Run by Kirk at 6:48:26.43 on Sun 09/06/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.959.400 [GMT -5:00]

SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\system32\IoctlSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Users\Kirk\Downloads\1695.dvb.pc.4.4.3\Zune\ZuneLauncher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Kirk\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://att.my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Live TV Toolbar: {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - c:\program files\live_tv\tbLive.dll
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Live TV Toolbar: {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - c:\program files\live_tv\tbLive.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll
TB: Live TV Toolbar: {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - c:\program files\live_tv\tbLive.dll
uRun: [Zinio DLM] c:\program files\zinio\ZinioReader.exe /autostart
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Zune Launcher] "c:\users\kirk\downloads\1695.dvb.pc.4.4.3\zune\ZuneLauncher.exe"
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [AmazonGSDownloaderTray] c:\program files\amazon\amazon games & software downloader\AmazonGSDownloaderTray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\users\kirk\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\server~1.lnk - c:\program files\technisat dvb\bin\Server4PC.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: electronicarts.com
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: pogo.com
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {588031A3-94BF-4CDD-86D0-939F6F93910F} - hxxps://fixit.support.microsoft.com/ActiveX/FixItClient.CAB
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game13.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-8-3 64160]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2008-11-24 29263712]
S2 Amazon Download Agent;Amazon Download Agent;c:\program files\amazon\amazon games & software downloader\AmazonGSDownloaderService.exe [2009-2-6 317440]
S2 gupdate1c98590c9c1b434;Google Update Service (gupdate1c98590c9c1b434);c:\program files\google\update\GoogleUpdate.exe [2009-2-2 133104]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]

=============== Created Last 30 ================

2009-09-06 03:07 2,048 a------- c:\windows\system32\tzres.dll
2009-09-05 20:11 313,344 a------- c:\windows\system32\wmpdxm.dll
2009-09-05 20:11 7,680 a------- c:\windows\system32\spwmp.dll
2009-09-05 20:11 4,096 a------- c:\windows\system32\msdxm.ocx
2009-09-05 20:11 4,096 a------- c:\windows\system32\dxmasf.dll
2009-09-05 20:11 8,147,456 a------- c:\windows\system32\wmploc.DLL
2009-09-05 20:11 43,520 a------- c:\windows\system32\msdxm.tlb
2009-09-05 20:11 18,432 a------- c:\windows\system32\amcompat.tlb
2009-09-05 20:11 28,672 a------- c:\windows\system32\Apphlpdm.dll
2009-09-05 20:11 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-05 18:23 <DIR> --dsh--- C:\$RECYCLE.BIN
2009-09-05 17:37 230,912 a------- c:\windows\PEV.exe
2009-09-05 17:37 161,792 a------- c:\windows\SWREG.exe
2009-09-05 17:37 98,816 a------- c:\windows\sed.exe
2009-08-11 20:18 <DIR> --d----- c:\users\kirk\appdata\roaming\TechSmith
2009-08-11 19:02 <DIR> --d----- c:\programdata\TechSmith
2009-08-11 19:00 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-08-11 10:57 <DIR> --d----- c:\users\kirk\appdata\roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

==================== Find3M ====================

2009-08-28 07:39 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 07:38 2,153,984 a------- c:\windows\apppatch\AcGenral.dll
2009-08-28 07:38 541,696 a------- c:\windows\apppatch\AcLayers.dll
2009-08-28 07:38 459,776 a------- c:\windows\apppatch\AcSpecfc.dll
2009-08-20 01:19 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-04 14:23 2,560 a------- c:\windows\_MSRSTRT.EXE
2009-07-21 00:21 172,912 a---h--- c:\windows\system32\mlfcache.dat
2009-07-19 21:30 4,096 a------- c:\windows\d3dx.dat
2009-07-18 11:06 827,904 a------- c:\windows\system32\wininet.dll
2009-07-18 11:01 78,336 a------- c:\windows\system32\ieencode.dll
2009-07-18 04:46 26,624 a------- c:\windows\system32\ieUnatt.exe
2009-07-17 09:35 71,680 a------- c:\windows\system32\atl.dll
2009-07-16 18:36 3,277 a------- C:\awFLEXLM.dat
2009-07-03 09:49 15,688 a------- c:\windows\system32\lsdelete.exe
2009-06-17 20:43 51,200 a------- c:\windows\inf\infpub.dat
2009-06-17 20:43 86,016 a------- c:\windows\inf\infstrng.dat
2009-06-17 20:43 86,016 a------- c:\windows\inf\infstor.dat
2009-06-15 10:24 156,672 a------- c:\windows\system32\t2embed.dll
2009-06-15 10:20 72,704 a------- c:\windows\system32\fontsub.dll
2009-06-15 10:20 10,240 a------- c:\windows\system32\dciman32.dll
2009-06-15 07:52 289,792 a------- c:\windows\system32\atmfd.dll
2009-06-10 07:12 160,256 a------- c:\windows\system32\wkssvc.dll
2009-06-10 07:07 91,136 a------- c:\windows\system32\avifil32.dll
2009-03-05 01:01 174 a--sh--- c:\program files\desktop.ini
2008-10-03 12:10 473,823 a--sh--- c:\users\kirk\css.exe
2008-10-03 12:10 100,775 a--sh--- c:\users\kirk\sccs.exe
2008-10-03 12:10 10,961 a--sh--- c:\users\kirk\MediaTubeCodec_ver1.1463.0.exe
2008-07-26 23:19 665,600 a------- c:\windows\inf\drvindex.dat
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib409\perfi.dat
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib409\perfh.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib409\perfd.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib409\perfc.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib00\perfi.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib00\perfh.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib00\perfd.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib00\perfc.dat
2009-05-21 23:26 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-05-21 23:26 32,768 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-05-21 23:26 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat

============= FINISH: 6:49:35.56 ===============




The New Attach is compressed and attatched.Thank You so much!
Blade81
Hi,

Please go to control panel and "programs and features" there. Check if Uninstall option appears for each entry on your installed programs list (highlight entry and see if there's uninstall option visible for it. Repeat for each entry on the list).
Bowtie41
You are correct,the uninstall,etc. were missing biggrin.gif .I went ahead and rebooted from last night and looked again.They are all still unable to uninstall/change/repair except for the following:

Microsoft Silverlight shows it is able to uninstall,change,and repair.

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 shows it is able to uninstall only.


On the reboot,it showed a list of updates that were done yesterday.I thought you might want to see those too since the one for SP2 failed.They are: (I took the colons out of the hyperlinks to disable them)

Windows Vista Service Pack 2 (KB948465)
Installation date: ‎9/‎5/‎2009 5:31 PM
Installation status: Failed
Error details: Code 80072EFD
Update type: Important
Windows Vista Service Pack 2 is an update to Windows Vista that includes all of the updates that have been delivered since Service Pack 1, as well as support for new types of hardware and emerging hardware standards. After you install this item, you may have to restart your computer. This update is provided to you and licensed under the Windows Vista License Terms.
More information:
http//support.microsoft.com/kb/948465
Help and Support:
http//technet.microsoft.com/en-us/windows/dd767387.aspx

Definition Update for Windows Defender - KB915597 (Definition 1.65.330.0)
Installation date: ‎9/‎5/‎2009 8:13 PM
Installation status: Successful
Update type: Important
Install this update to revise the definition files used to detect spyware and other potentially unwanted software. Once you have installed this item, it cannot be removed.
More information:
http//www.microsoft.com/athome/security/spyware/software/about/overview.mspx
Help and Support:
http//go.microsoft.com/fwlink/?LinkId=52661

Windows Malicious Software Removal Tool - August 2009 (KB890830)
Installation date: ‎9/‎6/‎2009 3:02 AM
Installation status: Successful
Update type: Important
After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product.
More information:
http//go.microsoft.com/fwlink/?LinkId=39987
Help and Support:
http//support.microsoft.com

Security Update for Microsoft Visual C++ 2008 Redistributable Package (KB973924)
Installation date: ‎9/‎6/‎2009 3:03 AM
Installation status: Successful
Update type: Important
A security issue has been identified that could allow an attacker to compromise your Windows-based system with Microsoft Visual C++ 2008 Redistributable Package and gain complete control over it. You can help protect your computer by installing this update from Microsoft. After you install this item, you may have to restart your computer.
More information:
http//go.microsoft.com/fwlink/?LinkID=158264
Help and Support:
http//support.microsoft.com

Update for Windows Mail Junk E-mail Filter [August 2009] (KB905866)
Installation date: ‎9/‎6/‎2009 3:03 AM
Installation status: Successful
Update type: Recommended
Install this update for Windows Mail to revise the definition files that are used to detect e-mail messages that should be considered junk e-mail or that may contain phishing content. After you install this item, you may have to restart your computer.
More information:
http//go.microsoft.com/fwlink/?LinkID=79015
Help and Support:
http//support.microsoft.com

Update for Windows Vista (KB972036)
Installation date: ‎9/‎6/‎2009 3:03 AM
Installation status: Successful
Update type: Recommended
Install this update to resolve issues with non-compatible applications for Windows Vista. For complete details of this update, see Knowledge Base Article KB972036. After you install this item, you may have to restart your computer.
More information:
http//support.microsoft.com/KB/972036
Help and Support:
http//support.microsoft.com

Security Update for Windows Vista (KB973540)
Installation date: ‎9/‎6/‎2009 3:04 AM
Installation status: Successful
Update type: Important
A security issue has been identified that could allow an unauthenticated remote attacker to compromise your system and gain control over it. You can help protect your system by installing this update from Microsoft. After you install this update, you may have to restart your system.
More information:
http//go.microsoft.com/fwlink/?LinkId=158695
Help and Support:
http//support.microsoft.com

Cumulative Security Update for Internet Explorer 7 for Windows Vista (KB972260)
Installation date: ‎9/‎6/‎2009 3:05 AM
Installation status: Successful
Update type: Important
Security issues have been identified that could allow an attacker to compromise a system that is running Microsoft Internet Explorer and gain control over it. You can help protect your system by installing this update from Microsoft. After you install this item, you may have to restart your computer. This update is provided to you and licensed under the Windows Vista License Terms.
More information:
http//go.microsoft.com/fwlink/?LinkId=158199
Help and Support:
http//support.microsoft.com

Update for Microsoft Silverlight (KB970363)
Installation date: ‎9/‎6/‎2009 3:05 AM
Installation status: Successful
Update type: Important
This update to Silverlight improves security and reliability, enhances graphical performance and creative effects, expands the range of supported media formats, broadens support for rich internet applications, and enables Silverlight applications to run outside of the browser. This update is backward compatible with web applications built in previous versions of Silverlight.
More information:
http//go.microsoft.com/fwlink/?LinkId=147308
Help and Support:
http//go.microsoft.com/fwlink/?LinkID=105787

Update for the 2007 Microsoft Office System (KB967642)
Installation date: ‎9/‎6/‎2009 3:05 AM
Installation status: Successful
Update type: Important
This update fixes an error that may occur when installing the Microsoft Office suite Service Packs.
More information:
http//www.microsoft.com/downloads/details.aspx?FamilyId=E93AB1BE-ADE6-4FF8-8637-DBD3EBE3C5C5&displaylang=en
Help and Support:
http//support.microsoft.com/?LN=en-us

Update for Microsoft Office Outlook 2007 Junk Email Filter (KB972691)
Installation date: ‎9/‎6/‎2009 3:06 AM
Installation status: Successful
Update type: Important
This update provides the Junk E-mail Filter in Microsoft Office Outlook 2007 with a more current definition of which e-mail messages should be considered junk e-mail.
More information:
http//support.microsoft.com/kb/972691
Help and Support:
http//support.microsoft.com/?LN=en-us

Security Update for Windows Vista (KB971557)
Installation date: ‎9/‎6/‎2009 3:06 AM
Installation status: Successful
Update type: Important
A security issue has been identified that could allow an unauthenticated remote attacker to compromise your system and gain control over it. You can help protect your system by installing this update from Microsoft. After you install this update, you may have to restart your system.
More information:
http//go.microsoft.com/fwlink/?LinkId=155975
Help and Support:
http//support.microsoft.com

Security Update for Windows Vista (KB956744)
Installation date: ‎9/‎6/‎2009 3:07 AM
Installation status: Successful
Update type: Important
A security issue has been identified that could allow an unauthenticated remote attacker to compromise your system and gain control over it. You can help protect your system by installing this update from Microsoft. After you install this update, you may have to restart your system.
More information:
http//go.microsoft.com/fwlink/?LinkID=157861
Help and Support:
http//support.microsoft.com

Security Update for Windows Vista (KB971657)
Installation date: ‎9/‎6/‎2009 3:07 AM
Installation status: Successful
Update type: Important
A security issue has been identified that could allow an authenticated remote attacker to compromise your system and gain control over it. You can help protect your system by installing this update from Microsoft. After you install this update, you may have to restart your system.
More information:
http//go.microsoft.com/fwlink/?LinkId=155977
Help and Support:
http//support.microsoft.com

Security Update for Windows Vista (KB973507)
Installation date: ‎9/‎6/‎2009 3:07 AM
Installation status: Successful
Update type: Important
A security issue has been identified that could allow an unauthenticated remote attacker to compromise your system and gain control over it. You can help protect your system by installing this update from Microsoft. After you install this update, you may have to restart your system.
More information:
http//go.microsoft.com/fwlink/?LinkId=158695
Help and Support:
http//support.microsoft.com

Update for Windows Vista (KB970653)
Installation date: ‎9/‎6/‎2009 3:09 AM
Installation status: Successful
Update type: Important
Install this update to resolve issues caused by revised daylight saving time and time zone laws in several countries. This update enables your computer to automatically adjust the computer clock on the correct date in 2009. After you install this item, you may have to restart your computer.
More information:
http//support.microsoft.com/KB/970653
Help and Support:
http//support.microsoft.com

Hopefully this will help you help me,lol.
Thank You Again!
Kirk
Blade81
Hi,

We have to take system back to the point where programs were still uninstallable.

Start button All Programs > Accessories > System Tools and start System Restore there.
"Choose a different restore point" and find point that is just before 09/05/2009 18:01 timestamp.
Bowtie41
Blade81,
The only 2 restore points available are:
9/6/2009 3:00:25AM and,
9/5/2009 8:13:06PM
both of which are after the time stamp you requested.
Should I go ahead and do the 9/5 at 20:13?

Thanks,
Kirk

Blade81
Hi,

Let's use another way to restore things back before ComboFix run.

Go to C:\WINDOWS\ERDNT\Hiv-backup folder and double-click erdnt.exe file there. Follow the instructions and reboot the system after operation is done.

After reboot, post fresh dds logs.
Bowtie41
Hi,
ERDNT ran,I rebooted,disabled Ad-Aware and Windows Firewall,and reran DDS.Here are the logs:
Thank You again so much!
Kirk


DDS (Ver_09-07-30.01) - NTFSx86
Run by Kirk at 15:51:31.14 on Mon 09/07/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.959.412 [GMT -5:00]

SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Users\Kirk\Downloads\1695.dvb.pc.4.4.3\Zune\ZuneLauncher.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\system32\IoctlSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Kirk\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://att.my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Live TV Toolbar: {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - c:\program files\live_tv\tbLive.dll
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Live TV Toolbar: {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - c:\program files\live_tv\tbLive.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll
TB: Live TV Toolbar: {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - c:\program files\live_tv\tbLive.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [Zinio DLM] c:\program files\zinio\ZinioReader.exe /autostart
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Zune Launcher] "c:\users\kirk\downloads\1695.dvb.pc.4.4.3\zune\ZuneLauncher.exe"
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [AmazonGSDownloaderTray] c:\program files\amazon\amazon games & software downloader\AmazonGSDownloaderTray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\users\kirk\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\server~1.lnk - c:\program files\technisat dvb\bin\Server4PC.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: electronicarts.com
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: pogo.com
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {588031A3-94BF-4CDD-86D0-939F6F93910F} - hxxps://fixit.support.microsoft.com/ActiveX/FixItClient.CAB
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game13.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
TCP: NameServer = 85.255.112.19,85.255.112.120
TCP: {2546DED6-C367-4202-9013-30245EDB0A0E} = 85.255.112.19,85.255.112.120
TCP: {58C5F947-D101-42C2-B9E6-F88196B0567A} = 85.255.112.19,85.255.112.120

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-8-3 64160]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2008-11-24 29263712]
S2 Amazon Download Agent;Amazon Download Agent;c:\program files\amazon\amazon games & software downloader\AmazonGSDownloaderService.exe [2009-2-6 317440]
S2 gupdate1c98590c9c1b434;Google Update Service (gupdate1c98590c9c1b434);c:\program files\google\update\GoogleUpdate.exe [2009-2-2 133104]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
S3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\drivers\SkyNET.sys [2008-6-9 418832]

=============== Created Last 30 ================

2009-09-07 02:44 499,712 a------- c:\windows\system32\kerberos.dll
2009-09-07 02:44 213,504 a------- c:\windows\system32\msv1_0.dll
2009-09-07 02:44 175,104 a------- c:\windows\system32\wdigest.dll
2009-09-07 02:44 1,256,448 a------- c:\windows\system32\lsasrv.dll
2009-09-07 02:44 270,848 a------- c:\windows\system32\schannel.dll
2009-09-07 02:44 439,896 a------- c:\windows\system32\drivers\ksecdd.sys
2009-09-07 02:44 72,704 a------- c:\windows\system32\secur32.dll
2009-09-07 02:44 9,728 a------- c:\windows\system32\lsass.exe
2009-09-06 03:07 2,048 a------- c:\windows\system32\tzres.dll
2009-09-05 20:11 313,344 a------- c:\windows\system32\wmpdxm.dll
2009-09-05 20:11 7,680 a------- c:\windows\system32\spwmp.dll
2009-09-05 20:11 4,096 a------- c:\windows\system32\msdxm.ocx
2009-09-05 20:11 4,096 a------- c:\windows\system32\dxmasf.dll
2009-09-05 20:11 8,147,456 a------- c:\windows\system32\wmploc.DLL
2009-09-05 20:11 43,520 a------- c:\windows\system32\msdxm.tlb
2009-09-05 20:11 18,432 a------- c:\windows\system32\amcompat.tlb
2009-09-05 20:11 28,672 a------- c:\windows\system32\Apphlpdm.dll
2009-09-05 20:11 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-05 18:23 <DIR> --dsh--- C:\$RECYCLE.BIN
2009-09-05 17:37 230,912 a------- c:\windows\PEV.exe
2009-09-05 17:37 161,792 a------- c:\windows\SWREG.exe
2009-09-05 17:37 98,816 a------- c:\windows\sed.exe
2009-08-11 20:18 <DIR> --d----- c:\users\kirk\appdata\roaming\TechSmith
2009-08-11 19:02 <DIR> --d----- c:\programdata\TechSmith
2009-08-11 19:00 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-08-11 10:57 <DIR> --d----- c:\users\kirk\appdata\roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

==================== Find3M ====================

2009-08-28 07:39 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 07:38 2,153,984 a------- c:\windows\apppatch\AcGenral.dll
2009-08-28 07:38 541,696 a------- c:\windows\apppatch\AcLayers.dll
2009-08-28 07:38 459,776 a------- c:\windows\apppatch\AcSpecfc.dll
2009-08-20 01:19 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-04 14:23 2,560 a------- c:\windows\_MSRSTRT.EXE
2009-07-21 00:21 172,912 a---h--- c:\windows\system32\mlfcache.dat
2009-07-19 21:30 4,096 a------- c:\windows\d3dx.dat
2009-07-18 11:06 827,904 a------- c:\windows\system32\wininet.dll
2009-07-18 11:01 78,336 a------- c:\windows\system32\ieencode.dll
2009-07-18 04:46 26,624 a------- c:\windows\system32\ieUnatt.exe
2009-07-17 09:35 71,680 a------- c:\windows\system32\atl.dll
2009-07-16 18:36 3,277 a------- C:\awFLEXLM.dat
2009-07-03 09:49 15,688 a------- c:\windows\system32\lsdelete.exe
2009-06-17 20:43 51,200 a------- c:\windows\inf\infpub.dat
2009-06-17 20:43 86,016 a------- c:\windows\inf\infstrng.dat
2009-06-17 20:43 86,016 a------- c:\windows\inf\infstor.dat
2009-06-15 10:24 156,672 a------- c:\windows\system32\t2embed.dll
2009-06-15 10:20 72,704 a------- c:\windows\system32\fontsub.dll
2009-06-15 10:20 10,240 a------- c:\windows\system32\dciman32.dll
2009-06-15 07:52 289,792 a------- c:\windows\system32\atmfd.dll
2009-06-10 07:12 160,256 a------- c:\windows\system32\wkssvc.dll
2009-06-10 07:07 91,136 a------- c:\windows\system32\avifil32.dll
2009-03-05 01:01 174 a--sh--- c:\program files\desktop.ini
2008-10-03 12:10 473,823 a--sh--- c:\users\kirk\css.exe
2008-10-03 12:10 100,775 a--sh--- c:\users\kirk\sccs.exe
2008-10-03 12:10 10,961 a--sh--- c:\users\kirk\MediaTubeCodec_ver1.1463.0.exe
2008-07-26 23:19 665,600 a------- c:\windows\inf\drvindex.dat
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib409\perfi.dat
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib409\perfh.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib409\perfd.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib409\perfc.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib00\perfi.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib00\perfh.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib00\perfd.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib00\perfc.dat
2009-05-21 23:26 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-05-21 23:26 32,768 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-05-21 23:26 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat

============= FINISH: 15:53:39.84 ===============
Blade81
Thanks for the logs. Time to create a new one smile.gif


Open notepad and then copy and paste the bolded lines below into it. Go to File > save as and name the file fixes.bat, change the Save as type to all files and save it to your desktop.
@echo off
SWREG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" /s >>Logit.txt
SWREG QUERY "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" /s >>Logit.txt

Double-click on fixes.bat file to execute it.

c:\Logit.txt file should exist after that batch run. Please, attach the file to your reply.
Bowtie41
Blade,
Thank You.Here is the Logit file:
Kirk


SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall
UninstallString REG_EXPAND_SZ "C:\Program Files\Uninstall.exe"
InstallLocation REG_EXPAND_SZ C:\Program Files
DisplayName REG_SZ
DisplayIcon REG_SZ C:\Program Files\Uninstall.exe,0

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Ad-Aware
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
NoRemove REG_DWORD 0 (0x0)
DisplayIcon REG_SZ C:\ProgramData\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
DisplayName REG_SZ Ad-Aware
UninstallString REG_SZ "C:\ProgramData\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
ModifyPath REG_SZ C:\ProgramData\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
Publisher REG_SZ Lavasoft
Contact REG_SZ
HelpLink REG_SZ http://www.lavasoft.com/support/supportcenter
URLUpdateInfo REG_SZ PRODUCTUPDATESLINK
Comments REG_SZ All rights reserved
InstallLocation REG_SZ C:\Program Files\Lavasoft\Ad-Aware

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\AddressBook

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Adobe AIR
DisplayIcon REG_SZ c:\PROGRA~1\COMMON~1\ADOBEA~1\Versions\1.0\RESOUR~1\ADOBEA~1.EXE
DisplayName REG_SZ Adobe AIR
DisplayVersion REG_SZ 1.5.0.7220
InstallLocation REG_SZ D:\
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Adobe Systems Inc.
UninstallString REG_SZ c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Adobe Flash Player ActiveX
DisplayName REG_SZ Adobe Flash Player 10 ActiveX
DisplayVersion REG_SZ 10.0.22.87
Publisher REG_SZ Adobe Systems Incorporated
URLInfoAbout REG_SZ http://www.adobe.com/go/getflashplayer
VersionMajor REG_SZ 10
VersionMinor REG_SZ 0
HelpLink REG_SZ http://www.adobe.com/go/flashplayer_support/
URLUpdateInfo REG_SZ http://www.adobe.com/go/flashplayer/
DisplayIcon REG_SZ C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
UninstallString REG_SZ C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
RequiresIESysFile REG_SZ 4.70.0.1155
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Adobe Shockwave Player
<NO NAME> REG_SZ
DisplayName REG_SZ Adobe Shockwave Player 11
UninstallString REG_SZ C:\Windows\system32\adobe\SHOCKW~1\UNWISE.EXE C:\Windows\system32\Adobe\SHOCKW~1\Install.log
DisplayVersion REG_SZ 11
Publisher REG_SZ Adobe Systems, Inc.
URLInfoAbout REG_SZ http://www.adobe.com
InstallLocation REG_SZ C:\Windows\system32\Adobe\
VersionMajor REG_DWORD 11 (0xb)
VersionMinor REG_DWORD 0 (0x0)
DisplayIcon REG_SZ C:\Windows\system32\Adobe\Shockwave 11\SwInit.exe,0
HelpLink REG_SZ http://www.adobe.com/support/shockwave
URLUpdateInfo REG_SZ http://www.adobe.com/software/shockwaveplayer/index.html

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Amazon Games & Software Downloader_is1
Inno Setup: Setup Version REG_SZ 5.1.9
Inno Setup: App Path REG_SZ C:\Program Files\Amazon\Amazon Games & Software Downloader
InstallLocation REG_SZ C:\Program Files\Amazon\Amazon Games & Software Downloader\
Inno Setup: Icon Group REG_SZ Amazon\Amazon Games & Software
Inno Setup: User REG_SZ Kirk
DisplayName REG_SZ Amazon Games & Software Downloader
DisplayIcon REG_SZ Resources\ico_a_installer.ico
UninstallString REG_SZ "C:\Program Files\Amazon\Amazon Games & Software Downloader\uninst\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\Amazon\Amazon Games & Software Downloader\uninst\unins000.exe" /SILENT
DisplayVersion REG_SZ 2.0.0.0
Publisher REG_SZ Amazon
URLInfoAbout REG_SZ http://www.amazon.com/GamesAndSoftwareDownloads/How/
HelpLink REG_SZ http://www.amazon.com/Help/GamesAndSoftwareDownloads/
URLUpdateInfo REG_SZ http://www.amazon.com/GamesAndSoftwareDownloads/Upgrade/
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20090206

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Amazon MP3 Downloader
DisplayName REG_SZ Amazon MP3 Downloader 1.0.3
UninstallString REG_SZ C:\Program Files\Amazon\MP3 Downloader\Uninstall.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Any DVD Converter for Zune_is1
Inno Setup: Setup Version REG_SZ 5.2.3
Inno Setup: App Path REG_SZ C:\Program Files\Any DVD Converter for Zune
InstallLocation REG_SZ C:\Program Files\Any DVD Converter for Zune\
Inno Setup: Icon Group REG_SZ Any DVD Converter for Zune
Inno Setup: User REG_SZ Kirk
Inno Setup: Selected Tasks REG_SZ
Inno Setup: Deselected Tasks REG_SZ desktopicon
DisplayName REG_SZ Any DVD Converter for Zune 3.7.1
UninstallString REG_SZ "C:\Program Files\Any DVD Converter for Zune\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\Any DVD Converter for Zune\unins000.exe" /SILENT
Publisher REG_SZ Any-DVD-Converter.com
URLInfoAbout REG_SZ http://www.any-dvd-converter.com/
HelpLink REG_SZ http://www.any-dvd-converter.com/
URLUpdateInfo REG_SZ http://www.any-dvd-converter.com/
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20090305

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Any Video Converter_is1
Inno Setup: Setup Version REG_SZ 5.2.3
Inno Setup: App Path REG_SZ C:\Program Files\Any Video Converter
InstallLocation REG_SZ C:\Program Files\Any Video Converter\
Inno Setup: Icon Group REG_SZ Any Video Converter
Inno Setup: User REG_SZ Kirk
Inno Setup: Selected Tasks REG_SZ desktopicon
Inno Setup: Deselected Tasks REG_SZ
DisplayName REG_SZ Any Video Converter 2.7.0
UninstallString REG_SZ "C:\Program Files\Any Video Converter\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\Any Video Converter\unins000.exe" /SILENT
Publisher REG_SZ Any-Video-Converter.com
URLInfoAbout REG_SZ http://www.any-video-converter.com/
HelpLink REG_SZ http://www.any-video-converter.com/
URLUpdateInfo REG_SZ http://www.any-video-converter.com/
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20090209

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Applian FLV Player2.0.24
DisplayName REG_SZ Applian FLV Player
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
UninstallString REG_SZ "C:\Windows\Applian FLV Player\uninstall.exe" "/U:C:\Program Files\FLV Player\Uninstall\uninstall.xml"
Publisher REG_SZ Applian Technologies Inc.
URLInfoAbout REG_SZ http://www.applian.com
HelpLink REG_SZ http://www.applian.com
Contact REG_SZ Applian Technologies Inc. Support Department
DisplayVersion REG_SZ 2.0.24
DisplayIcon REG_SZ "C:\Windows\Applian FLV Player\uninstall.exe"

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\AudibleManager
DisplayName REG_SZ AudibleManager
UninstallString REG_SZ C:\Program Files\Audible\Bin\Upgrade.exe /Uninstall
Publisher REG_SZ Audible, Inc.
DisplayVersion REG_SZ 4759644.48.2147311616.4759644

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\BFGC
UninstallString REG_SZ C:\Program Files\bfgclient\Uninstall.exe
DisplayName REG_SZ Big Fish Games Client

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Buildalot_is1
Inno Setup: Setup Version REG_SZ 5.2.3
Inno Setup: App Path REG_SZ C:\Program Files\Buildalot
InstallLocation REG_SZ C:\Program Files\Buildalot\
Inno Setup: Icon Group REG_SZ Amazon Games\Buildalot
Inno Setup: User REG_SZ Kirk
DisplayName REG_SZ Buildalot
DisplayIcon REG_SZ C:\Program Files\Buildalot\Buildalot.exe
UninstallString REG_SZ "C:\Program Files\Buildalot\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\Buildalot\unins000.exe" /SILENT
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20090206

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
DisplayIcon REG_SZ C:\Program Files\Adobe Media Player\Adobe Media Player.exe
DisplayName REG_SZ Adobe Media Player
DisplayVersion REG_SZ 1.1
InstallLocation REG_SZ C:\Program Files\Adobe Media Player\
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Adobe Systems Incorporated
UninstallString REG_SZ msiexec /qb /x {5C74694C-A687-E3EB-FF18-B018D4A76ECD}

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Connection Manager
SystemComponent REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\DirectDrawEx

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\DVBViewer_is1
Inno Setup: Setup Version REG_SZ 5.2.0
Inno Setup: App Path REG_SZ C:\Program Files\DVBViewerTE
InstallLocation REG_SZ C:\Program Files\DVBViewerTE\
Inno Setup: Icon Group REG_SZ TechniSat PVR
Inno Setup: User REG_SZ Kirk
Inno Setup: Selected Tasks REG_SZ quicklaunchicon
Inno Setup: Deselected Tasks REG_SZ desktopicon
DisplayName REG_SZ DVBViewer Technisat Edition
DisplayIcon REG_SZ C:\Program Files\DVBViewerTE\dvbviewer.exe
UninstallString REG_SZ "C:\Program Files\DVBViewerTE\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\DVBViewerTE\unins000.exe" /SILENT
Publisher REG_SZ CM&V
URLInfoAbout REG_SZ http://www.dvbviewer.com
HelpLink REG_SZ http://www.dvbviewer.com
URLUpdateInfo REG_SZ http://www.dvbviewer.com
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20080711

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\DXM_Runtime

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ERUNT_is1
Inno Setup: Setup Version REG_SZ 4.2.7
Inno Setup: App Path REG_SZ C:\Program Files\ERUNT
InstallLocation REG_SZ C:\Program Files\ERUNT\
Inno Setup: Icon Group REG_SZ ERUNT
Inno Setup: User REG_SZ Kirk
Inno Setup: Selected Tasks REG_SZ eruntdesktopicon,ntregoptdesktopicon
Inno Setup: Deselected Tasks REG_SZ eruntquicklaunchicon,ntregoptquicklaunchicon,installgermanlanguagefiles
DisplayName REG_SZ ERUNT 1.1j
UninstallString REG_SZ "C:\Program Files\ERUNT\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\ERUNT\unins000.exe" /SILENT
Publisher REG_SZ Lars Hederer
URLInfoAbout REG_SZ http://www.larshederer.homepage.t-online.de
HelpLink REG_SZ http://www.larshederer.homepage.t-online.de/erunt
URLUpdateInfo REG_SZ http://www.larshederer.homepage.t-online.de/erunt
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ffdshow_is1
Inno Setup: Setup Version REG_SZ 5.2.3
Inno Setup: App Path REG_SZ C:\Program Files\K-Lite Codec Pack\ffdshow
InstallLocation REG_SZ C:\Program Files\K-Lite Codec Pack\ffdshow\
Inno Setup: Icon Group REG_SZ ffdshow
Inno Setup: User REG_SZ Kirk
Inno Setup: Setup Type REG_SZ normal
Inno Setup: Selected Components REG_SZ ffdshow,ffdshow\vfw,ffdshow\plugins,ffdshow\plugins\avisynth,ffdshow\plugins\virtualdub,ffdshow\plugins\dscaler
Inno Setup: Deselected Components REG_SZ ffdshow\makeavis
Inno Setup: Selected Tasks REG_SZ video,video\divx,video\xvid,video\mpeg4,video\flv,video\h263,video\qt,video\wmv1,video\wmv2,video\wmv3,video\rawv,audio,audio\aac,audio\aac\libfaad2,audio\ac3,audio\ac3\liba52,audio\eac3,audio\mlp,audio\tta,audio\amr,audio\qt,filter,filter\normalize
Inno Setup: Deselected Tasks REG_SZ resetsettings,video\h264,video\mpeg1,video\mpeg1\libmpeg2,video\mpeg1\libavcodec,video\mpeg2,video\mpeg2\libmpeg2,video\mpeg2\libavcodec,video\huffyuv,video\vp56,video\vc1,video\vc1\wmv9,video\vc1\libavcodec,video\wvp2,video\mss2,video\dvsd,audio\mp3,audio\mp3\libmad,audio\mp3\libavcodec,audio\ac3\libavcodec,audio\dts,audio\dts\libdts,audio\dts\libavcodec,audio\lpcm,audio\mp2,audio\mp2\libmad,audio\mp2\libavcodec,audio\vorbis,audio\vorbis\tremor,audio\vorbis\libavcodec,audio\flac,audio\rawa,filter\passthroughac3,filter\passthroughdts,filter\subtitles
DisplayName REG_SZ ffdshow [rev 2527] [2008-12-19]
UninstallString REG_SZ "C:\Program Files\K-Lite Codec Pack\ffdshow\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\K-Lite Codec Pack\ffdshow\unins000.exe" /SILENT
DisplayVersion REG_SZ 1.0
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20090712

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Fontcore

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Free Audio Converter_is1
Inno Setup: Setup Version REG_SZ 5.2.3
Inno Setup: App Path REG_SZ C:\Program Files\DVDVideoSoft\Free Audio Converter
InstallLocation REG_SZ C:\Program Files\DVDVideoSoft\Free Audio Converter\
Inno Setup: Icon Group REG_SZ DVDVideoSoft
Inno Setup: User REG_SZ Kirk
DisplayName REG_SZ Free Audio Converter version 1.1
UninstallString REG_SZ "C:\Program Files\DVDVideoSoft\Free Audio Converter\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\DVDVideoSoft\Free Audio Converter\unins000.exe" /SILENT
Publisher REG_SZ DVD Video Soft Limited.
URLInfoAbout REG_SZ http://www.dvdvideosoft.com
URLUpdateInfo REG_SZ http://www.dvdvideosoft.com/
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20090220

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Free Video to iPod Converter_is1
Inno Setup: Setup Version REG_SZ 5.2.3
Inno Setup: App Path REG_SZ C:\Program Files\DVDVideoSoft\Free Video to iPod Converter
InstallLocation REG_SZ C:\Program Files\DVDVideoSoft\Free Video to iPod Converter\
Inno Setup: Icon Group REG_SZ DVDVideoSoft
Inno Setup: User REG_SZ Kirk
DisplayName REG_SZ Free Video to iPod Converter version 3.1
UninstallString REG_SZ "C:\Program Files\DVDVideoSoft\Free Video to iPod Converter\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\DVDVideoSoft\Free Video to iPod Converter\unins000.exe" /SILENT
Publisher REG_SZ DVD Video Soft Limited.
URLInfoAbout REG_SZ http://www.dvdvideosoft.com
URLUpdateInfo REG_SZ http://www.dvdvideosoft.com/
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20090209

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Google Chrome

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Google Updater
DisplayIcon REG_SZ C:\Program Files\Google\Google Updater\GoogleUpdater.exe
DisplayName REG_SZ Google Updater
DisplayVersion REG_SZ 2.4.1536.6592
HelpLink REG_SZ http://pack.google.com:80/pack-support?hl=en&gl=us
InstallLocation REG_SZ C:\Program Files\Google\Google Updater
Publisher REG_SZ Google Inc.
UninstallString REG_SZ "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
URLUpdateInfo REG_SZ http://pack.google.com/?hl=en&gl=us
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
VersionMajor REG_DWORD 2 (0x2)
VersionMinor REG_DWORD 4 (0x4)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\HangARoo_is1
Inno Setup: Setup Version REG_SZ 5.0.8
Inno Setup: App Path REG_SZ C:\Program Files\NCBuy\HangARoo
InstallLocation REG_SZ C:\Program Files\NCBuy\HangARoo\
Inno Setup: Icon Group REG_SZ NCBuy Entertainment Network
Inno Setup: User REG_SZ Kirk
Inno Setup: Selected Tasks REG_SZ desktopicon
Inno Setup: Deselected Tasks REG_SZ
DisplayName REG_SZ HangARoo v2.052
UninstallString REG_SZ "C:\Program Files\NCBuy\HangARoo\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\NCBuy\HangARoo\unins000.exe" /SILENT
Publisher REG_SZ NCBuy.com
URLInfoAbout REG_SZ http://www.ncbuy.com/
HelpLink REG_SZ http://www.ncbuy.com/servicecenter/
URLUpdateInfo REG_SZ http://games.ncbuy.com/
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\IE40

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\IE4Data

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\IE5BAKEX

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\IEData

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\InfoTag Magic 1.0
UninstallString REG_SZ "C:\Program Files\InfoTag Magic 1.0\uninstall.exe"
DisplayName REG_SZ InfoTag Magic 1.0
DisplayIcon REG_SZ C:\Program Files\InfoTag Magic 1.0\uninstall.exe
DisplayVersion REG_SZ 1.0.beta5
HelpLink REG_SZ
HelpTelephone REG_SZ
Publisher REG_SZ ContextMagic.com
URLInfoAbout REG_SZ http://www.ContextMagic.com
URLUpdateInfo REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Jewel Quest 2_is1
Inno Setup: Setup Version REG_SZ 5.2.3
Inno Setup: App Path REG_SZ C:\Program Files\Jewel Quest 2
InstallLocation REG_SZ C:\Program Files\Jewel Quest 2\
Inno Setup: Icon Group REG_SZ Amazon Games\Jewel Quest 2
Inno Setup: User REG_SZ Kirk
DisplayName REG_SZ Jewel Quest 2
DisplayIcon REG_SZ C:\Program Files\Jewel Quest 2\JewelQuest2.exe
UninstallString REG_SZ "C:\Program Files\Jewel Quest 2\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\Jewel Quest 2\unins000.exe" /SILENT
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20090206

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\KLiteCodecPack_is1
Inno Setup: Setup Version REG_SZ 5.1.14
Inno Setup: App Path REG_SZ C:\Program Files\K-Lite Codec Pack
InstallLocation REG_SZ C:\Program Files\K-Lite Codec Pack\
Inno Setup: Icon Group REG_SZ K-Lite Codec Pack
Inno Setup: User REG_SZ Kirk
Inno Setup: Setup Type REG_SZ custom
Inno Setup: Selected Components REG_SZ video,video\xvid,video\xvid\ffdshow,video\h264,video\h264\coreavc,video\vp6,video\vp7,video\mpeg2,video\mpeg2\cyberlink,video\ffdshow,video\ffdshow\mpeg4,video\ffdshow\h263,video\ffdshow\flv,video\ffdshow\mpegavi,video\ffdshow\huffyuv,video\ffdshow\qt,video\ffdshow\indeo,video\ffdshow\other1,video\ffdshow\other2,video\ffdshow\other3,video\ffdshow\other4,audio,audio\mp3,audio\mp3\fhg,audio\ac3,audio\ac3\ac3filter,audio\vorbis,audio\vorbis\corevorbis,audio\aac,audio\aac\ffdshow,audio\musepack,audio\wavpack,audio\optimfrog,audio\ffdshow,audio\ffdshow\amr,audio\ffdshow\tta,audio\ffdshow\qt,audio\ffdshow\law,audio\ffdshow\other,audio\ffdshow\imaadpcm,audio\ffdshow\msadpcm,audio\dcbass,audio\dcbass\alac,audio\dcbass\flac,audio\dcbass\ape,audio\dcbass\mod,audio\dcbass\tta,audio\dcbass\aac,sourcefilter,sourcefilter\mp4,sourcefilter\mp4\haali,sourcefilter\mov,sourcefilter\mov\gabest,sourcefilter\matroska,sourcefilter\matroska\haali,sourcefilter\ogg,sourcefilter\ogg\haali,sourcefilter\mpeg,sourcefilter\mpeg\gabest,sourcefilter\mpeg\haali_ts,sourcefilter\flv,sourcefilter\cdda,sourcefilter\cdxa,sourcefilter\ac3file,subtitles,subtitles\vsfilter,subtitles\vsfilter\238,videovfw,videovfw\ffdshow,videovfw\xvid,videovfw\x264,videovfw\vp6,videovfw\vp7,videovfw\indeo4,videovfw\indeo5,videovfw\i263,videovfw\huffyuv,videovfw\yv12,audioacm,audioacm\mp3fhg,audioacm\mp3lame,audioacm\ac3acm,audioacm\ac3filteracm,audioacm\vorbis,audioacm\divxwma,misc,misc\brokencodecs,misc\brokenfilters
Inno Setup: Deselected Components REG_SZ player,player\mpclassic,video\xvid\xvid,video\divx,video\divx\divx2,video\divx\ffdshow,video\h264\ffdshow,video\mpeg2\microsoft,video\mpeg2\libmpeg2,video\mpeg2\libavcodec,video\mpeg2\gabest,video\mpeg1,video\mpeg1\microsoft,video\mpeg1\mainconcept,video\ffdshow\vc1,audio\mp3\ffdshow,audio\ac3\ffdshow,audio\mpeg,audio\mpeg\microsoft,audio\mpeg\ffdshow,audio\mpeg\ac3filter,audio\vorbis\tremor,audio\vorbis\libavcodec,audio\aac\coreaac,sourcefilter\avi,sourcefilter\avi\microsoft,sourcefilter\avi\gabest,sourcefilter\avi\haali,sourcefilter\mp4\gabest,sourcefilter\matroska\gabest,sourcefilter\ogg\gabest,sourcefilter\mpeg\haali_ps,subtitles\vsfilter\233,videovfw\divx2,tools,tools\codectweaktool,tools\gspot,tools\vobsubstrip,tools\graphedit,tools\avifixed,tools\fourcc,tools\minicalc
Inno Setup: Selected Tasks REG_SZ ff_plugins,ffrawvideo,speaker,speaker\20,normalize,boostac3volume,vsfilter_prebuffer,cyberlink_hwa
Inno Setup: Deselected Tasks REG_SZ reset_settings,fa,fa\wmp,fa\video,fa\video\avi,fa\video\mpeg,fa\video\ts,fa\video\mkv,fa\video\mp4,fa\video\3gp,fa\video\ogm,fa\video\flv,fa\video\wmv,fa\video\asf,fa\video\qt,fa\audio,fa\audio\ogg,fa\audio\m4a,fa\audio\flac,fa\audio\ape,fa\audio\mpc,fa\audio\wv,ff_force_rgb32,ffwhitelist,ffhideicons,haalishell,autoloadvsfilter,speak
er\21,speaker\40,speaker\41,speaker\51,systemrestorepoint
DisplayName REG_SZ K-Lite Codec Pack 3.4.5 Full
UninstallString REG_SZ "C:\Program Files\K-Lite Codec Pack\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\K-Lite Codec Pack\unins000.exe" /SILENT
DisplayVersion REG_SZ 3.45
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20090209

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Live_TV Toolbar
DisplayName REG_SZ Live_TV Toolbar
UninstallString REG_SZ C:\PROGRA~1\Live_TV\UNWISE.EXE C:\PROGRA~1\Live_TV\INSTALL.LOG
DisplayVersion REG_SZ
HelpLink REG_SZ
Publisher REG_SZ
URLInfoAbout REG_SZ
Contact REG_SZ
Comments REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Microsoft .NET Framework 3.5 SP1
DisplayIcon REG_SZ C:\Windows\system32\msiexec.exe
DisplayName REG_SZ Microsoft .NET Framework 3.5 SP1
UninstallString REG_SZ C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
VersionMinor REG_SZ 5
VersionMajor REG_SZ 3
Publisher REG_SZ Microsoft Corporation
InstallLocation REG_SZ C:\Windows\Microsoft.NET\Framework\v3.5\
UninstallPath REG_SZ C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
URLUpdateInfo REG_SZ http://go.microsoft.com/fwlink/?LinkId=120338
HelpLink REG_SZ http://go.microsoft.com/fwlink/?LinkId=120337

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Microsoft Office Accounting 2008
DisplayName REG_SZ Microsoft Office Accounting 2008
DisplayIcon REG_SZ "C:\Program Files\Microsoft Small Business\Office Accounting 2008\SetupBootstrap\office16_32_48.ico"
HelpLink REG_SZ http://go.microsoft.com/fwlink/?LinkId=99383
Publisher REG_SZ Microsoft Corporation
DisplayVersion REG_SZ 3.0.8627.1
UninstallString REG_SZ "C:\Program Files\Microsoft Small Business\Office Accounting 2008\SetupBootstrap\Setup.exe" /remove {270940EA-C235-40D9-B2AE-2D450356DF8E}
Readme REG_SZ "C:\Program Files\Microsoft Small Business\Office Accounting 2008\Readme.htm"

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Microsoft SQL Server 2005
DisplayName REG_SZ Microsoft SQL Server 2005
DisplayIcon REG_SZ "c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\setup.exe",1
HelpLink REG_SZ http://go.microsoft.com/fwlink/?LinkId=52152
HelpTelephone REG_SZ
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
ModifyPath REG_SZ "c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe"
UninstallString REG_SZ "c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
NoModify REG_DWORD 0 (0x0)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\mIRC
DisplayName REG_SZ mIRC
UninstallString REG_SZ "C:\Excursion9.5\mIRC.ExCurSioN.exe" -uninstall

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\MobileOptionPack

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Move Networks Player - IE
DisplayName REG_SZ Move Networks Media Player for Internet Explorer
UninstallString REG_SZ C:\Users\Kirk\AppData\Roaming\Move Networks\ie_bin\Uninst.exe
DisplayIcon REG_SZ C:\Users\Kirk\AppData\Roaming\Move Networks\ie_bin\qsp2ie07103010.dll

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\MPlayer2

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\MsJavaVM
<NO NAME> REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Nero - Burning Rom!UninstallKey
UninstallString REG_SZ C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\NeroBackItUp!UninstallKey
UninstallString REG_SZ C:\Windows\UNNeroBackItUp.exe /UNINSTALL

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\NeroMediaHome!UninstallKey
UninstallString REG_SZ C:\Windows\UNNeroMediaHome.exe /UNINSTALL

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\NeroRecode!UninstallKey
UninstallString REG_SZ C:\Windows\UNRecode.exe /UNINSTALL

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\NeroShowTime!UninstallKey
UninstallString REG_SZ C:\Windows\UNNeroShowTime.exe /UNINSTALL

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\NeroVision!UninstallKey
UninstallString REG_SZ C:\Windows\UNNeroVision.exe /UNINSTALL

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\PROR
Publisher REG_SZ Microsoft Corporation
CacheLocation REG_SZ C:\MSOCache\All Users
Comments REG_SZ
DisplayIcon REG_SZ C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\OSETUP.DLL,1
DisplayName REG_SZ Microsoft Office Professional 2007 Trial
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallLocation REG_SZ C:\Program Files\Microsoft Office
ModifyPath REG_SZ "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /modify PROR /dll OSETUP.DLL
NoElevateOnModify REG_DWORD 1 (0x1)
NoModify REG_DWORD 0 (0x0)
NoRemove REG_DWORD 0 (0x0)
NoRepair REG_DWORD 1 (0x1)
PackageIds REG_MULTI_SZ OfficeMUI.en-usOfficeMUISet.en-usAccessMUI.en-usAccessMUISet.en-usExcelMUI.en-usOutlookMUI.en-usPowerPointMUI.en-usProof.es-esProof.fr-frProof.en-usProofing.en-usPublisherMUI.en-usWordMUI.en-usProrWW\
ProductCodes REG_MULTI_SZ {90120000-006E-0409-0000-0000000FF1CE}{90120000-0115-0409-0000-0000000FF1CE}{90120000-0015-0409-0000-0000000FF1CE}{90120000-0117-0409-0000-0000000FF1CE}{90120000-0016-0409-0000-0000000FF1CE}{90120000-001A-0409-0000-0000000FF1CE}{90120000-0018-0409-0000-0000000FF1CE}{90120000-001F-0C0A-0000-0000000FF1CE}{90120000-001F-040C-0000-0000000FF1CE}{90120000-001F-0409-0000-0000000FF1CE}{90120000-002C-0409-0000-0000000FF1CE}{90120000-0019-0409-0000-0000000FF1CE}{90120000-001B-0409-0000-0000000FF1CE}{91120000-0014-0000-0000-0000000FF1CE}\
SkuComponents REG_MULTI_SZ C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Proofing.en-us\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Publisher.en-us\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Access.en-us\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Office.en-us\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\PowerPoint.en-us\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\PROR\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Excel.en-us\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Outlook.en-us\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Word.en-us\setup.xml\
SystemComponent REG_DWORD 0 (0x0)
UninstallString REG_SZ "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROR /dll OSETUP.DLL
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
ShellUITransformLanguage REG_SZ en-US
ProductID REG_SZ 81605-327-6814702-65485

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\RealPlayer 12.0
<NO NAME> REG_SZ
UninstallString REG_SZ C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|12.0
DisplayName REG_SZ RealPlayer
DisplayIcon REG_SZ C:\Program Files\Real\RealPlayer\realplay.exe
URLInfoAbout REG_SZ http://www.real.com
Comments REG_SZ Play, Save, and Organize your music and videos, Burn a CD, or simply take your music with you.
Contact REG_SZ RealNetworks
Publisher REG_SZ RealNetworks
InstallLocation REG_SZ C:\Program Files\Real\RealPlayer\realplay.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Rhapsody
DisplayName REG_SZ Rhapsody
DisplayIcon REG_SZ C:\Program Files\Rhapsody\Rhapsody.exe
UninstallString REG_SZ C:\PROGRA~1\Rhapsody\Unwise32.exe /A C:\PROGRA~1\Rhapsody\INSTALL.LOG

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\SchedulingAgent

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Scorched3D
DisplayName REG_SZ Scorched3D 42.1
UninstallString REG_SZ C:\Program Files\Scorched3D\uninst.exe
DisplayVersion REG_SZ 42.1
URLInfoAbout REG_SZ http://www.scorched3d.co.uk
Publisher REG_SZ Scorched

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Shockwave
QuietDisplayName REG_SZ Shockwave Director 11.0.3
QuietUninstallString REG_SZ RunDll32 advpack.dll,LaunchINFSection C:\Windows\\INF\\swdir.inf,DefaultUninstall,5
RequiresIESysFile REG_SZ 4.70.0.1155

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\STANDARDR
Publisher REG_SZ Microsoft Corporation
CacheLocation REG_SZ C:\MSOCache\All Users
Comments REG_SZ
DisplayIcon REG_SZ C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\OSETUP.DLL,1
DisplayName REG_SZ Microsoft Office Standard 2007 Trial
DisplayVersion REG_SZ 12.0.4518.1014
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallLocation REG_SZ C:\Program Files\Microsoft Office
ModifyPath REG_SZ "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /modify STANDARDR /dll OSETUP.DLL
NoElevateOnModify REG_DWORD 1 (0x1)
NoModify REG_DWORD 0 (0x0)
NoRemove REG_DWORD 0 (0x0)
NoRepair REG_DWORD 1 (0x1)
PackageIds REG_MULTI_SZ OfficeMUI.en-usOfficeMUISet.en-usExcelMUI.en-usOutlookMUI.en-usPowerPointMUI.en-usProof.es-esProof.fr-frProof.en-usProofing.en-usWordMUI.en-usStandardrWW\
ProductCodes REG_MULTI_SZ {90120000-006E-0409-0000-0000000FF1CE}{90120000-0115-0409-0000-0000000FF1CE}{90120000-0016-0409-0000-0000000FF1CE}{90120000-001A-0409-0000-0000000FF1CE}{90120000-0018-0409-0000-0000000FF1CE}{90120000-001F-0C0A-0000-0000000FF1CE}{90120000-001F-040C-0000-0000000FF1CE}{90120000-001F-0409-0000-0000000FF1CE}{90120000-002C-0409-0000-0000000FF1CE}{90120000-001B-0409-0000-0000000FF1CE}{91120000-0012-0000-0000-0000000FF1CE}\
SkuComponents REG_MULTI_SZ C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Excel.en-us\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Outlook.en-us\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Proofing.en-us\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\STANDARDR\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Word.en-us\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Office.en-us\setup.xmlC:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\PowerPoint.en-us\setup.xml\
SystemComponent REG_DWORD 0 (0x0)
UninstallString REG_SZ "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall STANDARDR /dll OSETUP.DLL
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
ShellUITransformLanguage REG_SZ en-US
ProductID REG_SZ 81607-310-0586547-64746

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\TagScanner_is1
Inno Setup: Setup Version REG_SZ 5.2.3
Inno Setup: App Path REG_SZ C:\Program Files\TagScanner
InstallLocation REG_SZ C:\Program Files\TagScanner\
Inno Setup: Icon Group REG_SZ TagScanner
Inno Setup: No Icons REG_DWORD 1 (0x1)
Inno Setup: User REG_SZ Kirk
Inno Setup: Selected Tasks REG_SZ quicklaunchicon
Inno Setup: Deselected Tasks REG_SZ desktopicon
DisplayName REG_SZ TagScanner 5.0 build 530
UninstallString REG_SZ "C:\Program Files\TagScanner\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\TagScanner\unins000.exe" /SILENT
Publisher REG_SZ Sergey Serkov
URLInfoAbout REG_SZ http://www.xdlab.ru
HelpLink REG_SZ http://www.xdlab.ru
URLUpdateInfo REG_SZ http://www.xdlab.ru
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20090623

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\The Price Is Right_is1
Inno Setup: Setup Version REG_SZ 5.2.3
Inno Setup: App Path REG_SZ C:\Program Files\The Price Is Right
InstallLocation REG_SZ C:\Program Files\The Price Is Right\
Inno Setup: Icon Group REG_SZ Amazon Games\The Price Is Right
Inno Setup: User REG_SZ Kirk
DisplayName REG_SZ The Price Is Right
DisplayIcon REG_SZ C:\Program Files\The Price Is Right\TPIR[WinDesktop].exe
UninstallString REG_SZ "C:\Program Files\The Price Is Right\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\The Price Is Right\unins000.exe" /SILENT
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20090206

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\The Scruffs_is1
Inno Setup: Setup Version REG_SZ 5.2.3
Inno Setup: App Path REG_SZ C:\Program Files\The Scruffs
InstallLocation REG_SZ C:\Program Files\The Scruffs\
Inno Setup: Icon Group REG_SZ Amazon Games\The Scruffs
Inno Setup: User REG_SZ Kirk
DisplayName REG_SZ The Scruffs
DisplayIcon REG_SZ C:\Program Files\The Scruffs\TheScruffs.exe
UninstallString REG_SZ "C:\Program Files\The Scruffs\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\The Scruffs\unins000.exe" /SILENT
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20090206

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\TMD-Recruit Pack
DisplayName REG_SZ TMD-Recruit Pack
UninstallString REG_SZ D:\TMD-Recruit.5.1\Uninstal.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Virtual DJ - Atomix Productions
DisplayName REG_SZ Virtual DJ - Atomix Productions
UninstallString REG_SZ C:\PROGRA~1\VIRTUA~1\UNWISE.EXE C:\PROGRA~1\VIRTUA~1\INSTALL.LOG

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\VLC media player
DisplayName REG_SZ VideoLAN VLC media player 0.8.6d
UninstallString REG_SZ C:\Program Files\VideoLAN\VLC\uninstall.exe
DisplayIcon REG_SZ C:\Program Files\VideoLAN\VLC\vlc.exe
DisplayVersion REG_SZ 0.8.6d
URLInfoAbout REG_SZ http://www.videolan.org
Publisher REG_SZ VideoLAN Team

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\WIC
NoRemove REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\WinLiveSuite_Wave3
URLInfoAbout REG_SZ http://support.live.com/
DisplayName REG_SZ Windows Live Essentials
DisplayIcon REG_SZ C:\Program Files\Windows Live\Installer\wlarp.exe
UninstallString REG_SZ C:\Program Files\Windows Live\Installer\wlarp.exe
InstallLocation REG_SZ C:\Program Files\Windows Live\
Publisher REG_SZ Microsoft Corporation
DisplayVersion REG_SZ 14.0.8064.0206
Language REG_DWORD 9 (0x9)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\WinRAR archiver
DisplayName REG_SZ WinRAR archiver
UninstallString REG_SZ C:\Program Files\WinRAR\uninstall.exe
DisplayIcon REG_SZ C:\Program Files\WinRAR\WinRAR.exe
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\XviD & MP3 Codec Pack_is1
Inno Setup: Setup Version REG_SZ 5.0.8
Inno Setup: App Path REG_SZ
Inno Setup: Icon Group REG_SZ (Default)
Inno Setup: User REG_SZ Kirk
DisplayName REG_SZ XviD & MP3 Codec Pack (remove only)
UninstallString REG_SZ "C:\Windows\unins000.exe"
QuietUninstallString REG_SZ "C:\Windows\unins000.exe" /SILENT
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Xvid_is1
Inno Setup: Setup Version REG_SZ 4.2.7
Inno Setup: App Path REG_SZ C:\Program Files\Xvid
InstallLocation REG_SZ C:\Program Files\Xvid\
Inno Setup: Icon Group REG_SZ Xvid
Inno Setup: User REG_SZ Kirk
Inno Setup: Selected Tasks REG_SZ DecodeAll
Inno Setup: Deselected Tasks REG_SZ
DisplayName REG_SZ XviD MPEG-4 Video Codec
DisplayIcon REG_SZ C:\Program Files\Xvid\xvid.ico
UninstallString REG_SZ "C:\Program Files\Xvid\unins000.exe"
QuietUninstallString REG_SZ "C:\Program Files\Xvid\unins000.exe" /SILENT
DisplayVersion REG_SZ XviD-1.0.3-20122004
Publisher REG_SZ XviD Team (Koepi)
URLInfoAbout REG_SZ http://www.xvid.org/
HelpLink REG_SZ http://forum.doom9.org/forumdisplay.php?s=&forumid=52
URLUpdateInfo REG_SZ http://www.koepi.org/
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Yahoo! Applications
DisplayName REG_SZ AT&T Yahoo! Applications
Publisher REG_SZ AT&T Yahoo!
UninstallString REG_SZ C:\Program Files\Yahoo!\Common\uninstall.exe
DisplayIcon REG_SZ C:\Program Files\Yahoo!\Common\Icons\attfav.ico

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Zinio Reader
DisplayName REG_SZ Zinio Reader
UninstallString REG_SZ C:\Program Files\Zinio\uninstall.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\Zune
DisplayIcon REG_SZ C:\Users\Kirk\Downloads\1695.dvb.pc.4.4.3\Zune\Zune.exe
DisplayName REG_SZ Zune
DisplayVersion REG_SZ 03.01.0620.00
HelpLink REG_SZ http://go.microsoft.com/fwlink/?LinkID=71730
InstallLocation REG_SZ C:\Users\Kirk\Downloads\1695.dvb.pc.4.4.3\Zune\
Publisher REG_SZ Microsoft Corporation
UninstallPath REG_SZ C:\Users\Kirk\Downloads\1695.dvb.pc.4.4.3\Zune\ZuneSetup.exe
UninstallString REG_SZ C:\Users\Kirk\Downloads\1695.dvb.pc.4.4.3\Zune\ZuneSetup.exe /x
URLUpdateInfo REG_SZ
NoModify REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 03.01.0620.00
HelpLink REG_EXPAND_SZ http://go.microsoft.com/fwlink/?LinkID=71730
HelpTelephone REG_SZ
InstallDate REG_SZ 20090203
InstallLocation REG_SZ
InstallSource REG_SZ D:\5bbfdf46d3cfadb8411edee2\packages\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 472 (0x1d8)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 3 (0x3)
VersionMinor REG_DWORD 1 (0x1)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 50397804 (0x301026c)
Language REG_DWORD 1036 (0x40c)
DisplayName REG_SZ Zune Language Pack (FR)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{044F9133-B8D7-4d11-BF39-803FA20F5C8B}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ Update/Uninstall/Repair this SDK
Contact REG_SZ
DisplayVersion REG_SZ 6.1.5295.17011
HelpLink REG_EXPAND_SZ http://go.microsoft.com/fwlink/?linkid=55774
HelpTelephone REG_SZ
InstallDate REG_SZ 20090514
InstallLocation REG_SZ
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp\IXP070FC.tmp\wcu\winsdk\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{044F9133-B8D7-4d11-BF39-803FA20F5C8B}
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 2672 (0xa70)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{044F9133-B8D7-4d11-BF39-803FA20F5C8B}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ http://go.microsoft.com/fwlink/?linkid=55774
VersionMajor REG_DWORD 6 (0x6)
VersionMinor REG_DWORD 1 (0x1)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 100734127 (0x60114af)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{059A00AC-1205-423C-91C7-7E6168D804DA}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ info@mainconcept.com
DisplayVersion REG_SZ 1.5.0.2
HelpLink REG_EXPAND_SZ support@mainconcept.com
HelpTelephone REG_SZ
InstallDate REG_SZ 20080711
InstallLocation REG_SZ C:\Program Files\MainConcept\DTV Decoder Standard\
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp\Temp1_1695.dvb.pc.4.4.3[1].zip\4_4_3_Release\Install\MainConcept\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{059A00AC-1205-423C-91C7-7E6168D804DA}
Publisher REG_SZ MainConcept GmbH
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 9198 (0x23ee)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{059A00AC-1205-423C-91C7-7E6168D804DA}
URLInfoAbout REG_SZ http://www.mainconcept.com/site/
URLUpdateInfo REG_SZ http://www.mainconcept.com/site/index.php?id=6
VersionMajor REG_DWORD 1 (0x1)
VersionMinor REG_DWORD 5 (0x5)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 17104896 (0x1050000)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ MainConcept DTV Decoder Standard

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{07287123-B8AC-41CE-8346-3D777245C35B}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ AppleCare Support
DisplayVersion REG_SZ 1.0.106
HelpLink REG_EXPAND_SZ http://www.apple.com/support/
HelpTelephone REG_SZ 1-800-275-2273
InstallDate REG_SZ 20090318
InstallLocation REG_SZ C:\Program Files\Bonjour\
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Apple\Apple Software Update\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Publisher REG_SZ Apple Inc.
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 493 (0x1ed)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
URLInfoAbout REG_SZ http://www.apple.com
URLUpdateInfo REG_SZ http://www.apple.com/bonjour/
VersionMajor REG_DWORD 1 (0x1)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 16777322 (0x100006a)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Bonjour

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{0C2AF762-0565-4C91-9F55-B8B53BB82A38}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ Microsoft Office Accounting 2008 Equifax Addin
Contact REG_SZ
DisplayVersion REG_SZ 3.0.8231.0
HelpLink REG_EXPAND_SZ http://support.microsoft.com/
HelpTelephone REG_SZ
InstallDate REG_SZ 20081013
InstallLocation REG_SZ C:\Program Files\Microsoft Small Business\
InstallSource REG_SZ d:\128258114fb2955e75cadb\Equifax\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{0C2AF762-0565-4C91-9F55-B8B53BB82A38}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 2442 (0x98a)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{0C2AF762-0565-4C91-9F55-B8B53BB82A38}
URLInfoAbout REG_SZ http://office.microsoft.com/
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 3 (0x3)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 50339879 (0x3002027)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Accounting 2008 Equifax Addin

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ OpenOffice.org Installer 1.0 (en-US) (OOG680m5(Build:9221))[CWS:c18v001]
Contact REG_SZ
DisplayVersion REG_SZ 1.0.9221
HelpLink REG_EXPAND_SZ http://www.sun.com/getopenoffice
HelpTelephone REG_SZ
InstallDate REG_SZ 20090310
InstallLocation REG_SZ C:\Program Files\Sun\OpenOffice.org Installer 1.0\
InstallSource REG_SZ http://javadl-esd.sun.com/update/1.6.0/sp-1.6.0_11-b03/sp3/
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Sun Microsystems
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 2444 (0x98c)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
URLInfoAbout REG_SZ http://www.sun.com
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 1 (0x1)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 16786437 (0x1002405)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ OpenOffice.org Installer 1.0

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{134007CC-7026-46C2-B46F-40D9FD2AF385}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 1.0.0
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20080711
InstallLocation REG_SZ
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp\{830CCC02-A78F-4CA2-B01D-F7D5934DC587}\{D032A7F0-8B5C-4603-8B46-235025D5F9C1}\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{134007CC-7026-46C2-B46F-40D9FD2AF385}
Publisher REG_SZ Technisat
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 4339 (0x10f3)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{134007CC-7026-46C2-B46F-40D9FD2AF385}
URLInfoAbout REG_SZ www.technisat.com
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 1 (0x1)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 16777216 (0x1000000)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Technisat DVB-VC80 Redistributable Modules

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{18D10072035C4515918F7E37EAFAACFC}
FinishedFlag REG_DWORD 0 (0x0)
DisplayName REG_SZ AutoUpdate
DisplayVersion REG_SZ 1.1
Locale REG_SZ en
InstallLocation REG_SZ C:\Program Files\DivX\AutoUpdate
RebootFlag REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{205C6BDD-7B73-42DE-8505-9A093F35A238}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 14.0.8014.1029
HelpLink REG_EXPAND_SZ http://go.microsoft.com/fwlink/?LinkId=118310
HelpTelephone REG_SZ
InstallDate REG_SZ 20090516
InstallLocation REG_SZ
InstallSource REG_SZ C:\Program Files\Common Files\Windows Live\.cache\963ed9b01c9d6a2\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 225 (0xe1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 14 (0xe)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 234889038 (0xe001f4e)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Windows Live Upload Tool

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 14.0.1468.721
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090516
InstallLocation REG_SZ
InstallSource REG_SZ C:\Program Files\Common Files\Windows Live\.cache\7af5097c1c9d6a2\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
Publisher REG_SZ Microsoft
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 1856 (0x740)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 14 (0xe)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 234882492 (0xe0005bc)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ MSVCRT

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{26A24AE4-039D-4CA4-87B4-2F83216013FB}
DisplayIcon REG_SZ C:\Program Files\Java\jre6\\bin\javaws.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{26A24AE4-039D-4CA4-87B4-2F83216015FF}
DisplayIcon REG_SZ C:\Program Files\Java\jre6\\bin\javaws.exe
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ http://java.com
DisplayVersion REG_SZ 6.0.150
HelpLink REG_EXPAND_SZ http://java.com
HelpTelephone REG_SZ
InstallDate REG_SZ 20090820
InstallLocation REG_SZ C:\Program Files\Java\jre6\
InstallSource REG_SZ C:\Users\Kirk\AppData\LocalLow\Sun\Java\jre1.6.0_15\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216015FF}
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Sun Microsystems, Inc.
Readme REG_EXPAND_SZ C:\Program Files\Java\jre6\README.txt
Size REG_SZ
EstimatedSize REG_DWORD 97244 (0x17bdc)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216015FF}
URLInfoAbout REG_SZ http://java.com
URLUpdateInfo REG_SZ http://java.sun.com
VersionMajor REG_DWORD 6 (0x6)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 100663446 (0x6000096)
Language REG_DWORD 0 (0x0)
DisplayName REG_SZ Java™ 6 Update 15

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{270940EA-C235-40D9-B2AE-2D450356DF8E}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 3.0.8627.1
HelpLink REG_EXPAND_SZ http://go.microsoft.com/fwlink/?LinkId=99383
HelpTelephone REG_SZ
InstallDate REG_SZ 20081014
InstallLocation REG_SZ C:\Program Files\Microsoft Small Business\
InstallSource REG_SZ d:\128258114fb2955e75cadb\SBA\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{270940EA-C235-40D9-B2AE-2D450356DF8E}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_EXPAND_SZ C:\Program Files\Microsoft Small Business\Office Accounting 2008\Readme.htm
Size REG_SZ
EstimatedSize REG_DWORD 467834 (0x7237a)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{270940EA-C235-40D9-B2AE-2D450356DF8E}
URLInfoAbout REG_SZ http://www.microsoft.com/
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 3 (0x3)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 50340275 (0x30021b3)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Accounting 2008

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 9.3.4035.00
HelpLink REG_EXPAND_SZ http://go.microsoft.com/fwlink/?LinkId=52152
HelpTelephone REG_SZ
InstallDate REG_SZ 20090319
InstallLocation REG_SZ c:\Program Files\Microsoft SQL Server\
InstallSource REG_SZ c:\662704032cc380743aab84d50409e8\Setup\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 203971 (0x31cc3)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 9 (0x9)
VersionMinor REG_DWORD 3 (0x3)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 151195587 (0x9030fc3)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft SQL Server 2005 Tools Express Edition

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{27F00C63-449B-2FAB-CBE8-24AB80E17449}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 1.7.258
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090811
InstallLocation REG_SZ c:\program files\adobe\Acrobat.com
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp\flaDB07.tmp\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{27F00C63-449B-2FAB-CBE8-24AB80E17449}
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Adobe Systems Incorporated
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 1664 (0x680)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{27F00C63-449B-2FAB-CBE8-24AB80E17449}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 1 (0x1)
VersionMinor REG_DWORD 7 (0x7)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 17236226 (0x1070102)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Acrobat.com

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 9.3.4035.00
HelpLink REG_EXPAND_SZ http://go.microsoft.com/fwlink/?LinkId=52152
HelpTelephone REG_SZ
InstallDate REG_SZ 20090319
InstallLocation REG_SZ C:\Program Files\Microsoft SQL Server\
InstallSource REG_SZ d:\7e442af05ab748982d6b3c349c2e05\Setup\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 443464 (0x6c448)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 9 (0x9)
VersionMinor REG_DWORD 3 (0x3)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 151195587 (0x9030fc3)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{2D87E961-577B-492B-AD54-1368680FB9A7}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 4.0.903.16005
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090630
InstallLocation REG_SZ
InstallSource REG_SZ C:\Program Files\Virtual Earth 3D\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{2D87E961-577B-492B-AD54-1368680FB9A7}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 15434 (0x3c4a)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{2D87E961-577B-492B-AD54-1368680FB9A7}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 4 (0x4)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 67109767 (0x4000387)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Bing Maps 3D

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ The Rhapsody Player Engine is a Web browser plugin used for Rhapsody On The Web.
Contact REG_SZ RealNetworks
DisplayVersion REG_SZ 1.0.604
HelpLink REG_EXPAND_SZ http://www.rhapsody.com
HelpTelephone REG_SZ
InstallDate REG_SZ 20090319
InstallLocation REG_SZ
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp\Rhapsody\Staging\rhapweb\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}
Publisher REG_SZ RealNetworks
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 1205 (0x4b5)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}
URLInfoAbout REG_SZ http://www.rhapsody.com
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 1 (0x1)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 16777820 (0x100025c)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Rhapsody Player Engine

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{38F2E726-1FF5-4AAB-96AD-CAB5079E8846}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 4.0.179.0
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090715
InstallLocation REG_SZ C:\Program Files\Common Files\Autodesk Shared\DirectConnect2010\
InstallSource REG_SZ E:\Alias\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{38F2E726-1FF5-4AAB-96AD-CAB5079E8846}
Publisher REG_SZ Autodesk
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 417196 (0x65dac)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{38F2E726-1FF5-4AAB-96AD-CAB5079E8846}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 4 (0x4)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 67109043 (0x40000b3)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Autodesk DirectConnect 2010

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{3921A67A-5AB1-4E48-9444-C71814CF3027}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ Nero AG
DisplayVersion REG_SZ 1.0.0
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20081222
InstallLocation REG_SZ
InstallSource REG_SZ C:\Users\Kirk\Desktop\Media\ahead_nero_burning_rom_v8.3.6.0_en_+_keygen\Data\Redist\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
Publisher REG_SZ Nero AG
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 5949 (0x173d)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 1 (0x1)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 16777216 (0x1000000)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ VCRedistSetup

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{3B4E636E-9D65-4D67-BA61-189800823F52}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 14.0.8064.206
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090516
InstallLocation REG_SZ
InstallSource REG_SZ C:\Program Files\Common Files\Windows Live\.cache\81d31ccf1c9d6a2\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 1945 (0x799)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 14 (0xe)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 234889088 (0xe001f80)
Language REG_DWORD 0 (0x0)
DisplayName REG_SZ Windows Live Communications Platform

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 9.0.30729
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090514
InstallLocation REG_SZ
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp\IXP011DC.tmp\wcu\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 590 (0x24e)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 9 (0x9)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 151025673 (0x9007809)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{3C52E7DA-C431-4239-B66B-1BF703D5B194}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 14.0.8064.206
HelpLink REG_EXPAND_SZ http://photogallery.live.com/
HelpTelephone REG_SZ
InstallDate REG_SZ 20090516
InstallLocation REG_SZ
InstallSource REG_SZ C:\Program Files\Common Files\Windows Live\.cache\47cee9d61c9d6a3\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{3C52E7DA-C431-4239-B66B-1BF703D5B194}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 32166 (0x7da6)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{3C52E7DA-C431-4239-B66B-1BF703D5B194}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 14 (0xe)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 234889088 (0xe001f80)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Windows Live Photo Gallery

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{477CB625-93BA-4ED1-B636-29DAE5893F79}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 16.00.0000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090715
InstallLocation REG_SZ
InstallSource REG_SZ E:\StudioViewer\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{477CB625-93BA-4ED1-B636-29DAE5893F79}
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Autodesk
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 819885 (0xc82ad)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{477CB625-93BA-4ED1-B636-29DAE5893F79}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 16 (0x10)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 268435456 (0x10000000)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Autodesk StudioViewer 2010

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 14.0.8064.206
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090516
InstallLocation REG_SZ
InstallSource REG_SZ C:\Program Files\Common Files\Windows Live\.cache\918a9d961c9d6a2\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 3512 (0xdb8)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 14 (0xe)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 234889088 (0xe001f80)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Junk Mail filter update

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 9.00.4035.00
HelpLink REG_EXPAND_SZ http://go.microsoft.com/fwlink/?LinkId=52154
HelpTelephone REG_SZ
InstallDate REG_SZ 20090319
InstallLocation REG_SZ c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\
InstallSource REG_SZ c:\662704032cc380743aab84d50409e8\Setup\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 25181 (0x625d)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 9 (0x9)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 150998979 (0x9000fc3)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft SQL Server Setup Support Files (English)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{56B4002F-671C-49F4-984C-C760FE3806B5}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 9.00.4035.00
HelpLink REG_EXPAND_SZ http://go.microsoft.com/fwlink/?LinkId=52155
HelpTelephone REG_SZ
InstallDate REG_SZ 20090319
InstallLocation REG_SZ C:\Program Files\Microsoft SQL Server\
InstallSource REG_SZ d:\7e442af05ab748982d6b3c349c2e05\Setup\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{56B4002F-671C-49F4-984C-C760FE3806B5}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 679 (0x2a7)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{56B4002F-671C-49F4-984C-C760FE3806B5}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 9 (0x9)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 150998979 (0x9000fc3)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft SQL Server VSS Writer

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ Nero AG
DisplayVersion REG_SZ 1.0.0
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20081222
InstallLocation REG_SZ
InstallSource REG_SZ C:\Users\Kirk\Desktop\Media\ahead_nero_burning_rom_v8.3.6.0_en_+_keygen\Data\Redist\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Publisher REG_SZ Nero AG
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 3795 (0xed3)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 1 (0x1)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 16777216 (0x1000000)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ neroxml

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 3.5.30729
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090514
InstallLocation REG_SZ
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp\IXP070AA.tmp\wcu\winsdk\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 4518 (0x11a6)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 3 (0x3)
VersionMinor REG_DWORD 5 (0x5)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 50690057 (0x3057809)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5C74694C-A687-E3EB-FF18-B018D4A76ECD}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 0.0.0
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20080830
InstallLocation REG_SZ
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp\flaAC63.tmp\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{5C74694C-A687-E3EB-FF18-B018D4A76ECD}
Publisher REG_SZ Adobe Systems Incorporated
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 2744 (0xab8)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{5C74694C-A687-E3EB-FF18-B018D4A76ECD}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 0 (0x0)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 0 (0x0)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Adobe Media Player

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5D601655-6D54-4384-B52C-17EC5385FBBD}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ AppleCare Support
DisplayVersion REG_SZ 8.2.0.23
HelpLink REG_EXPAND_SZ http://www.apple.com/support/
HelpTelephone REG_SZ 1-800-275-2273
InstallDate REG_SZ 20090617
InstallLocation REG_SZ C:\Program Files\iTunes\
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Apple\Apple Software Update\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{5D601655-6D54-4384-B52C-17EC5385FBBD}
Publisher REG_SZ Apple Inc.
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 114485 (0x1bf35)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{5D601655-6D54-4384-B52C-17EC5385FBBD}
URLInfoAbout REG_SZ http://www.apple.com/
URLUpdateInfo REG_SZ http://www.apple.com/itunes/
VersionMajor REG_DWORD 8 (0x8)
VersionMinor REG_DWORD 2 (0x2)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 134348800 (0x8020000)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ iTunes

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5FA793A6-0071-42C1-9355-8F69A428C44F}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ PayrollSDK@adp.com
DisplayVersion REG_SZ 0.0.0.0
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20081013
InstallLocation REG_SZ
InstallSource REG_SZ d:\128258114fb2955e75cadb\ADP\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{5FA793A6-0071-42C1-9355-8F69A428C44F}
Publisher REG_SZ ADP
Readme REG_SZ
Size REG_DWORD 1782 (0x6f6)
EstimatedSize REG_DWORD 3501 (0xdad)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{5FA793A6-0071-42C1-9355-8F69A428C44F}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 0 (0x0)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 0 (0x0)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Accounting ADP Payroll Addin

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{62369F2F77534556AEF4C58152E3BDE5}
FinishedFlag REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{63C1109E-D977-49ED-BCE3-D00D0BF187D6}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 14.0.8064.0206
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090516
InstallLocation REG_SZ
InstallSource REG_SZ C:\Program Files\Common Files\Windows Live\.cache\dcef734c1c9d6a2\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{63C1109E-D977-49ED-BCE3-D00D0BF187D6}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 28408 (0x6ef8)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{63C1109E-D977-49ED-BCE3-D00D0BF187D6}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 14 (0xe)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 234889088 (0xe001f80)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Windows Live Mail

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ AppleCare Support
DisplayVersion REG_SZ 2.1.1.116
HelpLink REG_EXPAND_SZ http://www.apple.com/support/
HelpTelephone REG_SZ 1-800-275-2273
InstallDate REG_SZ 20080930
InstallLocation REG_SZ C:\Program Files\Apple Software Update\
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp\IXP370.TMP\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Publisher REG_SZ Apple Inc.
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 2208 (0x8a0)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
URLInfoAbout REG_SZ http://www.apple.com
URLUpdateInfo REG_SZ http://www.apple.com/macosx/
VersionMajor REG_DWORD 2 (0x2)
VersionMinor REG_DWORD 1 (0x1)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 33619969 (0x2010001)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Apple Software Update

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{6F6594CB-DA1B-4FFB-B397-CACE3D5F668B}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 14.0.8064.0206
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090516
InstallLocation REG_SZ
InstallSource REG_SZ C:\Program Files\Common Files\Windows Live\.cache\610c3d4a1c9d6a3\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{6F6594CB-DA1B-4FFB-B397-CACE3D5F668B}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 11307 (0x2c2b)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{6F6594CB-DA1B-4FFB-B397-CACE3D5F668B}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 14 (0xe)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 234889088 (0xe001f80)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Windows Live Movie Maker Beta

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{7585478E9D9B42108671C12F8714CEFE}
InstallLocation REG_SZ C:\Program Files\DivX\DivX Converter
DisplayIcon REG_SZ C:\Program Files\DivX\DivX Converter\Converter.exe,0
Publisher REG_SZ DivX, Inc.
UninstallString REG_SZ C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DisplayVersion REG_SZ 6.6.1
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Locale REG_SZ en
RebootFlag REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{7B63B2922B174135AFC0E1377DD81EC2}
DisplayName REG_SZ DivX Codec
InstallLocation REG_SZ C:\Program Files\DivX\DivX Codec
DisplayIcon REG_SZ C:\Program Files\DivX\DivX Codec\config.exe,0
Publisher REG_SZ DivX, Inc.
UninstallString REG_SZ C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DisplayVersion REG_SZ 6.8.3
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Locale REG_SZ en
Cart URL override REG_SZ http://go.divx.com/divx/create/buy/en
RebootFlag REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116802393}
DisplayName REG_SZ Fishing Craze
UninstallString REG_SZ "C:\Program Files\Oberon Media\Fishing Craze\Uninstall.exe" "C:\Program Files\Oberon Media\Fishing Craze\install.log"
InstallLocation REG_SZ C:\Program Files\Oberon Media\Fishing Craze
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp
InstallSourceFile REG_SZ C:\Users\Kirk\AppData\Local\Temp\fishing_craze-setup[1] Setup.exe
InstallDate REG_SZ 05/22/2009
DisplayIcon REG_SZ C:\Program Files\Oberon Media\Fishing Craze\TGB.exe
Publisher REG_SZ Oberon Media
SilentSettings REG_SZ C:\Program Files\Oberon Media\Fishing Craze\install.sss

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{8355F970-601D-442D-A79B-1D7DB4F24CAD}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ AppleCare Support
DisplayVersion REG_SZ 2.5.1.3
HelpLink REG_EXPAND_SZ http://www.apple.com/support/
HelpTelephone REG_SZ 1-800-275-2273
InstallDate REG_SZ 20090617
InstallLocation REG_SZ C:\Program Files\Common Files\Apple\Mobile Device Support\
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Apple\Apple Software Update\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{8355F970-601D-442D-A79B-1D7DB4F24CAD}
Publisher REG_SZ Apple Inc.
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 40848 (0x9f90)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{8355F970-601D-442D-A79B-1D7DB4F24CAD}
URLInfoAbout REG_SZ http://www.apple.com
URLUpdateInfo REG_SZ http://www.apple.com/
VersionMajor REG_DWORD 2 (0x2)
VersionMinor REG_DWORD 5 (0x5)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 33882113 (0x2050001)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Apple Mobile Device Support

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 4.20.9870.0
HelpLink REG_EXPAND_SZ http://support.microsoft.com/kb/954430
HelpTelephone REG_SZ
InstallDate REG_SZ 20081224
InstallLocation REG_SZ
InstallSource REG_SZ c:\36b6cd09ea1c3e01e1086b75142dfd\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 1309 (0x51d)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 4 (0x4)
VersionMinor REG_DWORD 20 (0x14)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 68429454 (0x414268e)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ MSXML 4.0 SP2 (KB954430)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 2.0.40115.0
HelpLink REG_EXPAND_SZ http://go.microsoft.com/fwlink/?LinkID=91955
HelpTelephone REG_SZ
InstallDate REG_SZ 20090226
InstallLocation REG_SZ C:\Program Files\Microsoft Silverlight\
InstallSource REG_SZ c:\temp\ext18866\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 29844 (0x7494)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 2 (0x2)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 33594547 (0x2009cb3)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Silverlight

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{8ADFC4160D694100B5B8A22DE9DCABD9}
FinishedFlag REG_DWORD 0 (0x0)
DisplayName REG_SZ DivX Player
InstallLocation REG_SZ C:\Program Files\DivX\DivX Player
UninstallString REG_SZ C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DisplayIcon REG_SZ C:\Program Files\DivX\DivX Player\DivX Player.exe,0
DisplayVersion REG_SZ 6.8.2
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Locale REG_SZ en
RebootFlag REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 1.2.87.0
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090516
InstallLocation REG_SZ
InstallSource REG_SZ C:\Program Files\Common Files\Windows Live\.cache\a70399a21c9d6a2\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 186 (0xba)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 1 (0x1)
VersionMinor REG_DWORD 2 (0x2)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 16908375 (0x1020057)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Choice Guard

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0015-0409-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 90992 (0x16370)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Access MUI (English) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
DisplayName REG_SZ Microsoft Office 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
SystemComponent REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0015-0409-0000-0000000FF1CE}_PROR_{6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}
DisplayName REG_SZ Update for Microsoft Office Access 2007 Help (KB963663)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/963663
URLInfoAbout REG_SZ http://support.microsoft.com/kb/963663
HelpLink REG_SZ http://support.microsoft.com/kb/963663
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0016-0409-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-0016-0409-0000-0000000FF1CE}-C\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 74948 (0x124c4)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Excel MUI (English) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0016-0409-0000-0000000FF1CE}_PROR_{199DF7B6-169C-448C-B511-1054101BE9C9}
DisplayName REG_SZ Update for Microsoft Office Excel 2007 Help (KB963678)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/963678
URLInfoAbout REG_SZ http://support.microsoft.com/kb/963678
HelpLink REG_SZ http://support.microsoft.com/kb/963678
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {199DF7B6-169C-448C-B511-1054101BE9C9}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
DisplayName REG_SZ Microsoft Office 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
SystemComponent REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0018-0409-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-0018-0409-0000-0000000FF1CE}-C\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 42997 (0xa7f5)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office PowerPoint MUI (English) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
DisplayName REG_SZ Microsoft Office 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
SystemComponent REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0018-0409-0000-0000000FF1CE}_PROR_{397B1D4F-ED7B-4ACA-A637-43B670843876}
DisplayName REG_SZ Update for Microsoft Office Powerpoint 2007 Help (KB963669)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/963669
URLInfoAbout REG_SZ http://support.microsoft.com/kb/963669
HelpLink REG_SZ http://support.microsoft.com/kb/963669
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {397B1D4F-ED7B-4ACA-A637-43B670843876}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0019-0409-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-0019-0409-0000-0000000FF1CE}-C\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 43206 (0xa8c6)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Publisher MUI (English) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2E40DE55-B289-4C8B-8901-5D369B16814F}
DisplayName REG_SZ Update for Microsoft Office Publisher 2007 Help (KB963667)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/963667
URLInfoAbout REG_SZ http://support.microsoft.com/kb/963667
HelpLink REG_SZ http://support.microsoft.com/kb/963667
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {2E40DE55-B289-4C8B-8901-5D369B16814F}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
DisplayName REG_SZ Microsoft Office 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
SystemComponent REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-001A-0409-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-001A-0409-0000-0000000FF1CE}-C\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 58656 (0xe520)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Outlook MUI (English) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-001A-0409-0000-0000000FF1CE}_PROR_{0451F231-E3E3-4943-AB9F-58EB96171784}
DisplayName REG_SZ Update for Microsoft Office Outlook 2007 Help (KB963677)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/963677
URLInfoAbout REG_SZ http://support.microsoft.com/kb/963677
HelpLink REG_SZ http://support.microsoft.com/kb/963677
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {0451F231-E3E3-4943-AB9F-58EB96171784}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
DisplayName REG_SZ Microsoft Office 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
SystemComponent REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-001B-0409-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-001B-0409-0000-0000000FF1CE}-C\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 48093 (0xbbdd)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Word MUI (English) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
DisplayName REG_SZ Microsoft Office 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
SystemComponent REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-001B-0409-0000-0000000FF1CE}_PROR_{80E762AA-C921-4839-9D7D-DB62A72C0726}
DisplayName REG_SZ Update for Microsoft Office Word 2007 Help (KB963665)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/963665
URLInfoAbout REG_SZ http://support.microsoft.com/kb/963665
HelpLink REG_SZ http://support.microsoft.com/kb/963665
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {80E762AA-C921-4839-9D7D-DB62A72C0726}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-001F-0409-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-002C-0409-0000-0000000FF1CE}-C\Proof.en\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 57591 (0xe0f7)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Proof (English) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
DisplayName REG_SZ Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
SystemComponent REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-001F-040C-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-002C-0409-0000-0000000FF1CE}-C\Proof.fr\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 24444 (0x5f7c)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 1036 (0x40c)
DisplayName REG_SZ Microsoft Office Proof (French) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}
DisplayName REG_SZ Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
SystemComponent REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-001F-0C0A-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-002C-0409-0000-0000000FF1CE}-C\Proof.es\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 45861 (0xb325)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 3082 (0xc0a)
DisplayName REG_SZ Microsoft Office Proof (Spanish) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}
DisplayName REG_SZ Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
SystemComponent REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-002C-0409-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.4518.1014
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20081013
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-002C-0409-0000-0000000FF1CE}-C\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 506 (0x1fa)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201331110 (0xc0011a6)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Proofing (English) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-006E-0409-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-0115-0409-0000-0000000FF1CE}-C\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 76022 (0x128f6)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Shared MUI (English) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-006E-0409-0000-0000000FF1CE}_PROR_{AB365889-0395-4FAD-B702-CA5985D53D42}
DisplayName REG_SZ Update for Microsoft Office 2007 Help for Common Features (KB963673)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/963673
URLInfoAbout REG_SZ http://support.microsoft.com/kb/963673
HelpLink REG_SZ http://support.microsoft.com/kb/963673
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-006E-0409-0000-0000000FF1CE}_PROR_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
DisplayName REG_SZ Update for Microsoft Office Script Editor Help (KB963671)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/963671
URLInfoAbout REG_SZ http://support.microsoft.com/kb/963671
HelpLink REG_SZ http://support.microsoft.com/kb/963671
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}
DisplayName REG_SZ Microsoft Office 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
SystemComponent REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0115-0409-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-0115-0409-0000-0000000FF1CE}-C\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 502 (0x1f6)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Shared Setup Metadata MUI (English) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}
DisplayName REG_SZ Microsoft Office 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
SystemComponent REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0117-0409-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{90120000-0117-0409-0000-0000000FF1CE}-C\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 502 (0x1f6)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Access Setup Metadata MUI (English) 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
DisplayName REG_SZ Microsoft Office 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
SystemComponent REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{90850409-6000-11D3-8CFE-0150048383C9}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 11.0.8173.0
HelpLink REG_EXPAND_SZ http://www.microsoft.com/support
HelpTelephone REG_SZ
InstallDate REG_SZ 20090611
InstallLocation REG_SZ
InstallSource REG_SZ C:\MSOCache\All Users\90850409-6000-11D3-8CFE-0150048383C9\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{90850409-6000-11D3-8CFE-0150048383C9}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 101920 (0x18e20)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{90850409-6000-11D3-8CFE-0150048383C9}
URLInfoAbout REG_SZ http://www.microsoft.com/support
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 11 (0xb)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 184557549 (0xb001fed)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Word Viewer 2003
QuietUninstallString REG_SZ MsiExec.Exe /x {90850409-6000-11D3-8CFE-0150048383C9} /qn

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0012-0000-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.4518.1014
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090812
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{91120000-0012-0000-0000-0000000FF1CE}-C\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{91120000-0012-0000-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 89548 (0x15dcc)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{91120000-0012-0000-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201331110 (0xc0011a6)
Language REG_DWORD 0 (0x0)
DisplayName REG_SZ Microsoft Office Standard 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0014-0000-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6425.1000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090716
InstallLocation REG_SZ C:\Program Files\Microsoft Office\
InstallSource REG_SZ C:\MSOCache\All Users\{91120000-0014-0000-0000-0000000FF1CE}-C\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{91120000-0014-0000-0000-0000000FF1CE}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 1397692 (0x1553bc)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{91120000-0014-0000-0000-0000000FF1CE}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201333017 (0xc001919)
Language REG_DWORD 0 (0x0)
DisplayName REG_SZ Microsoft Office Professional 2007

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
DisplayName REG_SZ Microsoft Office 2007 Service Pack 2 (SP2)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/954711
URLInfoAbout REG_SZ http://support.microsoft.com/kb/954711
HelpLink REG_SZ http://support.microsoft.com/kb/954711
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{53C200F4-3B4B-49A5-8539-2C61F1A88CA2}
DisplayName REG_SZ Update for Outlook 2007 Junk Email Filter (kb971933)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/971933
URLInfoAbout REG_SZ http://support.microsoft.com/kb/971933
HelpLink REG_SZ http://support.microsoft.com/kb/971933
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {53C200F4-3B4B-49A5-8539-2C61F1A88CA2}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
DisplayName REG_SZ Security Update for Microsoft Office system 2007 (KB969613)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/969613
URLInfoAbout REG_SZ http://support.microsoft.com/kb/969613
HelpLink REG_SZ http://support.microsoft.com/kb/969613
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
DisplayName REG_SZ Security Update for 2007 Microsoft Office System (KB969559)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/969559
URLInfoAbout REG_SZ http://support.microsoft.com/kb/969559
HelpLink REG_SZ http://support.microsoft.com/kb/969559
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{74F98B24-AFBD-4800-9BD6-87D349B5C462}
DisplayName REG_SZ Update for Microsoft Office Outlook 2007 (KB969907)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/969907
URLInfoAbout REG_SZ http://support.microsoft.com/kb/969907
HelpLink REG_SZ http://support.microsoft.com/kb/969907
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {74F98B24-AFBD-4800-9BD6-87D349B5C462}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{7559E742-FF9F-4FAE-B279-008ED296CB4D}
DisplayName REG_SZ Security Update for Microsoft Office PowerPoint 2007 (KB957789)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/957789
URLInfoAbout REG_SZ http://support.microsoft.com/kb/957789
HelpLink REG_SZ http://support.microsoft.com/kb/957789
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
DisplayName REG_SZ Security Update for Microsoft Office Publisher 2007 (KB969693)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/969693
URLInfoAbout REG_SZ http://support.microsoft.com/kb/969693
HelpLink REG_SZ http://support.microsoft.com/kb/969693
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{C03803BD-745A-46F8-8557-817DED578780}
DisplayName REG_SZ Security Update for Microsoft Office Excel 2007 (KB969682)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/969682
URLInfoAbout REG_SZ http://support.microsoft.com/kb/969682
HelpLink REG_SZ http://support.microsoft.com/kb/969682
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}
DisplayName REG_SZ Update for 2007 Microsoft Office System (KB967642)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/967642
URLInfoAbout REG_SZ http://support.microsoft.com/kb/967642
HelpLink REG_SZ http://support.microsoft.com/kb/967642
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
NoRemove REG_DWORD 1 (0x1)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
DisplayName REG_SZ Security Update for 2007 Microsoft Office System (KB969679)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/969679
URLInfoAbout REG_SZ http://support.microsoft.com/kb/969679
HelpLink REG_SZ http://support.microsoft.com/kb/969679
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{CF3D6499-709C-43D0-8908-BC5652656050}
DisplayName REG_SZ Security Update for Microsoft Office Word 2007 (KB969604)
MoreInfoURL REG_SZ http://support.microsoft.com/kb/969604
URLInfoAbout REG_SZ http://support.microsoft.com/kb/969604
HelpLink REG_SZ http://support.microsoft.com/kb/969604
Publisher REG_SZ Microsoft
ParentKeyName REG_SZ PROR
ParentDisplayName REG_SZ Microsoft Office Professional 2007 Trial
UninstallString REG_SZ msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
NoRemove REG_DWORD 0 (0x0)
NoModify REG_DWORD 1 (0x1)
IsMinorUpgrade REG_DWORD 0 (0x0)
NoRepair REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{9422C8EA-B0C6-4197-B8FC-DC797658CA00}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 5.000.818.6
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090306
InstallLocation REG_SZ
InstallSource REG_SZ C:\Windows\SoftwareDistribution\Download\969d5e0decf4405a8c76196232e05be2\img\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{9422C8EA-B0C6-4197-B8FC-DC797658CA00}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 1981 (0x7bd)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{9422C8EA-B0C6-4197-B8FC-DC797658CA00}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 5 (0x5)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 83886898 (0x5000332)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Windows Live Sign-in Assistant

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{95120000-00B9-0409-0000-0000000FF1CE}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 12.0.6012.5000
HelpLink REG_EXPAND_SZ http://support.microsoft.com
HelpTelephone REG_SZ
InstallDate REG_SZ 20080725
InstallLocation REG_SZ
InstallSource REG_SZ C:\Windows\SoftwareDistribution\Download\bd29afd3f639530bf85ce5815b193bba\img\
NoModify REG_DWORD 1 (0x1)
NoRemove REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 9631 (0x259f)
SystemComponent REG_DWORD 1 (0x1)
URLInfoAbout REG_SZ http://support.microsoft.com
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 12 (0xc)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 201332604 (0xc00177c)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Application Error Reporting

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 14.0.8064.206
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090516
InstallLocation REG_SZ
InstallSource REG_SZ C:\Program Files\Common Files\Windows Live\.cache\a36691c9d6a3\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 2856 (0xb28)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 14 (0xe)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 234889088 (0xe001f80)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Windows Live Sync

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{A2BCA9F1-566C-4805-97D1-7FDC93386723}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 1.5.0.7220
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090811
InstallLocation REG_SZ
InstallSource REG_SZ c:\users\kirk\appdata\local\temp\air139f.tmp\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Publisher REG_SZ Adobe Systems Inc.
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 31047 (0x7947)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 1 (0x1)
VersionMinor REG_DWORD 5 (0x5)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 17104896 (0x1050000)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Adobe AIR

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 1.2.183.7
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090628
InstallLocation REG_SZ
InstallSource REG_SZ C:\Program Files\Google\Update\1.2.183.7\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Publisher REG_SZ Google Inc.
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 28 (0x1c)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 1 (0x1)
VersionMinor REG_DWORD 2 (0x2)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 16908471 (0x10200b7)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Google Update Helper

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{A939D341-5A04-4E0A-BB55-3E65B386432D}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 2.0.7024.0
HelpLink REG_EXPAND_SZ http://support.microsoft.com/
HelpTelephone REG_SZ
InstallDate REG_SZ 20081013
InstallLocation REG_SZ C:\Program Files\Microsoft Small Business\
InstallSource REG_SZ d:\128258114fb2955e75cadb\Loader\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{A939D341-5A04-4E0A-BB55-3E65B386432D}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 158 (0x9e)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{A939D341-5A04-4E0A-BB55-3E65B386432D}
URLInfoAbout REG_SZ http://www.microsoft.com/
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 2 (0x2)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 33561456 (0x2001b70)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Small Business Connectivity Components

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{AC76BA86-7AD7-1033-7B44-A91000000001}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ Customer Support
DisplayVersion REG_SZ 9.1.3
HelpLink REG_EXPAND_SZ http://www.adobe.com/support/main.html
HelpTelephone REG_SZ
InstallDate REG_SZ 20090812
InstallLocation REG_SZ
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Adobe\Updater6\Install\reader9rdr-en_US\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A91000000001}
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Adobe Systems Incorporated
Readme REG_EXPAND_SZ C:\Program Files\Adobe\Reader 9.0\Readme.htm
Size REG_SZ
EstimatedSize REG_DWORD 142515 (0x22cb3)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A91000000001}
URLInfoAbout REG_SZ http://www.adobe.com
URLUpdateInfo REG_SZ http://www.adobe.com/products/acrobat/readstep.html
VersionMajor REG_DWORD 9 (0x9)
VersionMinor REG_DWORD 1 (0x1)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 151060483 (0x9010003)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Adobe Reader 9.1.3

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{AC76BA86-7AD7-5464-3428-900000000004}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ This is a placeholder for ARP comments for Spelling Dictionaries for Adobe Reader 9.0
Contact REG_SZ Customer Support
DisplayVersion REG_SZ 9.0.0
HelpLink REG_EXPAND_SZ http://www.adobe.com/support/main.html
HelpTelephone REG_SZ 1-800-833-6687
InstallDate REG_SZ 20080830
InstallLocation REG_SZ
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Adobe\Updater6\Install\reader9rdr-en_US\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Adobe Systems Incorporated
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 31030 (0x7936)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
URLInfoAbout REG_SZ http://www.adobe.com
URLUpdateInfo REG_SZ http://www.adobe.com/acrofamily/main.html
VersionMajor REG_DWORD 9 (0x9)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 150994944 (0x9000000)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Spelling Dictionaries Support For Adobe Reader 9

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{B13A7C41581B411290FBC0395694E2A9}
DisplayName REG_SZ DivX Converter
InstallLocation REG_SZ C:\Program Files\DivX\DivX Converter
DisplayIcon REG_SZ C:\Program Files\DivX\DivX Converter\Converter.exe,0
Publisher REG_SZ DivX, Inc.
UninstallString REG_SZ C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DisplayVersion REG_SZ 6.6.1
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Locale REG_SZ en
RebootFlag REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{B391EECE-DFEA-4FC5-9D40-47FA43E2DBE6}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ Microsoft Office Accounting PayPal Addin
Contact REG_SZ
DisplayVersion REG_SZ 3.0.8231.0
HelpLink REG_EXPAND_SZ http://support.microsoft.com/
HelpTelephone REG_SZ
InstallDate REG_SZ 20081013
InstallLocation REG_SZ C:\Program Files\Microsoft Small Business\
InstallSource REG_SZ d:\128258114fb2955e75cadb\PayPal\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{B391EECE-DFEA-4FC5-9D40-47FA43E2DBE6}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 2179 (0x883)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{B391EECE-DFEA-4FC5-9D40-47FA43E2DBE6}
URLInfoAbout REG_SZ http://office.microsoft.com/
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 3 (0x3)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 50339879 (0x3002027)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Accounting 2008 PayPal Addin

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{B440D659-FECA-4BDD-A12B-5C9F05790FF3}
DisplayIcon REG_SZ C:\Program Files\TechSmith\Snagit 9\Snagit32.exe,0
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 9.1.2.304
HelpLink REG_EXPAND_SZ http://support.techsmith.com
HelpTelephone REG_SZ
InstallDate REG_SZ 20090811
InstallLocation REG_SZ C:\Program Files\TechSmith\Snagit 9\
InstallSource REG_SZ C:\Program Files\Common Files\Wise Installation Wizard\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{B440D659-FECA-4BDD-A12B-5C9F05790FF3}
Publisher REG_SZ TechSmith Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 63506 (0xf812)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{B440D659-FECA-4BDD-A12B-5C9F05790FF3}
URLInfoAbout REG_SZ http://www.techsmith.com
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 9 (0x9)
VersionMinor REG_DWORD 1 (0x1)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 151060482 (0x9010002)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Snagit 9.1.2

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{B4FEA924-630D-11D4-B78E-005004566E4D}
UninstallString REG_SZ RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B4FEA924-630D-11D4-B78E-005004566E4D}\Setup.exe" -l0x9
DisplayName REG_SZ Optiquest Monitor Drivers
LogFile REG_SZ C:\Program Files\InstallShield Installation Information\{B4FEA924-630D-11D4-B78E-005004566E4D}\setup.ilg

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{B535B621-5559-11DE-A7A1-005056806466}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 5.0.11738.1858
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090628
InstallLocation REG_SZ C:\Program Files\Google\Google Earth Plugin\
InstallSource REG_SZ C:\Windows\Temp\7ZipSfx.000\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{B535B621-5559-11DE-A7A1-005056806466}
Publisher REG_SZ Google
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 33290 (0x820a)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{B535B621-5559-11DE-A7A1-005056806466}
URLInfoAbout REG_SZ http://www.Google.com
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 5 (0x5)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 83897818 (0x5002dda)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Google Earth Plugin

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{B7050CBDB2504B34BC2A9CA0A692CC29}
DisplayName REG_SZ DivX Web Player
InstallLocation REG_SZ C:\Program Files\DivX\DivX Web Player
DisplayIcon REG_SZ C:\Program Files\DivX\DivX Web Player\npdivx32.dll,0
Publisher REG_SZ DivX,Inc.
UninstallString REG_SZ C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DisplayVersion REG_SZ 1.4.0
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Locale REG_SZ en
RebootFlag REG_DWORD 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{BB8B979E-E336-47E7-96BC-1031C1B94561}
SystemComponent REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 9.00.4035.00
HelpLink REG_EXPAND_SZ http://go.microsoft.com/fwlink/?LinkId=52153
HelpTelephone REG_SZ
InstallDate REG_SZ 20090319
InstallLocation REG_SZ C:\Program Files\Microsoft SQL Server\
InstallSource REG_SZ d:\7e442af05ab748982d6b3c349c2e05\setup\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 2669 (0xa6d)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 9 (0x9)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 150998979 (0x9000fc3)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft SQL Server Native Client

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{C6CA8874-5F22-4AF0-9BE3-016BF299C536}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 14.0.8064.206
HelpLink REG_EXPAND_SZ http://support.live.com/
HelpTelephone REG_SZ
InstallDate REG_SZ 20090516
InstallLocation REG_SZ
InstallSource REG_SZ C:\Program Files\Common Files\Windows Live\.cache\a33297f11c9d6a2\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{C6CA8874-5F22-4AF0-9BE3-016BF299C536}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 1255 (0x4e7)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{C6CA8874-5F22-4AF0-9BE3-016BF299C536}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 14 (0xe)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 234889088 (0xe001f80)
Language REG_DWORD 9 (0x9)
DisplayName REG_SZ Windows Live Essentials

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ AppleCare Support
DisplayVersion REG_SZ 7.62.14.0
HelpLink REG_EXPAND_SZ http://www.apple.com/support/
HelpTelephone REG_SZ 1-800-275-2273
InstallDate REG_SZ 20090617
InstallLocation REG_SZ C:\Program Files\QuickTime\
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Apple\Apple Software Update\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
Publisher REG_SZ Apple Inc.
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 76435 (0x12a93)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
URLInfoAbout REG_SZ http://www.apple.com
URLUpdateInfo REG_SZ http://www.apple.com/quicktime/
VersionMajor REG_DWORD 7 (0x7)
VersionMinor REG_DWORD 62 (0x3e)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 121503758 (0x73e000e)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ QuickTime

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{CC016F21-3970-11DE-B878-005056806466}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 5.0.11733.9347
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090519
InstallLocation REG_SZ C:\Program Files\Google\Google Earth\
InstallSource REG_SZ C:\Windows\Temp\7ZipSfx.000\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{CC016F21-3970-11DE-B878-005056806466}
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Google
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 33005 (0x80ed)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{CC016F21-3970-11DE-B878-005056806466}
URLInfoAbout REG_SZ http://earth.google.com
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 5 (0x5)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 83897813 (0x5002dd5)
Language REG_DWORD 0 (0x0)
DisplayName REG_SZ Google Earth

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 3.5.30729
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090627
InstallLocation REG_SZ
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp\IXP0675A.tmp\dotnetfx35\x86\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 72486 (0x11b26)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 3 (0x3)
VersionMinor REG_DWORD 5 (0x5)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 50690057 (0x3057809)
Language REG_DWORD 0 (0x0)
DisplayName REG_SZ Microsoft .NET Framework 3.5 SP1

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB350003
<NO NAME> REG_SZ KB350003
NoRemove REG_DWORD 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
ReleaseType REG_SZ Hotfix
NoRemove REG_DWORD 1 (0x1)
<NO NAME> REG_SZ KB953595
Comments REG_SZ This hotfix is for Microsoft .NET Framework 3.5 SP1.
If you later install a more recent service pack, this hotfix will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/953595.
DisplayName REG_SZ Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
DisplayVersion REG_SZ 1
HelpLink REG_SZ http://support.microsoft.com/kb/953595
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
ParentKeyName REG_SZ Microsoft .NET Framework 3.5 SP1
ParentDisplayName REG_SZ Microsoft .NET Framework 3.5 SP1
Publisher REG_SZ Microsoft Corporation
RegistryLocation REG_SZ HKEY_LOCAL_MACHINE\Software\Microsoft\Updates\Microsoft .NET Framework 3.5 SP1\KB953595
UninstallString REG_SZ C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
URLInfoAbout REG_SZ http://support.microsoft.com

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
<NO NAME> REG_SZ KB958484
ReleaseType REG_SZ Hotfix
Comments REG_SZ This hotfix is for Microsoft .NET Framework 3.5 SP1.
If you later install a more recent service pack, this hotfix will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/958484.
DisplayName REG_SZ Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
DisplayVersion REG_SZ 1
HelpLink REG_SZ http://support.microsoft.com/kb/958484
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
ParentDisplayName REG_SZ Microsoft .NET Framework 3.5 SP1
ParentKeyName REG_SZ Microsoft .NET Framework 3.5 SP1
Publisher REG_SZ Microsoft Corporation
RegistryLocation REG_SZ HKEY_LOCAL_MACHINE\Software\Microsoft\Updates\Microsoft .NET Framework 3.5 SP1\SP1\KB958484
UninstallString REG_SZ C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
URLInfoAbout REG_SZ http://support.microsoft.com

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB960043
NoRemove REG_DWORD 1 (0x1)
<NO NAME> REG_SZ KB960043

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
<NO NAME> REG_SZ KB963707
ReleaseType REG_SZ Update
Comments REG_SZ This update is for Microsoft .NET Framework 3.5 SP1.
If you later install a more recent service pack, this update will be uninstalled automatically.
For more information, visit http://support.microsoft.com/kb/963707.
DisplayName REG_SZ Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
DisplayVersion REG_SZ 1
HelpLink REG_SZ http://support.microsoft.com/kb/963707
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
ParentDisplayName REG_SZ Microsoft .NET Framework 3.5 SP1
ParentKeyName REG_SZ Microsoft .NET Framework 3.5 SP1
Publisher REG_SZ Microsoft Corporation
RegistryLocation REG_SZ HKEY_LOCAL_MACHINE\Software\Microsoft\Updates\Microsoft .NET Framework 3.5 SP1\SP1\KB963707
UninstallString REG_SZ C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
URLInfoAbout REG_SZ http://support.microsoft.com

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{D032A7F0-8B5C-4603-8B46-235025D5F9C1}
UninstallString REG_SZ RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D032A7F0-8B5C-4603-8B46-235025D5F9C1}\setup.exe" -l0x9 anything -removeonly
LogFile REG_SZ C:\Program Files\InstallShield Installation Information\{D032A7F0-8B5C-4603-8B46-235025D5F9C1}\setup.ilg
InstallLocation REG_SZ C:\Program Files\TechniSat DVB
ProductGuid REG_SZ {D032A7F0-8B5C-4603-8B46-235025D5F9C1}
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp\Temp1_1695.dvb.pc.4.4.3[1].zip\4_4_3_Release\Install\
DisplayName REG_SZ TechniSat DVB-PC TV Star
Publisher REG_SZ TechniSat
URLInfoAbout REG_SZ www.technisat.com
Contact REG_SZ Technical Support
RegOwner REG_SZ Kirk
NoModify REG_DWORD 1 (0x1)
NoRemove REG_DWORD 0 (0x0)
NoRepair REG_DWORD 1 (0x1)
InstallDate REG_SZ 20080711
Language REG_DWORD 9 (0x9)
DisplayVersion REG_SZ 4.3.3
Version REG_DWORD 67305475 (0x4030003)
MajorVersion REG_DWORD 4 (0x4)
MinorVersion REG_DWORD 3 (0x3)
LogMode REG_DWORD 1 (0x1)
DisplayIcon REG_SZ C:\Program Files\TechniSat DVB\BIN\TechniSat.ico

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{D6C9AF27-9414-46C8-B9D8-D878BA041033}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ Nero AG
Contact REG_SZ http://www.nero.com
DisplayVersion REG_SZ 8.3.314
HelpLink REG_EXPAND_SZ http://support.nero.com
HelpTelephone REG_SZ xxxxxxxxxxxxxx
InstallDate REG_SZ 20081222
InstallLocation REG_SZ C:\Program Files\Nero\Nero8\
InstallSource REG_SZ C:\Users\Kirk\Desktop\Media\ahead_nero_burning_rom_v8.3.6.0_en_+_keygen\Data\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{D6C9AF27-9414-46C8-B9D8-D878BA041033}
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Nero AG
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 1786283 (0x1b41ab)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{D6C9AF27-9414-46C8-B9D8-D878BA041033}
URLInfoAbout REG_SZ http://www.nero.com/
URLUpdateInfo REG_SZ http://support.nero.com
VersionMajor REG_DWORD 8 (0x8)
VersionMinor REG_DWORD 3 (0x3)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 134414650 (0x803013a)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Nero 8 Ultra Edition HD

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 8.0.7
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090803
InstallLocation REG_SZ C:\Program Files\Lavasoft\Ad-Aware
InstallSource REG_SZ C:\Users\Kirk\AppData\Local\Temp\mia1\
NoModify REG_DWORD 1 (0x1)
NoRemove REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Lavasoft
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 86576 (0x15230)
SystemComponent REG_DWORD 1 (0x1)
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 8 (0x8)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 134217735 (0x8000007)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Ad-Aware
UninstallString REG_SZ C:\ProgramData\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{E0BA659A-45CC-4EC2-AA1C-E73CAFC6408B}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 16.00.0000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090715
InstallLocation REG_SZ C:\Program Files\Autodesk\Alias2010\
InstallSource REG_SZ E:\Alias\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{E0BA659A-45CC-4EC2-AA1C-E73CAFC6408B}
Publisher REG_SZ Autodesk
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 1052317 (0x100e9d)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{E0BA659A-45CC-4EC2-AA1C-E73CAFC6408B}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 16 (0x10)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 268435456 (0x10000000)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Autodesk Alias 2010

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{E2EF186D-5853-4734-8758-1E1B843E5DF1}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 16.00.0000
HelpLink REG_SZ
HelpTelephone REG_SZ
InstallDate REG_SZ 20090715
InstallLocation REG_SZ 0
InstallSource REG_SZ E:\Alias\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{E2EF186D-5853-4734-8758-1E1B843E5DF1}
Publisher REG_SZ Autodesk
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 430901 (0x69335)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{E2EF186D-5853-4734-8758-1E1B843E5DF1}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 16 (0x10)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 268435456 (0x10000000)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Autodesk Alias 2010 Documentation

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{E3DF6916-2472-43D9-8B3C-9F2F0AAB01B5}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ Microsoft Office Accounting Fixed Asset Manager
Contact REG_SZ
DisplayVersion REG_SZ 3.0.8231.0
HelpLink REG_EXPAND_SZ http://support.microsoft.com/
HelpTelephone REG_SZ
InstallDate REG_SZ 20081013
InstallLocation REG_SZ C:\Program Files\Microsoft Small Business\
InstallSource REG_SZ d:\128258114fb2955e75cadb\FAM\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{E3DF6916-2472-43D9-8B3C-9F2F0AAB01B5}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 4988 (0x137c)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{E3DF6916-2472-43D9-8B3C-9F2F0AAB01B5}
URLInfoAbout REG_SZ http://www.microsoft.com/
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 3 (0x3)
VersionMinor REG_DWORD 0 (0x0)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 50339879 (0x3002027)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft Office Accounting 2008 Fixed Asset Manager

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{EE4ACABF-531E-419A-9225-B8E0FA4955AF}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 03.01.0620.00
HelpLink REG_EXPAND_SZ http://go.microsoft.com/fwlink/?LinkID=71730
HelpTelephone REG_SZ
InstallDate REG_SZ 20090203
InstallLocation REG_SZ
InstallSource REG_SZ D:\5bbfdf46d3cfadb8411edee2\packages\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{EE4ACABF-531E-419A-9225-B8E0FA4955AF}
NoModify REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 480 (0x1e0)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{EE4ACABF-531E-419A-9225-B8E0FA4955AF}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 3 (0x3)
VersionMinor REG_DWORD 1 (0x1)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 50397804 (0x301026c)
Language REG_DWORD 3082 (0xc0a)
DisplayName REG_SZ Zune Language Pack (ES)

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 3.1.0000
HelpLink REG_EXPAND_SZ http://www.microsoft.com/sql/everywhere
HelpTelephone REG_SZ
InstallDate REG_SZ 20090516
InstallLocation REG_SZ C:\Program Files\Microsoft SQL Server Compact Edition\
InstallSource REG_SZ C:\Program Files\Common Files\Windows Live\.cache\ebd0fc871c9d6a2\
ModifyPath REG_EXPAND_SZ MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 1783 (0x6f7)
UninstallString REG_EXPAND_SZ MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 3 (0x3)
VersionMinor REG_DWORD 1 (0x1)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 50397184 (0x3010000)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Microsoft SQL Server 2005 Compact Edition [ENU]

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{FF70513F-E3A7-402F-84FB-B7810A064BE2}
AuthorizedCDFPrefix REG_SZ
Comments REG_SZ
Contact REG_SZ
DisplayVersion REG_SZ 03.01.0620.00
HelpLink REG_EXPAND_SZ http://go.microsoft.com/fwlink/?LinkID=71730
HelpTelephone REG_SZ
InstallDate REG_SZ 20090203
InstallLocation REG_SZ
InstallSource REG_SZ D:\5bbfdf46d3cfadb8411edee2\packages\
ModifyPath REG_EXPAND_SZ MsiExec.exe /X{FF70513F-E3A7-402F-84FB-B7810A064BE2}
NoModify REG_DWORD 1 (0x1)
NoRepair REG_DWORD 1 (0x1)
Publisher REG_SZ Microsoft Corporation
Readme REG_SZ
Size REG_SZ
EstimatedSize REG_DWORD 153127 (0x25627)
SystemComponent REG_DWORD 1 (0x1)
UninstallString REG_EXPAND_SZ MsiExec.exe /X{FF70513F-E3A7-402F-84FB-B7810A064BE2}
URLInfoAbout REG_SZ
URLUpdateInfo REG_SZ
VersionMajor REG_DWORD 3 (0x3)
VersionMinor REG_DWORD 1 (0x1)
WindowsInstaller REG_DWORD 1 (0x1)
Version REG_DWORD 50397804 (0x301026c)
Language REG_DWORD 1033 (0x409)
DisplayName REG_SZ Zune

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{PRODUCT}
NoModify REG_DWORD 1 (0x1)

SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\uninstall

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\uninstall\Google Chrome
Blade81
Hi,

Was that full contents? To be sure everything gets included, please attach the file as an attachment instead of posting contents.
Bowtie41
Blade,
Sorry.It looked like the whole thing when I looked at it,but here it is attached.
Thank You.
Kirk
Blade81
Thanks, Kirk. I'll be back with next instructions asap (have to share the results with ComboFix author).
Blade81
Ok. Let's continue smile.gif

Open notepad and then copy and paste the bolded line below into it. Go to File > save as and name the file fixes.bat, change the Save as type to all files and save it to your desktop.
xcopy /e/c/i/g/h/r/k/o/y C:\WINDOWS\erdnt\Hiv-backup \QooBox\hiv-backup

Double-click on fixes.bat file to execute it.

Let me know if you experience any problems there.

Save text below as fix.reg on Notepad (save it as all files (*.*)) on the Desktop.

CODE
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall]
"UninstallString"=-
"InstallLocation"=-
"DisplayName"=-
"DisplayIcon"=-


It should look like this ->

Doubleclick fix.reg, press Yes and ok.

When done, run ComboFix again and post back its report & fresh dds.txt & attach.txt logs.
Bowtie41
Okay,
Let's see if I can remember all of this,lol.
I disabled firewall and AA.
I did the fixes.bat,and a DOS window opened,it scrolled a few lines and closed.
I did the fix.reg,I ran it and nothing appeared to happen.
I ran combofix again,it said a newer version was available,so I updated and ran it.After the reboot and the log was made,I was unable to open browser or anything like before,so I did as you suggested before and rebooted manually,and that took care of it smile.gif .
I reran DDS.
Logs are below.
Thank You again!
Kirk

ComboFix 09-09-08.01 - Kirk 09/08/2009 15:35.1.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.959.434 [GMT -5:00]
Running from: c:\users\Kirk\Desktop\Combo-Fix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Installer\1e2ea4d.msi
c:\windows\Installer\1e2ea54.msp
c:\windows\Installer\1e2ea77.msp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ESQULserv.sys
-------\Legacy_SKYNET
-------\Service_ESQULserv.sys
-------\Service_SKYNET


((((((((((((((((((((((((( Files Created from 2009-08-08 to 2009-09-08 )))))))))))))))))))))))))))))))
.

2009-09-08 20:45 . 2009-09-08 20:48 -------- d-----w- c:\users\Kirk\AppData\Local\temp
2009-09-08 20:45 . 2009-09-08 20:45 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-09-08 20:45 . 2009-09-08 20:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-07 07:44 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-09-07 07:44 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-09-07 07:44 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-07 07:44 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
2009-09-07 07:44 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2009-09-07 07:44 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-09-07 07:44 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
2009-09-07 07:44 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
2009-09-06 08:07 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-09-06 01:11 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-09-06 01:11 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-09-06 01:11 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-09-06 01:11 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-09-06 01:11 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-06 01:11 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-20 06:19 . 2009-08-20 06:19 -------- d-----w- c:\program files\Java
2009-08-18 21:34 . 2009-08-18 21:34 -------- d-----w- c:\program files\ERUNT
2009-08-17 11:05 . 2009-08-17 11:05 -------- d-----w- c:\users\Kirk\AppData\Local\Live_TV
2009-08-12 01:18 . 2009-08-12 01:18 -------- d-----w- c:\users\Kirk\AppData\Roaming\TechSmith
2009-08-12 00:02 . 2009-08-12 00:02 -------- d-----w- c:\programdata\TechSmith
2009-08-12 00:02 . 2009-08-12 00:02 -------- d-----w- c:\users\Kirk\AppData\Local\TechSmith
2009-08-12 00:02 . 2009-08-12 00:02 -------- d-----w- c:\program files\TechSmith
2009-08-12 00:00 . 2009-08-12 00:00 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-11 15:57 . 2009-08-11 15:57 -------- d-----w- c:\users\Kirk\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-08-11 15:56 . 2009-08-11 15:56 -------- d-----w- c:\program files\Common Files\Adobe AIR

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-08 20:47 . 2008-07-11 04:44 1356 ----a-w- c:\users\Kirk\AppData\Local\d3d9caps.dat
2009-09-08 08:06 . 2008-10-13 20:46 -------- d-----w- c:\programdata\Microsoft Help
2009-09-07 20:45 . 2009-02-02 23:44 -------- d-----w- c:\programdata\Google Updater
2009-09-06 08:16 . 2008-07-14 05:40 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-06 08:03 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-05 20:12 . 2008-08-15 21:03 -------- d-----w- c:\users\Kirk\AppData\Roaming\ContentGuard
2009-08-20 06:19 . 2008-12-19 10:49 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-17 11:05 . 2009-08-04 18:57 -------- d-----w- c:\program files\Live_TV
2009-08-17 11:05 . 2009-08-04 18:57 -------- d-----w- c:\program files\Conduit
2009-08-12 05:40 . 2008-10-13 16:08 -------- d-----w- c:\users\Kirk\AppData\Roaming\GetRightToGo
2009-08-04 19:23 . 2009-08-04 19:23 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-08-04 13:03 . 2009-08-04 13:03 -------- d-----w- c:\program files\Trend Micro
2009-08-04 01:37 . 2009-08-04 01:27 -------- d-----w- c:\programdata\Lavasoft
2009-08-04 01:27 . 2009-08-04 01:27 -------- dc-h--w- c:\programdata\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-04 01:27 . 2009-08-04 01:27 -------- d-----w- c:\program files\Lavasoft
2009-08-03 23:12 . 2009-03-05 00:07 -------- d-----w- c:\programdata\McAfee
2009-08-03 23:12 . 2009-03-18 00:54 -------- d-----w- c:\program files\Common Files\McAfee
2009-08-03 23:11 . 2009-03-18 00:53 -------- d-----w- c:\program files\McAfee
2009-08-03 19:42 . 2008-08-08 23:12 -------- d-----w- c:\program files\Coupons
2009-07-21 05:21 . 2008-07-31 07:31 172912 ---ha-w- c:\windows\system32\mlfcache.dat
2009-07-20 02:30 . 2009-07-20 02:30 4096 ----a-w- c:\windows\d3dx.dat
2009-07-20 02:27 . 2009-07-20 02:27 552 ----a-w- c:\users\Kirk\AppData\Local\d3d8caps.dat
2009-07-20 02:26 . 2009-02-06 15:23 -------- d-----w- c:\program files\The Price Is Right
2009-07-18 16:06 . 2009-09-06 01:12 827904 ----a-w- c:\windows\system32\wininet.dll
2009-07-18 16:01 . 2009-09-06 01:12 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-18 09:46 . 2009-09-06 01:12 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:35 . 2009-09-06 01:12 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-16 23:36 . 2009-07-16 23:35 3277 ----a-w- C:\awFLEXLM.dat
2009-07-16 04:28 . 2009-07-16 04:28 -------- d-----w- c:\users\Kirk\AppData\Roaming\Autodesk
2009-07-16 03:32 . 2009-07-16 02:37 -------- d-----w- c:\program files\Autodesk
2009-07-16 03:14 . 2009-07-16 02:37 -------- d-----w- c:\program files\Common Files\Alias Shared
2009-07-16 03:12 . 2009-07-16 03:12 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2009-07-03 14:49 . 2009-08-04 01:37 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-03 14:49 . 2009-08-04 05:19 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-27 18:12 . 2008-07-11 04:45 104248 ----a-w- c:\users\Kirk\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-15 15:24 . 2009-07-15 10:49 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 15:20 . 2009-07-15 10:49 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 15:20 . 2009-07-15 10:49 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:52 . 2009-07-15 10:49 289792 ----a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zinio DLM"="c:\program files\Zinio\ZinioReader.exe" [2008-07-08 3874886]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Zune Launcher"="c:\users\Kirk\Downloads\1695.dvb.pc.4.4.3\Zune\ZuneLauncher.exe" [2008-11-10 157312]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"AmazonGSDownloaderTray"="c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-02-02 246272]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-25 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-20 149280]

c:\users\Kirk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Server4PC.lnk - c:\program files\TechniSat DVB\bin\Server4PC.exe [2008-7-11 338448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E6B77BCC-89C6-466A-9985-8446164FBFE9}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C2C61E87-73E6-4C7F-8432-813998F6F46E}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{BD42AE93-415F-4E1A-BA9E-36C363AB003A}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{6EB61C02-E80B-4035-A7DF-EF56EACB465A}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{4FAB8BC1-ADA5-4B47-A3F8-C69C6CC622AA}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{EDB07C8F-B1A2-4C7F-B34F-640B79BAAA79}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{B30CC371-7C9E-48F0-AB4A-140F20358DA4}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{CB829BD1-BC37-41A2-AB22-15718DBE33B4}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{4E6DC5CE-F86D-463D-BE06-D1CDBDE941BC}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D2D5F2E2-4D0E-4388-9BE7-E645DFE1A6A2}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{C48E482A-A1F4-43FD-95C7-4954D34F1FF6}c:\\done\\done\\tmd-recruit.5.1\\mirc.exe"= UDP:c:\done\done\tmd-recruit.5.1\mirc.exe:mIRC
"UDP Query User{70D64D7E-0509-4D9F-AF5B-9EAF022E2207}c:\\done\\done\\tmd-recruit.5.1\\mirc.exe"= TCP:c:\done\done\tmd-recruit.5.1\mirc.exe:mIRC
"TCP Query User{B6DC8950-31AF-4945-A892-0E4F0E52DEDA}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{E7200DC0-AE53-409E-94AC-2CDB8A32D32B}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [8/3/2009 8:37 PM 64160]
R2 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2/6/2009 9:10 AM 317440]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712]
S2 gupdate1c98590c9c1b434;Google Update Service (gupdate1c98590c9c1b434);c:\program files\Google\Update\GoogleUpdate.exe [2/2/2009 6:48 PM 133104]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
.
Contents of the 'Scheduled Tasks' folder

2009-09-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]

2009-09-08 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-02 09:12]

2009-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-02 23:48]

2009-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-02 23:48]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://att.my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: electronicarts.com
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: pogo.com
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game13.zylom.com/activex/zylomgamesplayer.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-08 15:48
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Kontiki\KService.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\System32\IoctlSvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\System32\WUDFHost.exe
c:\windows\ehome\ehmsas.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-09-08 15:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-08 20:56
ComboFix2.txt 2009-09-05 23:25

Pre-Run: 12,315,414,528 bytes free
Post-Run: 12,254,289,920 bytes free

213 --- E O F --- 2009-09-08 08:09



DDS (Ver_09-07-30.01) - NTFSx86
Run by Kirk at 16:10:00.16 on Tue 09/08/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.959.387 [GMT -5:00]

SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Users\Kirk\Downloads\1695.dvb.pc.4.4.3\Zune\ZuneLauncher.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\system32\IoctlSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Kirk\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://att.my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Live TV Toolbar: {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - c:\program files\live_tv\tbLive.dll
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Live TV Toolbar: {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - c:\program files\live_tv\tbLive.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll
TB: Live TV Toolbar: {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - c:\program files\live_tv\tbLive.dll
uRun: [Zinio DLM] c:\program files\zinio\ZinioReader.exe /autostart
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Zune Launcher] "c:\users\kirk\downloads\1695.dvb.pc.4.4.3\zune\ZuneLauncher.exe"
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [AmazonGSDownloaderTray] c:\program files\amazon\amazon games & software downloader\AmazonGSDownloaderTray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\users\kirk\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\server~1.lnk - c:\program files\technisat dvb\bin\Server4PC.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: electronicarts.com
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: pogo.com
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {588031A3-94BF-4CDD-86D0-939F6F93910F} - hxxps://fixit.support.microsoft.com/ActiveX/FixItClient.CAB
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game13.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-8-3 64160]
R2 Amazon Download Agent;Amazon Download Agent;c:\program files\amazon\amazon games & software downloader\AmazonGSDownloaderService.exe [2009-2-6 317440]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2008-11-24 29263712]
S2 gupdate1c98590c9c1b434;Google Update Service (gupdate1c98590c9c1b434);c:\program files\google\update\GoogleUpdate.exe [2009-2-2 133104]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]

=============== Created Last 30 ================

2009-09-08 15:53 <DIR> --dsh--- C:\$RECYCLE.BIN
2009-09-08 15:32 <DIR> --d----- C:\Combo-Fix
2009-09-07 02:44 499,712 a------- c:\windows\system32\kerberos.dll
2009-09-07 02:44 213,504 a------- c:\windows\system32\msv1_0.dll
2009-09-07 02:44 175,104 a------- c:\windows\system32\wdigest.dll
2009-09-07 02:44 1,256,448 a------- c:\windows\system32\lsasrv.dll
2009-09-07 02:44 270,848 a------- c:\windows\system32\schannel.dll
2009-09-07 02:44 439,896 a------- c:\windows\system32\drivers\ksecdd.sys
2009-09-07 02:44 72,704 a------- c:\windows\system32\secur32.dll
2009-09-07 02:44 9,728 a------- c:\windows\system32\lsass.exe
2009-09-06 03:07 2,048 a------- c:\windows\system32\tzres.dll
2009-09-05 20:11 313,344 a------- c:\windows\system32\wmpdxm.dll
2009-09-05 20:11 7,680 a------- c:\windows\system32\spwmp.dll
2009-09-05 20:11 4,096 a------- c:\windows\system32\msdxm.ocx
2009-09-05 20:11 4,096 a------- c:\windows\system32\dxmasf.dll
2009-09-05 20:11 8,147,456 a------- c:\windows\system32\wmploc.DLL
2009-09-05 20:11 43,520 a------- c:\windows\system32\msdxm.tlb
2009-09-05 20:11 18,432 a------- c:\windows\system32\amcompat.tlb
2009-09-05 20:11 28,672 a------- c:\windows\system32\Apphlpdm.dll
2009-09-05 20:11 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-05 17:37 230,912 a------- c:\windows\PEV.exe
2009-09-05 17:37 161,792 a------- c:\windows\SWREG.exe
2009-09-05 17:37 98,816 a------- c:\windows\sed.exe
2009-08-11 20:18 <DIR> --d----- c:\users\kirk\appdata\roaming\TechSmith
2009-08-11 19:02 <DIR> --d----- c:\programdata\TechSmith
2009-08-11 19:00 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-08-11 10:57 <DIR> --d----- c:\users\kirk\appdata\roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

==================== Find3M ====================

2009-08-28 07:39 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 07:38 2,153,984 a------- c:\windows\apppatch\AcGenral.dll
2009-08-28 07:38 541,696 a------- c:\windows\apppatch\AcLayers.dll
2009-08-28 07:38 459,776 a------- c:\windows\apppatch\AcSpecfc.dll
2009-08-20 01:19 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-04 14:23 2,560 a------- c:\windows\_MSRSTRT.EXE
2009-07-21 00:21 172,912 a---h--- c:\windows\system32\mlfcache.dat
2009-07-19 21:30 4,096 a------- c:\windows\d3dx.dat
2009-07-18 11:06 827,904 a------- c:\windows\system32\wininet.dll
2009-07-18 11:01 78,336 a------- c:\windows\system32\ieencode.dll
2009-07-18 04:46 26,624 a------- c:\windows\system32\ieUnatt.exe
2009-07-17 09:35 71,680 a------- c:\windows\system32\atl.dll
2009-07-16 18:36 3,277 a------- C:\awFLEXLM.dat
2009-07-03 09:49 15,688 a------- c:\windows\system32\lsdelete.exe
2009-06-17 20:43 51,200 a------- c:\windows\inf\infpub.dat
2009-06-17 20:43 86,016 a------- c:\windows\inf\infstrng.dat
2009-06-17 20:43 86,016 a------- c:\windows\inf\infstor.dat
2009-06-15 10:24 156,672 a------- c:\windows\system32\t2embed.dll
2009-06-15 10:20 72,704 a------- c:\windows\system32\fontsub.dll
2009-06-15 10:20 10,240 a------- c:\windows\system32\dciman32.dll
2009-06-15 07:52 289,792 a------- c:\windows\system32\atmfd.dll
2009-03-05 01:01 174 a--sh--- c:\program files\desktop.ini
2008-10-03 12:10 473,823 a--sh--- c:\users\kirk\css.exe
2008-10-03 12:10 100,775 a--sh--- c:\users\kirk\sccs.exe
2008-10-03 12:10 10,961 a--sh--- c:\users\kirk\MediaTubeCodec_ver1.1463.0.exe
2008-07-26 23:19 665,600 a------- c:\windows\inf\drvindex.dat
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib409\perfi.dat
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib409\perfh.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib409\perfd.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib409\perfc.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib00\perfi.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib00\perfh.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib00\perfd.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib00\perfc.dat
2009-05-21 23:26 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-05-21 23:26 32,768 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-05-21 23:26 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat

============= FINISH: 16:11:33.56 ===============
Blade81
Great. That went well smile.gif

Show hidden files (Vista)
-----------------
1. Open Folder Options by clicking the Start button, clicking Control Panel, clicking Appearance and Personalization, and then clicking Folder Options.
2. Click the View tab.
3. Under Advanced settings, click Show hidden files and folders, and then click OK.

Upload these to http://www.virustotal.com and post back links to the results:
c:\users\kirk\css.exe
c:\users\kirk\sccs.exe

Let me also know how's the system running.
Bowtie41
Blade,
Well,THAT was very disheartening to say the least!

The instructions to the show hidden files wasn't right for my system.I had to:
Start,Control Panel,(Go right to Folder Options),View Tab,then remembered I had it ticked on anyway,lol laugh.gif

Here is the link for the css:
http://www.virustotal.com/analisis/762fd2b...77d4-1252518188

and the sccs:
http://www.virustotal.com/analisis/478c92e...3c0e-1252518429

As far as how the systems running....................................
The Vimax ads have been gone a couple days now.Thank You for that!

The Google redirects are gone,Thank You!

Since I did my last cache clear and update on java,my pogo is working again,the whole family thanks you for that! rolleyes.gif

Today,all of a sudden,I'm able to get the link for my router to work.My daughter hates that because I can turn off her wireless,and leave MY hardwire on.Thank You for that!!

Other than that,the system is really slow.It takes almost a minute to log in here now.Another example.When I'm at my email panel,like this morning,I had clicked on about 15 messages to delete them,it took about a minute for the ticks to show up,and then about 30 seconds more to delete them.Also,if I scroll down a page,it may take 5-10 seconds for the window to move after the mouse does.However,typing usually isn't too bad,but on some online forms,it also has a lag.
At first,I thought it may just be my internet connection(I'm on DSL),so I fired up the laptop to see if it did the same.Result,BSOD(Gosh,I love Windows).I rebooted the laptop,and it seems okay.It just crashed again while typing this,lol.That's not normal for that machine(reason:IRQL less or not equal or something like that,but that's for another session)
Anway,after this system rebooted,it is better,but still slow.The reason for BSOD here was Memory Management I think.Maybe it has a bad stick,but the system isn't that old,and the memory was replaced last year,first time I remember seeing that reason.
Hope this helps,and Thanks for what you've done so far!
Kirk
Blade81
Hi,

Open notepad and copy/paste the text in the quotebox below into it:

CODE
http://www.lavasoftsupport.com/index.php?showtopic=26748&st=20&start=20
Collect::
c:\users\kirk\css.exe
c:\users\kirk\sccs.exe
c:\users\kirk\MediaTubeCodec_ver1.1463.0.exe



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe. You'll be asked to submit some samples. Follow the instructions there.
Then post the resultant log.


Have you defragged hard drive lately? That might help. For defragging I'd use 3rd party solution. Good commercial ones are PerfectDisk and Diskeeper. Of free options I recommend JkDefrag.

Bowtie41
Blade,
That all went well.I'll let you know how the system runs after I run CCleaner and JkDefrag,but it will probably be the weekend before I can get to it.Combofix had another update,and I had to do a manual reboot to get the browser working again.Here is the new log,and Thank You once again!
Kirk

ComboFix 09-09-09.04 - Kirk 09/09/2009 22:35.2.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.959.547 [GMT -5:00]
Running from: c:\users\Kirk\Desktop\Combo-Fix.exe
Command switches used :: c:\users\Kirk\Desktop\CFScript.txt
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

file zipped: c:\users\kirk\css.exe
file zipped: c:\users\kirk\MediaTubeCodec_ver1.1463.0.exe
file zipped: c:\users\kirk\sccs.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Kirk\css.exe
c:\users\kirk\MediaTubeCodec_ver1.1463.0.exe
c:\users\kirk\sccs.exe

.
((((((((((((((((((((((((( Files Created from 2009-08-10 to 2009-09-10 )))))))))))))))))))))))))))))))
.

2009-09-10 03:44 . 2009-09-10 03:45 -------- d-----w- c:\users\Kirk\AppData\Local\temp
2009-09-10 03:44 . 2009-09-10 03:44 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-09-10 03:44 . 2009-09-10 03:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-09 04:58 . 2009-08-14 17:07 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-09 04:58 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-09 04:58 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-09 04:58 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-09 04:58 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-09 04:58 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-09 04:58 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-09 04:58 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-09 04:58 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-09 04:58 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-09 04:57 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-09 04:56 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-09 04:56 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-09 04:56 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-09 04:56 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-07 07:44 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-09-07 07:44 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-09-07 07:44 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-07 07:44 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
2009-09-07 07:44 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2009-09-07 07:44 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-09-07 07:44 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
2009-09-07 07:44 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
2009-09-06 08:07 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-09-06 01:11 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-09-06 01:11 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-09-06 01:11 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-09-06 01:11 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-09-06 01:11 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-06 01:11 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-20 06:19 . 2009-08-20 06:19 -------- d-----w- c:\program files\Java
2009-08-18 21:34 . 2009-08-18 21:34 -------- d-----w- c:\program files\ERUNT
2009-08-17 11:05 . 2009-08-17 11:05 -------- d-----w- c:\users\Kirk\AppData\Local\Live_TV
2009-08-12 01:18 . 2009-08-12 01:18 -------- d-----w- c:\users\Kirk\AppData\Roaming\TechSmith
2009-08-12 00:02 . 2009-08-12 00:02 -------- d-----w- c:\programdata\TechSmith
2009-08-12 00:02 . 2009-08-12 00:02 -------- d-----w- c:\users\Kirk\AppData\Local\TechSmith
2009-08-12 00:02 . 2009-08-12 00:02 -------- d-----w- c:\program files\TechSmith
2009-08-12 00:00 . 2009-08-12 00:00 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-11 15:57 . 2009-08-11 15:57 -------- d-----w- c:\users\Kirk\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-08-11 15:56 . 2009-08-11 15:56 -------- d-----w- c:\program files\Common Files\Adobe AIR

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-09 22:47 . 2009-02-02 23:44 -------- d-----w- c:\programdata\Google Updater
2009-09-09 18:11 . 2008-07-11 04:44 1356 ----a-w- c:\users\Kirk\AppData\Local\d3d9caps.dat
2009-09-09 17:38 . 2008-08-15 21:03 -------- d-----w- c:\users\Kirk\AppData\Roaming\ContentGuard
2009-09-09 08:37 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-09 08:08 . 2008-07-14 05:40 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-09 08:06 . 2008-10-13 20:46 -------- d-----w- c:\programdata\Microsoft Help
2009-08-20 06:19 . 2008-12-19 10:49 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-17 11:05 . 2009-08-04 18:57 -------- d-----w- c:\program files\Live_TV
2009-08-17 11:05 . 2009-08-04 18:57 -------- d-----w- c:\program files\Conduit
2009-08-12 05:40 . 2008-10-13 16:08 -------- d-----w- c:\users\Kirk\AppData\Roaming\GetRightToGo
2009-08-04 19:23 . 2009-08-04 19:23 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-08-04 13:03 . 2009-08-04 13:03 -------- d-----w- c:\program files\Trend Micro
2009-08-04 01:37 . 2009-08-04 01:27 -------- d-----w- c:\programdata\Lavasoft
2009-08-04 01:27 . 2009-08-04 01:27 -------- dc-h--w- c:\programdata\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-04 01:27 . 2009-08-04 01:27 -------- d-----w- c:\program files\Lavasoft
2009-08-03 23:12 . 2009-03-05 00:07 -------- d-----w- c:\programdata\McAfee
2009-08-03 23:12 . 2009-03-18 00:54 -------- d-----w- c:\program files\Common Files\McAfee
2009-08-03 23:11 . 2009-03-18 00:53 -------- d-----w- c:\program files\McAfee
2009-08-03 19:42 . 2008-08-08 23:12 -------- d-----w- c:\program files\Coupons
2009-07-21 05:21 . 2008-07-31 07:31 172912 ---ha-w- c:\windows\system32\mlfcache.dat
2009-07-20 02:30 . 2009-07-20 02:30 4096 ----a-w- c:\windows\d3dx.dat
2009-07-20 02:27 . 2009-07-20 02:27 552 ----a-w- c:\users\Kirk\AppData\Local\d3d8caps.dat
2009-07-20 02:26 . 2009-02-06 15:23 -------- d-----w- c:\program files\The Price Is Right
2009-07-18 16:06 . 2009-09-06 01:12 827904 ----a-w- c:\windows\system32\wininet.dll
2009-07-18 16:01 . 2009-09-06 01:12 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-18 09:46 . 2009-09-06 01:12 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:35 . 2009-09-06 01:12 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-16 23:36 . 2009-07-16 23:35 3277 ----a-w- C:\awFLEXLM.dat
2009-07-16 04:28 . 2009-07-16 04:28 -------- d-----w- c:\users\Kirk\AppData\Roaming\Autodesk
2009-07-16 03:32 . 2009-07-16 02:37 -------- d-----w- c:\program files\Autodesk
2009-07-16 03:14 . 2009-07-16 02:37 -------- d-----w- c:\program files\Common Files\Alias Shared
2009-07-16 03:12 . 2009-07-16 03:12 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2009-07-03 14:49 . 2009-08-04 01:37 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-03 14:49 . 2009-08-04 05:19 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-27 18:12 . 2008-07-11 04:45 104248 ----a-w- c:\users\Kirk\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-15 15:24 . 2009-07-15 10:49 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 15:20 . 2009-07-15 10:49 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 15:20 . 2009-07-15 10:49 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:52 . 2009-07-15 10:49 289792 ----a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-09-08_20.48.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-09 04:56 . 2009-07-11 19:10 68096 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\wlanhlp.dll
+ 2009-09-09 04:56 . 2009-07-11 19:10 65024 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\wlanapi.dll
+ 2008-07-26 15:06 . 2008-01-05 11:34 15181 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\gatherWirelessInfo.vbs
+ 2009-09-09 04:56 . 2009-04-11 06:28 68096 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\wlanhlp.dll
+ 2009-09-09 04:56 . 2009-07-11 19:01 65024 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\wlanapi.dll
+ 2008-07-26 15:06 . 2008-01-05 11:34 15181 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\gatherWirelessInfo.vbs
+ 2009-09-09 04:56 . 2009-07-11 19:17 68096 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\wlanhlp.dll
+ 2009-09-09 04:56 . 2009-07-11 19:17 64512 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\wlanapi.dll
+ 2008-07-26 15:06 . 2008-01-05 11:34 15181 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\gatherWirelessInfo.vbs
+ 2008-07-26 15:09 . 2008-01-19 07:36 68096 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\wlanhlp.dll
+ 2008-07-26 15:09 . 2008-01-19 07:36 64512 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\wlanapi.dll
+ 2008-07-26 15:06 . 2008-01-05 11:34 15181 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\gatherWirelessInfo.vbs
+ 2009-09-09 04:56 . 2009-07-11 19:24 67584 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\wlanhlp.dll
+ 2009-09-09 04:56 . 2009-07-11 19:24 47104 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\wlanapi.dll
+ 2006-11-02 12:34 . 2006-11-02 12:34 14827 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\gatherWirelessInfo.vbs
+ 2009-09-09 04:56 . 2009-07-11 19:32 67584 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\wlanhlp.dll
+ 2009-09-09 04:56 . 2009-07-11 19:32 47104 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\wlanapi.dll
+ 2006-11-02 12:34 . 2006-11-02 12:34 14827 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\gatherWirelessInfo.vbs
+ 2009-09-09 04:58 . 2009-08-15 21:30 22016 c:\windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21108_none_6030d425ab49af00\netiougc.exe
+ 2009-09-09 04:58 . 2009-08-15 23:56 49152 c:\windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21108_none_6030d425ab49af00\netiomig.dll
+ 2009-09-09 04:58 . 2009-08-14 14:23 22016 c:\windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16908_none_5fa75f38922bdbf4\netiougc.exe
+ 2009-09-09 04:58 . 2009-08-14 16:40 49152 c:\windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16908_none_5fa75f38922bdbf4\netiomig.dll
+ 2009-09-09 04:58 . 2009-08-14 13:52 17920 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.22200_none_353709f565220c3d\ROUTE.EXE
+ 2009-09-09 04:58 . 2009-08-14 13:52 27136 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.22200_none_353709f565220c3d\NETSTAT.EXE
+ 2009-09-09 04:58 . 2009-08-14 13:52 11264 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.22200_none_353709f565220c3d\MRINFO.EXE
+ 2009-09-09 04:58 . 2009-08-14 13:52 10240 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.22200_none_353709f565220c3d\finger.exe
+ 2009-09-09 04:58 . 2009-08-14 13:52 19968 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.22200_none_353709f565220c3d\ARP.EXE
+ 2009-09-09 04:58 . 2009-08-14 13:49 17920 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.18091_none_344d1c424c4c841c\ROUTE.EXE
+ 2009-09-09 04:58 . 2009-08-14 13:49 27136 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.18091_none_344d1c424c4c841c\NETSTAT.EXE
+ 2009-09-09 04:58 . 2009-08-14 13:49 11264 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.18091_none_344d1c424c4c841c\MRINFO.EXE
+ 2009-09-09 04:58 . 2009-08-14 13:49 10240 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.18091_none_344d1c424c4c841c\finger.exe
+ 2009-09-09 04:58 . 2009-08-14 13:49 19968 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.18091_none_344d1c424c4c841c\ARP.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:11 17920 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.22497_none_32f648e1683e66cc\ROUTE.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:11 27136 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.22497_none_32f648e1683e66cc\NETSTAT.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:11 11264 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.22497_none_32f648e1683e66cc\MRINFO.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:11 10240 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.22497_none_32f648e1683e66cc\finger.exe
+ 2009-09-09 04:58 . 2009-08-14 14:11 19968 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.22497_none_32f648e1683e66cc\ARP.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:16 17920 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.18311_none_32bd29ba4ee54f70\ROUTE.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:16 27136 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.18311_none_32bd29ba4ee54f70\NETSTAT.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:16 11264 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.18311_none_32bd29ba4ee54f70\MRINFO.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:16 10240 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.18311_none_32bd29ba4ee54f70\finger.exe
+ 2009-09-09 04:58 . 2009-08-14 14:16 19968 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.18311_none_32bd29ba4ee54f70\ARP.EXE
+ 2009-09-09 04:58 . 2009-08-15 21:31 17920 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.21108_none_317231f36ace26fb\ROUTE.EXE
+ 2009-09-09 04:58 . 2009-08-15 21:31 27136 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.21108_none_317231f36ace26fb\NETSTAT.EXE
+ 2009-09-09 04:58 . 2009-08-15 21:31 11264 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.21108_none_317231f36ace26fb\MRINFO.EXE
+ 2009-09-09 04:58 . 2009-08-15 21:31 10240 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.21108_none_317231f36ace26fb\finger.exe
+ 2009-09-09 04:58 . 2009-08-15 21:31 19968 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.21108_none_317231f36ace26fb\ARP.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:25 17920 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.16908_none_30e8bd0651b053ef\ROUTE.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:25 27136 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.16908_none_30e8bd0651b053ef\NETSTAT.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:25 11264 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.16908_none_30e8bd0651b053ef\MRINFO.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:25 10240 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.16908_none_30e8bd0651b053ef\finger.exe
+ 2009-09-09 04:58 . 2009-08-14 14:25 19968 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.16908_none_30e8bd0651b053ef\ARP.EXE
+ 2009-09-09 04:58 . 2009-08-14 17:01 98376 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22497_none_cd53c52043eb1c22\FWPKCLNT.SYS
+ 2009-09-09 04:58 . 2009-08-15 21:29 85504 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6000.21108_none_cbcfae32467adc51\FWPKCLNT.SYS
+ 2009-09-09 04:58 . 2009-08-14 16:00 17920 c:\windows\winsxs\x86_microsoft-windows-netevent_31bf3856ad364e35_6.0.6002.22200_none_5cb66ecc80d2b9bd\netevent.dll
+ 2009-09-09 04:58 . 2009-08-14 15:53 17920 c:\windows\winsxs\x86_microsoft-windows-netevent_31bf3856ad364e35_6.0.6002.18091_none_5bcc811967fd319c\netevent.dll
+ 2009-09-09 04:58 . 2009-08-14 16:24 17920 c:\windows\winsxs\x86_microsoft-windows-netevent_31bf3856ad364e35_6.0.6001.22497_none_5a75adb883ef144c\netevent.dll
+ 2009-09-09 04:58 . 2009-08-14 16:29 17920 c:\windows\winsxs\x86_microsoft-windows-netevent_31bf3856ad364e35_6.0.6001.18311_none_5a3c8e916a95fcf0\netevent.dll
+ 2009-09-09 04:58 . 2009-08-15 23:56 15360 c:\windows\winsxs\x86_microsoft-windows-netevent_31bf3856ad364e35_6.0.6000.21108_none_58f196ca867ed47b\netevent.dll
+ 2009-09-09 04:58 . 2009-08-14 16:40 15360 c:\windows\winsxs\x86_microsoft-windows-netevent_31bf3856ad364e35_6.0.6000.16908_none_586821dd6d61016f\netevent.dll
+ 2009-09-09 04:57 . 2009-06-10 09:53 53248 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.22150_none_9e993405232e229b\rrinstaller.exe
+ 2009-09-09 04:57 . 2009-06-10 09:54 98816 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.22150_none_9e993405232e229b\mfps.dll
+ 2009-09-09 04:57 . 2009-06-10 09:53 24576 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.22150_none_9e993405232e229b\mfpmp.exe
+ 2009-09-09 04:57 . 2009-04-11 06:27 53248 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\rrinstaller.exe
+ 2009-09-09 04:57 . 2009-04-11 06:28 98816 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\mfps.dll
+ 2009-09-09 04:57 . 2009-04-11 06:27 24576 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\mfpmp.exe
+ 2009-09-09 04:57 . 2009-06-10 10:10 53248 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.22447_none_9cc4940f25f962e7\rrinstaller.exe
+ 2009-09-09 04:57 . 2009-06-10 11:56 98816 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.22447_none_9cc4940f25f962e7\mfps.dll
+ 2009-09-09 04:57 . 2009-06-10 10:10 24576 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.22447_none_9cc4940f25f962e7\mfpmp.exe
+ 2008-07-26 15:08 . 2008-01-19 07:33 53248 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\rrinstaller.exe
+ 2008-07-26 15:08 . 2008-01-19 07:34 98816 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\mfps.dll
+ 2008-07-26 15:08 . 2008-01-19 07:33 24576 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\mfpmp.exe
+ 2009-09-09 04:57 . 2009-06-10 10:01 52736 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6000.21065_none_9ac68b3928e50d45\rrinstaller.exe
+ 2009-09-09 04:57 . 2009-06-10 12:00 98816 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6000.21065_none_9ac68b3928e50d45\mfps.dll
+ 2009-09-09 04:57 . 2009-06-10 10:01 24576 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6000.21065_none_9ac68b3928e50d45\mfpmp.exe
+ 2009-09-09 04:57 . 2009-06-10 10:14 52736 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6000.16868_none_9a40172a0fc4863e\rrinstaller.exe
+ 2009-09-09 04:57 . 2009-06-10 12:07 98816 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6000.16868_none_9a40172a0fc4863e\mfps.dll
+ 2009-09-09 04:57 . 2009-06-10 10:15 24576 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6000.16868_none_9a40172a0fc4863e\mfpmp.exe
+ 2009-09-09 04:58 . 2009-08-14 13:51 30720 c:\windows\winsxs\x86_microsoft-windows-l..istry-support-tcpip_31bf3856ad364e35_6.0.6002.22200_none_888d4c521bb0e416\tcpipreg.sys
+ 2009-09-09 04:58 . 2009-08-14 13:48 30720 c:\windows\winsxs\x86_microsoft-windows-l..istry-support-tcpip_31bf3856ad364e35_6.0.6002.18091_none_87a35e9f02db5bf5\tcpipreg.sys
+ 2008-07-11 07:21 . 2009-09-09 08:41 47952 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-09-09 18:14 52998 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-07-11 04:46 . 2009-09-09 18:14 14732 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1102098282-1699462974-3711131293-1000_UserData.bin
+ 2006-11-02 13:02 . 2009-09-10 03:25 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-09-08 20:42 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:02 . 2009-09-10 03:25 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:02 . 2009-09-08 20:42 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-09-10 03:25 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-11-02 13:02 . 2009-09-08 20:42 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-10-13 20:56 . 2009-09-08 08:06 35088 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-10-13 20:56 . 2009-09-09 08:06 35088 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-10-13 20:56 . 2009-09-09 08:06 18704 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-10-13 20:56 . 2009-09-08 08:06 18704 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-10-13 20:56 . 2009-09-08 08:06 20240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-10-13 20:56 . 2009-09-09 08:06 20240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-08-12 05:19 . 2009-09-09 08:06 35088 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-08-12 05:19 . 2009-09-08 08:06 35088 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-08-12 05:19 . 2009-09-08 08:06 18704 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-08-12 05:19 . 2009-09-09 08:06 18704 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-08-12 05:19 . 2009-09-09 08:06 20240 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\cagicon.exe
- 2009-08-12 05:19 . 2009-09-08 08:06 20240 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-09-09 04:58 . 2009-08-14 13:52 9728 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.22200_none_353709f565220c3d\TCPSVCS.EXE
+ 2009-09-09 04:58 . 2009-08-14 13:52 8704 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.22200_none_353709f565220c3d\HOSTNAME.EXE
+ 2009-09-09 04:58 . 2009-08-14 13:49 9728 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.18091_none_344d1c424c4c841c\TCPSVCS.EXE
+ 2009-09-09 04:58 . 2009-08-14 13:49 8704 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.18091_none_344d1c424c4c841c\HOSTNAME.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:11 9728 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.22497_none_32f648e1683e66cc\TCPSVCS.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:11 8704 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.22497_none_32f648e1683e66cc\HOSTNAME.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:16 9728 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.18311_none_32bd29ba4ee54f70\TCPSVCS.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:16 8704 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.18311_none_32bd29ba4ee54f70\HOSTNAME.EXE
+ 2009-09-09 04:58 . 2009-08-15 21:31 9728 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.21108_none_317231f36ace26fb\TCPSVCS.EXE
+ 2009-09-09 04:58 . 2009-08-15 21:31 8704 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.21108_none_317231f36ace26fb\HOSTNAME.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:25 9728 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.16908_none_30e8bd0651b053ef\TCPSVCS.EXE
+ 2009-09-09 04:58 . 2009-08-14 14:25 8704 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.16908_none_30e8bd0651b053ef\HOSTNAME.EXE
+ 2009-09-09 04:57 . 2009-06-10 09:53 2048 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.22150_none_9e993405232e229b\mferror.dll
+ 2009-09-09 04:57 . 2009-04-11 04:54 2048 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\mferror.dll
+ 2009-09-09 04:57 . 2009-06-10 10:10 2048 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.22447_none_9cc4940f25f962e7\mferror.dll
+ 2006-11-02 12:35 . 2006-11-02 12:35 2048 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\mferror.dll
+ 2009-09-09 04:57 . 2009-06-10 08:43 2048 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6000.21065_none_9ac68b3928e50d45\mferror.dll
+ 2009-09-09 04:57 . 2009-06-10 08:50 2048 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6000.16868_none_9a40172a0fc4863e\mferror.dll
+ 2009-09-09 08:38 . 2009-09-09 18:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-09-09 08:38 . 2009-09-09 18:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-09-09 04:56 . 2009-07-11 19:10 513536 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\wlansvc.dll
+ 2009-09-09 04:56 . 2009-07-11 19:10 302592 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\wlansec.dll
+ 2009-09-09 04:56 . 2009-07-11 19:10 293376 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\wlanmsm.dll
+ 2009-09-09 04:56 . 2009-07-11 19:01 513536 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\wlansvc.dll
+ 2009-09-09 04:56 . 2009-07-11 19:01 302592 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\wlansec.dll
+ 2009-09-09 04:56 . 2009-07-11 19:01 293376 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\wlanmsm.dll
+ 2009-09-09 04:56 . 2009-07-11 19:17 513536 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\wlansvc.dll
+ 2009-09-09 04:56 . 2009-07-11 19:17 302592 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\wlansec.dll
+ 2009-09-09 04:56 . 2009-07-11 19:17 293376 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\wlanmsm.dll
+ 2009-09-09 04:56 . 2009-07-11 19:32 513024 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\wlansvc.dll
+ 2009-09-09 04:56 . 2009-07-11 19:32 302592 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\wlansec.dll
+ 2009-09-09 04:56 . 2009-07-11 19:32 293376 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\wlanmsm.dll
+ 2009-09-09 04:56 . 2009-07-11 19:24 502784 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\wlansvc.dll
+ 2009-09-09 04:56 . 2009-07-11 19:24 299520 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\wlansec.dll
+ 2009-09-09 04:56 . 2009-07-11 19:24 289280 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\wlanmsm.dll
+ 2009-09-09 04:56 . 2009-07-11 19:32 502272 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\wlansvc.dll
+ 2009-09-09 04:56 . 2009-07-11 19:32 297984 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\wlansec.dll
+ 2009-09-09 04:56 . 2009-07-11 19:32 290816 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\wlanmsm.dll
+ 2009-09-09 04:58 . 2009-08-15 23:58 167424 c:\windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21108_none_6030d425ab49af00\tcpipcfg.dll
+ 2009-09-09 04:58 . 2009-08-15 21:30 816640 c:\windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21108_none_6030d425ab49af00\tcpip.sys
+ 2009-09-09 04:58 . 2009-08-14 16:42 167424 c:\windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16908_none_5fa75f38922bdbf4\tcpipcfg.dll
+ 2009-09-09 04:58 . 2009-08-14 14:24 813568 c:\windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16908_none_5fa75f38922bdbf4\tcpip.sys
+ 2009-09-09 04:58 . 2009-08-14 13:51 106496 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.22200_none_353709f565220c3d\netiohlp.dll
+ 2009-09-09 04:58 . 2009-08-14 13:48 105984 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6002.18091_none_344d1c424c4c841c\netiohlp.dll
+ 2009-09-09 04:58 . 2009-08-14 16:24 105472 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.22497_none_32f648e1683e66cc\netiohlp.dll
+ 2009-09-09 04:58 . 2009-08-14 16:29 104960 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6001.18311_none_32bd29ba4ee54f70\netiohlp.dll
+ 2009-09-09 04:58 . 2009-08-15 23:56 103936 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.21108_none_317231f36ace26fb\netiohlp.dll
+ 2009-09-09 04:58 . 2009-08-14 16:40 103936 c:\windows\winsxs\x86_microsoft-windows-tcpip-utility_31bf3856ad364e35_6.0.6000.16908_none_30e8bd0651b053ef\netiohlp.dll
+ 2009-09-09 04:58 . 2009-08-14 16:33 905784 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22200_none_b58e289d7caa2a80\tcpip.sys
+ 2009-09-09 04:58 . 2009-08-14 16:27 904776 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18091_none_b4a43aea63d4a25f\tcpip.sys
+ 2009-09-09 04:58 . 2009-08-14 17:01 900168 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys
+ 2009-09-09 04:58 . 2009-08-14 17:07 897608 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18311_none_b3144862666d6db3\tcpip.sys
+ 2009-09-09 04:56 . 2009-06-04 12:55 512000 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_6.0.6002.22146_none_852abf080d834b3e\jscript.dll
+ 2009-09-09 04:56 . 2009-06-04 12:07 512000 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_6.0.6002.18045_none_84a021f2f466921d\jscript.dll
+ 2009-09-09 04:56 . 2009-06-04 12:32 512000 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_6.0.6001.22443_none_83414c42105faa15\jscript.dll
+ 2009-09-09 04:56 . 2009-06-04 12:33 512000 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_6.0.6001.18266_none_82a50e96f74f910b\jscript.dll
+ 2009-09-09 04:56 . 2009-06-04 12:28 512000 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_6.0.6000.21061_none_8143436c134b5473\jscript.dll
+ 2009-09-09 04:56 . 2009-06-04 12:40 512000 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_6.0.6000.16865_none_80bdcfa6fa29e6c3\jscript.dll
+ 2009-09-09 04:58 . 2009-08-14 16:23 438272 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22497_none_cd53c52043eb1c22\IKEEXT.DLL
+ 2009-09-09 04:58 . 2009-08-14 16:22 595456 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22497_none_cd53c52043eb1c22\FWPUCLNT.DLL
+ 2009-09-09 04:58 . 2009-08-14 16:21 328704 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22497_none_cd53c52043eb1c22\BFE.DLL
+ 2009-09-09 04:58 . 2009-08-15 23:54 416768 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6000.21108_none_cbcfae32467adc51\IKEEXT.DLL
+ 2009-09-09 04:58 . 2009-08-15 23:54 543232 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6000.21108_none_cbcfae32467adc51\FWPUCLNT.DLL
+ 2009-09-09 04:58 . 2009-08-15 23:53 317440 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6000.21108_none_cbcfae32467adc51\BFE.DLL
+ 2009-09-09 04:58 . 2009-08-14 17:01 220232 c:\windows\winsxs\x86_microsoft-windows-netio-infrastructure_31bf3856ad364e35_6.0.6001.22497_none_56cac20cceadcb78\netio.sys
+ 2009-09-09 04:58 . 2009-08-16 00:32 214104 c:\windows\winsxs\x86_microsoft-windows-netio-infrastructure_31bf3856ad364e35_6.0.6000.21108_none_5546ab1ed13d8ba7\netio.sys
+ 2009-09-09 04:58 . 2009-08-14 17:16 213592 c:\windows\winsxs\x86_microsoft-windows-netio-infrastructure_31bf3856ad364e35_6.0.6000.16908_none_54bd3631b81fb89b\netio.sys
+ 2009-09-09 04:56 . 2009-07-11 17:07 127488 c:\windows\winsxs\x86_microsoft-windows-l..securityhelperclass_31bf3856ad364e35_6.0.6002.22170_none_883d49e88f57f26d\L2SecHC.dll
+ 2009-09-09 04:56 . 2009-07-11 17:03 127488 c:\windows\winsxs\x86_microsoft-windows-l..securityhelperclass_31bf3856ad364e35_6.0.6002.18064_none_87c27e31762e9c0e\L2SecHC.dll
+ 2009-09-09 04:56 . 2009-07-11 19:14 127488 c:\windows\winsxs\x86_microsoft-windows-l..securityhelperclass_31bf3856ad364e35_6.0.6001.22468_none_8669aa3c92224c10\L2SecHC.dll
+ 2009-09-09 04:56 . 2009-07-11 19:29 127488 c:\windows\winsxs\x86_microsoft-windows-l..securityhelperclass_31bf3856ad364e35_6.0.6001.18288_none_85ca6bb37914e701\L2SecHC.dll
+ 2009-09-09 04:56 . 2009-07-11 19:18 124928 c:\windows\winsxs\x86_microsoft-windows-l..securityhelperclass_31bf3856ad364e35_6.0.6000.21082_none_8467a03e95119112\L2SecHC.dll
+ 2009-09-09 04:56 . 2009-07-11 19:26 123904 c:\windows\winsxs\x86_microsoft-windows-l..securityhelperclass_31bf3856ad364e35_6.0.6000.16884_none_83e02be57bf1f0b4\L2SecHC.dll
+ 2009-09-09 04:56 . 2009-07-21 12:27 171008 c:\windows\winsxs\x86_microsoft-windows-ehome-ehkeyctl_31bf3856ad364e35_6.0.6002.22181_none_d867f28696ca3d06\ehkeyctl.dll
+ 2009-09-09 04:56 . 2009-07-21 12:26 171008 c:\windows\winsxs\x86_microsoft-windows-ehome-ehkeyctl_31bf3856ad364e35_6.0.6002.18072_none_d7ea25f17da39aa2\ehkeyctl.dll
+ 2009-09-09 04:56 . 2009-07-22 00:24 171008 c:\windows\winsxs\x86_microsoft-windows-ehome-ehkeyctl_31bf3856ad364e35_6.0.6001.22476_none_d69151fc99974aa4\ehkeyctl.dll
+ 2009-09-09 04:56 . 2009-07-21 14:45 171008 c:\windows\winsxs\x86_microsoft-windows-ehome-ehkeyctl_31bf3856ad364e35_6.0.6001.18295_none_d5f11329808acc3e\ehkeyctl.dll
+ 2009-09-09 04:56 . 2009-07-21 14:39 171008 c:\windows\winsxs\x86_microsoft-windows-ehome-ehkeyctl_31bf3856ad364e35_6.0.6000.21090_none_d48f47fe9c868fa6\ehkeyctl.dll
+ 2009-09-09 04:56 . 2009-07-21 14:56 171008 c:\windows\winsxs\x86_microsoft-windows-ehome-ehkeyctl_31bf3856ad364e35_6.0.6000.16891_none_d406d35b8367d5f1\ehkeyctl.dll
+ 2009-09-09 04:56 . 2009-06-04 12:33 512000 c:\windows\System32\jscript.dll
- 2008-07-27 12:50 . 2008-05-08 21:59 512000 c:\windows\System32\jscript.dll
- 2008-10-13 20:56 . 2009-09-08 08:06 888080 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-10-13 20:56 . 2009-09-09 08:06 888080 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-10-13 20:56 . 2009-09-09 08:06 272648 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
- 2008-10-13 20:56 . 2009-09-08 08:06 272648 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-10-13 20:56 . 2009-09-09 08:06 922384 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
- 2008-10-13 20:56 . 2009-09-08 08:06 922384 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
- 2008-10-13 20:56 . 2009-09-08 08:06 845584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-10-13 20:56 . 2009-09-09 08:06 845584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-10-13 20:56 . 2009-09-09 08:06 217864 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
- 2008-10-13 20:56 . 2009-09-08 08:06 217864 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
- 2009-08-12 05:19 . 2009-09-08 08:06 888080 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-08-12 05:19 . 2009-09-09 08:06 888080 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-08-12 05:19 . 2009-09-09 08:06 922384 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\pptico.exe
- 2009-08-12 05:19 . 2009-09-08 08:06 922384 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\pptico.exe
- 2009-08-12 05:19 . 2009-09-08 08:06 845584 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-08-12 05:19 . 2009-09-09 08:06 845584 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\outicon.exe
- 2009-08-12 05:19 . 2009-09-08 08:06 217864 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\misc.exe
+ 2009-08-12 05:19 . 2009-09-09 08:06 217864 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\misc.exe
+ 2009-09-09 08:41 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\9-9-2009\ERDNT.EXE
- 2008-07-26 15:09 . 2008-01-19 07:34 171008 c:\windows\ehome\ehkeyctl.dll
+ 2009-09-09 04:56 . 2009-07-21 14:45 171008 c:\windows\ehome\ehkeyctl.dll
+ 2009-09-09 04:57 . 2009-08-10 07:23 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22215_none_f4f261f581c1d755\OESpamFilter.dat
+ 2009-09-09 04:57 . 2009-08-10 07:23 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18103_none_f4719482689de8ec\OESpamFilter.dat
+ 2009-09-09 04:57 . 2009-08-10 07:22 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22511_none_f307eee5849f1cd5\OESpamFilter.dat
+ 2009-09-09 04:57 . 2009-08-10 07:23 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18322_none_f27480926b88b52c\OESpamFilter.dat
+ 2009-09-09 04:57 . 2009-08-10 07:22 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21119_none_f12988cb87718cb7\OESpamFilter.dat
+ 2009-09-09 04:57 . 2009-08-10 07:23 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16919_none_f0a013de6e53b9ab\OESpamFilter.dat
+ 2009-09-09 04:57 . 2009-06-10 11:45 2386944 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-wmvcore_31bf3856ad364e35_6.0.6002.22150_none_096c8896ec43f957\WMVCORE.DLL
+ 2009-09-09 04:57 . 2009-06-10 11:41 2386944 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-wmvcore_31bf3856ad364e35_6.0.6002.18049_none_08f6be51d31621ab\WMVCORE.DLL
+ 2009-09-09 04:57 . 2009-06-10 11:59 2386944 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-wmvcore_31bf3856ad364e35_6.0.6001.22447_none_0797e8a0ef0f39a3\WMVCORE.DLL
+ 2009-09-09 04:57 . 2009-06-10 12:11 2386944 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-wmvcore_31bf3856ad364e35_6.0.6001.18270_none_06e6d825d6103f24\WMVCORE.DLL
+ 2009-09-09 04:57 . 2009-06-10 12:06 2436096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-wmvcore_31bf3856ad364e35_6.0.6000.21065_none_0599dfcaf1fae401\WMVCORE.DLL
+ 2009-09-09 04:57 . 2009-06-10 12:16 2433536 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-wmvcore_31bf3856ad364e35_6.0.6000.16868_none_05136bbbd8da5cfa\WMVCORE.DLL
+ 2009-09-09 04:57 . 2009-06-10 11:45 2868224 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.22150_none_9e993405232e229b\mf.dll
+ 2009-09-09 04:57 . 2009-06-10 11:41 2868224 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\mf.dll
+ 2009-09-09 04:57 . 2009-06-10 11:59 2868224 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.22447_none_9cc4940f25f962e7\mf.dll
+ 2009-09-09 04:57 . 2009-06-10 12:11 2868224 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\mf.dll
+ 2009-09-09 04:57 . 2009-06-10 12:00 2855424 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6000.21065_none_9ac68b3928e50d45\mf.dll
+ 2009-09-09 04:57 . 2009-06-10 12:07 2855424 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6000.16868_none_9a40172a0fc4863e\mf.dll
- 2008-12-12 09:47 . 2008-06-23 01:59 2386944 c:\windows\System32\WMVCORE.DLL
+ 2009-09-09 04:57 . 2009-06-10 12:11 2386944 c:\windows\System32\WMVCORE.DLL
+ 2006-11-02 10:22 . 2009-09-09 08:49 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 10:22 . 2009-09-07 20:51 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 12:47 . 2009-09-09 08:39 2684577 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
- 2006-11-02 12:47 . 2009-09-06 08:17 2684577 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
+ 2009-08-18 17:56 . 2009-08-18 17:56 5020672 c:\windows\Installer\25c4bd6.msp
- 2008-10-13 20:56 . 2009-09-08 08:06 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-10-13 20:56 . 2009-09-09 08:06 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-10-13 20:56 . 2009-09-08 08:06 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-10-13 20:56 . 2009-09-09 08:06 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
- 2009-08-12 05:19 . 2009-09-08 08:06 1172240 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-08-12 05:19 . 2009-09-09 08:06 1172240 c:\windows\Installer\{91120000-0012-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-09-09 08:41 . 2009-09-09 08:41 3588096 c:\windows\ERDNT\AutoBackup\9-9-2009\Users000002\UsrClass.dat
+ 2009-09-09 08:41 . 2009-09-09 08:41 4460544 c:\windows\ERDNT\AutoBackup\9-9-2009\Users000001\NTUSER.DAT
+ 2006-11-02 10:24 . 2009-08-28 21:38 24689600 c:\windows\System32\mrt.exe
+ 2009-09-09 08:07 . 2009-09-09 08:07 15709696 c:\windows\Installer\25c4bef.msp
+ 2009-06-04 08:04 . 2009-09-09 08:29 111215593 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zinio DLM"="c:\program files\Zinio\ZinioReader.exe" [2008-07-08 3874886]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Zune Launcher"="c:\users\Kirk\Downloads\1695.dvb.pc.4.4.3\Zune\ZuneLauncher.exe" [2008-11-10 157312]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"AmazonGSDownloaderTray"="c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-02-02 246272]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-25 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-20 149280]

c:\users\Kirk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Server4PC.lnk - c:\program files\TechniSat DVB\bin\Server4PC.exe [2008-7-11 338448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E6B77BCC-89C6-466A-9985-8446164FBFE9}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C2C61E87-73E6-4C7F-8432-813998F6F46E}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{BD42AE93-415F-4E1A-BA9E-36C363AB003A}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{6EB61C02-E80B-4035-A7DF-EF56EACB465A}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{4FAB8BC1-ADA5-4B47-A3F8-C69C6CC622AA}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{EDB07C8F-B1A2-4C7F-B34F-640B79BAAA79}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{B30CC371-7C9E-48F0-AB4A-140F20358DA4}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{CB829BD1-BC37-41A2-AB22-15718DBE33B4}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{4E6DC5CE-F86D-463D-BE06-D1CDBDE941BC}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D2D5F2E2-4D0E-4388-9BE7-E645DFE1A6A2}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{C48E482A-A1F4-43FD-95C7-4954D34F1FF6}c:\\done\\done\\tmd-recruit.5.1\\mirc.exe"= UDP:c:\done\done\tmd-recruit.5.1\mirc.exe:mIRC
"UDP Query User{70D64D7E-0509-4D9F-AF5B-9EAF022E2207}c:\\done\\done\\tmd-recruit.5.1\\mirc.exe"= TCP:c:\done\done\tmd-recruit.5.1\mirc.exe:mIRC
"TCP Query User{B6DC8950-31AF-4945-A892-0E4F0E52DEDA}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{E7200DC0-AE53-409E-94AC-2CDB8A32D32B}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [8/3/2009 8:37 PM 64160]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712]
S2 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2/6/2009 9:10 AM 317440]
S2 gupdate1c98590c9c1b434;Google Update Service (gupdate1c98590c9c1b434);c:\program files\Google\Update\GoogleUpdate.exe [2/2/2009 6:48 PM 133104]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
.
Contents of the 'Scheduled Tasks' folder

2009-09-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]

2009-09-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-02 09:12]

2009-09-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-02 23:48]

2009-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-02 23:48]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://att.my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: electronicarts.com
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: pogo.com
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game13.zylom.com/activex/zylomgamesplayer.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-09 22:45
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-09-10 22:49
ComboFix-quarantined-files.txt 2009-09-10 03:48
ComboFix2.txt 2009-09-08 20:56
ComboFix3.txt 2009-09-05 23:25

Pre-Run: 13,136,216,064 bytes free
Post-Run: 13,100,093,440 bytes free

450 --- E O F --- 2009-09-09 08:29
Upload was successful
Blade81
QUOTE
I'll let you know how the system runs after I run CCleaner and JkDefrag

Are you using CCleaner to clean registry? It's not recommended. I'm personally against registry cleaners since it's easy to cause more damage than benefit from them.
Bowtie41
Blade,
I've read in posts that you helped others with what you had said about you not liking/recommending the use of registry cleaners.When I went to the JkDefrag site(Program is now known as MyDefrag),the first tip they show is the use of either Windows Disk Cleanup,or the use of freeware CCleaner.I used it as recommended to clean up old junk.I did not let it clean the registry.I then followed their other tips about changing the virtual memory before the Defrag,and letting the Defrag run in Safe Mode(BTW Slow Optimization in Safe Mode w/200GB HD......50hrs! huh.gif )I didn't use the tips about moving the swap file because I was afraid I might screw it up.
The system seems marginally better.When we get done with everything else,I'll upgrade to the new IE8 to see if it helps.

I await you next command Master! ninja.gif
Blade81

Hi,

QUOTE
I used it as recommended to clean up old junk.I did not let it clean the registry.

Ok. Just wanted to ask since CCleaner offers registry cleaning option too smile.gif This might be a good moment to see if IE8 improves the system.
Bowtie41
Blade,
Sorry for the delay in replying.I really do appreciate all you've done so far smile.gif .I've been fighting trying to get IE8 on my system.It kept hanging up and rebooting a couple times.I finally decided to check for Windows updates.It had installed some automatically the other night.It then said I needed to install SP2.Every time I tried to run it throught the browser,it gave me errors,so I downloaded it as a standalone.I kept getting error code 0x80070490,error:ERROR_NOT_FOUND.it said element not found.I went to Windows Knowledge Base and it suggested running Windows Update Standalone Installer.I downloaded it,ran it,and it did the same thing,so I went to Knowledge Base and searched for the error and found the problem.

"This issue may occur if there is corruption in the Component Based Servicing (CBS) manifest."

"To resolve this issue, you must perform a repair installation of Windows Vista or Windows Server 2008. Performing a repair installation will restore the current Windows installation to the version of the installation DVD. This also requires the installation of all updates that are not included on the installation DVD."

I'm going to be away from my PC from tomorrow AM til Next Monday PM so it will all have to wait till I get back.

Even though I haven't been able to install IE8,my Yahoo browser is still a sluggish,but it is much better than it was.

BTW,since I had to upload ths css and sccs to virustotal,am I still infected?

Thanks for all you do,have a great weekend!!
Kirk
Blade81
Hi,

Do you have service pack 1 installed in Vista? Service pack 2 requires sp1 to be present.

QUOTE
BTW,since I had to upload ths css and sccs to virustotal,am I still infected?

Both files were removed by ComboFix smile.gif
Bowtie41
Blade,
Sorry for the delay again,I've been trying different things to no avail.I do have SP1 already.I have made sure ad-aware or anything else is turned off when trying to install SP2.I downloaded and ran the KB947821 System Update Readiness Tool(per the troubleshooting page),with and without a reboot before trying to install SP2.I have tried both the run from the website version,and the download then run version standalone of SP2,and had the same error.I deleted the standalone version,and redownloaded it,but I still get the same error as before.I'm stumped huh.gif maybe I have other malware?Thank You for all you have done,you rock! cool.gif
Kirk
Blade81
Hi Kirk,

Looks like you may have to do repair install. However, before that you may want to post on some general problems forum, like http://forums.techguy.org or http://forums.whatthetech.com for example to find out if someone has any other ideas. We handle malware issues here only and to me that remaining issue is more like a general issue with Windows.
Blade81
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else please begin a New Topic.

Thank You !
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.