PDA

View Full Version : Google Redirect Virus? . . . Blocks spybot from running . . Help Please!



jlauv
2009-08-10, 20:55
I believe I at least have a virus that causes links in Google to go to shopping pages. It also claims safer-networking.org does not exist when clicking on the link in a search engine. I am running Windows XP with Verizon's Internet Security Suite 8.0. Yesterday the anti-virus started detecting and deleting numerous files that were trying to access the internet. Then the computer slowed down and I discovered the redirecting with search engines.

I don't know if it is related, but the Security Suite firewall keeps blocking a program called Lexpps.exe

I downloaded and installed spybot (after all of this), but it is being blocked from running.

I downloaded and ran erunt and backed up my registry.

Here is my Hijackthis log. Thank you for any help!



Logfile of HijackThis v1.99.1
Scan saved at 2:31:06 PM, on 8/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Verizon\Verizon Internet Security Suite\rps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
C:\Program Files\Verizon\VSP\VerizonServicepointComHandler.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaMonitor.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\Program Files\Common Files\MotiveBrowser\MotiveBrowser.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
C:\Documents and Settings\Jeremy\Desktop\Downloads\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Verizon\Verizon Internet Security Suite\pkR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [DACSMiniApp] C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - https://activatemydsl.verizon.net/sdcCommon/download/tgctlcm.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - https://www.psea.org/CFIDE/classes/CFJava.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139618482060
O16 - DPF: {88B507F9-C6B2-45CC-AAB6-720A652DE11C} (TenOfTen Class) - http://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} - http://hutchence.armstrong.com/ib/databases/actimage40803.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} (RegPropsCtrl Class) - http://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: Verizon Internet Security Suite (Radialpoint Security Services) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
O23 - Service: Verizon Internet Security Suite SafeConnectAgent (RadialpointSafeConnectAgent) - Unknown owner - C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe" RadialpointSafeConnectAgent (file missing)
O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe

km2357
2009-08-11, 20:17
Hello and welcome to Safer Networking.

My name is km2357 and I will be helping you to remove any infection(s) that you may have.

I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.

Please do not start another thread or topic, I will assist you at this thread until we solve your problems.

Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.

I will be back as soon as possible with your first instructions!

km2357
2009-08-11, 20:27
I don't know if it is related, but the Security Suite firewall keeps blocking a program called Lexpps.exe

Lexpps.exe (http://www.processlibrary.com/directory/files/lexpps/) is a "Lexmark Printer Sharing application which allows you to share a printer over a network." If you have a Lexmark Printer, then this is nothing to worry about. :)

Step # 1: Make an uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.


Step # 2 Download and Run RSIT

Download random's system information tool (RSIT) by random/random from here (http://images.malwareremoval.com/random/RSIT.exe) and save it to your desktop.
Double click on RSIT.exe to run RSIT.
Click Continue at the disclaimer screen.
Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)


In your next post/reply, I need to see the following:

1. Uninstall List
2. The two RSIT Logs (info and log.txt)

jlauv
2009-08-11, 22:11
Thanks for helping me. (I do have a Dell printer and I guess it is really a Lexmark. So that must be where the lexpps.exe comes from.)

Here is the information for what is taking over Firefox.

Here is the Hijackthis Uninstall list:

ABBYY FineReader 5.0 Sprint
Ad-Aware SE Personal
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 10 Plugin
Adobe Flash Player 9 ActiveX
Adobe Reader 7.1.0
Adobe Shockwave Player
Advertisement Service
Apple Software Update
Arthur's Wilderness Rescue
Beginning Sounds
Bible Stories
Blue's Reading Time Activities
CCHelp
CCleaner (remove only)
CCScore
Chem ASAP!
Conexant SmartHSFi V92 56K DF PCI Modem
CR2
Critical Update for Windows Media Player 11 (KB959772)
Curious George v1.0
DAO
David and Goliath
Dell AIO Printer A940
Dell Digital Jukebox Driver
Dell Picture Studio - Dell Image Expert
Dell Solution Center
Dell Support
Digital Line Detect
DivX Codec
DivX Player
DVD Flick
DVDSentry
Easy CD Creator 5 Basic
ERUNT 1.1j
ESSAdpt
ESSANUP
ESSBrwr
ESSCAM
ESSCDBK
ESScore
ESSCT
ESSEMAIL
ESSgui
ESShelp
ESSini
ESSPCD
ESSSONIC
ESSvpaht
ESSvpot
ExamView Pro
Expert Home Design 3D v5.0
exPressit S.E. 2.1
Family Tree Maker
Garfield K Phonics
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
HijackThis 1.99.1
HLPCCTR
HLPIndex
HLPSFO
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Intel(R) PRO Network Adapters and Drivers
Intel(R) PROSet
ISEngineUpdate
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Kodak EasyShare software
KSU
LBT Preschool Adventure
Magic 3D Coloring Book
Memorex exPressit Label Design Studio
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard 2003
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 SR-1 Disc 2
Microsoft Office 2000 SR-1 Premium
Microsoft Picture It! Photo 7.0
Microsoft Silverlight
Microsoft Streets and Trips 2002
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Word 2002
Microsoft Works 2003 Setup Launcher
Microsoft Works 7.0
Microsoft Works Suite Add-in for Microsoft Word
Minnesota Cuke
Modem Helper
Mozilla Firefox (3.0.12)
MSN Music Assistant
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Musicmatch® Jukebox
MyDVD
Netflix Movie Viewer
NetWaiting
Notifier
NVIDIA Windows 2000/XP Display Drivers
OfotoXMI
OTtBP
OTtBPSDK
Paint Shop Pro 7
PCDLNCH
PerfectDisk 2008
Photo Viewer 2.3
PowerDVD
QuickTime
Reader Rabbit Math Ages 4-6
Reader Rabbit(R) Playtime For Baby & Toddler
RealOne Player
RPS Burn
RPS CRT
RPS CRT
RPS Diagnostic Utility
RPS Firewall
RPS Ksdk
RPS ParentalControl
RPS PerfectDiskStub
RPS PopupBlocker
RPS RpsCore
RPS SafeConnect
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB973346)
SFR
SFR2
Shockwave
Spybot - Search & Destroy
The Digital Arts and Crafts Studio
The Land Before Time Kindergarten Adventure
Thomas & Friends - Trouble on the Tracks
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
USB Driver for Panasonic DVC
VCAMCEN
Verizon Internet Security Suite
Verizon Online
Verizon Online DSL
Verizon Online Help & Support
Verizon Servicepoint 1.5.24
VPRINTOL
Windows Installer Clean Up
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver

Here is the RSIT info text:

info.txt logfile of random's system information tool 1.06 2009-08-11 15:50:25

======Uninstall list======

-->C:\PROGRA~1\VERIZO~1\HELPSU~1\Uninstall.exe Verizon
-->C:\Program Files\Common Files\Real\Update_OB\rnuninst.exe RealNetworks|RealPlayer|6.0
-->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
-->C:\WINDOWS\Motive\Verizon\MCCUninst.exe
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00BF-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00C6-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00D1-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF03DA-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2D261CA3-5C68-494A-89D1-5DE68ED23146}\Setup.exe" -l0x9 UNINSTALL
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{55BC7EFA-D832-4EE3-9DEA-49B0C07539D9}\setup.exe" -l0x9 -L0x9anything
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DCDC8E79-4600-4C02-9824-CD3BB8971D4E}\Setup.exe" -l0x9 -L0x9anything
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ABBYY FineReader 5.0 Sprint-->MsiExec.exe /X{4468EF97-A253-4699-9E1C-88CAE2C6832D}
Ad-Aware SE Personal-->C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
Adobe Atmosphere Player for Acrobat and Adobe Reader-->C:\WINDOWS\atmoUn.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe -q
Adobe Reader 7.1.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002}
Adobe Shockwave Player-->C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~2\Install.log
Advertisement Service-->C:\WINDOWS\system32\net.net Uninstall
Apple Software Update-->MsiExec.exe /I{74EC78BC-B379-4E29-9006-8F161DCAABA6}
Arthur's Wilderness Rescue-->C:\WINDOWS\TLCUninstall.exe -f "C:\Program Files\The Learning Company\Arthur's Wilderness Rescue\Uninstall.xml"
Beginning Sounds-->C:\WINDOWS\unvise32.exe C:\Program Files\sz8031\uninstal.log
Bible Stories-->C:\WINDOWS\uninst.exe -r"DK Multimedia\Bible Stories\1, 0, 0, 1" -n"Bible Stories" -fC:\PROGRA~1\DKMULT~1\BIBLES~1\DeIsL1.isu -cC:\PROGRA~1\DKMULT~1\BIBLES~1\uninst.dll
Blue's Reading Time Activities-->C:\WINDOWS\IsUninst.exe -f"C:\HEGames\Blue's Reading Time Activities\Uninst.isu"
CCHelp-->MsiExec.exe /I{9D1CF8B6-17B3-4832-B062-2C2DD0B57B04}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
CCScore-->MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
Chem ASAP!-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Addison Wesley Longman\Chem ASAP!\Uninst.isu"
Conexant SmartHSFi V92 56K DF PCI Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2702\HXFSETUP.EXE -U -IDel8d8xk.INF
CR2-->MsiExec.exe /I{432C3720-37BF-4BD7-8E49-F38E090246D0}
Critical Update for Windows Media Player 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
Curious George v1.0-->"C:\Program Files\Namco\Curious George\uninstall.exe"
DAO-->MsiExec.exe /I{64116298-93C5-401D-B06C-39D8E3338508}
David and Goliath-->C:\PROGRA~1\BRIGHT~1\David\UNWISE.EXE C:\PROGRA~1\BRIGHT~1\David\INSTALL.LOG
Dell AIO Printer A940-->C:\WINDOWS\System32\spool\drivers\w32x86\3\DLBAUN5C.EXE -dDell AIO Printer A940
Dell Digital Jukebox Driver-->C:\Program Files\Dell\Digital Jukebox Drivers\DrvUnins.exe /s
Dell Picture Studio - Dell Image Expert-->MsiExec.exe /I{151C555A-A9E7-4A2E-B6D7-165D04A3C956}
Dell Solution Center-->MsiExec.exe /X{11F1920A-56A2-4642-B6E0-3B31A12C9288}
Dell Support-->MsiExec.exe /X{43FCA273-9534-40DB-B7C5-D7758875616A}
Digital Line Detect-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DVD Flick-->"C:\Program Files\DVD Flick\unins000.exe"
DVDSentry-->MsiExec.exe /I{98DF85D9-96C0-4F57-A92E-C3539477EF5E}
Easy CD Creator 5 Basic-->MsiExec.exe /I{609F7AC8-C510-11D4-A788-009027ABA5D0}
ERUNT 1.1j-->"C:\Program Files\ERUNT\unins000.exe"
ESSAdpt-->MsiExec.exe /I{D15E9DB5-6BEB-4534-901E-80C0A29BAB97}
ESSANUP-->MsiExec.exe /I{A6F18A67-B771-4191-8A33-36D2E742D6D9}
ESSBrwr-->MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6}
ESSCAM-->MsiExec.exe /I{469730CC-78DF-4CD3-B286-562D459EA619}
ESSCDBK-->MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
ESScore-->MsiExec.exe /I{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}
ESSCT-->MsiExec.exe /I{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}
ESSEMAIL-->MsiExec.exe /I{FEDE2483-87B7-44C1-A5BB-D75AEB8B6340}
ESSgui-->MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A}
ESShelp-->MsiExec.exe /I{87843A41-7808-4F2E-B13F-25C1E67CF2FD}
ESSini-->MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765}
ESSPCD-->MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
ESSSONIC-->MsiExec.exe /I{4F677FC7-7AA8-412B-A957-F13CBE1C7331}
ESSvpaht-->MsiExec.exe /I{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}
ESSvpot-->MsiExec.exe /I{48C82F7A-F100-4DAB-A310-8E18BF2159E1}
ExamView Pro-->C:\WINDOWS\unvise32.exe C:\ExamView\uninstal.log
Expert Home Design 3D v5.0-->C:\WINDOWS\uninst.exe -f"C:\Program Files\Expert Software\Home Design 3D v5.0\DeIsL1.isu"
exPressit S.E. 2.1-->"C:\Program Files\exPressit S.E. 2.1\UninstallerData\Uninstall exPressit S.E. 2.1.exe"
Family Tree Maker-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC93A5F4-45D4-4C19-AF79-808794229BE9}\SETUP.EXE" -l0x9
Garfield K Phonics-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E47BAD4-742D-4725-AA87-ED70403B0F25}\setup.exe" -l0x9 -removeonly
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_874698634E0FC940.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
HLPCCTR-->MsiExec.exe /I{F2D0C1B1-80FF-46F9-BA61-33B01A07FAFC}
HLPIndex-->MsiExec.exe /I{38441BE7-79B0-42B8-8297-833704F949FE}
HLPSFO-->MsiExec.exe /I{8DD94CA3-BCD2-49C0-B537-F3B5D95FF0C8}
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Intel(R) PRO Network Adapters and Drivers-->Prounstl.exe
Intel(R) PROSet-->MsiExec.exe /I{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}
ISEngineUpdate-->MsiExec.exe /I{A28BECB7-2BF4-4171-8CDE-3803F0FE2874}
J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
J2SE Runtime Environment 5.0 Update 9-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
Kodak EasyShare software-->C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_10009_2a677\Setup.exe /APR-REMOVE
KSU-->MsiExec.exe /I{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}
LBT Preschool Adventure-->C:\PROGRA~1\BRIGHT~1\LBTPRE~1\UNWISE.EXE C:\PROGRA~1\BRIGHT~1\LBTPRE~1\INSTALL.LOG
Magic 3D Coloring Book-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM and Crayola\Magic 3D\Uninst.isu"
Memorex exPressit Label Design Studio-->C:\WINDOWS\mvuninst\App1\mvuninst.exe "Memorex exPressit Label Design Studio"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Data Access Components KB870669-->C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Encarta Encyclopedia Standard 2003-->MsiExec.exe /I{03410014-3975-4267-9F39-1DC4745090B7}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Money 2003 System Pack-->MsiExec.exe /I{02B42D23-10F2-4862-ADA4-3DF1EA0021B2}
Microsoft Money 2003-->MsiExec.exe /I{01F9D88C-3C86-4E82-840A-101A3221F67A}
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2000 SR-1 Disc 2-->MsiExec.exe /I{00040409-78E1-11D2-B60F-006097C998E7}
Microsoft Office 2000 SR-1 Premium-->MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7}
Microsoft Picture It! Photo 7.0-->MsiExec.exe /I{369B36BE-3D64-4641-9AEA-808D436FE132}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Streets and Trips 2002-->MsiExec.exe /I{12BDDF23-B1DB-49C8-92D3-3E6841CCED61}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Word 2002-->MsiExec.exe /I{911B0409-6000-11D3-8CFE-0050048383C9}
Microsoft Works 2003 Setup Launcher-->C:\Program Files\Microsoft Works Suite 2003\Setup\Launcher.exe D:\
Microsoft Works 7.0-->MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}
Microsoft Works Suite Add-in for Microsoft Word-->MsiExec.exe /I{7EE9DE0D-9228-4C33-B80E-FDD1773600DF}
Minnesota Cuke-->C:\WINDOWS\iun507.exe C:\Program Files\BigIdea\Minnesota Cuke\irunin.ini
Modem Helper-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
Mozilla Firefox (3.0.12)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN Music Assistant-->rundll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msninst.inf,Uninstall
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Musicmatch® Jukebox-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}\setup.exe" -l0x9 -uninst
MyDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5E835305-63BB-4E55-BBB7-EEBBE67774DB}\setup.exe" -l0x9 -L0x9 /SMAINT
Netflix Movie Viewer-->MsiExec.exe /X{BCE72AED-3332-4863-9567-C5DCB9052CA2}
NetWaiting-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
Notifier-->MsiExec.exe /I{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}
NVIDIA Windows 2000/XP Display Drivers-->rundll32.exe C:\WINDOWS\System32\nvinstnt.dll,NvUninstallNT4 nvdd.inf
OfotoXMI-->MsiExec.exe /I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}
OTtBP-->MsiExec.exe /I{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}
OTtBPSDK-->MsiExec.exe /I{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}
Paint Shop Pro 7-->MsiExec.exe /I{D6DE02C7-1F47-11D4-9515-00105AE4B89A}
PCDLNCH-->MsiExec.exe /I{69BD6399-3D8F-45B7-81D9-819361F5101D}
PerfectDisk 2008-->MsiExec.exe /I{2B6EC03E-6FA0-4D7C-9CCE-1B03819AB613}
Photo Viewer 2.3-->"C:\Program Files\Photo Viewer\uninstall.exe"
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
QuickTime-->MsiExec.exe /I{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}
Reader Rabbit Math Ages 4-6-->C:\Program Files\The Learning Company\Reader Rabbit Math Ages 4-6\uninstal.exe
Reader Rabbit(R) Playtime For Baby & Toddler-->C:\Program Files\The Learning Company\Reader Rabbit(R) Playtime For Baby & Toddler\uninstall.exe
RealOne Player-->C:\Program Files\Common Files\Real\Update_OB\rnuninst.exe RealNetworks|RealPlayer|6.0
RPS Burn-->MsiExec.exe /I{FFE078E6-0288-4405-B26D-05D38F20295E}
RPS CRT-->MsiExec.exe /I{011A2240-08DF-45BB-AA4E-1A78637CCF80}
RPS CRT-->MsiExec.exe /I{258749E2-3A46-42B1-9A01-BF977AA06FAC}
RPS Diagnostic Utility-->MsiExec.exe /I{F573B950-CC14-4E55-8F29-F054485E11AA}
RPS Firewall-->MsiExec.exe /I{44850125-B5A7-420F-BF19-FFF249F95896}
RPS Ksdk-->MsiExec.exe /I{5DE3D989-A820-4247-8963-9287C28B3613}
RPS ParentalControl-->MsiExec.exe /I{61D85BCA-6150-4A90-938B-D426BF166777}
RPS PerfectDiskStub-->MsiExec.exe /I{3C7B1086-F873-4826-91A5-195CB5364C5B}
RPS PopupBlocker-->MsiExec.exe /I{A486CFF9-A3E6-4312-A1B9-ABD28F9FC255}
RPS RpsCore-->MsiExec.exe /I{C03B8026-694C-4326-88A8-1387097B50E8}
RPS SafeConnect-->MsiExec.exe /I{D55DA406-3031-42AB-B7C4-2183C00803F3}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Step By Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
SFR-->MsiExec.exe /I{C354C9B6-A4E0-4BB0-A368-6DC6BCA0E314}
SFR2-->MsiExec.exe /I{A0AF08BA-3630-4505-BFB2-A41F3837B0D0}
Shockwave-->C:\WINDOWS\SYSTEM32\MACROMED\SHOCKW~1\UNWISE.EXE C:\WINDOWS\SYSTEM32\MACROMED\SHOCKW~1\Install.log
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
The Digital Arts and Crafts Studio-->MsiExec.exe /I{983338D4-D972-4C58-AA6D-B81445070451}
The Land Before Time Kindergarten Adventure-->C:\Lbtkind\UNWISE.EXE C:\Lbtkind\INSTALL.LOG
Thomas & Friends - Trouble on the Tracks-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Hasbro Interactive\Thomas & Friends - Trouble on the Tracks\Uninst.isu"
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
USB Driver for Panasonic DVC-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{709E6F62-1168-11D5-8202-00E0294A926C}\setup.exe" anythinganythinganything
VCAMCEN-->MsiExec.exe /I{10E98E14-832C-4AF7-A4D1-6A9EF83B282E}
Verizon Internet Security Suite-->"C:\Program Files\InstallShield Installation Information\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\setup.exe" -runfromtemp -l0x0009 -removeonly
Verizon Online DSL-->C:\Program Files\Common Files\SupportSoft\Verizon\vzuninstall.exe /starthidden
Verizon Online Help & Support-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00D0-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
Verizon Online-->C:\WINDOWS\system32\VerizonUninstaller.exe
Verizon Servicepoint 1.5.24-->"C:\Program Files\Verizon\VSP\unins000.exe"
VPRINTOL-->MsiExec.exe /I{999D43F4-9709-4887-9B1A-83EBB15A8370}
Windows Installer Clean Up-->MsiExec.exe /I{121634B0-2F4A-11D3-ADA3-00C04F52DD53}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe

======Hosts File======

127.0.0.1 localhost

======Security center information======

AV: Verizon Internet Security Suite Anti-Virus
FW: Verizon Internet Security Suite Firewall

======System event log======

Computer Name: DHW4VG31
Event Code: 7001
Message: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


Record Number: 659062
Source Name: Service Control Manager
Time Written: 20090810211543.000000-240
Event Type: error
User:

Computer Name: DHW4VG31
Event Code: 7001
Message: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


Record Number: 659061
Source Name: Service Control Manager
Time Written: 20090810211543.000000-240
Event Type: error
User:

Computer Name: DHW4VG31
Event Code: 7001
Message: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


Record Number: 659060
Source Name: Service Control Manager
Time Written: 20090810211543.000000-240
Event Type: error
User:

Computer Name: DHW4VG31
Event Code: 7001
Message: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


Record Number: 659059
Source Name: Service Control Manager
Time Written: 20090810211343.000000-240
Event Type: error
User:

Computer Name: DHW4VG31
Event Code: 7001
Message: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


Record Number: 659058
Source Name: Service Control Manager
Time Written: 20090810211343.000000-240
Event Type: error
User:

=====Application event log=====

Computer Name: DHW4VG31
Event Code: 1517
Message: Windows saved user DHW4VG31\Jeremy registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 32918
Source Name: Userenv
Time Written: 20080414130209.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: DHW4VG31
Event Code: 1517
Message: Windows saved user DHW4VG31\Jeremy registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 32891
Source Name: Userenv
Time Written: 20080409085054.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: DHW4VG31
Event Code: 1517
Message: Windows saved user DHW4VG31\Jeremy registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 32787
Source Name: Userenv
Time Written: 20080315172033.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: DHW4VG31
Event Code: 1517
Message: Windows saved user DHW4VG31\Jeremy registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 32776
Source Name: Userenv
Time Written: 20080313191300.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: DHW4VG31
Event Code: 1517
Message: Windows saved user DHW4VG31\Jeremy registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 32753
Source Name: Userenv
Time Written: 20080311085046.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Sonic\MyDVD;C:\Program Files\Common Files\Adaptec Shared\System;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Maestro Learning\Common
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0209
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_09\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.5.0_09\lib\ext\QTJava.zip

-----------------EOF-----------------

jlauv
2009-08-11, 22:13
The RSIT log text was to long to be in the last reply.

Here is the RSIT log text:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Jeremy at 2009-08-11 15:49:54
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 20 GB (26%) free of 76 GB
Total RAM: 511 MB (21% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:50:21 PM, on 8/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Verizon\Verizon Internet Security Suite\rps.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
C:\Program Files\Verizon\VSP\VerizonServicepointComHandler.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaMonitor.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\Program Files\Common Files\MotiveBrowser\MotiveBrowser.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\Jeremy\Desktop\Downloads\RSIT.exe
C:\Program Files\trend micro\Jeremy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Verizon\Verizon Internet Security Suite\pkR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [DACSMiniApp] C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - https://activatemydsl.verizon.net/sdcCommon/download/tgctlcm.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - https://www.psea.org/CFIDE/classes/CFJava.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139618482060
O16 - DPF: {88B507F9-C6B2-45CC-AAB6-720A652DE11C} (TenOfTen Class) - http://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} - http://hutchence.armstrong.com/ib/databases/actimage40803.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} (RegPropsCtrl Class) - http://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: Verizon Internet Security Suite (Radialpoint Security Services) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
O23 - Service: Verizon Internet Security Suite SafeConnectAgent (RadialpointSafeConnectAgent) - Sana Security - C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe
O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe

--
End of file - 9900 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{243B17DE-77C7-46BF-B94B-0B5F309A0E64}]
C:\Program Files\Microsoft Money\System\mnyside.dll [2002-07-17 163906]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3C060EA2-E6A9-4E49-A530-D4657B8C449A}]
PopKill Class - C:\Program Files\Verizon\Verizon Internet Security Suite\pkR.dll [2009-04-22 55536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll [2006-10-12 434279]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-07-02 256112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2009-07-02 761840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-07-02 458736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-07-02 256112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\System32\NvCpl.dll [2003-04-24 4616192]
"AdaptecDirectCD"=C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe [2002-12-17 684032]
"Dell AIO Printer A940"=C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe [2003-02-17 86102]
"Motive SmartBridge"=C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe [2005-08-02 385024]
"A Verizon App"=C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE [2005-05-23 50744]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2007-06-29 286720]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe [2006-10-12 49263]
"DACSMiniApp"=C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe [2008-03-13 128256]
"mmtask"=C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe [2005-03-15 53248]
"DVDSentry"=C:\WINDOWS\System32\DSentry.exe [2002-08-14 28672]
"VerizonServicepoint.exe"=C:\Program Files\Verizon\VSP\VerizonServicepoint.exe [2009-03-12 2303216]
"net"=C:\WINDOWS\system32\net.net []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-07-30 68856]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe"="C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Disabled:Kodak Software Updater"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\StubInstaller.exe"="C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealOne Player"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c1c09384-3f1b-11dc-ae45-0007e94dd380}]
shell\AutoRun\command - F:\JDSecure\Windows\JDSecure31.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd5c7bb3-e15a-11dc-aeab-0007e94dd380}]
shell\AutoRun\command - F:\LaunchU3.exe -a


======List of files/folders created in the last 1 months======

2009-08-11 15:49:55 ----D---- C:\Program Files\trend micro
2009-08-11 15:49:54 ----D---- C:\rsit
2009-08-11 13:01:29 ----A---- C:\WINDOWS\ntbtlog.txt
2009-08-10 14:35:07 ----D---- C:\Program Files\ERUNT
2009-08-10 13:51:11 ----D---- C:\WINDOWS\ERDNT
2009-08-07 14:03:19 ----D---- C:\GLF1D9.tmp
2009-08-07 14:03:14 ----D---- C:\Program Files\Common Files\SureThing Shared
2009-08-07 14:03:13 ----D---- C:\WINDOWS\MVUNINST
2009-08-07 14:03:13 ----D---- C:\Program Files\Memorex exPressit Label Design Studio
2009-07-16 12:30:56 ----HDC---- C:\WINDOWS\$NtUninstallKB973346$
2009-07-16 12:30:41 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2009-07-16 12:26:12 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$

======List of files/folders modified in the last 1 months======

2009-08-11 15:49:55 ----AD---- C:\Program Files
2009-08-11 15:49:15 ----D---- C:\Program Files\Mozilla Firefox
2009-08-11 15:39:09 ----AD---- C:\WINDOWS\SYSTEM32
2009-08-11 15:39:05 ----D---- C:\WINDOWS\Temp
2009-08-11 15:28:15 ----AD---- C:\WINDOWS
2009-08-10 19:28:14 ----A---- C:\Documents and Settings\All Users\Application Data\DirectCDUserNameE.txt
2009-08-10 12:57:04 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-08-10 11:37:46 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-10 11:34:18 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-08-10 11:11:14 ----D---- C:\WINDOWS\Prefetch
2009-08-10 08:11:57 ----A---- C:\WINDOWS\DELLSTAT.INI
2009-08-10 02:45:51 ----AD---- C:\WINDOWS\system32\DRIVERS
2009-08-08 23:37:15 ----D---- C:\Program Files\Prentice Hall
2009-08-08 23:35:55 ----SHD---- C:\WINDOWS\Installer
2009-08-08 23:35:54 ----D---- C:\Config.Msi
2009-08-07 14:51:44 ----RSD---- C:\WINDOWS\Fonts
2009-08-07 14:03:14 ----D---- C:\Program Files\Common Files
2009-08-05 08:51:51 ----D---- C:\Program Files\Microsoft Silverlight
2009-07-31 14:40:05 ----A---- C:\WINDOWS\DMI.INI
2009-07-30 09:29:50 ----HD---- C:\WINDOWS\INF
2009-07-30 09:29:25 ----RSHD---- C:\WINDOWS\system32\DLLCACHE
2009-07-30 09:29:18 ----D---- C:\WINDOWS\system32\en-US
2009-07-30 09:29:18 ----D---- C:\Program Files\Internet Explorer
2009-07-29 07:14:44 ----D---- C:\WINDOWS\system32\CatRoot2
2009-07-29 07:10:48 ----HD---- C:\WINDOWS\$hf_mig$
2009-07-19 09:33:02 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-07-19 09:32:59 ----A---- C:\WINDOWS\system32\ieframe.dll
2009-07-16 12:31:01 ----A---- C:\WINDOWS\imsins.BAK

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2008-02-20 9336]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2008-02-20 9464]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2002-12-17 241152]
R1 DCCAM;Kodak Camera Proxy; C:\WINDOWS\System32\DRIVERS\DcCam.sys [2004-05-20 36918]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 KLIF;KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [2009-04-03 179984]
R1 omci;OMCI WDM Device Driver; C:\WINDOWS\System32\DRIVERS\omci.sys [2002-11-08 17217]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2003-09-11 143834]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2003-09-11 206464]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2003-09-11 206464]
R2 DCFS2K;Kodak DCFS2K Driver; C:\WINDOWS\system32\drivers\dcfs2k.sys [2004-06-02 38705]
R2 DefragFS;DefragFS; C:\WINDOWS\system32\drivers\DefragFS.sys [2008-08-28 71184]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2002-10-07 11027]
R2 RPSKT;Security Services Driver (x86); C:\WINDOWS\system32\DRIVERS\rp_skt32.sys [2008-11-26 53192]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2003-09-11 25898]
R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\System32\DRIVERS\e100b325.sys [2003-03-04 145408]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSF_DP.sys [2002-10-29 1175536]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys [2002-10-29 170499]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2003-04-24 1271706]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2002-11-11 9856]
R3 RadialpointSafeConnectDriver;RadialpointSafeConnectDriver; \??\C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Driver\platform_XP\SafeConnectDriver.sys []
R3 RadialpointSafeConnectFilter;RadialpointSafeConnectFilter; \??\C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Driver\platform_XP\SafeConnectFilter.sys []
R3 RadialpointSafeConnectShim;RadialpointSafeConnectShim; \??\C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Driver\platform_XP\SafeConnectShim.sys []
R3 RPPKT;Radialpoint Filter (x86); C:\WINDOWS\system32\DRIVERS\rp_pkt32.sys [2008-08-06 48384]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-02-28 545024]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys [2002-10-29 604240]
S1 Exportit;Exportit; C:\WINDOWS\System32\DRIVERS\exportit.sys [2004-06-02 151985]
S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\System32\DRIVERS\p3.sys [2008-04-13 42752]
S1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys []
S3 61883;61883 Unit Device; C:\WINDOWS\System32\DRIVERS\61883.sys [2008-04-13 48128]
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 Avc;AVC Device; C:\WINDOWS\System32\DRIVERS\avc.sys [2008-04-13 38912]
S3 bvrp_pci;bvrp_pci; C:\WINDOWS\system32\drivers\bvrp_pci.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 DcFpoint;DcFpoint; C:\WINDOWS\System32\DRIVERS\DcFpoint.sys [2004-05-20 61564]
S3 DcLps;Legacy Polling Service; C:\WINDOWS\System32\DRIVERS\DcLps.sys [2004-05-20 8022]
S3 DcPTP;dcptp; C:\WINDOWS\System32\DRIVERS\DcPTP.sys [2004-05-20 68950]
S3 EL90XBC;3Com EtherLink XL 90XB/C Adapter Driver; C:\WINDOWS\System32\DRIVERS\el90xbc5.sys [2001-08-17 66591]
S3 i81x;i81x; C:\WINDOWS\System32\DRIVERS\i81xnt5.sys [2004-08-04 161020]
S3 iAimFP0;iAimFP0; C:\WINDOWS\System32\DRIVERS\wADV01nt.sys [2004-08-04 12415]
S3 iAimFP1;iAimFP1; C:\WINDOWS\System32\DRIVERS\wADV02NT.sys [2004-08-04 12127]
S3 iAimFP2;iAimFP2; C:\WINDOWS\System32\DRIVERS\wADV05NT.sys [2004-08-04 11775]
S3 iAimFP3;iAimFP3; C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys [2004-08-04 12063]
S3 iAimFP4;iAimFP4; C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys [2004-08-04 19455]
S3 iAimTV0;iAimTV0; C:\WINDOWS\System32\DRIVERS\wATV01nt.sys [2004-08-04 29311]
S3 iAimTV1;iAimTV1; C:\WINDOWS\System32\DRIVERS\wATV02NT.sys [2004-08-04 19551]
S3 iAimTV2;iAimTV2; C:\WINDOWS\System32\DRIVERS\wATV03nt.sys []
S3 iAimTV3;iAimTV3; C:\WINDOWS\System32\DRIVERS\wATV04nt.sys [2004-08-04 33599]
S3 iAimTV4;iAimTV4; C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys [2004-08-04 23615]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2003-09-11 30630]
S3 MSDV;Microsoft DV Camera and VCR; C:\WINDOWS\System32\DRIVERS\msdv.sys [2008-04-13 51200]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\System32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 cbidf;cbidf; C:\WINDOWS\System32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\System32\DRIVERS\intelide.sys [2008-04-13 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\viaagp.sys [2008-04-13 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 KodakCCS;Kodak Camera Connection Software; C:\WINDOWS\system32\drivers\KodakCCS.exe [2004-05-24 322104]
R2 LexBceS;LexBce Server; C:\WINDOWS\system32\LEXBCES.EXE [2003-02-17 303104]
R2 PD91Agent;PD91Agent; C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe [2008-09-22 693512]
R2 RadialpointSafeConnectAgent;Verizon Internet Security Suite SafeConnectAgent; C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe [2008-11-14 4937752]
R2 RP_FWS;Verizon Internet Security Suite Firewall; C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe [2009-04-22 371440]
R2 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
R3 PD91Engine;PD91Engine; C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe [2008-09-22 910600]
R3 Radialpoint Security Services;Verizon Internet Security Suite; C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe [2009-04-22 170736]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-02 182768]
S3 NetSvc;Intel NCS NetService; C:\Program Files\Intel\NCS\Sync\NetSvc.exe [2003-03-03 143360]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S4 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\System32\nvsvc32.exe [2003-04-24 69632]

-----------------EOF-----------------

km2357
2009-08-12, 07:16
Step # 1: Disable Teatimer

Spybot S&D's tea timer normally provides real-time protection from spyware, however it may interfere with what we need to do. We will disable it until the machine is clean when it can be re-enabled.

This is a two step process.
First step: Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
If you have the version 1.5 or 1.6, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
If you have Version 1.4, Click on Exit Spybot S&D Resident

Second step, For Either Version : Open Spybot S&D
Click Mode, choose Advanced Mode
Go To the bottom of the Vertical Panel on the Left, Click Tools
then, also in left panel, click Resident shows a red/white shield.
If your firewall raises a question, say OK
In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
OK any prompts.
Use File, Exit to terminate Spybot
Reboot your machine for the changes to take effect.



Step # 2: Download and Run ComboFix

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

*Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

* IMPORTANT !!! Save ComboFix.exe to your Desktop

When finished, it shall produce a log for you. Please include C:\ComboFix.txt and a fresh HiJackThis Log in your next reply.

Use multiple posts if you can't fit everything into one post.

jlauv
2009-08-12, 17:05
I could not open Spybot to turn off Teatimer. I tried to install spybot (2 days ago) after my computer started acting up and it would never open. (The icon in the system tray was there, but I could never open the Spybot window.)
To keep Teatimer from messing up Combofix, I uninstalled Spybot. I then ran Combofix.

I don't know if you need to know this- since my computer began acting strangely, a window has been popping up at start up saying that Internet Explorer had closed unexpectedly. The window asked if I wanted to send a report to Microsoft.

Also, the last thing that I had installed (when the computer was working normally) was "memorex expressit Label design maker". Everything worked fine with that program.

The problems started show up while surfing with Firefox later that day. Sometime, I must have clicked on something and then the anti-virus started finding all kinds of viruses.


Here is the Combofix log:

ComboFix 09-08-10.06 - Jeremy 08/12/2009 9:34.1.1 - NTFSx86
Running from: c:\documents and settings\Jeremy\Desktop\Combo-Fix.exe
AV: Verizon Internet Security Suite Anti-Virus *On-access scanning disabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
FW: Verizon Internet Security Suite Firewall *disabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\ALLUSE~1\APPLIC~1\CrucialSoft Ltd
C:\setup.exe
c:\windows\run.log
c:\windows\system32\drivers\SKYNETitucbowp.sys
c:\windows\system32\drivers\UACmdebakayuc.sys
c:\windows\system32\SKYNETadmlabod.dat
c:\windows\system32\SKYNETjonmuely.dat
c:\windows\system32\SKYNETxstowktj.dll
c:\windows\system32\SKYNETytyxdktk.dll
c:\windows\system32\UACcrffrrlqon.dat
c:\windows\system32\UACeoueesttna.dll
c:\windows\system32\UACeundqjnrvx.dll
c:\windows\system32\UACgwgwjcglnw.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACmpopyrxtju.db
c:\windows\system32\UACnotaflleyi.dll
c:\windows\system32\UACpokmtoeomu.dll


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_SKYNETdcxeerbn
-------\Legacy_SKYNETdcxeerbn
-------\Service_UACd.sys
-------\Legacy_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-07-12 to 2009-08-12 )))))))))))))))))))))))))))))))
.

2009-08-11 19:49 . 2009-08-11 19:50 -------- d-----w- c:\program files\trend micro
2009-08-11 19:49 . 2009-08-11 19:50 -------- d-----w- C:\rsit
2009-08-10 18:35 . 2009-08-10 18:35 -------- d-----w- c:\program files\ERUNT
2009-08-07 18:17 . 2009-08-07 18:59 -------- d-----w- c:\documents and settings\Jeremy\Local Settings\Application Data\MicroVision Applications
2009-08-07 18:03 . 2009-08-07 18:03 -------- d-----w- C:\GLF1D9.tmp
2009-08-07 18:03 . 2009-08-07 18:50 -------- d-----w- c:\program files\Common Files\SureThing Shared
2009-08-07 18:03 . 2009-08-07 18:52 -------- d-----w- c:\program files\Memorex exPressit Label Design Studio
2009-08-07 18:03 . 2009-08-07 18:03 -------- d-----w- c:\windows\MVUNINST

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-12 13:56 . 2008-12-03 19:58 1209376 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-08-12 13:56 . 2008-12-03 19:58 13785888 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-08-12 13:31 . 2008-12-03 19:58 184580 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-12 13:31 . 2008-12-03 19:58 114164 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-08-12 12:34 . 2005-08-29 22:39 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-12 12:34 . 2005-08-29 22:39 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-08-09 03:37 . 2003-10-14 23:54 -------- d-----w- c:\program files\Prentice Hall
2009-08-07 18:54 . 2003-09-17 02:16 111544 ----a-w- c:\documents and settings\Jeremy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 12:51 . 2008-11-16 20:12 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-02 04:22 . 2005-04-26 03:14 -------- d-----w- c:\program files\Google
2009-06-29 16:12 . 2004-08-24 00:32 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2002-08-29 10:00 17408 ------w- c:\windows\system32\corpol.dll
2009-06-16 14:36 . 2002-08-29 10:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2002-08-29 10:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:09 . 2003-05-30 13:00 1291264 ----a-w- c:\windows\system32\quartz.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-31 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-04-24 4616192]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"Dell AIO Printer A940"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-02-17 86102]
"Motive SmartBridge"="c:\progra~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe" [2005-08-03 385024]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 49263]
"DACSMiniApp"="c:\program files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe" [2008-03-13 128256]
"mmtask"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2005-03-15 53248]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2009-03-12 2303216]

c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2003-9-11 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-net - c:\windows\system32\net.net


.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = 127.0.0.1;localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: {88B507F9-C6B2-45CC-AAB6-720A652DE11C} - hxxp://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} - hxxp://hutchence.armstrong.com/ib/databases/actimage40803.cab
DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} - hxxp://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
FF - ProfilePath - c:\docume~1\Jeremy\APPLIC~1\Mozilla\Firefox\Profiles\7pzczmxw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - plugin: c:\documents and settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\7pzczmxw.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJPI150_09.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPOJI610.dll
FF - plugin: c:\program files\Verizon\VSP\nprpspa.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-12 09:56
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-08-12 10:04
ComboFix-quarantined-files.txt 2009-08-12 14:04

Pre-Run: 20,546,150,400 bytes free
Post-Run: 20,758,614,016 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

140 --- E O F --- 2009-07-31 15:31


Here is the Hijackthis log, created after running Combofix:

Logfile of HijackThis v1.99.1
Scan saved at 10:43:09 AM, on 8/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\RPS.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
C:\Program Files\Verizon\VSP\VerizonServicepointComHandler.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaMonitor.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jeremy\Desktop\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Verizon\Verizon Internet Security Suite\pkR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [DACSMiniApp] C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - https://activatemydsl.verizon.net/sdcCommon/download/tgctlcm.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - https://www.psea.org/CFIDE/classes/CFJava.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139618482060
O16 - DPF: {88B507F9-C6B2-45CC-AAB6-720A652DE11C} (TenOfTen Class) - http://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} - http://hutchence.armstrong.com/ib/databases/actimage40803.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} (RegPropsCtrl Class) - http://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: Verizon Internet Security Suite (Radialpoint Security Services) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
O23 - Service: Verizon Internet Security Suite SafeConnectAgent (RadialpointSafeConnectAgent) - Unknown owner - C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe" RadialpointSafeConnectAgent (file missing)
O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe

km2357
2009-08-12, 20:16
Step # 1 Update Java

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Please follow these steps to remove older version Java components and update.

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6u15 (http://www.java.com/en/download/manual.jsp).
Click on the link to download Windows Offline Installation and save to your desktop. Do NOT use the Sun Download Manager.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Remove the following old versions of Java:


J2SE Runtime Environment 5.0 Update 6

J2SE Runtime Environment 5.0 Update 9


Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.

From your desktop double-click on the download to install the newest version.


Step # 2 Run CCleaner

CCleaner will remove everything from the temp/temporary folders but please note that it will not make back ups!


Before first use, select Options > Advanced and UNCHECK Only delete files in Windows Temp folder older than 48 hours
Then select the items you wish to clean up.

In the Windows Tab:

Clean all entries in the Internet Explorer section except Cookies
Clean all the entries in the Windows Explorer section
Clean all entries in the System section
Clean all entries in the Advanced section
Clean any others that you choose

In the Applications Tab:

Clean all except cookies in the Firefox/Mozilla section if you use it
Clean all in the Opera section if you use it
Clean Sun Java in the Internet Section
Clean any others that you choose

Click the Run Cleaner button.
A pop up box will appear advising this process will permanently delete files from your system.
Click OK and it will scan and clean your system.
Click exit when done.
If it asks you to reboot at the end, click NO


Step # 3 Download and Run Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware from Here (http://www.malwarebytes.org/mbam-download.php).

Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.


Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


In your next post/reply, I need to see the following:

1. MalwareBytes' Log
2. A fresh HiJackThis Log

jlauv
2009-08-12, 22:02
I cannot remove J2SE Runtime Environment 5.0 Update 6 or J2SE Runtime Environment 5.0 Update 9 from the add/remove in the control panel.

When I click on the program, the Change/Remove button does not show up.

The change/remove button does not show up for any program, except for Hijackthis. Also, Hijackthis is the only one that shows up with a place to "click here for support information."

jlauv
2009-08-12, 22:10
I don't know if you need to know this- the combofix had a list of 13 Rootkit activities. (Things like system32\skynet and system32\UAC with a bunch of letters after each showed up.)

I have them written down and can post them if they would help.

jlauv
2009-08-12, 22:18
Sorry for so many posts, I wanted to tell you that since I could not uninstall the Java I was not sure if I should continue with your instructions. So, I did not run CCleaner or download and run Malwarebytes.

jlauv
2009-08-12, 22:43
Sorry for so many posts, I wanted to tell you that since I could not uninstall the Java I was not sure if I should continue with your instructions. So, I did not run CCleaner or download and run Malwarebytes.

I was searching through my start menu and found that I have a program called Windows Install Cleanup. I opened it and it appeared that I can remove any programs with it. (I don't remember installing it before, but it says that it was last used in 2005, which is around the last time I had a virus.)

Should I use this to remove the Java?

km2357
2009-08-13, 07:29
I don't know if you need to know this- the combofix had a list of 13 Rootkit activities. (Things like system32\skynet and system32\UAC with a bunch of letters after each showed up.)

I have them written down and can post them if they would help.

No need to post them as ComboFix has already taken the Rootkits out. :)



I was searching through my start menu and found that I have a program called Windows Install Cleanup. I opened it and it appeared that I can remove any programs with it. (I don't remember installing it before, but it says that it was last used in 2005, which is around the last time I had a virus.)

Should I use this to remove the Java?

Is this what you're talking about when you say Windows Install Cleanup?:

http://support.microsoft.com/kb/290301

If so, "Be aware that Windows Installer CleanUp Utility will not remove the actual program from your computer. However, it will remove the installation files so that you can start the installation, upgrade, or uninstall over."


Instead of using that, let's try using CCleaner to uninstall those two old Javas:


Step # 1 Uninstall a program using CCleaner


Launch CCleaner
Click Tools
If Uninstall is not selected, click it to select it
Under Programs to Remove,scroll down till J2SE Runtime Environment 5.0 Update 6 is selected
Click Run Uninstaller
Repeat with J2SE Runtime Environment 5.0 Update 9
Close CCleaner


If you were successful in uninstalling those two Java with CCleaner, then go ahead and do the three steps (install new Java, run CCleaner and download and run MalwareBytes) listed in my last post. Post the MalwareBytes' log and a fresh HiJackThis log in your next reply/post.

If you weren't successful let me know and we'll try another way of uninstalling the two Javas.

jlauv
2009-08-13, 13:37
I was able to use CCleaner to remove Java and I reinstalled Java from my desktop.

(Perhaps it doesn't matter, but I think that the change/remove buttons disappeared after running the combofix program. After running combofix the add/remove program window seems to look different to me and everything reset the dates as to when they were last used. Would combofix have removed the buttons?)


I am ready to run the CCleaner for step 2, but I have a question because of warnings that came up.



Step # 2 Run CCleaner

CCleaner will remove everything from the temp/temporary folders but please note that it will not make back ups!

[list]
Before first use, select Options > Advanced and UNCHECK Only delete files in Windows Temp folder older than 48 hours
Then select the items you wish to clean up.

In the Windows Tab:


Clean all entries in the Advanced section

Click the Run Cleaner button.



Should I checkmark all the light gray entries under the "advanced section" of CCleaner? Some of them gave warnings. The gray ones that give warnings are tray notifications cache, window size/location cache, and user assist history.

km2357
2009-08-13, 20:19
(Perhaps it doesn't matter, but I think that the change/remove buttons disappeared after running the combofix program. After running combofix the add/remove program window seems to look different to me and everything reset the dates as to when they were last used. Would combofix have removed the buttons?)

As far as I'm aware ComboFix doesn't change anything in Add/Remove Programs. It's possible that the malware you had caused what happened to Add/Remove Programs. Later on, I'll have you uninstall ComboFix and we'll see if that fixes the problem. If not, then we'll work on getting it fixed. :)



I am ready to run the CCleaner for step 2, but I have a question because of warnings that came up.

Should I checkmark all the light gray entries under the "advanced section" of CCleaner? Some of them gave warnings. The gray ones that give warnings are tray notifications cache, window size/location cache, and user assist history.

You can go ahead and uncheck those three in the "Advanced Section", then continue on with the rest of the CCleaner instructions.

jlauv
2009-08-15, 02:35
I ran the Ccleaner and I ran the Malwarebytes.

Here are the logs for Malwarebytes and Hijackthis:

Malwarebytes' Anti-Malware 1.40
Database version: 2627
Windows 5.1.2600 Service Pack 3

8/14/2009 8:11:42 PM
mbam-log-2009-08-14 (20-11-42).txt

Scan type: Quick Scan
Objects scanned: 110678
Time elapsed: 7 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Logfile of HijackThis v1.99.1
Scan saved at 8:21:00 PM, on 8/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Verizon\Verizon Internet Security Suite\rps.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\Program Files\Verizon\VSP\VerizonServicepointComHandler.exe
C:\Program Files\Common Files\MotiveBrowser\MotiveBrowser.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaMonitor.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Jeremy\Desktop\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Verizon\Verizon Internet Security Suite\pkR.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DACSMiniApp] C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - https://activatemydsl.verizon.net/sdcCommon/download/tgctlcm.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - https://www.psea.org/CFIDE/classes/CFJava.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139618482060
O16 - DPF: {88B507F9-C6B2-45CC-AAB6-720A652DE11C} (TenOfTen Class) - http://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} - http://hutchence.armstrong.com/ib/databases/actimage40803.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} (RegPropsCtrl Class) - http://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: Verizon Internet Security Suite (Radialpoint Security Services) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
O23 - Service: Verizon Internet Security Suite SafeConnectAgent (RadialpointSafeConnectAgent) - Unknown owner - C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe" RadialpointSafeConnectAgent (file missing)
O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe



It seems like the Firefox is not being redirected when clicking on links in Google anymore.

The only thing that I noticed that is not right is that the change/remove buttons are not there in the control panel. (I checked, and Malwarebytes and Hijackthis have the button to remove them in the control panel. No other programs do.)

km2357
2009-08-15, 06:31
The only thing that I noticed that is not right is that the change/remove buttons are not there in the control panel. (I checked, and Malwarebytes and Hijackthis have the button to remove them in the control panel. No other programs do.)

Let's see if we can fix this. :)

I found two possible ways of fixing this problem.

The first one involves editing your Registry. So, the first thing to do is run ERUNT again and back up your Registry.

Once that is done, follow the instructions on the following website:

http://www.winxptutor.com/arpbuttons.htm

It'll probably take awhile as you'll have to do what it says on the webpage for each program listed in Add/Remove Programs that doesn't have the Change/Remove button listed.

============

If that doesn't work, we'll have try another alternative and that is to do a System Restore to a date when there were the Change/Remove buttons listed on Add/Remove Programs.

If you don't know how to do a System Restore, follow the instructions on the website below:

http://support.microsoft.com/kb/306084

If you need to do the System Restore, let me know if it fixed the problem with the missing Change/Remove buttons. Also, if you do need to do a System Restore, please rerun MalwareBytes' (You may need to redownload and update it again) and post its log in your next post.

jlauv
2009-08-15, 08:40
OK - some very strange things happened. (Including that my anti-virus ran before I started trying to get the change/remove buttons and it found 5 viruses.)

First I could not add the Change/Remove button by using the regedit. All the programs were missing except for Hijackthis and Malwarebytes.

So, I created a backup file with Erunt.

I then went to system restore, and the earliest restore date available was the one that Combofix created on Wednesday (which I believe is before we fixed anything with the virus). I restored to that date and as a result the buttons in the Add/Remove programs came back. But, because I was afraid of any viruses etc., I decided to undo the restore through the System Restore and go back to the way it was today on 8/15.

Once my computer restarted, after undoing the restore, not everything was the way it was before the restore. (I thought it should go back to being identical before.)

Here are some of the things I discovered:


The change/remove buttons are now back for the programs and each program is listed in the Uninstall of the Registry editor.

It did not appear that I had run Ccleaner. The old Java updates were back in the add/remove programs. Also, some of the other things that the cleaner cleaned were back.

Malewarebytes program did not come back.



After trying to get windows to undo the restore, I did the following:

Since it was gone, I decided to download and run Malewarebytes Anti-maleware. This time it found problems (which make me think that it did not completely undo my restore).

- I then checked out Firefox and the google links go to where they are supposed to (including safe-networking).

- I was skeptical of the "change/remove" buttons working, so I used the control panel to try and remove the first Java update (J2SE Runtime Environment Update 6). It removed the program.

- I then thought that I should stop and let you know what was happening. I ran a fresh Hijackthis log.

Below I have the Hijackthis Log and the most current Malewarebytes Log:

Logfile of HijackThis v1.99.1
Scan saved at 2:02:16 AM, on 8/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Verizon\Verizon Internet Security Suite\rps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
C:\Program Files\Verizon\VSP\VerizonServicepointComHandler.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaMonitor.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\Program Files\Common Files\MotiveBrowser\MotiveBrowser.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jeremy\Desktop\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Verizon\Verizon Internet Security Suite\pkR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DACSMiniApp] C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - https://activatemydsl.verizon.net/sdcCommon/download/tgctlcm.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - https://www.psea.org/CFIDE/classes/CFJava.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139618482060
O16 - DPF: {88B507F9-C6B2-45CC-AAB6-720A652DE11C} (TenOfTen Class) - http://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} - http://hutchence.armstrong.com/ib/databases/actimage40803.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} (RegPropsCtrl Class) - http://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: Verizon Internet Security Suite (Radialpoint Security Services) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
O23 - Service: Verizon Internet Security Suite SafeConnectAgent (RadialpointSafeConnectAgent) - Unknown owner - C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe" RadialpointSafeConnectAgent (file missing)
O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe

Malewarebytes Log:
Malwarebytes' Anti-Malware 1.40
Database version: 2628
Windows 5.1.2600 Service Pack 3

8/15/2009 1:48:22 AM
mbam-log-2009-08-15 (01-48-22).txt

Scan type: Quick Scan
Objects scanned: 110741
Time elapsed: 7 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\CrucialSoft Ltd (Rogue.MSantiSpyware2009) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\net (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UACd.sys (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\net (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009 (Rogue.Multiple) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\SYSTEM32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.



It does appears that Firefox links aren't being changed. :)
The computer seems to be slower again from the whole System Restore thing.
Do you think that I should finish uninstalling the Java and install the newest version?
Should I redo running of Ccleaner?

km2357
2009-08-15, 19:52
Don't know why when you tried to undo the System Restore it didn't go back to the way it was on 8/15. I knew that some of the malware/infections you had would come back when you did the System Restore to fix the Change/Remove buttons, that's why I had you run MalwareBytes' immediately after you did the System Restore.

Good to hear the Change/Remove buttons are back. :)



(Including that my anti-virus ran before I started trying to get the change/remove buttons and it found 5 viruses.)

Do you remember what viruses it found and what did it report as their location/path? Has it found any more viruses since it did that scan?



Do you think that I should finish uninstalling the Java and install the newest version?
Should I redo running of Ccleaner?

Yes, please uninstall J2SE Runtime Environment 5.0 Update 9 and install Java Runtime Environment (JRE) 6u15. Also , rerun CCleaner as well.


Besides doing those things, I'd like you to do these as well:


Step # 1 Update Adobe Acrobat Reader

There is a newer version of Adobe Acrobat Reader available. (See Note below)


First, go to Add/Remove Programs and uninstall all previous versions.
Please go to this link Adobe Acrobat Reader Download Link (http://www.adobe.com/products/acrobat/readstep2.html)
On the right Untick Adobe Phototshop Album Starter Edition if you do not wish to include this in the installation.
Click the Continue button
Click Run, and click Run again
Next click the Install Now button and follow the on screen prompts

Note: Adobe 9.1.3 is a large program and if you prefer a smaller program you can get Foxit 3.0 instead from http://www.foxitsoftware.com/pdf/rd_intro.php

If you decide to install Foxit 3.0 instead of Adobe, do the following during Foxit's Setup/Installation process:

Uncheck the following boxes:

I accept the License Terms and want to install Foxit Toolbar

Make Ask.com my default search

Create desktop, quick launch and start menu icon to eBay


Step # 2: Download and Run Gmer

Please download gmer.zip (http://www.gmer.net/gmer.zip) from Gmer and save it to your desktop.

***Please close any open programs ***

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised by a trained Security Analyst

If possible rootkit activity is found, you will be asked if you would like to perform a full scan. Click No.

Once the scan is complete, you may receive another notice about rootkit activity.
Click OK.

GMER will produce a log. Click on the Save button, and save the log as gmer.txt somewhere you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked. Click the Scan button and let the program do its work. GMER will produce a log.
Click on the Save button, and save the log as gmer.txt somewhere you can easily find it, such as your desktop.

DO NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc !

Please post the results from the GMER scan in your reply.


Step # 3: Run Kaspersky Online Scan

Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Mail databases Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply.


In your next post/reply, I need to see the following:

1. GMER Log
2. Kaspersky Log
3. A fresh HiJackThis Log
4. How is your computer doing now?

jlauv
2009-08-16, 14:35
After the system restore and then the undo of the system restore, the virus log in my Anti-virus disappeared. The five viruses that were found on 8/15 no longer appear.

I uninstalled the old Java and installed the newest version of Java.

I ran Ccleaner.

I uninstalled and installed the newest version of Adobe reader.



The initial running of gmer.exe was fine. After clicking on the scan it ran for a long time and then stopped when it found a rootkit activity file.
The log is below.

The Kaspersky Online scan found 9 files. They have the same ending as the files some of the files in the Combofix log that we ran a few days ago; the only difference is that they have the "Qoobox\quarantine" in front of them. It also is not all of the files that Combofix found. Do you think that the System restore undid some of the Combofix things or are these files leftover from Combofix?

The computer seems to be running ok. I think that it is a little slower than a day or two ago, but I'm not sure. The web browsing is definitely good.

Here are the logs:

Gmer Log
GMER 1.0.15.15020 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-16 00:48:52
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.15 ----

SSDT \??\C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Driver\platform_XP\SafeConnectShim.sys (SafeConnect Application Activity Monitor Loader Driver./Sana Security, Inc. ) ZwClose [0xF88CF8B0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwCreateProcess [0xEE002930]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwCreateProcessEx [0xEE002AA0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwCreateSection [0xEE003540]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xEE003190]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwCreateThread [0xEE003E20]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwDuplicateObject [0xEE002D60]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwLoadDriver [0xEE0012A0]
SSDT \??\C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Driver\platform_XP\SafeConnectShim.sys (SafeConnect Application Activity Monitor Loader Driver./Sana Security, Inc. ) ZwOpenProcess [0xF88CF8E0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwOpenSection [0xEE003370]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwQuerySystemInformation [0xEE003AD0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwResumeThread [0xEE003DD0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSetContextThread [0xEE004150]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSetInformationFile [0xEE004770]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSetInformationProcess [0xEE008160]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSetSecurityObject [0xEDFFFEC0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSuspendThread [0xEE003D80]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSystemDebugControl [0xEE001600]
SSDT \??\C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Driver\platform_XP\SafeConnectShim.sys (SafeConnect Application Activity Monitor Loader Driver./Sana Security, Inc. ) ZwTerminateProcess [0xF88CF990]
SSDT \??\C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Driver\platform_XP\SafeConnectShim.sys (SafeConnect Application Activity Monitor Loader Driver./Sana Security, Inc. ) ZwTerminateThread [0xF88CFA30]
SSDT \??\C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Driver\platform_XP\SafeConnectShim.sys (SafeConnect Application Activity Monitor Loader Driver./Sana Security, Inc. ) ZwWriteVirtualMemory [0xF88CFAD0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[284] [0xEDFFED40]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[285] [0xEDFFED50]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[286] [0xEDFFED60]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[287] [0xEDFFED80]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[288] [0xEDFFEDA0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[289] [0xEDFFEDD0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[290] [0xEDFFEDE0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[291] [0xEDFFEE00]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[292] [0xEDFFEE10]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[293] [0xEDFFEED0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[294] [0xEDFFEFA0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[295] [0xEDFFEFE0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[296] [0xEDFFF020]

Code \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) IoIsOperationSynchronous

---- Kernel code sections - GMER 1.0.15 ----

.text ntoskrnl.exe!KiDispatchInterrupt + BA 804DB92E 7 Bytes JMP EE008280 \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab)
.text ntoskrnl.exe!IoIsOperationSynchronous 804E875A 5 Bytes JMP EE005150 \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab)
.text ntoskrnl.exe!FsRtlCheckLockForReadAccess 80512919 5 Bytes JMP EE004B90 \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab)

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs klif.sys (spuper-ptor/Kaspersky Lab)
AttachedDevice \FileSystem\Ntfs \Ntfs SafeConnectFilter.sys (SafeConnect Application Activity Monitor Filter Driver./Sana Security, Inc. )
AttachedDevice \Driver\Tcpip \Device\Ip rp_skt32.sys (Radialpoint Filter/Radialpoint Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp rp_skt32.sys (Radialpoint Filter/Radialpoint Inc.)

Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort0 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)

AttachedDevice \Driver\Tcpip \Device\Udp rp_skt32.sys (Radialpoint Filter/Radialpoint Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp rp_skt32.sys (Radialpoint Filter/Radialpoint Inc.)
AttachedDevice \FileSystem\Fastfat \Fat klif.sys (spuper-ptor/Kaspersky Lab)
AttachedDevice \FileSystem\Fastfat \Fat SafeConnectFilter.sys (SafeConnect Application Activity Monitor Filter Driver./Sana Security, Inc. )
---- Processes - GMER 1.0.15 ----

Library C:\Program (*** hidden *** ) @ C:\WINDOWS\explorer.exe [3596] 0x01430000

---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000

---- EOF - GMER 1.0.15 ----


Kaspersky
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, August 16, 2009
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, August 16, 2009 07:20:06
Records in database: 2634154
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Objects scanned: 96134
Threats found: 9
Infected objects found: 9
Suspicious objects found: 0
Scan duration: 02:20:03


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\SKYNETitucbowp.sys.vir Infected: Trojan.Win32.TDSS.amve 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACmdebakayuc.sys.vir Infected: Rootkit.Win32.Agent.moy 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETxstowktj.dll.vir Infected: Trojan.Win32.Tdss.anuv 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETytyxdktk.dll.vir Infected: Trojan.Win32.Tdss.anus 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACeoueesttna.dll.vir Infected: Trojan.Win32.Tdss.anre 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACeundqjnrvx.dll.vir Infected: Trojan.Win32.Tdss.ajkj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACgwgwjcglnw.dll.vir Infected: Trojan.Win32.Tdss.anrc 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACnotaflleyi.dll.vir Infected: Packed.Win32.Tdss.m 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACpokmtoeomu.dll.vir Infected: Trojan.Win32.Tdss.anrd 1

Selected area has been scanned.

Hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 8:14:17 AM, on 8/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Verizon\Verizon Internet Security Suite\rps.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
C:\Program Files\Verizon\VSP\VerizonServicepointComHandler.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\Program Files\Common Files\MotiveBrowser\MotiveBrowser.exe
C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaMonitor.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\Documents and Settings\Jeremy\Local Settings\temp\jkos-Jeremy\binaries\ScanningProcess.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Jeremy\Desktop\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Verizon\Verizon Internet Security Suite\pkR.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DACSMiniApp] C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /Get1noarp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - https://activatemydsl.verizon.net/sdcCommon/download/tgctlcm.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - https://www.psea.org/CFIDE/classes/CFJava.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139618482060
O16 - DPF: {88B507F9-C6B2-45CC-AAB6-720A652DE11C} (TenOfTen Class) - http://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} - http://hutchence.armstrong.com/ib/databases/actimage40803.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} (RegPropsCtrl Class) - http://download.verizon.net/sfp/Cabs/hst/webinstall/HstWebInstall.cab
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: Verizon Internet Security Suite (Radialpoint Security Services) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
O23 - Service: Verizon Internet Security Suite SafeConnectAgent (RadialpointSafeConnectAgent) - Unknown owner - C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe" RadialpointSafeConnectAgent (file missing)
O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe

km2357
2009-08-16, 20:02
Your HJT log looks good and I don't see anything bad in the GMER log.


I think that it is a little slower than a day or two ago, but I'm not sure.

Try the tips at website below and see if they help out any:

http://www.malwareremoval.com/tutorials/runningslowly.php



The Kaspersky Online scan found 9 files. They have the same ending as the files some of the files in the Combofix log that we ran a few days ago; the only difference is that they have the "Qoobox\quarantine" in front of them. It also is not all of the files that Combofix found. Do you think that the System restore undid some of the Combofix things or are these files leftover from Combofix?

The Qoobox folder is where ComboFix keeps its quarantined files. Kaspersky will often find those files when it does its scan, but it often doesn't find every file in the Qoobox folder as its database might not be updated to find it.

The System Restore may have undid some of what ComboFix had done, if that was the case I think that MalwareBytes' would have found more than what it did. But to be on the safe side, let's run ComboFix again:

First, delete ComboFix.exe off of your computer.

Then, download the latest version below:

Step # 1: Download and Run ComboFix

Download ComboFix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)

http://i266.photobucket.com/albums/ii277/sUBs_/combofix/CF_download_FF.gif


http://i266.photobucket.com/albums/ii277/sUBs_/combofix/CF_download_rename.gif
--------------------------------------------------------------------

Double click on Combo-Fix.exe & follow the prompts.
When finished, it will produce a report for you.
Please include C:\ComboFix.txt in your next reply.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall

Let me know if you run to any problems with ComboFix, either running it or after its run (i.e. the Change/Remove buttons going away again)

jlauv
2009-08-17, 04:45
The gmer log had this file in red when it said there was rootkit activity is below.

Library C:\Program (*** hidden *** ) @ C:\WINDOWS\explorer.exe [3596] was the program that was red.



The computer seems to be running ok. I think everything is running at a good speed. I did follow some of the tips from the website and it helped.



Believe it or not, after I ran the Combofix the change/remove buttons disappeared from my control panels add or remove programs.

Should I try to use the system restore to bring them back?

Here is the log from Combofix.

ComboFix 09-08-10.06 - Jeremy 08/16/2009 21:42.1.1 - NTFSx86
Running from: c:\documents and settings\Jeremy\Desktop\Combo-Fix.exe
AV: Verizon Internet Security Suite Anti-Virus *On-access scanning disabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
FW: Verizon Internet Security Suite Firewall *disabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\setup.exe


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SKYNETdcxeerbn
-------\Legacy_UACd.sys
-------\Service_SKYNETdcxeerbn


((((((((((((((((((((((((( Files Created from 2009-07-17 to 2009-08-17 )))))))))))))))))))))))))))))))
.

2009-08-16 03:28 . 2009-08-17 00:33 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\NOS
2009-08-15 20:09 . 2009-08-15 20:08 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-15 05:39 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 05:39 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-15 05:10 . 2009-08-15 05:10 -------- d-----w- c:\windows\system32\wbem\Repository
2009-08-14 23:59 . 2009-08-14 23:59 -------- d-----w- c:\documents and settings\Jeremy\Application Data\Malwarebytes
2009-08-14 23:59 . 2009-08-14 23:59 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
2009-08-14 23:59 . 2009-08-15 05:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-14 22:27 . 2009-08-15 05:08 -------- d-----w- C:\RECYCLER(2)
2009-08-11 19:49 . 2009-08-11 19:50 -------- d-----w- c:\program files\trend micro
2009-08-11 19:49 . 2009-08-11 19:50 -------- d-----w- C:\rsit
2009-08-10 18:35 . 2009-08-10 18:35 -------- d-----w- c:\program files\ERUNT
2009-08-07 18:17 . 2009-08-07 18:59 -------- d-----w- c:\documents and settings\Jeremy\Local Settings\Application Data\MicroVision Applications
2009-08-07 18:03 . 2009-08-07 18:03 -------- d-----w- C:\GLF1D9.tmp
2009-08-07 18:03 . 2009-08-07 18:50 -------- d-----w- c:\program files\Common Files\SureThing Shared
2009-08-07 18:03 . 2009-08-07 18:52 -------- d-----w- c:\program files\Memorex exPressit Label Design Studio
2009-08-07 18:03 . 2009-08-07 18:03 -------- d-----w- c:\windows\MVUNINST

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-17 02:04 . 2008-12-03 19:58 1310240 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-08-17 02:04 . 2008-12-03 19:58 15368224 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-08-17 02:03 . 2008-12-03 19:58 206852 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-17 02:03 . 2008-12-03 19:58 123860 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-08-16 03:45 . 2003-09-11 05:32 -------- d-----w- c:\program files\Viewpoint
2009-08-16 03:39 . 2003-10-07 00:57 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-15 05:55 . 2006-10-06 00:17 -------- d-----w- c:\program files\Java
2009-08-12 12:34 . 2005-08-29 22:39 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-12 12:34 . 2005-08-29 22:39 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-08-09 03:37 . 2003-10-14 23:54 -------- d-----w- c:\program files\Prentice Hall
2009-08-07 18:54 . 2003-09-17 02:16 111544 ----a-w- c:\documents and settings\Jeremy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 12:51 . 2008-11-16 20:12 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-02 04:22 . 2005-04-26 03:14 -------- d-----w- c:\program files\Google
2009-06-29 16:12 . 2004-08-24 00:32 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2002-08-29 10:00 17408 ------w- c:\windows\system32\corpol.dll
2009-06-16 14:36 . 2002-08-29 10:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2002-08-29 10:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:09 . 2003-05-30 13:00 1291264 ----a-w- c:\windows\system32\quartz.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-31 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-04-24 4616192]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"Dell AIO Printer A940"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-02-17 86102]
"Motive SmartBridge"="c:\progra~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe" [2005-08-03 385024]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"DACSMiniApp"="c:\program files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe" [2008-03-13 128256]
"mmtask"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2005-03-15 53248]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2009-03-12 2303216]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-15 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2003-9-11 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\SYSTEM32\DRIVERS\sfsync03.sys [12/6/2005 11:11 AM 35328]
R2 PD91Agent;PD91Agent;c:\program files\Raxco\PerfectDisk2008\PD91Agent.exe [9/22/2008 4:58 PM 693512]
R2 RadialpointSafeConnectAgent;Verizon Internet Security Suite SafeConnectAgent;c:\program files\Verizon\Verizon Internet Security Suite\SafeConnect\bin\SanaAgent.exe [11/14/2008 6:28 PM 4937752]
R3 PD91Engine;PD91Engine;c:\program files\Raxco\PerfectDisk2008\PD91Engine.exe [9/22/2008 4:58 PM 910600]
R3 Radialpoint Security Services;Verizon Internet Security Suite;c:\program files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe [4/22/2009 10:38 AM 170736]
R3 RadialpointSafeConnectDriver;RadialpointSafeConnectDriver;c:\program files\Verizon\Verizon Internet Security Suite\SafeConnect\Driver\platform_XP\SafeConnectDriver.sys [11/14/2008 6:28 PM 161304]
R3 RadialpointSafeConnectFilter;RadialpointSafeConnectFilter;c:\program files\Verizon\Verizon Internet Security Suite\SafeConnect\Driver\platform_XP\SafeConnectFilter.sys [11/14/2008 6:28 PM 29720]
R3 RadialpointSafeConnectShim;RadialpointSafeConnectShim;c:\program files\Verizon\Verizon Internet Security Suite\SafeConnect\Driver\platform_XP\SafeConnectShim.sys [11/14/2008 6:28 PM 27376]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = 127.0.0.1;localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\docume~1\Jeremy\APPLIC~1\Mozilla\Firefox\Profiles\7pzczmxw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - plugin: c:\documents and settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\7pzczmxw.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF - plugin: c:\program files\Verizon\VSP\nprpspa.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-16 22:05
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3492)
c:\windows\system32\WININET.dll
c:\progra~1\VERIZO~1\HELPSU~1\SMARTB~1\SBHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Verizon\Verizon Internet Security Suite\Fws.exe
c:\windows\SYSTEM32\LEXBCES.EXE
c:\windows\SYSTEM32\LEXPPS.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\SYSTEM32\DRIVERS\KodakCCS.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\progra~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
c:\program files\Dell AIO Printer A940\dlbabmon.exe
c:\program files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
c:\program files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
c:\program files\Common Files\MotiveBrowser\MotiveBrowser.exe
.
**************************************************************************
.
Completion time: 2009-08-17 22:18 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-17 02:17
ComboFix2.txt 2009-08-12 14:04

Pre-Run: 19,561,762,816 bytes free
Post-Run: 19,538,178,048 bytes free

151 --- E O F --- 2009-07-31 15:31

jlauv
2009-08-17, 05:19
Apparently, combofix did not create a restore point automatically. I now realize that I should have manually created a System Restore point before I ran Combofix. I just thought Combofix would create one, because it did last time. (I guess I'm learning to not take anything for granted.)

(The only thing that I can find wrong is that the change/remove buttons are gone again.)

The latest system restore point available for me is on 8/15 when I installed Adobe reader 9. This point is after I had run Malwarebytes, after I had installed the newest version of Java , and before I ran the gmer and Kaspersky online scan.


Should I restore do a system restore to that point?
Am I right in thinking that I would not need to redo the Gmer and the Kaspersky scan since they did not find anything unusual? I think the computer should have been "clean" at this restore point. I would just have to reinstall Adobe Reader.

(The only thing is that gmer did say that it detected rootkit activity and had the one file in red that I mentioned in my last post, but perhaps that is just a false flag.)

Or does Combofix create another way to go back to the way the computer was before Combofix was run?

km2357
2009-08-17, 07:19
Hmmm...still no idea on why ComboFix removed the Change/Remove button after it had run. First time I've ever seen this happen in the all times I've had people run ComboFix.

I'm going to ask my fellow malware fighters if they have any other ideas on how to get the Change/Remove buttons back without doing a System Restore. As you know, doing a System Restore can/will bring back malware that was removed and we don't get into the loop of doing system restore, removing malware, finding out the change/remove buttons are gone, and repeating it over and over.



(The only thing is that gmer did say that it detected rootkit activity and had the one file in red that I mentioned in my last post, but perhaps that is just a false flag.)

Let's go ahead and scan that file, just to make sure that it is a false flag/positive:


Step # 1 Upload Files

Go to Jotti (http://virusscan.jotti.org)
Copy the following line into the white textbox:
C:\WINDOWS\explorer.exe
Click Submit.
Please post the results of this scan to this thread.

If Jotti is busy, Go to VirusTotal (http://www.virustotal.com/en/indexf.html) and scan the file(s) there.


Post the results of the Jotti/Virustotal scan in your next post and I'll be back ASAP.

jlauv
2009-08-17, 12:56
I ran Jotti on that file, and everything is fine.
Every scan reported "found nothing."

Everything seems to be running well with the computer. :)

I'll wait for your reply on the change/remove buttons.

km2357
2009-08-18, 09:07
I'd like for you to go to the following file and double-click it:

C:\WINDOWS\ERDNT\Hiv-backup\erdnt.exe

Once the file has run, reboot your computer.

The change/remove buttons should be back, let me know if they aren't.

Also, (after your computer has rebooted), I'd like for you to create the following batch files. When you run these batch files, notepad will open up after each one. Be sure to save the batch file results so you can post them here in your next post.

Run Batchfile 1

Please copy (Ctrl+C) and paste (Ctrl+V) the following text in the codebox to Notepad. Save it as "All Files" and name it look.bat Please save it on your desktop.


regedit /e look.txt "[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"
notepad look.txt
del /q look.txt

Double click look.bat. A window will open and close. This is normal.


Run Batchfile2
Please copy (Ctrl+C) and paste (Ctrl+V) the following text in the codebox to Notepad. Save it as "All Files" and name it look1.bat Please save it on your desktop.


regedit /e look1.txt "[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"
notepad look1.txt
del /q look1.txt

Double click look1.bat. A window will open and close. This is normal.


In your next post, I need to see the following:

1. Let me know if the change/remove buttons came back.
2. The results of the look and look1 batch files.

jlauv
2009-08-19, 15:27
I ran ERDNT and it did bring back the change/remove buttons in the add/remove programs. :)

I'm having trouble with the look.bat and look1.bat.

After clicking on the Look.bat a window opens up, and then notepad opens with a blank file and it says that it "cannot find look.txt file. Do you want to create a new file?" I clicked yes one time and no another time and nothing happens. I can't seem to find a file titled Look.txt to post.

The same thing happened for the look1.bat.

km2357
2009-08-19, 20:24
Ok, let's try this instead.

First, delete both look and look1.bat.

Then, do the following:

Step # 1: Run Batchfile

Please copy (Ctrl+C) and paste (Ctrl+V) the following text in the codebox to Notepad. Save it as "All Files" and name it lookreg.bat Please save it on your desktop.


regedit /e peek1.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall"
regedit /e peek2.txt "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall"
type peek1.txt >> lookreg.txt
type peek2.txt >> lookreg.txt
del peek*.txt
start notepad lookreg.txt

Double click lookreg.bat. A window will open and close. This is normal.


Post the contents of the lookreg.txt file in your next post.

jlauv
2009-08-19, 21:02
The lookreg is too long, so I'm going to use multiple posts:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"DisplayName"=""
"UninstallString"="C:\\DOCUME~1\\Jeremy\\LOCALS~1\\Temp\\mpf542tk.tmp\\UNWISE.EXE C:\\DOCUME~1\\Jeremy\\LOCALS~1\\Temp\\mpf542tk.tmp\\INSTALL.LOG"
"NoRemove"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\3dhomeDeinstKey]
"UninstallString"="C:\\WINDOWS\\uninst.exe -f\"C:\\Program Files\\Expert Software\\Home Design 3D v5.0\\DeIsL1.isu\""
"DisplayName"="Expert Home Design 3D v5.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ABBYY FineReader 5.0 Sprint]
"TradeMark"="This software is licensed to Lexmark International, Inc. SN: SPR5-2100002-84500"
"ProductID"="5.0.0.22227"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ad-Aware SE Personal]
"DisplayName"="Ad-Aware SE Personal"
"UninstallString"="C:\\PROGRA~1\\Lavasoft\\AD-AWA~1\\UNWISE.EXE C:\\PROGRA~1\\Lavasoft\\AD-AWA~1\\INSTALL.LOG"
"HelpLink"="http://www.lavasoft.com"
"Publisher"="Lavasoft"
"DisplayIcon"="C:\\PROGRA~1\\Lavasoft\\AD-AWA~1\\Ad-Aware.exe,-0"
"URLInfoAbout"="http://www.lavasoft.com"
"DisplayVersion"="1.06"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player Plugin]
"DisplayName"="Adobe Flash Player 10 Plugin"
"DisplayVersion"="10.0.22.87"
"Publisher"="Adobe Systems Incorporated"
"URLInfoAbout"="http://www.adobe.com/go/getflashplayer"
"DisplayIcon"="C:\\WINDOWS\\system32\\Macromed\\Flash\\uninstall_plugin.exe"
"UninstallString"="C:\\WINDOWS\\system32\\Macromed\\Flash\\uninstall_plugin.exe"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Shockwave Player]
"DisplayName"="Adobe Shockwave Player"
"UninstallString"="C:\\WINDOWS\\SYSTEM32\\Macromed\\SHOCKW~2\\UNWISE.EXE C:\\WINDOWS\\SYSTEM32\\Macromed\\SHOCKW~2\\Install.log"
"DisplayVersion"="10.2.0.23"
"Publisher"="Adobe Systems, Inc."
"URLInfoAbout"="http://www.adobe.com"
"HelpLink"="http://www.adobe.com/support/shockwave"
"URLUpdateInfo"="http://www.adobe.com/software/shockwaveplayer/index.html"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Arthur's Wilderness Rescue]
"UninstallString"="C:\\WINDOWS\\TLCUninstall.exe -f \"C:\\Program Files\\The Learning Company\\Arthur's Wilderness Rescue\\Uninstall.xml\""
"DisplayName"="Arthur's Wilderness Rescue"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Automap 9.0]
"ProductID"="55058-OEM-0000007-00000"
"RegOwner"="Preferred Customer"
"RegCompany"="PreInstalled"
"URLInfoAbout"="http://www.microsoft.com/streets"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Beginning Sounds]
"DisplayName"="Beginning Sounds"
"UninstallString"="C:\\WINDOWS\\unvise32.exe C:\\Program Files\\sz8031\\uninstal.log"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bible Stories]
"UninstallString"="C:\\WINDOWS\\uninst.exe -r\"DK Multimedia\\Bible Stories\\1, 0, 0, 1\" -n\"Bible Stories\" -fC:\\PROGRA~1\\DKMULT~1\\BIBLES~1\\DeIsL1.isu -cC:\\PROGRA~1\\DKMULT~1\\BIBLES~1\\uninst.dll"
"DisplayName"="Bible Stories"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Blue's Reading Time Activities]
"UninstallString"="C:\\WINDOWS\\IsUninst.exe -f\"C:\\HEGames\\Blue's Reading Time Activities\\Uninst.isu\""
"DisplayName"="Blue's Reading Time Activities"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Branding]
"QuietUninstallString"="Rundll32 IedkCS32.dll,BrandCleanInstallStubs"
"RequiresIESysFile"="100.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CCleaner]
"DisplayName"="CCleaner (remove only)"
"UninstallString"="\"C:\\Program Files\\CCleaner\\uninst.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ChemASAP]
"UninstallString"="C:\\WINDOWS\\IsUninst.exe -f\"C:\\Program Files\\Addison Wesley Longman\\Chem ASAP!\\Uninst.isu\""
"DisplayName"="Chem ASAP!"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CNXT_MODEM_PCI_VEN_14F1&DEV_2702]
"DisplayName"="Conexant SmartHSFi V92 56K DF PCI Modem"
"UninstallString"="C:\\Program Files\\CONEXANT\\CNXT_MODEM_PCI_VEN_14F1&DEV_2702\\HXFSETUP.EXE -U -IDel8d8xk.INF"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Curious George v1.0]
"DisplayName"="Curious George v1.0"
"UninstallString"="\"C:\\Program Files\\Namco\\Curious George\\uninstall.exe\""
"NoModify"=dword:00000001
"NoRepair"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\David and Goliath]
"DisplayName"="David and Goliath"
"UninstallString"="C:\\PROGRA~1\\BRIGHT~1\\David\\UNWISE.EXE C:\\PROGRA~1\\BRIGHT~1\\David\\INSTALL.LOG"
"Publisher"="Brighter Child"
"URLInfoAbout"="http://www.brighterchild.com"
"DisplayIcon"="C:\\PROGRA~1\\BRIGHT~1\\David\\Jesus.ico,-0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dell AIO Printer A940]
"DisplayName"="Dell AIO Printer A940"
"UninstallString"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\DLBAUN5C.EXE -dDell AIO Printer A940"
"DisplayIcon"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\DLBAUN5C.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dell Digital Jukebox Driver]
"DisplayName"="Dell Digital Jukebox Driver"
"UninstallString"="C:\\Program Files\\Dell\\Digital Jukebox Drivers\\DrvUnins.exe /s"
"UnwiseLog"="C:\\WINDOWS\\UNWISE.EXE C:\\WINDOWS\\DJBDRV.LOG"
"DisplayIcon"="C:\\Program Files\\Dell\\Digital Jukebox Drivers\\CtDrvStp.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectAnimation]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVD Flick_is1]
"Inno Setup: Setup Version"="5.1.12"
"Inno Setup: App Path"="C:\\Program Files\\DVD Flick"
"InstallLocation"="C:\\Program Files\\DVD Flick\\"
"Inno Setup: Icon Group"="DVD Flick"
"Inno Setup: No Icons"=dword:00000001
"Inno Setup: User"="Jeremy"
"Inno Setup: Selected Tasks"="desktopicon"
"Inno Setup: Deselected Tasks"="associate"
"DisplayName"="DVD Flick"
"DisplayIcon"="C:\\Program Files\\DVD Flick\\dvdflick.exe"
"UninstallString"="\"C:\\Program Files\\DVD Flick\\unins000.exe\""
"QuietUninstallString"="\"C:\\Program Files\\DVD Flick\\unins000.exe\" /SILENT"
"DisplayVersion"="1.2.2.0"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"InstallDate"="20070831"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ERUNT_is1]
"Inno Setup: Setup Version"="4.2.7"
"Inno Setup: App Path"="C:\\Program Files\\ERUNT"
"InstallLocation"="C:\\Program Files\\ERUNT\\"
"Inno Setup: Icon Group"="ERUNT"
"Inno Setup: User"="Jeremy"
"Inno Setup: Selected Tasks"="eruntdesktopicon"
"Inno Setup: Deselected Tasks"="ntregoptdesktopicon,eruntquicklaunchicon,ntregoptquicklaunchicon,installgermanlanguagefiles"
"DisplayName"="ERUNT 1.1j"
"UninstallString"="\"C:\\Program Files\\ERUNT\\unins000.exe\""
"QuietUninstallString"="\"C:\\Program Files\\ERUNT\\unins000.exe\" /SILENT"
"Publisher"="Lars Hederer"
"URLInfoAbout"="http://www.larshederer.homepage.t-online.de"
"HelpLink"="http://www.larshederer.homepage.t-online.de/erunt"
"URLUpdateInfo"="http://www.larshederer.homepage.t-online.de/erunt"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ExamView Pro]
"DisplayName"="ExamView Pro"
"UninstallString"="C:\\WINDOWS\\unvise32.exe C:\\ExamView\\uninstal.log"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\exPressit S.E. 2.1]
"DisplayName"="exPressit S.E. 2.1"
"UninstallString"="\"C:\\Program Files\\exPressit S.E. 2.1\\UninstallerData\\Uninstall exPressit S.E. 2.1.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Help and Support]
"UninstallString"="C:\\PROGRA~1\\VERIZO~1\\HELPSU~1\\Uninstall.exe Verizon"
"Publisher"="Motive Communications, Inc."
"DisplayIcon"="C:\\Program Files\\Verizon Online\\Help Support\\bin\\resource.dll,1"
"DisplayVersion"="5.6.17.asst_classic.asst_install"
"URLInfoAbout"="http://www.motive.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis]
"DisplayName"="HijackThis 1.99.1"
"UninstallString"="C:\\Documents and Settings\\Jeremy\\Desktop\\Downloads\\HijackThis.exe /uninstall"
"DisplayIcon"="C:\\Documents and Settings\\Jeremy\\Desktop\\Downloads\\HijackThis.exe"
"DisplayVersion"="1.99.1"
"Publisher"="Soeperman Enterprises Ltd."
"URLInfoAbout"="http://www.spywareinfo.com/~merijn/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ICW]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IDNMitigationAPIs]
"DisplayName"="Microsoft Internationalized Domain Names Mitigation APIs"
"UninstallString"="\"C:\\WINDOWS\\$NtServicePackUninstallIDNMitigationAPIs$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20071118"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HiddenByIE7Setup"=dword:00000001
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7]
"DisplayName"="Windows Internet Explorer 7"
"UninstallString"=""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20071118"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://www.microsoft.com/ie"
"URLInfoAbout"="http://www.microsoft.com/ie"
"DisplayVersion"="20070813.185237"
"DisplayIcon"="C:\\Program Files\\Internet Explorer\\iexplore.exe"
"NoRemove"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield Uninstall Information]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield Uninstall Information\{6DD58468-7E3B-4B8B-BE9C-67E6595D9C55}]
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{6DD58468-7E3B-4B8B-BE9C-67E6595D9C55}\\Setup.ilg"
"StatusText"="Internet Security Suite Setup is preparing the InstallShield Wizard, which will guide you through the program setup process. Please wait."

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB870669]
"DisplayName"="Microsoft Data Access Components KB870669"
"QuietDisplayName"="Microsoft Data Access Components KB870669"
"UninstallString"="C:\\WINDOWS\\muninst.exe C:\\WINDOWS\\INF\\KB870669.inf"
"RequiresIESysFile"="6.0.2800.1106"
"QuietUninstallString"="C:\\WINDOWS\\muninst.exe /d C:\\WINDOWS\\INF\\KB870669.inf"
"HelpLinK"="http://support.microsoft.com?kbid=KB870669"
"URLInfoAbout"="http://support.microsoft.com"
"Publisher"="Microsoft Corporation"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB884016]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB884267]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB885353]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB886612]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB887078]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB887626]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888656]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB889858]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB891122]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB892313]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB893240]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB893241]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB895181]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB895316]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB895572]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB897586]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB898549]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB900399]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB902344]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB907658]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911564]
"DisplayName"="Security Update for Windows Media Player (KB911564)"
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070628"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com/?kbid=911564"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayIcon"=hex(2):22,00,25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
00,69,00,6c,00,65,00,73,00,25,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,6d,00,65,00,64,00,69,00,61,00,20,00,70,00,6c,00,61,00,79,00,65,\
00,72,00,5c,00,77,00,6d,00,70,00,6c,00,61,00,79,00,65,00,72,00,2e,00,65,00,\
78,00,65,00,22,00,00,00
"ParentKeyName"="OperatingSystem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911565]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911854]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923561]
"DisplayName"="Security Update for Windows XP (KB923561)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB923561$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090415"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=923561"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB923561"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923723]
"DisplayName"="Security Update for Step By Step Interactive Training (KB923723)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB923723$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070628"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com/kb/923723"
"DisplayVersion"="20050502.101010"
"ParentKeyName"="Microsoft Learning"
"ParentDisplayName"="Microsoft Learning - Software Updates"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64]
"DisplayName"="Security Update for Windows Media Player 6.4 (KB925398)"
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070628"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com/?kbid=925398"
"URLInfoAbout"="http://support.microsoft.com"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows Media Player 6.4\\KB925398_WMP64"
"ReleaseType"="Security Update"
"DisplayIcon"=hex(2):22,00,25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
00,69,00,6c,00,65,00,73,00,25,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,6d,00,65,00,64,00,69,00,61,00,20,00,70,00,6c,00,61,00,79,00,65,\
00,72,00,5c,00,6d,00,70,00,6c,00,61,00,79,00,65,00,72,00,32,00,2e,00,65,00,\
78,00,65,00,22,00,00,00
"ParentKeyName"="OperatingSystem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929399]
"DisplayName"="Hotfix for Windows Media Format 11 SDK (KB929399)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB929399$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070628"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com/?kbid=929399"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayIcon"=hex(2):22,00,25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
00,69,00,6c,00,65,00,73,00,25,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,6d,00,65,00,64,00,69,00,61,00,20,00,70,00,6c,00,61,00,79,00,65,\
00,72,00,5c,00,77,00,6d,00,70,00,6c,00,61,00,79,00,65,00,72,00,2e,00,65,00,\
78,00,65,00,22,00,00,00
"ParentKeyName"="OperatingSystem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB931906]
"DisplayName"="Security Update for CAPICOM (KB931906)"
"DisplayVersion"="2.1.0.2"
"ParentDisplayName"="CAPICOM"
"ParentKeyName"="CAPICOM"
"Publisher"="Microsoft Corporation"
"ReleaseType"="Security Update"
"UninstallString"="MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}"
"HelpLink"="http://support.microsoft.com?kbid=931906"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB936782_WMP11]
"DisplayName"="Security Update for Windows Media Player 11 (KB936782)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB936782_WMP11$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070815"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com/?kbid=936782"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayIcon"=hex(2):22,00,25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
00,69,00,6c,00,65,00,73,00,25,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,6d,00,65,00,64,00,69,00,61,00,20,00,70,00,6c,00,61,00,79,00,65,\
00,72,00,5c,00,77,00,6d,00,70,00,6c,00,61,00,79,00,65,00,72,00,2e,00,65,00,\
78,00,65,00,22,00,00,00
"ParentKeyName"="OperatingSystem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB938127-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB938127)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB938127-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20071118"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=938127"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB938127-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB938464]
"DisplayName"="Security Update for Windows XP (KB938464)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB938464$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=938464"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB938464"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB938464-v2]
"DisplayName"="Security Update for Windows XP (KB938464-v2)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB938464-v2$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090312"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=938464"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="2"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB938464-v2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB939653-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB939653)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB939653-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20071118"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=939653"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB939653-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB939683]
"DisplayName"="Hotfix for Windows Media Player 11 (KB939683)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB939683$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070831"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com/?kbid=939683"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayIcon"=hex(2):22,00,25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
00,69,00,6c,00,65,00,73,00,25,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,6d,00,65,00,64,00,69,00,61,00,20,00,70,00,6c,00,61,00,79,00,65,\
00,72,00,5c,00,77,00,6d,00,70,00,6c,00,61,00,79,00,65,00,72,00,2e,00,65,00,\
78,00,65,00,22,00,00,00
"ParentKeyName"="OperatingSystem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB941569]
"DisplayName"="Security Update for Windows XP (KB941569)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB941569$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20071212"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=941569"
"URLInfoAbout"="http://support.microsoft.com"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\KB941569"
"ReleaseType"="Security Update"
"ParentKeyName"="OperatingSystem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB942615-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB942615)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB942615-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20071212"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=942615"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB942615-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB944533-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB944533)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB944533-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20080214"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=944533"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB944533-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB946648]
"DisplayName"="Security Update for Windows XP (KB946648)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB946648$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=946648"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB946648"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB947864-IE7]
"DisplayName"="Hotfix for Windows Internet Explorer 7 (KB947864)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB947864-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20080409"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=947864"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB947864-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Hotfix"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB950759-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB950759)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB950759-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20080611"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=950759"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB950759-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB950760]
"DisplayName"="Security Update for Windows XP (KB950760)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB950760$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20080611"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=950760"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB950760"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB950762]
"DisplayName"="Security Update for Windows XP (KB950762)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB950762$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=950762"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB950762"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB950974]
"DisplayName"="Security Update for Windows XP (KB950974)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB950974$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=950974"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB950974"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951066]
"DisplayName"="Security Update for Windows XP (KB951066)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB951066$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=951066"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB951066"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951072-v2]
"DisplayName"="Update for Windows XP (KB951072-v2)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB951072-v2$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20080813"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=951072"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="2"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB951072-v2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951376]
"DisplayName"="Security Update for Windows XP (KB951376)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB951376$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=951376"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB951376"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951376-v2]
"DisplayName"="Security Update for Windows XP (KB951376-v2)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB951376-v2$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=951376"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="2"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB951376-v2"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951698]
"DisplayName"="Security Update for Windows XP (KB951698)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB951698$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=951698"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB951698"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951748]
"DisplayName"="Security Update for Windows XP (KB951748)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB951748$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=951748"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB951748"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951978]
"DisplayName"="Update for Windows XP (KB951978)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB951978$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081204"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=951978"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB951978"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB952004]
"DisplayName"="Security Update for Windows XP (KB952004)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB952004$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090415"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=952004"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB952004"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB952069_WM9]
"DisplayName"="Security Update for Windows Media Player (KB952069)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB952069_WM9$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081211"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com/?kbid=952069"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayIcon"=hex(2):22,00,25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
00,69,00,6c,00,65,00,73,00,25,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,6d,00,65,00,64,00,69,00,61,00,20,00,70,00,6c,00,61,00,79,00,65,\
00,72,00,5c,00,77,00,6d,00,70,00,6c,00,61,00,79,00,65,00,72,00,2e,00,65,00,\
78,00,65,00,22,00,00,00
"ParentKeyName"="OperatingSystem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB952287]
"DisplayName"="Hotfix for Windows XP (KB952287)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB952287$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=952287"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB952287"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB952954]
"DisplayName"="Security Update for Windows XP (KB952954)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB952954$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=952954"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB952954"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB953838-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB953838)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB953838-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20080813"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=953838"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB953838-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB953839]
"DisplayName"="Security Update for Windows XP (KB953839)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB953839$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20080813"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=953839"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB953839"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB954154_WM11]
"DisplayName"="Security Update for Windows Media Player 11 (KB954154)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB954154_WM11$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20080910"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com/?kbid=954154"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayIcon"=hex(2):22,00,25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
00,69,00,6c,00,65,00,73,00,25,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,6d,00,65,00,64,00,69,00,61,00,20,00,70,00,6c,00,61,00,79,00,65,\
00,72,00,5c,00,77,00,6d,00,70,00,6c,00,61,00,79,00,65,00,72,00,2e,00,65,00,\
78,00,65,00,22,00,00,00
"ParentKeyName"="OperatingSystem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB954211]
"DisplayName"="Security Update for Windows XP (KB954211)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB954211$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=954211"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB954211"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB954459]
"DisplayName"="Security Update for Windows XP (KB954459)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB954459$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081204"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=954459"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB954459"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB954600]
"DisplayName"="Security Update for Windows XP (KB954600)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB954600$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081211"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=954600"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB954600"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB955069]
"DisplayName"="Security Update for Windows XP (KB955069)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB955069$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=955069"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB955069"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB955839]
"DisplayName"="Update for Windows XP (KB955839)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB955839$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081211"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=955839"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB955839"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956390-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB956390)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB956390-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081015"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=956390"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB956390-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956391]
"DisplayName"="Security Update for Windows XP (KB956391)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB956391$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081015"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=956391"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB956391"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956572]
"DisplayName"="Security Update for Windows XP (KB956572)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB956572$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090415"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=956572"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB956572"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956802]
"DisplayName"="Security Update for Windows XP (KB956802)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB956802$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081211"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=956802"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB956802"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956803]
"DisplayName"="Security Update for Windows XP (KB956803)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB956803$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=956803"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB956803"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956841]
"DisplayName"="Security Update for Windows XP (KB956841)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB956841$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=956841"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB956841"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB957095]
"DisplayName"="Security Update for Windows XP (KB957095)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB957095$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081203"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=957095"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB957095"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB957097]
"DisplayName"="Security Update for Windows XP (KB957097)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB957097$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081203"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=957097"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB957097"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

jlauv
2009-08-19, 21:03
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB958215-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB958215)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB958215-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081211"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=958215"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB958215-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB958644]
"DisplayName"="Security Update for Windows XP (KB958644)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB958644$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081203"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=958644"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB958644"
"NoRemove"=dword:00000001
"MigratedCount"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB958687]
"DisplayName"="Security Update for Windows XP (KB958687)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB958687$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090116"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=958687"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB958687"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB958690]
"DisplayName"="Security Update for Windows XP (KB958690)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB958690$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090312"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=958690"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB958690"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB959426]
"DisplayName"="Security Update for Windows XP (KB959426)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB959426$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090415"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=959426"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB959426"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB959772_WM11]
"DisplayName"="Critical Update for Windows Media Player 11 (KB959772)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB959772_WM11$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090312"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com/?kbid=959772"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayIcon"=hex(2):22,00,25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
00,69,00,6c,00,65,00,73,00,25,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,6d,00,65,00,64,00,69,00,61,00,20,00,70,00,6c,00,61,00,79,00,65,\
00,72,00,5c,00,77,00,6d,00,70,00,6c,00,61,00,79,00,65,00,72,00,2e,00,65,00,\
78,00,65,00,22,00,00,00
"ParentKeyName"="OperatingSystem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB960225]
"DisplayName"="Security Update for Windows XP (KB960225)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB960225$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090312"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=960225"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB960225"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB960714-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB960714)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB960714-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081219"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=960714"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB960714-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB960715]
"DisplayName"="Security Update for Windows XP (KB960715)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB960715$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090212"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=960715"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB960715"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB960803]
"DisplayName"="Security Update for Windows XP (KB960803)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB960803$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090415"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=960803"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB960803"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB961260-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB961260)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB961260-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090212"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=961260"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB961260-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB961371]
"DisplayName"="Security Update for Windows XP (KB961371)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB961371$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090716"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=961371"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB961371"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB961373]
"DisplayName"="Security Update for Windows XP (KB961373)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB961373$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090415"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=961373"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB961373"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB961501]
"DisplayName"="Security Update for Windows XP (KB961501)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB961501$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090611"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=961501"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB961501"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB963027-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB963027)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB963027-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090419"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=963027"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB963027-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB967715]
"DisplayName"="Update for Windows XP (KB967715)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB967715$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090226"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=967715"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB967715"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB968537]
"DisplayName"="Security Update for Windows XP (KB968537)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB968537$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090611"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=968537"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB968537"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB969897-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB969897)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB969897-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090611"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=969897"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB969897-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB969898]
"DisplayName"="Security Update for Windows XP (KB969898)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB969898$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090611"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=969898"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB969898"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB970238]
"DisplayName"="Security Update for Windows XP (KB970238)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB970238$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090611"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=970238"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB970238"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971633]
"DisplayName"="Security Update for Windows XP (KB971633)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB971633$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090716"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=971633"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB971633"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB972260-IE7]
"DisplayName"="Security Update for Windows Internet Explorer 7 (KB972260)"
"UninstallString"="\"C:\\WINDOWS\\ie7updates\\KB972260-IE7\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090730"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=972260"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"DisplayIcon"="C:\\Program Files\\internet explorer\\iexplore.exe"
"ParentKeyName"="ie7Hotfix"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP0\\KB972260-IE7"
"RemoveOnIE7Uninstall"=dword:00000001
"ParentDisplayName"="Windows Internet Explorer 7 - Software Updates"
"ReleaseType"="Security Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973346]
"DisplayName"="Security Update for Windows XP (KB973346)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB973346$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20090716"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=973346"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Security Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP4\\KB973346"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LBT Preschool Adventure]
"DisplayName"="LBT Preschool Adventure"
"UninstallString"="C:\\PROGRA~1\\BRIGHT~1\\LBTPRE~1\\UNWISE.EXE C:\\PROGRA~1\\BRIGHT~1\\LBTPRE~1\\INSTALL.LOG"
"Publisher"="Brighter Child"
"URLInfoAbout"="http://www.brighterchild.com"
"DisplayIcon"="C:\\PROGRA~1\\BRIGHT~1\\LBTPRE~1\\Jesus.ico,-0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\M928366]
"DisplayName"="Microsoft .NET Framework 1.1 Hotfix (KB928366)"
"DisplayIcon"="C:\\WINDOWS\\system32\\msiexec.exe"
"UninstallString"="\"C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.1.4322\\Updates\\hotfix.exe\" \"C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.1.4322\\Updates\\M928366\\M928366Uninstall.msp\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Magic 3D Coloring Book]
"UninstallString"="C:\\WINDOWS\\IsUninst.exe -f\"C:\\Program Files\\IBM and Crayola\\Magic 3D\\Uninst.isu\""
"DisplayName"="Magic 3D Coloring Book"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Malwarebytes' Anti-Malware_is1]
"Inno Setup: Setup Version"="5.2.4-dev"
"Inno Setup: App Path"="C:\\Program Files\\Malwarebytes' Anti-Malware"
"InstallLocation"="C:\\Program Files\\Malwarebytes' Anti-Malware\\"
"Inno Setup: Icon Group"="Malwarebytes' Anti-Malware"
"Inno Setup: User"="Jeremy"
"Inno Setup: Selected Tasks"="desktopicon"
"Inno Setup: Deselected Tasks"="quicklaunchicon"
"DisplayName"="Malwarebytes' Anti-Malware"
"DisplayIcon"="C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"
"UninstallString"="\"C:\\Program Files\\Malwarebytes' Anti-Malware\\unins000.exe\""
"QuietUninstallString"="\"C:\\Program Files\\Malwarebytes' Anti-Malware\\unins000.exe\" /SILENT"
"Publisher"="Malwarebytes Corporation"
"URLInfoAbout"="http://www.malwarebytes.org"
"HelpLink"="http://www.malwarebytes.org"
"URLUpdateInfo"="http://www.malwarebytes.org"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"InstallDate"="20090815"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 1.1 (1033)]
"UninstallString"="msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"
"Readme"="file://C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.1.4322\\1033\\RepairRedist.htm"
"DisplayName"="Microsoft .NET Framework 1.1"
"DisplayIcon"="C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.1.4322\\ndpsetup.ico"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 2.0]
"DisplayIcon"="C:\\WINDOWS\\system32\\msiexec.exe"
"DisplayName"="Microsoft .NET Framework 2.0"
"UninstallString"="C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\Microsoft .NET Framework 2.0\\install.exe"
"VersionMinor"="0"
"VersionMajor"="2"
"Publisher"="Microsoft Corporation"
"InstallLocation"="C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\"
"UninstallPath"="C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\Microsoft .NET Framework 2.0\\install.exe"
"URLUpdateInfo"="http://go.microsoft.com/fwlink/?LinkId=45660"
"HelpLink"="http://go.microsoft.com/fwlink/?LinkId=45396"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Interactive Training]
"UninstallString"="C:\\WINDOWS\\IsUninst.exe -fC:\\WINDOWS\\orun32.isu"
"ISUninstaller"="C:\\WINDOWS\\ISUNINST.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft NetShow Player 2.0]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox (3.0.12)]
"Comments"="Mozilla Firefox"
"DisplayIcon"="C:\\Program Files\\Mozilla Firefox\\firefox.exe,0"
"DisplayName"="Mozilla Firefox (3.0.12)"
"DisplayVersion"="3.0.12 (en-US)"
"InstallLocation"="C:\\Program Files\\Mozilla Firefox"
"Publisher"="Mozilla"
"UninstallString"="C:\\Program Files\\Mozilla Firefox\\uninstall\\helper.exe"
"URLInfoAbout"="http://en-US.www.mozilla.com/en-US/"
"URLUpdateInfo"="http://en-US.www.mozilla.com/en-US/firefox/"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSCompPackV1]
"DisplayName"="Microsoft Compression Client Pack 1.0 for Windows XP"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallMSCompPackV1$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://go.microsoft.com/fwlink/?LinkId=74087"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSI30-Beta1]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSI30-Beta2]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSI30-KB884016]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSI30-RC1]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSI30-RC2]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSI30a-KB884016]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSI31-Beta]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSI31-RC1]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MsJavaVM]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSN Music Assistant]
"DisplayName"="MSN Music Assistant"
"UninstallString"="rundll32 advpack.dll,LaunchINFSection C:\\WINDOWS\\INF\\msninst.inf,Uninstall"
"DisplayIcon"="C:\\Progra~1\\MsnMusic\\4226251\\MsnMusic.exe,0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MVApplication1]
"DisplayName"="Memorex exPressit Label Design Studio"
"UninstallString"="C:\\WINDOWS\\mvuninst\\App1\\mvuninst.exe \"Memorex exPressit Label Design Studio\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetMeeting]
"RequiresIESysFile"="4.71"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NLSDownlevelMapping]
"DisplayName"="Microsoft National Language Support Downlevel APIs"
"UninstallString"="\"C:\\WINDOWS\\$NtServicePackUninstallNLSDownlevelMapping$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20071118"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HiddenByIE7Setup"=dword:00000001
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NVIDIA]
@=""
"DisplayName"="NVIDIA Windows 2000/XP Display Drivers"
"UninstallString"="rundll32.exe C:\\WINDOWS\\System32\\nvinstnt.dll,NvUninstallNT4 nvdd.inf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OutlookExpress]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCHealth]
"UninstallString"="rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\\WINDOWS\\INF\\PCHealth.inf"
"QuietUninstallString"="rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\\WINDOWS\\INF\\PCHealth.inf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Photo Viewer]
"DisplayName"="Photo Viewer 2.3"
"UninstallString"="\"C:\\Program Files\\Photo Viewer\\uninstall.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name]
"DisplayName"="Minnesota Cuke"
"UninstallString"="C:\\WINDOWS\\iun507.exe C:\\Program Files\\BigIdea\\Minnesota Cuke\\irunin.ini"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PROSet]
"DisplayName"="Intel(R) PRO Network Adapters and Drivers"
"UninstallString"="Prounstl.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RadialpointClientGateway_is1]
"Inno Setup: Setup Version"="5.1.8"
"Inno Setup: App Path"="C:\\Program Files\\Verizon\\VSP"
"InstallLocation"="C:\\Program Files\\Verizon\\VSP\\"
"Inno Setup: Icon Group"="Verizon Servicepoint"
"Inno Setup: User"="Jeremy"
"DisplayName"="Verizon Servicepoint 1.5.24"
"DisplayIcon"="C:\\Program Files\\Verizon\\VSP\\VerizonServicepoint.exe"
"UninstallString"="\"C:\\Program Files\\Verizon\\VSP\\unins000.exe\""
"QuietUninstallString"="\"C:\\Program Files\\Verizon\\VSP\\unins000.exe\" /SILENT"
"DisplayVersion"="1.5.24"
"Publisher"="Verizon"
"URLInfoAbout"="http://www.verizon.freedom.net/vsp-support-page/"
"HelpLink"="http://www.verizon.freedom.net/vsp-support-page/"
"URLUpdateInfo"="http://www.verizon.freedom.net/vsp-support-page/"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"InstallDate"="20090602"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reader Rabbit Math Ages 4-6]
"UninstallString"="C:\\Program Files\\The Learning Company\\Reader Rabbit Math Ages 4-6\\uninstal.exe"
"DisplayName"="Reader Rabbit Math Ages 4-6"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reader Rabbit(R) Playtime For Baby & Toddler]
"UninstallString"="C:\\Program Files\\The Learning Company\\Reader Rabbit(R) Playtime For Baby & Toddler\\uninstall.exe"
"DisplayName"="Reader Rabbit(R) Playtime For Baby & Toddler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RealJukebox 1.0]
@=""
"UninstallString"="C:\\Program Files\\Common Files\\Real\\Update_OB\\rnuninst.exe RealNetworks|RealPlayer|6.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RealPlayer 6.0]
@=""
"UninstallString"="C:\\Program Files\\Common Files\\Real\\Update_OB\\rnuninst.exe RealNetworks|RealPlayer|6.0"
"DisplayName"="RealOne Player"
"DisplayIcon"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shockwave]
"DisplayName"="Shockwave"
"UninstallString"="C:\\WINDOWS\\SYSTEM32\\MACROMED\\SHOCKW~1\\UNWISE.EXE C:\\WINDOWS\\SYSTEM32\\MACROMED\\SHOCKW~1\\Install.log"
"QuietDisplayName"="Shockwave Director 10.2"
"QuietUninstallString"="RunDll32 advpack.dll,LaunchINFSection C:\\WINDOWS\\\\INF\\\\swdir.inf,DefaultUninstall,5"
"RequiresIESysFile"="4.70.0.1155"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShockwaveFlash]
"QuietDisplayName"="Shockwave Flash"
"QuietUninstallString"="RunDll32 advpack.dll,LaunchINFSection C:\\WINDOWS\\INF\\swflash.inf,DefaultUninstall,5"
"RequiresIESysFile"="4.70.0.1155"
"DisplayName"="Adobe Flash Player 9 ActiveX"
"UninstallString"="C:\\WINDOWS\\system32\\Macromed\\Flash\\UninstFl.exe -q"
"Publisher"="Adobe Systems"
"DisplayVersion"="9"
"VersionMajor"="9"
"VersionMinor"="0"
"HelpLink"="http://www.adobe.com/go/flashplayer_support/"
"URLUpdateInfo"="http://www.adobe.com/go/flashplayer/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\The Land Before Time Kindergarten Adventure]
"DisplayName"="The Land Before Time Kindergarten Adventure"
"UninstallString"="C:\\Lbtkind\\UNWISE.EXE C:\\Lbtkind\\INSTALL.LOG"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Thomas & Friends - Trouble on the Tracks]
"UninstallString"="C:\\WINDOWS\\IsUninst.exe -f\"C:\\Program Files\\Hasbro Interactive\\Thomas & Friends - Trouble on the Tracks\\Uninst.isu\""
"DisplayName"="Thomas & Friends - Trouble on the Tracks"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Verizon Online DSL_is1]
"Inno Setup: Setup Version"="5.1.14"
"Inno Setup: App Path"="C:\\Program Files\\Verizon\\DSL"
"InstallLocation"="C:\\Program Files\\Verizon\\DSL\\"
"Inno Setup: Icon Group"="(Default)"
"Inno Setup: User"="Jeremy"
"DisplayName"="Verizon Online DSL"
"DisplayIcon"="C:\\Program Files\\Common Files\\SupportSoft\\Verizon\\vzuninstall.exe"
"UninstallString"="C:\\Program Files\\Common Files\\SupportSoft\\Verizon\\vzuninstall.exe /starthidden"
"QuietUninstallString"="\"C:\\WINDOWS\\DSL\\unins000.exe\" /SILENT"
"Publisher"="Verizon"
"URLInfoAbout"="http://www.verizon.com/"
"HelpLink"="http://www.verizon.com/"
"URLUpdateInfo"="http://www.verizon.com/"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"InstallDate"="20070930"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Verizon.MCCInstall]
"UninstallString"="C:\\WINDOWS\\Motive\\Verizon\\MCCUninst.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WgaNotify]
"DisplayName"="Windows Genuine Advantage Notifications (KB905474)"
"UninstallString"=""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070707"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=905474"
"URLInfoAbout"="http://www.microsoft.com/genuine"
"NoRemove"=dword:00000001
"NoRemoveInitialValue"=dword:00000001
"DisplayVersion"="1.7.0018.5"
"VersionMajor"="2"
"VersionMinor"="0"
"ParentKeyName"="OperatingSystem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC]
"NoRemove"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Media Format Runtime]
"DisplayName"="Windows Media Format 11 runtime"
"UninstallString"="\"C:\\Program Files\\Windows Media Player\\wmsetsdk.exe\" /UninstallAll"
"DisplayIcon"="C:\\Program Files\\Windows Media Player\\wmplayer.exe"
"ParentKeyName"=""
"ParentDisplayName"=""
"HelpLink"="http://go.microsoft.com/fwlink/?LinkId=62768"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Media Player]
"DisplayName"="Windows Media Player 11"
"UninstallString"="\"C:\\Program Files\\Windows Media Player\\Setup_wm.exe\" /Uninstall"
"DisplayIcon"="C:\\Program Files\\Windows Media Player\\wmplayer.exe"
"ParentKeyName"=""
"ParentDisplayName"=""
"NoModify"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows XP Service Pack]
"DisplayName"="Windows XP Service Pack 3"
"UninstallString"="\"C:\\WINDOWS\\$NtServicePackUninstall$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20081202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=936929"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="20080414.031525"
"ParentDisplayName"="Windows XP - Software Updates"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver]
"DisplayName"="WinRAR archiver"
"UninstallString"="C:\\Program Files\\WinRAR\\uninstall.exe"
"DisplayIcon"="C:\\Program Files\\WinRAR\\WinRAR.exe"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WMCSetup]
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WMFDist11]
"DisplayName"="Windows Media Format 11 runtime"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallWMFDist11$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http:"
"URLInfoAbout"="http:"
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wmp11]
"DisplayName"="Windows Media Player 11"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallwmp11$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http:"
"URLInfoAbout"="http:"
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Works2003Setup]
"UninstallString"="C:\\Program Files\\Microsoft Works Suite 2003\\Setup\\Launcher.exe D:\\"
"DisplayName"="Microsoft Works 2003 Setup Launcher"
"HelpLink"="http://support.microsoft.com/support/works"
"DisplayIcon"="C:\\Program Files\\Microsoft Works Suite 2003\\Setup\\launcher.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wudf01000]
"DisplayName"="Microsoft User-Mode Driver Framework Feature Pack 1.0"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallWudf01000$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070202"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"URLInfoAbout"="http://support.microsoft.com"
"Comments"="Build Number 5716"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00000409-78E1-11D2-B60F-006097C998E7}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="9.00.3821"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,63,00,6f,\
00,6d,00,2f,00,73,00,75,00,70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"=""
"InstallDate"="20030919"
"InstallLocation"=""
"InstallSource"="D:\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,30,00,30,00,30,00,30,00,30,00,34,00,30,00,\
39,00,2d,00,37,00,38,00,45,00,31,00,2d,00,31,00,31,00,44,00,32,00,2d,00,42,\
00,36,00,30,00,46,00,2d,00,30,00,30,00,36,00,30,00,39,00,37,00,43,00,39,00,\
39,00,38,00,45,00,37,00,7d,00,00,00
"Publisher"="Microsoft Corporation"
"Readme"=hex(2):20,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,\
00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,\
73,00,6f,00,66,00,74,00,20,00,4f,00,66,00,66,00,69,00,63,00,65,00,5c,00,4f,\
00,66,00,66,00,69,00,63,00,65,00,5c,00,6f,00,66,00,72,00,65,00,61,00,64,00,\
39,00,2e,00,74,00,78,00,74,00,20,00,00,00
"Size"=""
"EstimatedSize"=dword:0002dcfa
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,30,00,30,00,30,00,30,00,30,00,34,00,30,\
00,39,00,2d,00,37,00,38,00,45,00,31,00,2d,00,31,00,31,00,44,00,32,00,2d,00,\
42,00,36,00,30,00,46,00,2d,00,30,00,30,00,36,00,30,00,39,00,37,00,43,00,39,\
00,39,00,38,00,45,00,37,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000009
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:09000eed
"Language"=dword:00000409
"DisplayName"="Microsoft Office 2000 SR-1 Premium"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00040409-78E1-11D2-B60F-006097C998E7}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="9.00.3821"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,63,00,6f,\
00,6d,00,2f,00,73,00,75,00,70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"=""
"InstallDate"="20030919"
"InstallLocation"=""
"InstallSource"="D:\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,30,00,30,00,30,00,34,00,30,00,34,00,30,00,\
39,00,2d,00,37,00,38,00,45,00,31,00,2d,00,31,00,31,00,44,00,32,00,2d,00,42,\
00,36,00,30,00,46,00,2d,00,30,00,30,00,36,00,30,00,39,00,37,00,43,00,39,00,\
39,00,38,00,45,00,37,00,7d,00,00,00
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00031870
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,30,00,30,00,30,00,34,00,30,00,34,00,30,\
00,39,00,2d,00,37,00,38,00,45,00,31,00,2d,00,31,00,31,00,44,00,32,00,2d,00,\
42,00,36,00,30,00,46,00,2d,00,30,00,30,00,36,00,30,00,39,00,37,00,43,00,39,\
00,39,00,38,00,45,00,37,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000009
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:09000eed
"Language"=dword:00000409
"DisplayName"="Microsoft Office 2000 SR-1 Disc 2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0101"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Notifier\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,30,00,30,00,30,00,38,00,35,00,34,00,36,00,\
45,00,2d,00,44,00,46,00,36,00,45,00,2d,00,34,00,43,00,43,00,31,00,2d,00,41,\
00,46,00,44,00,30,00,2d,00,32,00,43,00,42,00,38,00,45,00,31,00,36,00,43,00,\
39,00,35,00,41,00,32,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:000009d1
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,30,00,30,00,30,00,38,00,35,00,34,00,36,\
00,45,00,2d,00,44,00,46,00,36,00,45,00,2d,00,34,00,43,00,43,00,31,00,2d,00,\
41,00,46,00,44,00,30,00,2d,00,32,00,43,00,42,00,38,00,45,00,31,00,36,00,43,\
00,39,00,35,00,41,00,32,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="Notifier"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{011A2240-08DF-45BB-AA4E-1A78637CCF80}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="7.0.25"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20081203"
"InstallLocation"="C:\\Program Files\\Radialpoint\\Unicorn\\"
"InstallSource"="C:\\Program Files\\InstallShield Installation Information\\{6D01DFC8-AEA9-4F8F-B7C7-205E75F758D5}\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,30,00,31,00,31,00,41,00,32,00,32,00,34,00,\
30,00,2d,00,30,00,38,00,44,00,46,00,2d,00,34,00,35,00,42,00,42,00,2d,00,41,\
00,41,00,34,00,45,00,2d,00,31,00,41,00,37,00,38,00,36,00,33,00,37,00,43,00,\
43,00,46,00,38,00,30,00,7d,00,00,00
"Publisher"="Verizon"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:000012b1
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,30,00,31,00,31,00,41,00,32,00,32,00,34,\
00,30,00,2d,00,30,00,38,00,44,00,46,00,2d,00,34,00,35,00,42,00,42,00,2d,00,\
41,00,41,00,34,00,45,00,2d,00,31,00,41,00,37,00,38,00,36,00,33,00,37,00,43,\
00,43,00,46,00,38,00,30,00,7d,00,00,00
"URLInfoAbout"="http://www.Radialpoint.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000007
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:07000019
"Language"=dword:00000409
"DisplayName"="RPS CRT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{01F9D88C-3C86-4E82-840A-101A3221F67A}]
"AuthorizedCDFPrefix"=""
"Comments"="The Installation database contains the logic and data required to install Money 2003"
"Contact"=""
"DisplayVersion"="11.0.50"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,2e,00,63,00,6f,00,6d,00,00,00
"HelpTelephone"="(800) 936-5700"
"InstallDate"="20020930"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,30,00,31,00,46,00,39,00,44,00,38,00,38,00,\
43,00,2d,00,33,00,43,00,38,00,36,00,2d,00,34,00,45,00,38,00,32,00,2d,00,38,\
00,34,00,30,00,41,00,2d,00,31,00,30,00,31,00,41,00,33,00,32,00,32,00,31,00,\
46,00,36,00,37,00,41,00,7d,00,00,00
"Publisher"="Microsoft"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,30,00,31,00,46,00,39,00,44,00,38,00,38,\
00,43,00,2d,00,33,00,43,00,38,00,36,00,2d,00,34,00,45,00,38,00,32,00,2d,00,\
38,00,34,00,30,00,41,00,2d,00,31,00,30,00,31,00,41,00,33,00,32,00,32,00,31,\
00,46,00,36,00,37,00,41,00,7d,00,00,00
"URLInfoAbout"="http://support.microsoft.com"
"URLUpdateInfo"="http://www.microsoft.com/money"
"VersionMajor"=dword:0000000b
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0b000032
"Language"=dword:00000409
"DisplayName"="Microsoft Money 2003"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{02B42D23-10F2-4862-ADA4-3DF1EA0021B2}]
"AuthorizedCDFPrefix"=""
"Comments"="Installs system components used by Microsoft Money 2003."
"Contact"=""
"DisplayVersion"="11.0.80"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,2e,00,63,00,6f,00,6d,00,00,00
"HelpTelephone"="(800) 936-5700"
"InstallDate"="20020930"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,30,00,32,00,42,00,34,00,32,00,44,00,32,00,\
33,00,2d,00,31,00,30,00,46,00,32,00,2d,00,34,00,38,00,36,00,32,00,2d,00,41,\
00,44,00,41,00,34,00,2d,00,33,00,44,00,46,00,31,00,45,00,41,00,30,00,30,00,\
32,00,31,00,42,00,32,00,7d,00,00,00
"Publisher"="Microsoft"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,30,00,32,00,42,00,34,00,32,00,44,00,32,\
00,33,00,2d,00,31,00,30,00,46,00,32,00,2d,00,34,00,38,00,36,00,32,00,2d,00,\
41,00,44,00,41,00,34,00,2d,00,33,00,44,00,46,00,31,00,45,00,41,00,30,00,30,\
00,32,00,31,00,42,00,32,00,7d,00,00,00
"URLInfoAbout"="http://support.microsoft.com"
"URLUpdateInfo"="http://www.microsoft.com/money"
"VersionMajor"=dword:0000000b
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0b000050
"Language"=dword:00000409
"DisplayName"="Microsoft Money 2003 System Pack"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{03410014-3975-4267-9F39-1DC4745090B7}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="2003"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,2e,00,63,00,6f,00,6d,00,00,00
"HelpTelephone"=""
"InstallDate"="20020930"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,30,00,33,00,34,00,31,00,30,00,30,00,31,00,\
34,00,2d,00,33,00,39,00,37,00,35,00,2d,00,34,00,32,00,36,00,37,00,2d,00,39,\
00,46,00,33,00,39,00,2d,00,31,00,44,00,43,00,34,00,37,00,34,00,35,00,30,00,\
39,00,30,00,42,00,37,00,7d,00,00,00
"NoRepair"=dword:00000001
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,30,00,33,00,34,00,31,00,30,00,30,00,31,\
00,34,00,2d,00,33,00,39,00,37,00,35,00,2d,00,34,00,32,00,36,00,37,00,2d,00,\
39,00,46,00,33,00,39,00,2d,00,31,00,44,00,43,00,34,00,37,00,34,00,35,00,30,\
00,39,00,30,00,42,00,37,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:000007d3
"VersionMinor"=dword:000007d3
"WindowsInstaller"=dword:00000001
"Version"=dword:d3000000
"Language"=dword:00000409
"DisplayName"="Microsoft Encarta Encyclopedia Standard 2003"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="2.1.0.2"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20081118"
"InstallLocation"=""
"InstallSource"="C:\\WINDOWS\\TEMP\\IXP000.TMP\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,30,00,45,00,46,00,44,00,46,00,32,00,46,00,\
39,00,2d,00,38,00,33,00,36,00,44,00,2d,00,34,00,45,00,42,00,37,00,2d,00,41,\
00,33,00,32,00,44,00,2d,00,30,00,33,00,38,00,42,00,44,00,33,00,46,00,31,00,\
46,00,42,00,32,00,41,00,7d,00,00,00
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000302
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,30,00,45,00,46,00,44,00,46,00,32,00,46,\
00,39,00,2d,00,38,00,33,00,36,00,44,00,2d,00,34,00,45,00,42,00,37,00,2d,00,\
41,00,33,00,32,00,44,00,2d,00,30,00,33,00,38,00,42,00,44,00,33,00,46,00,31,\
00,46,00,42,00,32,00,41,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000002
"VersionMinor"=dword:00000001
"WindowsInstaller"=dword:00000001
"Version"=dword:02010000
"Language"=dword:00000409
"DisplayName"="Security Update for CAPICOM (KB931906)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F756CD9-4A1E-409B-B101-601DDC4C03AA}]
"AuthorizedCDFPrefix"=""
"Comments"="Go to http://support.dell.com."
"Contact"="Dell Support"
"DisplayVersion"="1.00.0004"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,64,00,65,00,6c,00,6c,00,2e,00,63,00,6f,00,6d,\
00,00,00
"HelpTelephone"="0"
"InstallDate"="20030911"
"InstallLocation"=""
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Dell"
"Readme"=""
"Size"=""
"SystemComponent"=dword:00000001
"URLInfoAbout"="http://www.dell.com"
"URLUpdateInfo"="http://support.dell.com"
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:01000004
"Language"=dword:00000409
"DisplayName"="Qualxserve Service Agreement"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{10E98E14-832C-4AF7-A4D1-6A9EF83B282E}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="Customer Support Department"
"DisplayVersion"="4.00.0000.0001"
"HelpLink"=hex(2):20,00,68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,\
77,00,2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,\
00,6f,00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,\
75,00,70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Sysext\\VCAMEN\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,31,00,30,00,45,00,39,00,38,00,45,00,31,00,\
34,00,2d,00,38,00,33,00,32,00,43,00,2d,00,34,00,41,00,46,00,37,00,2d,00,41,\
00,34,00,44,00,31,00,2d,00,36,00,41,00,39,00,45,00,46,00,38,00,33,00,42,00,\
32,00,38,00,32,00,45,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0000037d
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,31,00,30,00,45,00,39,00,38,00,45,00,31,\
00,34,00,2d,00,38,00,33,00,32,00,43,00,2d,00,34,00,41,00,46,00,37,00,2d,00,\
41,00,34,00,44,00,31,00,2d,00,36,00,41,00,39,00,45,00,46,00,38,00,33,00,42,\
00,32,00,38,00,32,00,45,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="VCAMCEN"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{11F1920A-56A2-4642-B6E0-3B31A12C9288}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="1.00.0000"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,73,00,75,00,70,00,70,00,6f,00,72,00,74,00,2e,00,64,00,65,00,6c,00,6c,\
00,2e,00,63,00,6f,00,6d,00,00,00
"HelpTelephone"="http://www.support.dell.com"
"InstallDate"="20030911"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,58,00,7b,00,31,00,31,00,46,00,31,00,39,00,32,00,30,00,\
41,00,2d,00,35,00,36,00,41,00,32,00,2d,00,34,00,36,00,34,00,32,00,2d,00,42,\
00,36,00,45,00,30,00,2d,00,33,00,42,00,33,00,31,00,41,00,31,00,32,00,43,00,\
39,00,32,00,38,00,38,00,7d,00,00,00
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Dell"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,58,00,7b,00,31,00,31,00,46,00,31,00,39,00,32,00,30,\
00,41,00,2d,00,35,00,36,00,41,00,32,00,2d,00,34,00,36,00,34,00,32,00,2d,00,\
42,00,36,00,45,00,30,00,2d,00,33,00,42,00,33,00,31,00,41,00,31,00,32,00,43,\
00,39,00,32,00,38,00,38,00,7d,00,00,00
"URLInfoAbout"="http://www.support.dell.com"
"URLUpdateInfo"="http://www.support.dell.com"
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:01000000
"Language"=dword:00000000
"DisplayName"="Dell Solution Center"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{121634B0-2F4A-11D3-ADA3-00C04F52DD53}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="2.05.00.0000"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20050701"
"InstallLocation"=""
"InstallSource"="C:\\DOCUME~1\\Jeremy\\LOCALS~1\\Temp\\IXP000.TMP\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,31,00,32,00,31,00,36,00,33,00,34,00,42,00,\
30,00,2d,00,32,00,46,00,34,00,41,00,2d,00,31,00,31,00,44,00,33,00,2d,00,41,\
00,44,00,41,00,33,00,2d,00,30,00,30,00,43,00,30,00,34,00,46,00,35,00,32,00,\
44,00,44,00,35,00,33,00,7d,00,00,00
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0000006d
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,31,00,32,00,31,00,36,00,33,00,34,00,42,\
00,30,00,2d,00,32,00,46,00,34,00,41,00,2d,00,31,00,31,00,44,00,33,00,2d,00,\
41,00,44,00,41,00,33,00,2d,00,30,00,30,00,43,00,30,00,34,00,46,00,35,00,32,\
00,44,00,44,00,35,00,33,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000002
"VersionMinor"=dword:00000005
"WindowsInstaller"=dword:00000001
"Version"=dword:02050000
"Language"=dword:00000409
"DisplayName"="Windows Installer Clean Up"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{12BDDF23-B1DB-49C8-92D3-3E6841CCED61}]
"DisplayIcon"="C:\\Program Files\\Microsoft Streets & Trips\\Streets.exe,0"
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="9.00.17.0200"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,63,00,6f,\
00,6d,00,2f,00,73,00,75,00,70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"=""
"InstallDate"="20020930"
"InstallLocation"="C:\\Program Files\\Microsoft Streets & Trips\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,31,00,32,00,42,00,44,00,44,00,46,00,32,00,\
33,00,2d,00,42,00,31,00,44,00,42,00,2d,00,34,00,39,00,43,00,38,00,2d,00,39,\
00,32,00,44,00,33,00,2d,00,33,00,45,00,36,00,38,00,34,00,31,00,43,00,43,00,\
45,00,44,00,36,00,31,00,7d,00,00,00
"NoRepair"=dword:00000001
"Publisher"="Microsoft"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,31,00,32,00,42,00,44,00,44,00,46,00,32,\
00,33,00,2d,00,42,00,31,00,44,00,42,00,2d,00,34,00,39,00,43,00,38,00,2d,00,\
39,00,32,00,44,00,33,00,2d,00,33,00,45,00,36,00,38,00,34,00,31,00,43,00,43,\
00,45,00,44,00,36,00,31,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000009
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:09000011
"Language"=dword:00000409
"DisplayName"="Microsoft Streets and Trips 2002"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Sysext\\ESSpcd\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,31,00,34,00,44,00,34,00,45,00,44,00,38,00,\
34,00,2d,00,36,00,41,00,39,00,41,00,2d,00,34,00,35,00,41,00,30,00,2d,00,39,\
00,36,00,46,00,36,00,2d,00,31,00,37,00,35,00,33,00,37,00,36,00,38,00,43,00,\
33,00,43,00,42,00,35,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000135
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,31,00,34,00,44,00,34,00,45,00,44,00,38,\
00,34,00,2d,00,36,00,41,00,39,00,41,00,2d,00,34,00,35,00,41,00,30,00,2d,00,\
39,00,36,00,46,00,36,00,2d,00,31,00,37,00,35,00,33,00,37,00,36,00,38,00,43,\
00,33,00,43,00,42,00,35,00,7d,00,00,00
"URLInfoAbout"="http://www.Kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESSPCD"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{151C555A-A9E7-4A2E-B6D7-165D04A3C956}]
"AuthorizedCDFPrefix"=""
"Comments"=" "
"Contact"="Customer Support Department"
"DisplayVersion"="3.4.1"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,64,00,65,00,6c,00,\
6c,00,2e,00,73,00,68,00,75,00,74,00,74,00,65,00,72,00,66,00,6c,00,79,00,2e,\
00,63,00,6f,00,6d,00,2f,00,68,00,65,00,6c,00,70,00,00,00
"HelpTelephone"="1-952-294-2692"
"InstallDate"="20030911"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,31,00,35,00,31,00,43,00,35,00,35,00,35,00,\
41,00,2d,00,41,00,39,00,45,00,37,00,2d,00,34,00,41,00,32,00,45,00,2d,00,42,\
00,36,00,44,00,37,00,2d,00,31,00,36,00,35,00,44,00,30,00,34,00,41,00,33,00,\
43,00,39,00,35,00,36,00,7d,00,00,00
"Publisher"="Jasc Software Inc"
"Readme"=hex(2):20,00,2d,00,00,00
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,31,00,35,00,31,00,43,00,35,00,35,00,35,\
00,41,00,2d,00,41,00,39,00,45,00,37,00,2d,00,34,00,41,00,32,00,45,00,2d,00,\
42,00,36,00,44,00,37,00,2d,00,31,00,36,00,35,00,44,00,30,00,34,00,41,00,33,\
00,43,00,39,00,35,00,36,00,7d,00,00,00
"URLInfoAbout"="http://www.jasc.com"
"URLUpdateInfo"="http://www.jasc.com"
"VersionMajor"=dword:00000003
"VersionMinor"=dword:00000004
"WindowsInstaller"=dword:00000001
"Version"=dword:03040001
"Language"=dword:00000409
"DisplayName"="Dell Picture Studio - Dell Image Expert"
"EstimatedSize"=dword:00000004

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="1.0.0"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090702"
"InstallLocation"="C:\\Program Files\\Google\\Installers\\"
"InstallSource"="C:\\Program Files\\Google\\Google Toolbar\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,31,00,38,00,34,00,35,00,35,00,35,00,38,00,\
31,00,2d,00,45,00,30,00,39,00,39,00,2d,00,34,00,42,00,41,00,38,00,2d,00,42,\
00,43,00,36,00,42,00,2d,00,46,00,33,00,34,00,42,00,32,00,46,00,30,00,36,00,\
36,00,30,00,30,00,43,00,7d,00,00,00
"Publisher"="Google Inc."
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0000001c
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,31,00,38,00,34,00,35,00,35,00,35,00,38,\
00,31,00,2d,00,45,00,30,00,39,00,39,00,2d,00,34,00,42,00,41,00,38,00,2d,00,\
42,00,43,00,36,00,42,00,2d,00,46,00,33,00,34,00,42,00,32,00,46,00,30,00,36,\
00,36,00,30,00,30,00,43,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:01000000
"Language"=dword:00000409
"DisplayName"="Google Toolbar for Internet Explorer"

jlauv
2009-08-19, 21:07
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18D10072035C4515918F7E37EAFAACFC}]
"FinishedFlag"=dword:00000000
"DisplayName"="AutoUpdate"
"DisplayVersion"="1.1"
"Locale"="en"
"InstallLocation"="C:\\Program Files\\DivX"
"RebootFlag"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
"DisplayName"="Google Toolbar for Internet Explorer"
"UninstallString"="\"C:\\Program Files\\Google\\Google Toolbar\\Component\\GoogleToolbarManager_874698634E0FC940.exe\" /uninstall"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Google Inc."
"DisplayIcon"="C:\\Program Files\\Google\\Google Toolbar\\Component\\GoogleToolbarManager_874698634E0FC940.exe"
"InstallLocation"="C:\\Program Files\\Google\\Google Toolbar\\"
"MajorVersion"="6"
"MinorVersion"="2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{258749E2-3A46-42B1-9A01-BF977AA06FAC}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="8.0.27"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090602"
"InstallLocation"="C:\\Program Files\\Radialpoint\\Unicorn\\"
"InstallSource"="C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,32,00,35,00,38,00,37,00,34,00,39,00,45,00,\
32,00,2d,00,33,00,41,00,34,00,36,00,2d,00,34,00,32,00,42,00,31,00,2d,00,39,\
00,41,00,30,00,31,00,2d,00,42,00,46,00,39,00,37,00,37,00,41,00,41,00,30,00,\
36,00,46,00,41,00,43,00,7d,00,00,00
"Publisher"="Verizon"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00001271
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,32,00,35,00,38,00,37,00,34,00,39,00,45,\
00,32,00,2d,00,33,00,41,00,34,00,36,00,2d,00,34,00,32,00,42,00,31,00,2d,00,\
39,00,41,00,30,00,31,00,2d,00,42,00,46,00,39,00,37,00,37,00,41,00,41,00,30,\
00,36,00,46,00,41,00,43,00,7d,00,00,00
"URLInfoAbout"="http://www.Radialpoint.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000008
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0800001b
"Language"=dword:00000409
"DisplayName"="RPS CRT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{25EF00BE-F17B-11D6-88EA-000476CD2443}]
"UninstallString"="C:\\WINDOWS\\system32\\VerizonUninstaller.exe"
"DisplayName"="Verizon Online"
"DisplayIcon"="C:\\Program Files\\Common Files\\Verizon Online\\SFP\\VerizonUninstaller.exe,0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{25EF00BF-F17B-11D6-88EA-000476CD2443}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{25EF00BF-F17B-11D6-88EA-000476CD2443}\\Setup.exe\" -l0x9 UNINSTALL"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{25EF00BF-F17B-11D6-88EA-000476CD2443}\\setup.ilg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{25EF00C6-F17B-11D6-88EA-000476CD2443}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{25EF00C6-F17B-11D6-88EA-000476CD2443}\\Setup.exe\" -l0x9 UNINSTALL"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{25EF00C6-F17B-11D6-88EA-000476CD2443}\\setup.ilg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{25EF00D0-F17B-11D6-88EA-000476CD2443}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{25EF00D0-F17B-11D6-88EA-000476CD2443}\\Setup.exe\" -l0x9 UNINSTALL"
"DisplayName"="Verizon Online Help & Support"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{25EF00D0-F17B-11D6-88EA-000476CD2443}\\setup.ilg"
"DisplayIcon"="\"C:\\DOCUME~1\\Jeremy\\LOCALS~1\\Temp\\{25EF00D0-F17B-11D6-88EA-000476CD2443}\\Verizon Online Setup.ico\""
"UUProduct"="Confirmed"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{25EF00D1-F17B-11D6-88EA-000476CD2443}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{25EF00D1-F17B-11D6-88EA-000476CD2443}\\Setup.exe\" -l0x9 UNINSTALL"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{25EF00D1-F17B-11D6-88EA-000476CD2443}\\setup.ilg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{25EF03DA-F17B-11D6-88EA-000476CD2443}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{25EF03DA-F17B-11D6-88EA-000476CD2443}\\Setup.exe\" -l0x9 UNINSTALL"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{25EF03DA-F17B-11D6-88EA-000476CD2443}\\setup.ilg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216015FF}]
"DisplayIcon"="C:\\Program Files\\Java\\jre6\\\\bin\\javaws.exe"
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"="http://java.com"
"DisplayVersion"="6.0.150"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,6a,00,61,00,76,00,\
61,00,2e,00,63,00,6f,00,6d,00,00,00
"HelpTelephone"=""
"InstallDate"="20090815"
"InstallLocation"="C:\\Program Files\\Java\\jre6\\"
"InstallSource"="C:\\Documents and Settings\\Jeremy\\Application Data\\Sun\\Java\\jre1.6.0_15\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,58,00,7b,00,32,00,36,00,41,00,32,00,34,00,41,00,45,00,\
34,00,2d,00,30,00,33,00,39,00,44,00,2d,00,34,00,43,00,41,00,34,00,2d,00,38,\
00,37,00,42,00,34,00,2d,00,32,00,46,00,38,00,33,00,32,00,31,00,36,00,30,00,\
31,00,35,00,46,00,46,00,7d,00,00,00
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Sun Microsystems, Inc."
"Readme"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,\
00,46,00,69,00,6c,00,65,00,73,00,5c,00,4a,00,61,00,76,00,61,00,5c,00,6a,00,\
72,00,65,00,36,00,5c,00,52,00,45,00,41,00,44,00,4d,00,45,00,2e,00,74,00,78,\
00,74,00,00,00
"Size"=""
"EstimatedSize"=dword:000186a0
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,58,00,7b,00,32,00,36,00,41,00,32,00,34,00,41,00,45,\
00,34,00,2d,00,30,00,33,00,39,00,44,00,2d,00,34,00,43,00,41,00,34,00,2d,00,\
38,00,37,00,42,00,34,00,2d,00,32,00,46,00,38,00,33,00,32,00,31,00,36,00,30,\
00,31,00,35,00,46,00,46,00,7d,00,00,00
"URLInfoAbout"="http://java.com"
"URLUpdateInfo"="http://java.sun.com"
"VersionMajor"=dword:00000006
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:06000096
"Language"=dword:00000000
"DisplayName"="Java(TM) 6 Update 15"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{27113CA3-36B8-48AB-A419-79CF1FC0ECED}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="5.00.0004"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,75,00,6c,00,65,00,61,00,64,00,2e,00,63,00,6f,00,6d,00,2f,00,74,00,65,\
00,63,00,68,00,2f,00,74,00,65,00,63,00,68,00,2e,00,68,00,74,00,6d,00,20,00,\
00,00
"HelpTelephone"="+1-310-869-6391"
"InstallDate"="20031018"
"InstallLocation"=""
"InstallSource"="D:\\Setup\\C\\E\\F\\G\\I\\J\\K\\P\\S\\SC\\"
"NoRemove"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Ulead Systems, Inc."
"Readme"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,2e,\
00,75,00,6c,00,65,00,61,00,64,00,2e,00,63,00,6f,00,6d,00,2f,00,76,00,73,00,\
2f,00,6e,00,65,00,77,00,2e,00,68,00,74,00,6d,00,00,00
"Size"=""
"EstimatedSize"=dword:00023566
"URLInfoAbout"="{\\TahomaWhiteBold12}http://www.ulead.com"
"URLUpdateInfo"="http://www.ulead.com/vs/runme.htm "
"VersionMajor"=dword:00000005
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:05000004
"Language"=dword:00000409
"DisplayName"="Ulead VideoStudio 5.0 DV"
"ProductID"="78302-95000-99929917"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2B6EC03E-6FA0-4D7C-9CCE-1B03819AB613}]
"AuthorizedCDFPrefix"=""
"Comments"="PerfectDisk disk defragmentation utility"
"Contact"="http://www.raxco.com/support/nt_email.cfm"
"DisplayVersion"="9.0.66"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,72,00,61,00,78,00,63,00,6f,00,2e,00,63,00,6f,00,6d,00,2f,00,73,00,75,\
00,70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="1-301-527-0803"
"InstallDate"="20090602"
"InstallLocation"="C:\\Program Files\\Raxco\\PerfectDisk2008\\"
"InstallSource"="C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,32,00,42,00,36,00,45,00,43,00,30,00,33,00,\
45,00,2d,00,36,00,46,00,41,00,30,00,2d,00,34,00,44,00,37,00,43,00,2d,00,39,\
00,43,00,43,00,45,00,2d,00,31,00,42,00,30,00,33,00,38,00,31,00,39,00,41,00,\
42,00,36,00,31,00,33,00,7d,00,00,00
"NoRepair"=dword:00000001
"Publisher"="Raxco Software Inc."
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00001100
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,32,00,42,00,36,00,45,00,43,00,30,00,33,\
00,45,00,2d,00,36,00,46,00,41,00,30,00,2d,00,34,00,44,00,37,00,43,00,2d,00,\
39,00,43,00,43,00,45,00,2d,00,31,00,42,00,30,00,33,00,38,00,31,00,39,00,41,\
00,42,00,36,00,31,00,33,00,7d,00,00,00
"URLInfoAbout"="http://www.Raxco.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000009
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:09000042
"Language"=dword:00000409
"DisplayName"="PerfectDisk 2008"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2D261CA3-5C68-494A-89D1-5DE68ED23146}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{2D261CA3-5C68-494A-89D1-5DE68ED23146}\\Setup.exe\" -l0x9 UNINSTALL"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{2D261CA3-5C68-494A-89D1-5DE68ED23146}\\setup.ilg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2E47BAD4-742D-4725-AA87-ED70403B0F25}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\PROFES~1\\RunTime\\10\\50\\Intel32\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{2E47BAD4-742D-4725-AA87-ED70403B0F25}\\setup.exe\" -l0x9 -removeonly"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{2E47BAD4-742D-4725-AA87-ED70403B0F25}\\setup.ilg"
"InstallLocation"="C:\\Program Files\\Maestro Learning\\Player"
"InstallSource"="C:\\DOCUME~1\\Jeremy\\LOCALS~1\\Temp\\bye110.tmp\\Disk1\\"
"ProductGuid"="{89AD21E2-18E8-4CA6-962B-C9F5C91C2BFB}"
"DisplayName"="Garfield K Phonics"
"NoModify"=dword:00000001
"NoRemove"=dword:00000000
"NoRepair"=dword:00000001
"InstallDate"="20081115"
"Language"=dword:00000009
"Version"=dword:03010000
"MajorVersion"=dword:00000003
"MinorVersion"=dword:00000001
"LogMode"=dword:00000004
"DisplayIcon"="C:\\Program Files\\Maestro Learning\\Data\\Garfield\\Products\\ZJH8-GCFR-P61W0D2AL9TU\\ZJH8-GCFR-P61W0D2AL9TU.ico"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="9.50.6513"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,63,00,6f,\
00,6d,00,2f,00,77,00,69,00,6e,00,64,00,6f,00,77,00,73,00,00,00
"HelpTelephone"=""
"InstallDate"="20020903"
"InstallLocation"=""
"InstallSource"="C:\\WINDOWS\\System32\\"
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:000009bc
"SystemComponent"=dword:00000001
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000009
"VersionMinor"=dword:00000032
"WindowsInstaller"=dword:00000001
"Version"=dword:09321971
"Language"=dword:00000409
"DisplayName"="WebFldrs XP"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{369B36BE-3D64-4641-9AEA-808D436FE132}]
"AuthorizedCDFPrefix"=""
"Comments"="Microsoft Picture It! Photo 7.0"
"Contact"=""
"DisplayVersion"="7.0.0.0000"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,67,00,6f,00,2e,00,\
6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,63,00,6f,00,6d,\
00,2f,00,66,00,77,00,6c,00,69,00,6e,00,6b,00,2f,00,3f,00,70,00,72,00,64,00,\
3d,00,31,00,30,00,39,00,36,00,34,00,26,00,70,00,76,00,65,00,72,00,3d,00,37,\
00,2e,00,30,00,26,00,70,00,6c,00,63,00,69,00,64,00,3d,00,30,00,78,00,34,00,\
30,00,39,00,26,00,61,00,72,00,3d,00,41,00,64,00,64,00,52,00,65,00,6d,00,6f,\
00,76,00,65,00,26,00,73,00,61,00,72,00,3d,00,50,00,69,00,63,00,74,00,75,00,\
72,00,65,00,49,00,74,00,00,00
"HelpTelephone"=" "
"InstallDate"="20020930"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,33,00,36,00,39,00,42,00,33,00,36,00,42,00,\
45,00,2d,00,33,00,44,00,36,00,34,00,2d,00,34,00,36,00,34,00,31,00,2d,00,39,\
00,41,00,45,00,41,00,2d,00,38,00,30,00,38,00,44,00,34,00,33,00,36,00,46,00,\
45,00,31,00,33,00,32,00,7d,00,00,00
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,33,00,36,00,39,00,42,00,33,00,36,00,42,\
00,45,00,2d,00,33,00,44,00,36,00,34,00,2d,00,34,00,36,00,34,00,31,00,2d,00,\
39,00,41,00,45,00,41,00,2d,00,38,00,30,00,38,00,44,00,34,00,33,00,36,00,46,\
00,45,00,31,00,33,00,32,00,7d,00,00,00
"URLInfoAbout"="http://go.microsoft.com/fwlink/?prd=10964&pver=7.0&plcid=0x409&ar=AddRemove&sar=Microsoft"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000007
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:07000000
"Language"=dword:00000409
"DisplayName"="Microsoft Picture It! Photo 7.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="4.20.9841.0"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,2e,00,63,00,6f,00,6d,00,2f,00,6b,00,62,00,2f,00,39,00,32,00,37,00,\
39,00,37,00,38,00,00,00
"HelpTelephone"=""
"InstallDate"="20070628"
"InstallLocation"=""
"InstallSource"="c:\\2185f019c23425c0a8e7\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,33,00,37,00,34,00,37,00,37,00,38,00,36,00,\
35,00,2d,00,41,00,33,00,46,00,31,00,2d,00,34,00,37,00,37,00,32,00,2d,00,41,\
00,44,00,34,00,33,00,2d,00,41,00,41,00,46,00,43,00,36,00,42,00,43,00,46,00,\
46,00,39,00,39,00,46,00,7d,00,00,00
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000a41
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,33,00,37,00,34,00,37,00,37,00,38,00,36,\
00,35,00,2d,00,41,00,33,00,46,00,31,00,2d,00,34,00,37,00,37,00,32,00,2d,00,\
41,00,44,00,34,00,33,00,2d,00,41,00,41,00,46,00,43,00,36,00,42,00,43,00,46,\
00,46,00,39,00,39,00,46,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000014
"WindowsInstaller"=dword:00000001
"Version"=dword:04142671
"Language"=dword:00000409
"DisplayName"="MSXML 4.0 SP2 (KB927978)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{38441BE7-79B0-42B8-8297-833704F949FE}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="4.00.0000.0003"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"=""
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\ESS\\HLPINDEX\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,33,00,38,00,34,00,34,00,31,00,42,00,45,00,\
37,00,2d,00,37,00,39,00,42,00,30,00,2d,00,34,00,32,00,42,00,38,00,2d,00,38,\
00,32,00,39,00,37,00,2d,00,38,00,33,00,33,00,37,00,30,00,34,00,46,00,39,00,\
34,00,39,00,46,00,45,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000031
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,33,00,38,00,34,00,34,00,31,00,42,00,45,\
00,37,00,2d,00,37,00,39,00,42,00,30,00,2d,00,34,00,32,00,42,00,38,00,2d,00,\
38,00,32,00,39,00,37,00,2d,00,38,00,33,00,33,00,37,00,30,00,34,00,46,00,39,\
00,34,00,39,00,46,00,45,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="HLPIndex"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3C7B1086-F873-4826-91A5-195CB5364C5B}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="8.0.27"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090602"
"InstallLocation"="C:\\Program Files\\Verizon\\Verizon Internet Security Suite\\"
"InstallSource"="C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,33,00,43,00,37,00,42,00,31,00,30,00,38,00,\
36,00,2d,00,46,00,38,00,37,00,33,00,2d,00,34,00,38,00,32,00,36,00,2d,00,39,\
00,31,00,41,00,35,00,2d,00,31,00,39,00,35,00,43,00,42,00,35,00,33,00,36,00,\
34,00,43,00,35,00,42,00,7d,00,00,00
"Publisher"="Verizon"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000154
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,33,00,43,00,37,00,42,00,31,00,30,00,38,\
00,36,00,2d,00,46,00,38,00,37,00,33,00,2d,00,34,00,38,00,32,00,36,00,2d,00,\
39,00,31,00,41,00,35,00,2d,00,31,00,39,00,35,00,43,00,42,00,35,00,33,00,36,\
00,34,00,43,00,35,00,42,00,7d,00,00,00
"URLInfoAbout"="http://www.Radialpoint.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000008
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0800001b
"Language"=dword:00000409
"DisplayName"="RPS PerfectDiskStub"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"="Customer Support Department"
"DisplayVersion"="4.00.0000.0000"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"=""
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\OTTBPSDK\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,33,00,43,00,41,00,33,00,39,00,42,00,30,00,\
43,00,2d,00,42,00,41,00,38,00,35,00,2d,00,34,00,44,00,34,00,32,00,2d,00,41,\
00,43,00,30,00,46,00,2d,00,31,00,46,00,46,00,35,00,46,00,36,00,30,00,43,00,\
33,00,33,00,35,00,33,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000226
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,33,00,43,00,41,00,33,00,39,00,42,00,30,\
00,43,00,2d,00,42,00,41,00,38,00,35,00,2d,00,34,00,44,00,34,00,32,00,2d,00,\
41,00,43,00,30,00,46,00,2d,00,31,00,46,00,46,00,35,00,46,00,36,00,30,00,43,\
00,33,00,33,00,35,00,33,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000409
"DisplayName"="OTtBPSDK"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F92ABBB-6BBF-11D5-B229-002078017FBF}]
"DisplayIcon"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,\
00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4e,00,65,00,74,00,57,00,61,00,\
69,00,74,00,69,00,6e,00,67,00,5c,00,4d,00,4f,00,48,00,2e,00,65,00,78,00,65,\
00,00,00
"Publisher"="BVRP Software, Inc"
"DisplayVersion"="2.5.4"
"VersionMajor"=dword:00000002
"VersionMinor"=dword:00000005
"InstallLocation"="C:\\Program Files\\NetWaiting"
"Language"=dword:00000009
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\\setup.exe\" -l0x9 ControlPanelAnyText"
"DisplayName"="NetWaiting"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\\setup.ilg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{432C3720-37BF-4BD7-8E49-F38E090246D0}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="3.01.0001.0003"
"HelpLink"=hex(2):5f,00,00,00
"HelpTelephone"="_"
"InstallDate"="20040408"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\KDEVICES\\CR2\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,34,00,33,00,32,00,43,00,33,00,37,00,32,00,\
30,00,2d,00,33,00,37,00,42,00,46,00,2d,00,34,00,42,00,44,00,37,00,2d,00,38,\
00,45,00,34,00,39,00,2d,00,46,00,33,00,38,00,45,00,30,00,39,00,30,00,32,00,\
34,00,36,00,44,00,30,00,7d,00,00,00
"Publisher"="Eastman Kodak Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000001
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,34,00,33,00,32,00,43,00,33,00,37,00,32,\
00,30,00,2d,00,33,00,37,00,42,00,46,00,2d,00,34,00,42,00,44,00,37,00,2d,00,\
38,00,45,00,34,00,39,00,2d,00,46,00,33,00,38,00,45,00,30,00,39,00,30,00,32,\
00,34,00,36,00,44,00,30,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="_"
"VersionMajor"=dword:00000003
"VersionMinor"=dword:00000001
"WindowsInstaller"=dword:00000001
"Version"=dword:03010001
"Language"=dword:00000409
"DisplayName"="CR2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{43FCA273-9534-40DB-B7C5-D7758875616A}]
"AuthorizedCDFPrefix"=""
"Comments"="Go to http://support.dell.com"
"Contact"="http://support.dell.com"
"DisplayVersion"="2.0.1.205"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,64,00,65,00,6c,00,6c,00,2e,00,63,00,6f,00,6d,\
00,00,00
"HelpTelephone"="1-800-BUY-DELL"
"InstallDate"="20030911"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,58,00,7b,00,34,00,33,00,46,00,43,00,41,00,32,00,37,00,\
33,00,2d,00,39,00,35,00,33,00,34,00,2d,00,34,00,30,00,44,00,42,00,2d,00,42,\
00,37,00,43,00,35,00,2d,00,44,00,37,00,37,00,35,00,38,00,38,00,37,00,35,00,\
36,00,31,00,36,00,41,00,7d,00,00,00
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Dell"
"Readme"=hex(2):30,00,00,00
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,58,00,7b,00,34,00,33,00,46,00,43,00,41,00,32,00,37,\
00,33,00,2d,00,39,00,35,00,33,00,34,00,2d,00,34,00,30,00,44,00,42,00,2d,00,\
42,00,37,00,43,00,35,00,2d,00,44,00,37,00,37,00,35,00,38,00,38,00,37,00,35,\
00,36,00,31,00,36,00,41,00,7d,00,00,00
"URLInfoAbout"="http://www.dell.com"
"URLUpdateInfo"="http://www.dell.com"
"VersionMajor"=dword:00000002
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:02000001
"Language"=dword:00000409
"DisplayName"="Dell Support"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4468EF97-A253-4699-9E1C-88CAE2C6832D}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"="support@abbyy.com"
"DisplayVersion"="5.0.0.22227"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,61,00,62,00,62,00,79,00,79,00,2e,00,63,00,6f,00,6d,00,2f,00,73,00,75,\
00,70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="+7 (095) 234 44 00"
"InstallDate"="20030911"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,58,00,7b,00,34,00,34,00,36,00,38,00,45,00,46,00,39,00,\
37,00,2d,00,41,00,32,00,35,00,33,00,2d,00,34,00,36,00,39,00,39,00,2d,00,39,\
00,45,00,31,00,43,00,2d,00,38,00,38,00,43,00,41,00,45,00,32,00,43,00,36,00,\
38,00,33,00,32,00,44,00,7d,00,00,00
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="ABBYY Software House"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,58,00,7b,00,34,00,34,00,36,00,38,00,45,00,46,00,39,\
00,37,00,2d,00,41,00,32,00,35,00,33,00,2d,00,34,00,36,00,39,00,39,00,2d,00,\
39,00,45,00,31,00,43,00,2d,00,38,00,38,00,43,00,41,00,45,00,32,00,43,00,36,\
00,38,00,33,00,32,00,44,00,7d,00,00,00
"URLInfoAbout"="http://www.abbyy.com"
"URLUpdateInfo"="http://www.abbyy.com"
"VersionMajor"=dword:00000005
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:05000000
"Language"=dword:00000000
"DisplayName"="ABBYY FineReader 5.0 Sprint"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{44850125-B5A7-420F-BF19-FFF249F95896}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="8.0.27"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090602"
"InstallLocation"="C:\\Program Files\\Verizon\\Verizon Internet Security Suite\\"
"InstallSource"="C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,34,00,34,00,38,00,35,00,30,00,31,00,32,00,\
35,00,2d,00,42,00,35,00,41,00,37,00,2d,00,34,00,32,00,30,00,46,00,2d,00,42,\
00,46,00,31,00,39,00,2d,00,46,00,46,00,46,00,32,00,34,00,39,00,46,00,39,00,\
35,00,38,00,39,00,36,00,7d,00,00,00
"Publisher"="Verizon"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0000057d
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,34,00,34,00,38,00,35,00,30,00,31,00,32,\
00,35,00,2d,00,42,00,35,00,41,00,37,00,2d,00,34,00,32,00,30,00,46,00,2d,00,\
42,00,46,00,31,00,39,00,2d,00,46,00,46,00,46,00,32,00,34,00,39,00,46,00,39,\
00,35,00,38,00,39,00,36,00,7d,00,00,00
"URLInfoAbout"="http://www.Radialpoint.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000008
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0800001b
"Language"=dword:00000409
"DisplayName"="RPS Firewall"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{469730CC-78DF-4CD3-B286-562D459EA619}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Sysext\\Esscam\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,34,00,36,00,39,00,37,00,33,00,30,00,43,00,\
43,00,2d,00,37,00,38,00,44,00,46,00,2d,00,34,00,43,00,44,00,33,00,2d,00,42,\
00,32,00,38,00,36,00,2d,00,35,00,36,00,32,00,44,00,34,00,35,00,39,00,45,00,\
41,00,36,00,31,00,39,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:000001a1
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,34,00,36,00,39,00,37,00,33,00,30,00,43,\
00,43,00,2d,00,37,00,38,00,44,00,46,00,2d,00,34,00,43,00,44,00,33,00,2d,00,\
42,00,32,00,38,00,36,00,2d,00,35,00,36,00,32,00,44,00,34,00,35,00,39,00,45,\
00,41,00,36,00,31,00,39,00,7d,00,00,00
"URLInfoAbout"="http://www.Kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESSCAM"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{48C82F7A-F100-4DAB-A310-8E18BF2159E1}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"="_"
"DisplayVersion"="4.00.0000.0101"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\ESS\\ESSvpot\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,34,00,38,00,43,00,38,00,32,00,46,00,37,00,\
41,00,2d,00,46,00,31,00,30,00,30,00,2d,00,34,00,44,00,41,00,42,00,2d,00,41,\
00,33,00,31,00,30,00,2d,00,38,00,45,00,31,00,38,00,42,00,46,00,32,00,31,00,\
35,00,39,00,45,00,31,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:000000d5
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,34,00,38,00,43,00,38,00,32,00,46,00,37,\
00,41,00,2d,00,46,00,31,00,30,00,30,00,2d,00,34,00,44,00,41,00,42,00,2d,00,\
41,00,33,00,31,00,30,00,2d,00,38,00,45,00,31,00,38,00,42,00,46,00,32,00,31,\
00,35,00,39,00,45,00,31,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESSvpot"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{49FC50FC-F965-40D9-89B4-CBFF80941033}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="2.0.0000"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,63,00,6f,\
00,6d,00,00,00
"HelpTelephone"=" "
"InstallDate"="20080229"
"InstallLocation"=""
"InstallSource"="C:\\DOCUME~1\\Jeremy\\LOCALS~1\\Temp\\IXP000.TMP\\"
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:000016bc
"SystemComponent"=dword:00000001
"URLInfoAbout"="http://www.microsoft.com"
"URLUpdateInfo"="http://www.microsoft.com"
"VersionMajor"=dword:00000002
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:02000000
"Language"=dword:00000409
"DisplayName"="Windows Movie Maker 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}]
"ModifyPath"="\"C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\setup.exe\" -runfromtemp -l0x0009"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"UninstallString"="\"C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\setup.exe\" -runfromtemp -l0x0009 -removeonly"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\setup.ilg"
"InstallLocation"="C:\\Program Files\\Verizon\\Verizon Internet Security Suite\\"
"ProductGuid"="{4CB90CB9-DD58-4CCC-A053-08FA70A42941}"
"InstallSource"="C:\\Documents and Settings\\Jeremy\\Local Settings\\Temp\\pbA2B\\"
"DisplayName"="Verizon Internet Security Suite"
"Publisher"="Verizon"
"URLInfoAbout"="http://www.verizon.net"
"DisplayIcon"="C:\\Program Files\\Verizon\\Verizon Internet Security Suite\\Product.ico"
"InstallDate"="20090602"
"Language"=dword:00000009
"DisplayVersion"="8.0.27"
"Version"=dword:0800001b
"MajorVersion"=dword:00000008
"MinorVersion"=dword:00000000
"LogMode"=dword:00000001
"RpProdId"="RPS"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4F677FC7-7AA8-412B-A957-F13CBE1C7331}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0003"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Sonic\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,34,00,46,00,36,00,37,00,37,00,46,00,43,00,\
37,00,2d,00,37,00,41,00,41,00,38,00,2d,00,34,00,31,00,32,00,42,00,2d,00,41,\
00,39,00,35,00,37,00,2d,00,46,00,31,00,33,00,43,00,42,00,45,00,31,00,43,00,\
37,00,33,00,33,00,31,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0000055d
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,34,00,46,00,36,00,37,00,37,00,46,00,43,\
00,37,00,2d,00,37,00,41,00,41,00,38,00,2d,00,34,00,31,00,32,00,42,00,2d,00,\
41,00,39,00,35,00,37,00,2d,00,46,00,31,00,33,00,43,00,42,00,45,00,31,00,43,\
00,37,00,33,00,33,00,31,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000409
"DisplayName"="ESSSONIC"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{54DD126C-E5F5-404C-B4B7-66DF7FD4F2FF}]
"AuthorizedCDFPrefix"=""
"Comments"="http://www.earthlink.net/software"
"Contact"="Customer Support Department"
"DisplayVersion"="2003.2.1.0"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,65,00,61,00,72,00,74,00,68,00,6c,00,69,00,6e,\
00,6b,00,2e,00,6e,00,65,00,74,00,00,00
"HelpTelephone"="1-800-EARTHLINK"
"InstallDate"="20030916"
"InstallLocation"=""
"InstallSource"="C:\\Program Files\\EarthLink Setup\\Windows\\MSSoap\\"
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="EarthLink, Inc."
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000153
"SystemComponent"=dword:00000001
"URLInfoAbout"="http://www.earthlink.net"
"URLUpdateInfo"="http://www.earthlink.net/software"
"VersionMajor"=dword:000007d3
"VersionMinor"=dword:00000002
"WindowsInstaller"=dword:00000001
"Version"=dword:d3020001
"Language"=dword:00000409
"DisplayName"="MSSoap"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{55BC7EFA-D832-4EE3-9DEA-49B0C07539D9}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{55BC7EFA-D832-4EE3-9DEA-49B0C07539D9}\\setup.exe\" -l0x9 -L0x9anything"
"DisplayName"=""
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{55BC7EFA-D832-4EE3-9DEA-49B0C07539D9}\\setup.ilg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5DE3D989-A820-4247-8963-9287C28B3613}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="8.0.27"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090602"
"InstallLocation"="C:\\Program Files\\Verizon\\Verizon Internet Security Suite\\"
"InstallSource"="C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,35,00,44,00,45,00,33,00,44,00,39,00,38,00,\
39,00,2d,00,41,00,38,00,32,00,30,00,2d,00,34,00,32,00,34,00,37,00,2d,00,38,\
00,39,00,36,00,33,00,2d,00,39,00,32,00,38,00,37,00,43,00,32,00,38,00,42,00,\
33,00,36,00,31,00,33,00,7d,00,00,00
"Publisher"="Verizon"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0000e11e
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,35,00,44,00,45,00,33,00,44,00,39,00,38,\
00,39,00,2d,00,41,00,38,00,32,00,30,00,2d,00,34,00,32,00,34,00,37,00,2d,00,\
38,00,39,00,36,00,33,00,2d,00,39,00,32,00,38,00,37,00,43,00,32,00,38,00,42,\
00,33,00,36,00,31,00,33,00,7d,00,00,00
"URLInfoAbout"="http://www.Radialpoint.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000008
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0800001b
"Language"=dword:00000409
"DisplayName"="RPS Ksdk"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E835305-63BB-4E55-BBB7-EEBBE67774DB}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{5E835305-63BB-4E55-BBB7-EEBBE67774DB}\\setup.exe\" -l0x9 -L0x9 /SMAINT"
"DisplayName"="MyDVD"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{5E835305-63BB-4E55-BBB7-EEBBE67774DB}\\setup.ilg"
"DisplayIcon"="C:\\Program Files\\Sonic\\MyDVD\\Components\\MyDVD3.ico"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{609F7AC8-C510-11D4-A788-009027ABA5D0}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="5.3.4.21"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,72,00,6f,00,78,00,69,00,6f,00,2e,00,63,00,6f,00,6d,00,2f,00,65,00,6e,\
00,2f,00,73,00,75,00,70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"=" "
"InstallDate"="20030911"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,36,00,30,00,39,00,46,00,37,00,41,00,43,00,\
38,00,2d,00,43,00,35,00,31,00,30,00,2d,00,31,00,31,00,44,00,34,00,2d,00,41,\
00,37,00,38,00,38,00,2d,00,30,00,30,00,39,00,30,00,32,00,37,00,41,00,42,00,\
41,00,35,00,44,00,30,00,7d,00,00,00
"NoRepair"=dword:00000001
"Publisher"="Roxio Inc"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,36,00,30,00,39,00,46,00,37,00,41,00,43,\
00,38,00,2d,00,43,00,35,00,31,00,30,00,2d,00,31,00,31,00,44,00,34,00,2d,00,\
41,00,37,00,38,00,38,00,2d,00,30,00,30,00,39,00,30,00,32,00,37,00,41,00,42,\
00,41,00,35,00,44,00,30,00,7d,00,00,00
"URLInfoAbout"="http://www.roxio.com"
"URLUpdateInfo"="http://www.roxio.com/en/updates.html"
"VersionMajor"=dword:00000005
"VersionMinor"=dword:00000001
"WindowsInstaller"=dword:00000001
"Version"=dword:05010000
"Language"=dword:00000000
"DisplayName"="Easy CD Creator 5 Basic"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{61D85BCA-6150-4A90-938B-D426BF166777}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="8.0.27"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090602"
"InstallLocation"="C:\\Program Files\\Verizon\\Verizon Internet Security Suite\\"
"InstallSource"="C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,36,00,31,00,44,00,38,00,35,00,42,00,43,00,\
41,00,2d,00,36,00,31,00,35,00,30,00,2d,00,34,00,41,00,39,00,30,00,2d,00,39,\
00,33,00,38,00,42,00,2d,00,44,00,34,00,32,00,36,00,42,00,46,00,31,00,36,00,\
36,00,37,00,37,00,37,00,7d,00,00,00
"Publisher"="Verizon"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0000030c
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,36,00,31,00,44,00,38,00,35,00,42,00,43,\
00,41,00,2d,00,36,00,31,00,35,00,30,00,2d,00,34,00,41,00,39,00,30,00,2d,00,\
39,00,33,00,38,00,42,00,2d,00,44,00,34,00,32,00,36,00,42,00,46,00,31,00,36,\
00,36,00,37,00,37,00,37,00,7d,00,00,00
"URLInfoAbout"="http://www.Radialpoint.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000008
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0800001b
"Language"=dword:00000409
"DisplayName"="RPS ParentalControl"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{62369F2F77534556AEF4C58152E3BDE5}]
"FinishedFlag"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{64116298-93C5-401D-B06C-39D8E3338508}]
"AuthorizedCDFPrefix"=""
"Comments"="Your Comments"
"Contact"="Customer Support Department"
"DisplayVersion"="3.50"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,79,00,6f,00,75,00,72,00,63,00,6f,00,6d,00,70,00,61,00,6e,00,79,00,2e,\
00,63,00,6f,00,6d,00,2f,00,68,00,65,00,6c,00,70,00,00,00
"HelpTelephone"="1-555-555-4505"
"InstallDate"="20030911"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,36,00,34,00,31,00,31,00,36,00,32,00,39,00,\
38,00,2d,00,39,00,33,00,43,00,35,00,2d,00,34,00,30,00,31,00,44,00,2d,00,42,\
00,30,00,36,00,43,00,2d,00,33,00,39,00,44,00,38,00,45,00,33,00,33,00,33,00,\
38,00,35,00,30,00,38,00,7d,00,00,00
"Publisher"="Jasc Software Inc"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,36,00,34,00,31,00,31,00,36,00,32,00,39,\
00,38,00,2d,00,39,00,33,00,43,00,35,00,2d,00,34,00,30,00,31,00,44,00,2d,00,\
42,00,30,00,36,00,43,00,2d,00,33,00,39,00,44,00,38,00,45,00,33,00,33,00,33,\
00,38,00,35,00,30,00,38,00,7d,00,00,00
"URLInfoAbout"="http://www.yourcompany.com"
"URLUpdateInfo"="http://www.yourcompany.com/updateinfo"
"VersionMajor"=dword:00000003
"VersionMinor"=dword:00000032
"WindowsInstaller"=dword:00000001
"Version"=dword:03320000
"Language"=dword:00000409
"DisplayName"="DAO"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{643EAE81-920C-4931-9F0B-4B343B225CA6}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Sysext\\Essbrwr\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,36,00,34,00,33,00,45,00,41,00,45,00,38,00,\
31,00,2d,00,39,00,32,00,30,00,43,00,2d,00,34,00,39,00,33,00,31,00,2d,00,39,\
00,46,00,30,00,42,00,2d,00,34,00,42,00,33,00,34,00,33,00,42,00,32,00,32,00,\
35,00,43,00,41,00,36,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000119
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,36,00,34,00,33,00,45,00,41,00,45,00,38,\
00,31,00,2d,00,39,00,32,00,30,00,43,00,2d,00,34,00,39,00,33,00,31,00,2d,00,\
39,00,46,00,30,00,42,00,2d,00,34,00,42,00,33,00,34,00,33,00,42,00,32,00,32,\
00,35,00,43,00,41,00,36,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESSBrwr"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\\setup.exe\" -uninstall"
"DisplayName"="PowerDVD"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\\setup.ilg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{68D60342-7686-45C9-B8EB-40EF843D0460}]
"AuthorizedCDFPrefix"=""
"Comments"="Go to http://support.dell.com."
"Contact"="Dell Support"
"DisplayVersion"="1.00.0001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,64,00,65,00,6c,00,6c,00,2e,00,63,00,6f,00,6d,\
00,00,00
"HelpTelephone"="0"
"InstallDate"="20030911"
"InstallLocation"=""
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Dell"
"Readme"=hex(2):30,00,00,00
"Size"=""
"SystemComponent"=dword:00000001
"URLInfoAbout"="http://www.dell.com"
"URLUpdateInfo"="http://support.dell.com"
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:01000001
"Language"=dword:00000409
"DisplayName"="Dell Networking Guide"

jlauv
2009-08-19, 21:08
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{69BD6399-3D8F-45B7-81D9-819361F5101D}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0101"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Sysext\\PCDLNCH\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,36,00,39,00,42,00,44,00,36,00,33,00,39,00,\
39,00,2d,00,33,00,44,00,38,00,46,00,2d,00,34,00,35,00,42,00,37,00,2d,00,38,\
00,31,00,44,00,39,00,2d,00,38,00,31,00,39,00,33,00,36,00,31,00,46,00,35,00,\
31,00,30,00,31,00,44,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:000000e2
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,36,00,39,00,42,00,44,00,36,00,33,00,39,\
00,39,00,2d,00,33,00,44,00,38,00,46,00,2d,00,34,00,35,00,42,00,37,00,2d,00,\
38,00,31,00,44,00,39,00,2d,00,38,00,31,00,39,00,33,00,36,00,31,00,46,00,35,\
00,31,00,30,00,31,00,44,00,7d,00,00,00
"URLInfoAbout"="http://www.Kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="PCDLNCH"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{709E6F62-1168-11D5-8202-00E0294A926C}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{709E6F62-1168-11D5-8202-00E0294A926C}\\setup.exe\" anythinganythinganything"
"DisplayName"="USB Driver for Panasonic DVC"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{709E6F62-1168-11D5-8202-00E0294A926C}\\setup.ilg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}]
"DisplayIcon"="C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\ndpsetup.ico"
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="2.0.50727"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090120"
"InstallLocation"=""
"InstallSource"="C:\\DOCUME~1\\Jeremy\\LOCALS~1\\Temp\\IS152.tmp\\"
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0003428f
"SystemComponent"=dword:00000001
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000002
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0200c627
"Language"=dword:00000000
"DisplayName"="Microsoft .NET Framework 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{74EC78BC-B379-4E29-9006-8F161DCAABA6}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"="AppleCare Support"
"DisplayVersion"="2.0.0.21"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,61,00,70,00,70,00,6c,00,65,00,2e,00,63,00,6f,00,6d,00,2f,00,73,00,75,\
00,70,00,70,00,6f,00,72,00,74,00,2f,00,00,00
"HelpTelephone"="1-800-275-2273"
"InstallDate"="20070906"
"InstallLocation"="C:\\Program Files\\Apple Software Update\\"
"InstallSource"="C:\\DOCUME~1\\Jeremy\\LOCALS~1\\Temp\\IXP735.TMP\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,37,00,34,00,45,00,43,00,37,00,38,00,42,00,\
43,00,2d,00,42,00,33,00,37,00,39,00,2d,00,34,00,45,00,32,00,39,00,2d,00,39,\
00,30,00,30,00,36,00,2d,00,38,00,46,00,31,00,36,00,31,00,44,00,43,00,41,00,\
41,00,42,00,41,00,36,00,7d,00,00,00
"Publisher"="Apple Inc."
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0000089c
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,37,00,34,00,45,00,43,00,37,00,38,00,42,\
00,43,00,2d,00,42,00,33,00,37,00,39,00,2d,00,34,00,45,00,32,00,39,00,2d,00,\
39,00,30,00,30,00,36,00,2d,00,38,00,46,00,31,00,36,00,31,00,44,00,43,00,41,\
00,41,00,42,00,41,00,36,00,7d,00,00,00
"URLInfoAbout"="http://www.apple.com"
"URLUpdateInfo"="http://www.apple.com/macosx/"
"VersionMajor"=dword:00000002
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:02000000
"Language"=dword:00000409
"DisplayName"="Apple Software Update"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}]
"AuthorizedCDFPrefix"=""
"Comments"="Microsoft Works 7.0 installation."
"Contact"=""
"DisplayVersion"="07.02.0710.1"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,2e,00,63,00,6f,00,6d,00,2f,00,73,00,75,00,70,00,70,00,6f,00,72,00,\
74,00,2f,00,77,00,6f,00,72,00,6b,00,73,00,00,00
"HelpTelephone"=" "
"InstallDate"="20020930"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,37,00,36,00,34,00,44,00,30,00,36,00,44,00,\
38,00,2d,00,44,00,38,00,44,00,45,00,2d,00,34,00,31,00,31,00,45,00,2d,00,41,\
00,31,00,43,00,38,00,2d,00,44,00,39,00,45,00,39,00,33,00,38,00,30,00,46,00,\
38,00,41,00,38,00,34,00,7d,00,00,00
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,37,00,36,00,34,00,44,00,30,00,36,00,44,\
00,38,00,2d,00,44,00,38,00,44,00,45,00,2d,00,34,00,31,00,31,00,45,00,2d,00,\
41,00,31,00,43,00,38,00,2d,00,44,00,39,00,45,00,39,00,33,00,38,00,30,00,46,\
00,38,00,41,00,38,00,34,00,7d,00,00,00
"URLInfoAbout"="http://www.microsoft.com"
"URLUpdateInfo"="http://works.msn.com"
"VersionMajor"=dword:00000007
"VersionMinor"=dword:00000002
"WindowsInstaller"=dword:00000001
"Version"=dword:070202c6
"Language"=dword:00000409
"DisplayName"="Microsoft Works 7.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7B63B2922B174135AFC0E1377DD81EC2}]
"InstallLocation"="C:\\Program Files\\DivX"
"Publisher"="DivX, Inc."
"DisplayVersion"="6.8.0"
"NoRepair"=dword:00000001
"Cart URL override"="http://go.divx.com/divx/create/buy/en"
"FinishedFlag"=dword:00000000
"DisplayName"="DivX Codec"
"DisplayIcon"="C:\\Program Files\\DivX\\DivX Codec\\config.exe,0"
"UninstallString"="C:\\Program Files\\DivX\\DivXCodecUninstall.exe /CODEC"
"NoModify"=dword:00000001
"Locale"="en"
"RebootFlag"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7EE9DE0D-9228-4C33-B80E-FDD1773600DF}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="2.0.0.0000"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,2e,00,63,00,6f,00,6d,00,2f,00,73,00,75,00,70,00,70,00,6f,00,72,00,\
74,00,2f,00,77,00,6f,00,72,00,6b,00,73,00,00,00
"HelpTelephone"=" "
"InstallDate"="20020930"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,37,00,45,00,45,00,39,00,44,00,45,00,30,00,\
44,00,2d,00,39,00,32,00,32,00,38,00,2d,00,34,00,43,00,33,00,33,00,2d,00,42,\
00,38,00,30,00,45,00,2d,00,46,00,44,00,44,00,31,00,37,00,37,00,33,00,36,00,\
30,00,30,00,44,00,46,00,7d,00,00,00
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,37,00,45,00,45,00,39,00,44,00,45,00,30,\
00,44,00,2d,00,39,00,32,00,32,00,38,00,2d,00,34,00,43,00,33,00,33,00,2d,00,\
42,00,38,00,30,00,45,00,2d,00,46,00,44,00,44,00,31,00,37,00,37,00,33,00,36,\
00,30,00,30,00,44,00,46,00,7d,00,00,00
"URLInfoAbout"="http://www.microsoft.com"
"URLUpdateInfo"="http://www.microsoft.com"
"VersionMajor"=dword:00000002
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:02000000
"Language"=dword:00000409
"DisplayName"="Microsoft Works Suite Add-in for Microsoft Word"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7F142D56-3326-11D5-B229-002078017FBF}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{7F142D56-3326-11D5-B229-002078017FBF}\\setup.exe\" -l0x9 ControlPanel"
"DisplayName"="Modem Helper"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{7F142D56-3326-11D5-B229-002078017FBF}\\setup.ilg"
"ModemHelperPath"="C:\\Program Files\\Modem Helper"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="4.20.9870.0"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,2e,00,63,00,6f,00,6d,00,2f,00,6b,00,62,00,2f,00,39,00,35,00,34,00,\
34,00,33,00,30,00,00,00
"HelpTelephone"=""
"InstallDate"="20081113"
"InstallLocation"=""
"InstallSource"="c:\\669ab8e73ffc3b78bca7cb47c54a4b\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,38,00,36,00,34,00,39,00,33,00,41,00,44,00,\
44,00,2d,00,38,00,32,00,34,00,44,00,2d,00,34,00,42,00,38,00,45,00,2d,00,42,\
00,44,00,37,00,32,00,2d,00,38,00,43,00,35,00,44,00,43,00,44,00,43,00,35,00,\
32,00,41,00,37,00,31,00,7d,00,00,00
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000aa9
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,38,00,36,00,34,00,39,00,33,00,41,00,44,\
00,44,00,2d,00,38,00,32,00,34,00,44,00,2d,00,34,00,42,00,38,00,45,00,2d,00,\
42,00,44,00,37,00,32,00,2d,00,38,00,43,00,35,00,44,00,43,00,44,00,43,00,35,\
00,32,00,41,00,37,00,31,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000014
"WindowsInstaller"=dword:00000001
"Version"=dword:0414268e
"Language"=dword:00000409
"DisplayName"="MSXML 4.0 SP2 (KB954430)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87843A41-7808-4F2E-B13F-25C1E67CF2FD}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0003"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\ESS\\ESShelp\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,38,00,37,00,38,00,34,00,33,00,41,00,34,00,\
31,00,2d,00,37,00,38,00,30,00,38,00,2d,00,34,00,46,00,32,00,45,00,2d,00,42,\
00,31,00,33,00,46,00,2d,00,32,00,35,00,43,00,31,00,45,00,36,00,37,00,43,00,\
46,00,32,00,46,00,44,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000601
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,38,00,37,00,38,00,34,00,33,00,41,00,34,\
00,31,00,2d,00,37,00,38,00,30,00,38,00,2d,00,34,00,46,00,32,00,45,00,2d,00,\
42,00,31,00,33,00,46,00,2d,00,32,00,35,00,43,00,31,00,45,00,36,00,37,00,43,\
00,46,00,32,00,46,00,44,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESShelp"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8851E12C-0EF9-11D4-A788-009027ABA5D0}]
"NoRemove"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="3.0.40723.0"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,67,00,6f,00,2e,00,\
6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,63,00,6f,00,6d,\
00,2f,00,66,00,77,00,6c,00,69,00,6e,00,6b,00,2f,00,3f,00,4c,00,69,00,6e,00,\
6b,00,49,00,44,00,3d,00,39,00,31,00,39,00,35,00,35,00,00,00
"HelpTelephone"=""
"InstallDate"="20090731"
"InstallLocation"="c:\\Program Files\\Microsoft Silverlight\\"
"InstallSource"="c:\\9eb44b8046a0575d954d2cfbbb4e77\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,58,00,7b,00,38,00,39,00,46,00,34,00,31,00,33,00,37,00,\
44,00,2d,00,36,00,43,00,32,00,36,00,2d,00,34,00,41,00,38,00,34,00,2d,00,42,\
00,44,00,42,00,38,00,2d,00,32,00,45,00,35,00,41,00,34,00,42,00,42,00,37,00,\
31,00,45,00,30,00,30,00,7d,00,00,00
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00009cc0
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,58,00,7b,00,38,00,39,00,46,00,34,00,31,00,33,00,37,\
00,44,00,2d,00,36,00,43,00,32,00,36,00,2d,00,34,00,41,00,38,00,34,00,2d,00,\
42,00,44,00,42,00,38,00,2d,00,32,00,45,00,35,00,41,00,34,00,42,00,42,00,37,\
00,31,00,45,00,30,00,30,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000003
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:03009f13
"Language"=dword:00000409
"DisplayName"="Microsoft Silverlight"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8ADFC4160D694100B5B8A22DE9DCABD9}]
"FinishedFlag"=dword:00000000
"DisplayName"="DivX Player"
"InstallLocation"="C:\\Program Files\\DivX"
"DisplayIcon"="C:\\Program Files\\DivX\\DivX Player\\DivX Player.exe,0"
"UninstallString"="C:\\Program Files\\DivX\\DivXPlayerUninstall.exe /PLAYER"
"DisplayVersion"="6.7.0"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Locale"="en"
"RebootFlag"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0101"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Sysext\\ESSCT\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,38,00,42,00,42,00,34,00,42,00,35,00,38,00,\
41,00,2d,00,41,00,34,00,30,00,32,00,2d,00,34,00,44,00,45,00,38,00,2d,00,38,\
00,46,00,43,00,44,00,2d,00,32,00,38,00,37,00,45,00,36,00,30,00,42,00,38,00,\
38,00,44,00,44,00,38,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:000000a1
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,38,00,42,00,42,00,34,00,42,00,35,00,38,\
00,41,00,2d,00,41,00,34,00,30,00,32,00,2d,00,34,00,44,00,45,00,38,00,2d,00,\
38,00,46,00,43,00,44,00,2d,00,32,00,38,00,37,00,45,00,36,00,30,00,42,00,38,\
00,38,00,44,00,44,00,38,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESSCT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8DD94CA3-BCD2-49C0-B537-F3B5D95FF0C8}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0103"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\ESS\\HLPSFO\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,38,00,44,00,44,00,39,00,34,00,43,00,41,00,\
33,00,2d,00,42,00,43,00,44,00,32,00,2d,00,34,00,39,00,43,00,30,00,2d,00,42,\
00,35,00,33,00,37,00,2d,00,46,00,33,00,42,00,35,00,44,00,39,00,35,00,46,00,\
46,00,30,00,43,00,38,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000181
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,38,00,44,00,44,00,39,00,34,00,43,00,41,\
00,33,00,2d,00,42,00,43,00,44,00,32,00,2d,00,34,00,39,00,43,00,30,00,2d,00,\
42,00,35,00,33,00,37,00,2d,00,46,00,33,00,42,00,35,00,44,00,39,00,35,00,46,\
00,46,00,30,00,43,00,38,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="HLPSFO"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8E92D746-CD9F-4B90-9668-42B74C14F765}]
"AuthorizedCDFPrefix"=""
"Comments"=" "
"Contact"=" "
"DisplayVersion"="4.00.0000.0107"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"=" "
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\ESS\\ESSini\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,38,00,45,00,39,00,32,00,44,00,37,00,34,00,\
36,00,2d,00,43,00,44,00,39,00,46,00,2d,00,34,00,42,00,39,00,30,00,2d,00,39,\
00,36,00,36,00,38,00,2d,00,34,00,32,00,42,00,37,00,34,00,43,00,31,00,34,00,\
46,00,37,00,36,00,35,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000081
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,38,00,45,00,39,00,32,00,44,00,37,00,34,\
00,36,00,2d,00,43,00,44,00,39,00,46,00,2d,00,34,00,42,00,39,00,30,00,2d,00,\
39,00,36,00,36,00,38,00,2d,00,34,00,32,00,42,00,37,00,34,00,43,00,31,00,34,\
00,46,00,37,00,36,00,35,00,7d,00,00,00
"URLInfoAbout"="http://www.Kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESSini"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\PROFES~1\\RunTime\\09\\01\\Intel32\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}\\setup.exe\" -l0x9 -uninst "
"DisplayName"="Musicmatch® Jukebox"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}\\setup.ilg"
"ProductGuid"="{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}"
"InstallLocation"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox"
"DisplayVersion"="9.00.5013"
"Version"=dword:09001395
"MajorVersion"=dword:00000009
"MinorVersion"=dword:00000000
"LogMode"=dword:00000001
"DisplayIcon"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mmjb.exe,0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"="http://www.support.dell.com"
"DisplayVersion"="1.00.0000"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,73,00,75,00,70,00,70,00,6f,00,72,00,74,00,2e,00,64,00,65,00,6c,00,6c,\
00,2e,00,63,00,6f,00,6d,00,00,00
"HelpTelephone"="http://www.support.dell.com"
"InstallDate"="20030911"
"InstallLocation"=""
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Dell"
"Readme"=hex(2):30,00,00,00
"Size"=""
"SystemComponent"=dword:00000001
"URLInfoAbout"="http://www.support.dell.com"
"URLUpdateInfo"="http://www.support.dell.com"
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:01000000
"Language"=dword:00000000
"DisplayName"="Help and Support Customization"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{911B0409-6000-11D3-8CFE-0050048383C9}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="10.0.2627.01"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,63,00,6f,\
00,6d,00,2f,00,73,00,75,00,70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"=""
"InstallDate"="20020930"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,39,00,31,00,31,00,42,00,30,00,34,00,30,00,\
39,00,2d,00,36,00,30,00,30,00,30,00,2d,00,31,00,31,00,44,00,33,00,2d,00,38,\
00,43,00,46,00,45,00,2d,00,30,00,30,00,35,00,30,00,30,00,34,00,38,00,33,00,\
38,00,33,00,43,00,39,00,7d,00,00,00
"Publisher"="Microsoft Corporation"
"Readme"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,\
00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,4f,00,66,00,66,00,69,00,63,00,65,00,5c,00,4f,00,66,\
00,66,00,69,00,63,00,65,00,31,00,30,00,5c,00,31,00,30,00,33,00,33,00,5c,00,\
4f,00,46,00,52,00,45,00,41,00,44,00,31,00,30,00,2e,00,48,00,54,00,4d,00,00,\
00
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,39,00,31,00,31,00,42,00,30,00,34,00,30,\
00,39,00,2d,00,36,00,30,00,30,00,30,00,2d,00,31,00,31,00,44,00,33,00,2d,00,\
38,00,43,00,46,00,45,00,2d,00,30,00,30,00,35,00,30,00,30,00,34,00,38,00,33,\
00,38,00,33,00,43,00,39,00,7d,00,00,00
"URLInfoAbout"="http://www.microsoft.com/support"
"URLUpdateInfo"=""
"VersionMajor"=dword:0000000a
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0a000a43
"Language"=dword:00000409
"DisplayName"="Microsoft Word 2002"
"QuietUninstallString"="MsiExec.Exe /x {911B0409-6000-11D3-8CFE-0050048383C9} /qn"
"InstallSource"=""
"EstimatedSize"=dword:fffffc50

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91517631-A9F3-4B7C-B482-43E0068FD55A}]
"AuthorizedCDFPrefix"=""
"Comments"=" "
"Contact"=" "
"DisplayVersion"="4.00.0000.0004"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"=" "
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\ESS\\ESSgui\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,39,00,31,00,35,00,31,00,37,00,36,00,33,00,\
31,00,2d,00,41,00,39,00,46,00,33,00,2d,00,34,00,42,00,37,00,43,00,2d,00,42,\
00,34,00,38,00,32,00,2d,00,34,00,33,00,45,00,30,00,30,00,36,00,38,00,46,00,\
44,00,35,00,35,00,41,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000cdd
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,39,00,31,00,35,00,31,00,37,00,36,00,33,\
00,31,00,2d,00,41,00,39,00,46,00,33,00,2d,00,34,00,42,00,37,00,43,00,2d,00,\
42,00,34,00,38,00,32,00,2d,00,34,00,33,00,45,00,30,00,30,00,36,00,38,00,46,\
00,44,00,35,00,35,00,41,00,7d,00,00,00
"URLInfoAbout"="http://www.Kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESSgui"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"="AppleCare Support"
"DisplayVersion"="7.2.0.240"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,61,00,70,00,70,00,6c,00,65,00,2e,00,63,00,6f,00,6d,00,2f,00,73,00,75,\
00,70,00,70,00,6f,00,72,00,74,00,2f,00,00,00
"HelpTelephone"="1-800-275-2273"
"InstallDate"="20070906"
"InstallLocation"="C:\\Program Files\\QuickTime\\"
"InstallSource"="C:\\DOCUME~1\\Jeremy\\LOCALS~1\\Temp\\IXP735.TMP\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,39,00,35,00,41,00,38,00,39,00,30,00,41,00,\
41,00,2d,00,42,00,33,00,42,00,31,00,2d,00,34,00,34,00,42,00,36,00,2d,00,39,\
00,43,00,31,00,38,00,2d,00,41,00,38,00,46,00,37,00,41,00,42,00,33,00,45,00,\
45,00,37,00,46,00,43,00,7d,00,00,00
"Publisher"="Apple Inc."
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0001280b
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,39,00,35,00,41,00,38,00,39,00,30,00,41,\
00,41,00,2d,00,42,00,33,00,42,00,31,00,2d,00,34,00,34,00,42,00,36,00,2d,00,\
39,00,43,00,31,00,38,00,2d,00,41,00,38,00,46,00,37,00,41,00,42,00,33,00,45,\
00,45,00,37,00,46,00,43,00,7d,00,00,00
"URLInfoAbout"="http://www.apple.com"
"URLUpdateInfo"="http://www.apple.com/quicktime/"
"VersionMajor"=dword:00000007
"VersionMinor"=dword:00000002
"WindowsInstaller"=dword:00000001
"Version"=dword:07020000
"Language"=dword:00000409
"DisplayName"="QuickTime"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{983338D4-D972-4C58-AA6D-B81445070451}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="1.0.0002"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090120"
"InstallLocation"="C:\\Program Files\\Fisher-Price\\DACS\\"
"InstallSource"="E:\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,39,00,38,00,33,00,33,00,33,00,38,00,44,00,\
34,00,2d,00,44,00,39,00,37,00,32,00,2d,00,34,00,43,00,35,00,38,00,2d,00,41,\
00,41,00,36,00,44,00,2d,00,42,00,38,00,31,00,34,00,34,00,35,00,30,00,37,00,\
30,00,34,00,35,00,31,00,7d,00,00,00
"Publisher"="Fisher-Price, Inc."
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0001cf9a
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,39,00,38,00,33,00,33,00,33,00,38,00,44,\
00,34,00,2d,00,44,00,39,00,37,00,32,00,2d,00,34,00,43,00,35,00,38,00,2d,00,\
41,00,41,00,36,00,44,00,2d,00,42,00,38,00,31,00,34,00,34,00,35,00,30,00,37,\
00,30,00,34,00,35,00,31,00,7d,00,00,00
"URLInfoAbout"="http://www.Fisher-Price,Inc..com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:01000002
"Language"=dword:00000409
"DisplayName"="The Digital Arts and Crafts Studio"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{98DF85D9-96C0-4F57-A92E-C3539477EF5E}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="1.00.0001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,73,00,75,00,70,00,70,00,6f,00,72,00,74,00,2e,00,64,00,65,00,6c,00,6c,\
00,2e,00,63,00,6f,00,6d,00,00,00
"HelpTelephone"="www.support.dell.com"
"InstallDate"="20030911"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,39,00,38,00,44,00,46,00,38,00,35,00,44,00,\
39,00,2d,00,39,00,36,00,43,00,30,00,2d,00,34,00,46,00,35,00,37,00,2d,00,41,\
00,39,00,32,00,45,00,2d,00,43,00,33,00,35,00,33,00,39,00,34,00,37,00,37,00,\
45,00,46,00,35,00,45,00,7d,00,00,00
"NoRepair"=dword:00000001
"Publisher"="Dell"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,39,00,38,00,44,00,46,00,38,00,35,00,44,\
00,39,00,2d,00,39,00,36,00,43,00,30,00,2d,00,34,00,46,00,35,00,37,00,2d,00,\
41,00,39,00,32,00,45,00,2d,00,43,00,33,00,35,00,33,00,39,00,34,00,37,00,37,\
00,45,00,46,00,35,00,45,00,7d,00,00,00
"URLInfoAbout"="http://www.support.dell.com"
"URLUpdateInfo"="http://www.support.dell.com"
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:01000001
"Language"=dword:00000409
"DisplayName"="DVDSentry"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{999D43F4-9709-4887-9B1A-83EBB15A8370}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="4.00.0000.0001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"=""
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\ESS\\VPRINTOL\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,39,00,39,00,39,00,44,00,34,00,33,00,46,00,\
34,00,2d,00,39,00,37,00,30,00,39,00,2d,00,34,00,38,00,38,00,37,00,2d,00,39,\
00,42,00,31,00,41,00,2d,00,38,00,33,00,45,00,42,00,42,00,31,00,35,00,41,00,\
38,00,33,00,37,00,30,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000175
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,39,00,39,00,39,00,44,00,34,00,33,00,46,\
00,34,00,2d,00,39,00,37,00,30,00,39,00,2d,00,34,00,38,00,38,00,37,00,2d,00,\
39,00,42,00,31,00,41,00,2d,00,38,00,33,00,45,00,42,00,42,00,31,00,35,00,41,\
00,38,00,33,00,37,00,30,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharew"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000409
"DisplayName"="VPRINTOL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9D1CF8B6-17B3-4832-B062-2C2DD0B57B04}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Cch\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,39,00,44,00,31,00,43,00,46,00,38,00,42,00,\
36,00,2d,00,31,00,37,00,42,00,33,00,2d,00,34,00,38,00,33,00,32,00,2d,00,42,\
00,30,00,36,00,32,00,2d,00,32,00,43,00,32,00,44,00,44,00,30,00,42,00,35,00,\
37,00,42,00,30,00,34,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=hex(2):5f,00,00,00
"Size"=""
"EstimatedSize"=dword:00000045
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,39,00,44,00,31,00,43,00,46,00,38,00,42,\
00,36,00,2d,00,31,00,37,00,42,00,33,00,2d,00,34,00,38,00,33,00,32,00,2d,00,\
42,00,30,00,36,00,32,00,2d,00,32,00,43,00,32,00,44,00,44,00,30,00,42,00,35,\
00,37,00,42,00,30,00,34,00,7d,00,00,00
"URLInfoAbout"="http://www.Kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="CCHelp"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}]
"AuthorizedCDFPrefix"=""
"Comments"=" "
"Contact"=" "
"DisplayVersion"="4.00.0000.0102"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"=" "
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\ESS\\ESScore\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,39,00,44,00,38,00,46,00,45,00,45,00,39,00,\
30,00,2d,00,30,00,33,00,37,00,37,00,2d,00,34,00,39,00,41,00,39,00,2d,00,41,\
00,45,00,46,00,42,00,2d,00,35,00,32,00,35,00,42,00,44,00,45,00,35,00,34,00,\
39,00,42,00,41,00,34,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00004022
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,39,00,44,00,38,00,46,00,45,00,45,00,39,\
00,30,00,2d,00,30,00,33,00,37,00,37,00,2d,00,34,00,39,00,41,00,39,00,2d,00,\
41,00,45,00,46,00,42,00,2d,00,35,00,32,00,35,00,42,00,44,00,45,00,35,00,34,\
00,39,00,42,00,41,00,34,00,7d,00,00,00
"URLInfoAbout"="http://www.Kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESScore"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A0AF08BA-3630-4505-BFB2-A41F3837B0D0}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="3.03.0000.0002"
"HelpLink"=hex(2):5f,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\SysFiles\\Sfr2\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,41,00,30,00,41,00,46,00,30,00,38,00,42,00,\
41,00,2d,00,33,00,36,00,33,00,30,00,2d,00,34,00,35,00,30,00,35,00,2d,00,42,\
00,46,00,42,00,32,00,2d,00,41,00,34,00,31,00,46,00,33,00,38,00,33,00,37,00,\
42,00,30,00,44,00,30,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000001
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,41,00,30,00,41,00,46,00,30,00,38,00,42,\
00,41,00,2d,00,33,00,36,00,33,00,30,00,2d,00,34,00,35,00,30,00,35,00,2d,00,\
42,00,46,00,42,00,32,00,2d,00,41,00,34,00,31,00,46,00,33,00,38,00,33,00,37,\
00,42,00,30,00,44,00,30,00,7d,00,00,00
"URLInfoAbout"="http://www.Kodak.com"
"URLUpdateInfo"="_"
"VersionMajor"=dword:00000003
"VersionMinor"=dword:00000003
"WindowsInstaller"=dword:00000001
"Version"=dword:03030000
"Language"=dword:00000000
"DisplayName"="SFR2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A28BECB7-2BF4-4171-8CDE-3803F0FE2874}]
"AuthorizedCDFPrefix"=""
"Comments"="Your Comments"
"Contact"="Customer Support Department"
"DisplayVersion"="1.00.0000"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,79,00,6f,00,75,00,72,00,63,00,6f,00,6d,00,70,00,61,00,6e,00,79,00,2e,\
00,63,00,6f,00,6d,00,2f,00,68,00,65,00,6c,00,70,00,00,00
"HelpTelephone"="123-4567"
"InstallDate"="20050708"
"InstallLocation"=""
"InstallSource"="C:\\DOCUME~1\\Jeremy\\LOCALS~1\\Temp\\Large IsEngineUpdate\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,41,00,32,00,38,00,42,00,45,00,43,00,42,00,\
37,00,2d,00,32,00,42,00,46,00,34,00,2d,00,34,00,31,00,37,00,31,00,2d,00,38,\
00,43,00,44,00,45,00,2d,00,33,00,38,00,30,00,33,00,46,00,30,00,46,00,45,00,\
32,00,38,00,37,00,34,00,7d,00,00,00
"Publisher"="ISEngineUpdate"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:000007f4
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,41,00,32,00,38,00,42,00,45,00,43,00,42,\
00,37,00,2d,00,32,00,42,00,46,00,34,00,2d,00,34,00,31,00,37,00,31,00,2d,00,\
38,00,43,00,44,00,45,00,2d,00,33,00,38,00,30,00,33,00,46,00,30,00,46,00,45,\
00,32,00,38,00,37,00,34,00,7d,00,00,00
"URLInfoAbout"="http://www.yourcompany.com"
"URLUpdateInfo"="http://www.yourcompany.com/updateinfo"
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:01000000
"Language"=dword:00000409
"DisplayName"="ISEngineUpdate"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A486CFF9-A3E6-4312-A1B9-ABD28F9FC255}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="8.0.27"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090602"
"InstallLocation"="C:\\Program Files\\Verizon\\Verizon Internet Security Suite\\"
"InstallSource"="C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,41,00,34,00,38,00,36,00,43,00,46,00,46,00,\
39,00,2d,00,41,00,33,00,45,00,36,00,2d,00,34,00,33,00,31,00,32,00,2d,00,41,\
00,31,00,42,00,39,00,2d,00,41,00,42,00,44,00,32,00,38,00,46,00,39,00,46,00,\
43,00,32,00,35,00,35,00,7d,00,00,00
"Publisher"="Verizon"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0000005c
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,41,00,34,00,38,00,36,00,43,00,46,00,46,\
00,39,00,2d,00,41,00,33,00,45,00,36,00,2d,00,34,00,33,00,31,00,32,00,2d,00,\
41,00,31,00,42,00,39,00,2d,00,41,00,42,00,44,00,32,00,38,00,46,00,39,00,46,\
00,43,00,32,00,35,00,35,00,7d,00,00,00
"URLInfoAbout"="http://www.Radialpoint.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000008
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0800001b
"Language"=dword:00000409
"DisplayName"="RPS PopupBlocker"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0003"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\ESS\\ESSvpaht\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,41,00,35,00,42,00,33,00,45,00,42,00,38,00,\
41,00,2d,00,34,00,30,00,37,00,31,00,2d,00,34,00,32,00,46,00,30,00,2d,00,38,\
00,45,00,38,00,45,00,2d,00,37,00,41,00,38,00,33,00,34,00,32,00,41,00,41,00,\
38,00,45,00,36,00,39,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0000009d
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,41,00,35,00,42,00,33,00,45,00,42,00,38,\
00,41,00,2d,00,34,00,30,00,37,00,31,00,2d,00,34,00,32,00,46,00,30,00,2d,00,\
38,00,45,00,38,00,45,00,2d,00,37,00,41,00,38,00,33,00,34,00,32,00,41,00,41,\
00,38,00,45,00,36,00,39,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesupport"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESSvpaht"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6F18A67-B771-4191-8A33-36D2E742D6D9}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Sysext\\ESSanup\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,41,00,36,00,46,00,31,00,38,00,41,00,36,00,\
37,00,2d,00,42,00,37,00,37,00,31,00,2d,00,34,00,31,00,39,00,31,00,2d,00,38,\
00,41,00,33,00,33,00,2d,00,33,00,36,00,44,00,32,00,45,00,37,00,34,00,32,00,\
44,00,36,00,44,00,39,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=hex(2):5f,00,00,00
"Size"=""
"EstimatedSize"=dword:00000281
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,41,00,36,00,46,00,31,00,38,00,41,00,36,\
00,37,00,2d,00,42,00,37,00,37,00,31,00,2d,00,34,00,31,00,39,00,31,00,2d,00,\
38,00,41,00,33,00,33,00,2d,00,33,00,36,00,44,00,32,00,45,00,37,00,34,00,32,\
00,44,00,36,00,44,00,39,00,7d,00,00,00
"URLInfoAbout"="http://www.Kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESSANUP"

jlauv
2009-08-19, 21:12
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}]
"AuthorizedCDFPrefix"=""
"Comments"="Intel(R) PROSet installation package"
"Contact"="Intel Customer Support"
"DisplayVersion"="6.05.2001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,69,00,6e,00,74,00,65,00,6c,00,2e,00,63,00,6f,\
00,6d,00,00,00
"HelpTelephone"=""
"InstallDate"="20030911"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,41,00,37,00,39,00,30,00,42,00,45,00,42,00,\
31,00,2d,00,42,00,43,00,43,00,46,00,2d,00,34,00,45,00,43,00,36,00,2d,00,38,\
00,30,00,37,00,42,00,2d,00,35,00,37,00,30,00,38,00,42,00,33,00,36,00,45,00,\
38,00,41,00,37,00,39,00,7d,00,00,00
"Publisher"="Intel"
"Readme"=""
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,41,00,37,00,39,00,30,00,42,00,45,00,42,\
00,31,00,2d,00,42,00,43,00,43,00,46,00,2d,00,34,00,45,00,43,00,36,00,2d,00,\
38,00,30,00,37,00,42,00,2d,00,35,00,37,00,30,00,38,00,42,00,33,00,36,00,45,\
00,38,00,41,00,37,00,39,00,7d,00,00,00
"URLInfoAbout"="http://www.intel.com"
"URLUpdateInfo"="http://downloadfinder.intel.com"
"VersionMajor"=dword:00000006
"VersionMinor"=dword:00000005
"WindowsInstaller"=dword:00000001
"Version"=dword:060507d1
"Language"=dword:00000000
"DisplayName"="Intel(R) PROSet"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-A91000000001}]
"AuthorizedCDFPrefix"=""
"Comments"=" "
"Contact"="Customer Support"
"DisplayVersion"="9.1.0"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,61,00,64,00,6f,00,62,00,65,00,2e,00,63,00,6f,00,6d,00,2f,00,73,00,75,\
00,70,00,70,00,6f,00,72,00,74,00,2f,00,6d,00,61,00,69,00,6e,00,2e,00,68,00,\
74,00,6d,00,6c,00,00,00
"HelpTelephone"=""
"InstallDate"="20090815"
"InstallLocation"="C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\"
"InstallSource"="C:\\Documents and Settings\\All Users\\Desktop\\Adobe Reader 9 Installer\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,41,00,43,00,37,00,36,00,42,00,41,00,38,00,\
36,00,2d,00,37,00,41,00,44,00,37,00,2d,00,31,00,30,00,33,00,33,00,2d,00,37,\
00,42,00,34,00,34,00,2d,00,41,00,39,00,31,00,30,00,30,00,30,00,30,00,30,00,\
30,00,30,00,30,00,31,00,7d,00,00,00
"NoRepair"=dword:00000001
"Publisher"="Adobe Systems Incorporated"
"Readme"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,\
00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,64,00,6f,00,62,00,65,00,5c,00,\
52,00,65,00,61,00,64,00,65,00,72,00,20,00,39,00,2e,00,30,00,5c,00,52,00,65,\
00,61,00,64,00,6d,00,65,00,2e,00,68,00,74,00,6d,00,00,00
"Size"=""
"EstimatedSize"=dword:00033701
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,41,00,43,00,37,00,36,00,42,00,41,00,38,\
00,36,00,2d,00,37,00,41,00,44,00,37,00,2d,00,31,00,30,00,33,00,33,00,2d,00,\
37,00,42,00,34,00,34,00,2d,00,41,00,39,00,31,00,30,00,30,00,30,00,30,00,30,\
00,30,00,30,00,30,00,31,00,7d,00,00,00
"URLInfoAbout"="http://www.adobe.com"
"URLUpdateInfo"="http://www.adobe.com/products/acrobat/readstep.html"
"VersionMajor"=dword:00000009
"VersionMinor"=dword:00000001
"WindowsInstaller"=dword:00000001
"Version"=dword:09010000
"Language"=dword:00000409
"DisplayName"="Adobe Reader 9.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"=""
"DisplayVersion"="4.00.0000.0001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Sysext\\Esscdbk\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,41,00,45,00,31,00,46,00,41,00,30,00,32,00,\
44,00,2d,00,45,00,36,00,41,00,34,00,2d,00,34,00,45,00,41,00,30,00,2d,00,38,\
00,45,00,35,00,38,00,2d,00,36,00,34,00,38,00,33,00,43,00,41,00,43,00,30,00,\
31,00,36,00,44,00,44,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000189
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,41,00,45,00,31,00,46,00,41,00,30,00,32,\
00,44,00,2d,00,45,00,36,00,41,00,34,00,2d,00,34,00,45,00,41,00,30,00,2d,00,\
38,00,45,00,35,00,38,00,2d,00,36,00,34,00,38,00,33,00,43,00,41,00,43,00,30,\
00,31,00,36,00,44,00,44,00,7d,00,00,00
"URLInfoAbout"="http://www.Kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESSCDBK"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0202"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Sysext\\OFOTOXMI\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,42,00,31,00,36,00,32,00,44,00,30,00,41,00,\
36,00,2d,00,39,00,41,00,31,00,44,00,2d,00,34,00,42,00,37,00,43,00,2d,00,39,\
00,31,00,41,00,35,00,2d,00,38,00,38,00,46,00,42,00,34,00,38,00,31,00,31,00,\
33,00,43,00,34,00,35,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=hex(2):5f,00,00,00
"Size"=""
"EstimatedSize"=dword:000000e5
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,42,00,31,00,36,00,32,00,44,00,30,00,41,\
00,36,00,2d,00,39,00,41,00,31,00,44,00,2d,00,34,00,42,00,37,00,43,00,2d,00,\
39,00,31,00,41,00,35,00,2d,00,38,00,38,00,46,00,42,00,34,00,38,00,31,00,31,\
00,33,00,43,00,34,00,35,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000409
"DisplayName"="OfotoXMI"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}]
"AuthorizedCDFPrefix"=""
"Comments"=" "
"Contact"=" "
"DisplayVersion"="4.00.0000.0001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"=" "
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\CCS\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,42,00,34,00,42,00,34,00,34,00,46,00,45,00,\
37,00,2d,00,34,00,31,00,46,00,46,00,2d,00,34,00,44,00,41,00,44,00,2d,00,38,\
00,43,00,30,00,41,00,2d,00,45,00,34,00,30,00,36,00,44,00,44,00,41,00,37,00,\
32,00,39,00,39,00,32,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=hex(2):20,00,00,00
"Size"=""
"EstimatedSize"=dword:00000731
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,42,00,34,00,42,00,34,00,34,00,46,00,45,\
00,37,00,2d,00,34,00,31,00,46,00,46,00,2d,00,34,00,44,00,41,00,44,00,2d,00,\
38,00,43,00,30,00,41,00,2d,00,45,00,34,00,30,00,36,00,44,00,44,00,41,00,37,\
00,32,00,39,00,39,00,32,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000409
"DisplayName"="CCScore"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="8.20.8730.4"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20030916"
"InstallLocation"=""
"InstallSource"="C:\\Program Files\\EarthLink Setup\\Windows\\MSXML\\"
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"SystemComponent"=dword:00000001
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000008
"VersionMinor"=dword:00000014
"WindowsInstaller"=dword:00000001
"Version"=dword:0814221a
"Language"=dword:00000000
"DisplayName"="Microsoft XML Parser"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="632.62.0002.0001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Ksu\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,42,00,39,00,39,00,37,00,43,00,32,00,41,00,\
30,00,2d,00,34,00,33,00,38,00,33,00,2d,00,34,00,31,00,42,00,46,00,2d,00,42,\
00,37,00,36,00,45,00,2d,00,39,00,42,00,38,00,42,00,37,00,45,00,43,00,46,00,\
42,00,32,00,36,00,37,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=hex(2):5f,00,00,00
"Size"=""
"EstimatedSize"=dword:00001a8b
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,42,00,39,00,39,00,37,00,43,00,32,00,41,\
00,30,00,2d,00,34,00,33,00,38,00,33,00,2d,00,34,00,31,00,42,00,46,00,2d,00,\
42,00,37,00,36,00,45,00,2d,00,39,00,42,00,38,00,42,00,37,00,45,00,43,00,46,\
00,42,00,32,00,36,00,37,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000278
"VersionMinor"=dword:0000003e
"WindowsInstaller"=dword:00000001
"Version"=dword:783e0002
"Language"=dword:00000000
"DisplayName"="KSU"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BCE72AED-3332-4863-9567-C5DCB9052CA2}]
"AuthorizedCDFPrefix"=""
"Comments"="Netflix Movie Viewer"
"Contact"="Netflix Customer Service"
"DisplayVersion"="1.2.211"
"HelpLink"=hex(2):77,00,77,00,77,00,2e,00,6e,00,65,00,74,00,66,00,6c,00,69,00,\
78,00,2e,00,63,00,6f,00,6d,00,2f,00,48,00,65,00,6c,00,70,00,00,00
"HelpTelephone"=""
"InstallDate"="20080626"
"InstallLocation"="C:\\Program Files\\Netflix\\Netflix Movie Viewer\\"
"InstallSource"="C:\\Documents and Settings\\Jeremy\\Local Settings\\Temporary Internet Files\\Content.IE5\\IL0DWP2Z\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,58,00,7b,00,42,00,43,00,45,00,37,00,32,00,41,00,45,00,\
44,00,2d,00,33,00,33,00,33,00,32,00,2d,00,34,00,38,00,36,00,33,00,2d,00,39,\
00,35,00,36,00,37,00,2d,00,43,00,35,00,44,00,43,00,42,00,39,00,30,00,35,00,\
32,00,43,00,41,00,32,00,7d,00,00,00
"NoModify"=dword:00000001
"Publisher"="Netflix"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:0000061c
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,58,00,7b,00,42,00,43,00,45,00,37,00,32,00,41,00,45,\
00,44,00,2d,00,33,00,33,00,33,00,32,00,2d,00,34,00,38,00,36,00,33,00,2d,00,\
39,00,35,00,36,00,37,00,2d,00,43,00,35,00,44,00,43,00,42,00,39,00,30,00,35,\
00,32,00,43,00,41,00,32,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000002
"WindowsInstaller"=dword:00000001
"Version"=dword:010200d3
"Language"=dword:00000409
"DisplayName"="Netflix Movie Viewer"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C03B8026-694C-4326-88A8-1387097B50E8}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="8.0.27"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090602"
"InstallLocation"="C:\\Program Files\\Verizon\\Verizon Internet Security Suite\\"
"InstallSource"="C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,43,00,30,00,33,00,42,00,38,00,30,00,32,00,\
36,00,2d,00,36,00,39,00,34,00,43,00,2d,00,34,00,33,00,32,00,36,00,2d,00,38,\
00,38,00,41,00,38,00,2d,00,31,00,33,00,38,00,37,00,30,00,39,00,37,00,42,00,\
35,00,30,00,45,00,38,00,7d,00,00,00
"Publisher"="Verizon"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00006725
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,43,00,30,00,33,00,42,00,38,00,30,00,32,\
00,36,00,2d,00,36,00,39,00,34,00,43,00,2d,00,34,00,33,00,32,00,36,00,2d,00,\
38,00,38,00,41,00,38,00,2d,00,31,00,33,00,38,00,37,00,30,00,39,00,37,00,42,\
00,35,00,30,00,45,00,38,00,7d,00,00,00
"URLInfoAbout"="http://www.Radialpoint.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000008
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0800001b
"Language"=dword:00000409
"DisplayName"="RPS RpsCore"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C04E32E0-0416-434D-AFB9-6969D703A9EF}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="4.20.9848.0"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,2e,00,63,00,6f,00,6d,00,2f,00,6b,00,62,00,2f,00,39,00,33,00,36,00,\
31,00,38,00,31,00,00,00
"HelpTelephone"=""
"InstallDate"="20070814"
"InstallLocation"=""
"InstallSource"="c:\\fcae099e552521b437a2abb85b\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,43,00,30,00,34,00,45,00,33,00,32,00,45,00,\
30,00,2d,00,30,00,34,00,31,00,36,00,2d,00,34,00,33,00,34,00,44,00,2d,00,41,\
00,46,00,42,00,39,00,2d,00,36,00,39,00,36,00,39,00,44,00,37,00,30,00,33,00,\
41,00,39,00,45,00,46,00,7d,00,00,00
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000a78
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,43,00,30,00,34,00,45,00,33,00,32,00,45,\
00,30,00,2d,00,30,00,34,00,31,00,36,00,2d,00,34,00,33,00,34,00,44,00,2d,00,\
41,00,46,00,42,00,39,00,2d,00,36,00,39,00,36,00,39,00,44,00,37,00,30,00,33,\
00,41,00,39,00,45,00,46,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000014
"WindowsInstaller"=dword:00000001
"Version"=dword:04142678
"Language"=dword:00000409
"DisplayName"="MSXML 4.0 SP2 (KB936181)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C354C9B6-A4E0-4BB0-A368-6DC6BCA0E314}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="3.03.0000.0001"
"HelpLink"=hex(2):5f,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\SysFiles\\Sfr1\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,43,00,33,00,35,00,34,00,43,00,39,00,42,00,\
36,00,2d,00,41,00,34,00,45,00,30,00,2d,00,34,00,42,00,42,00,30,00,2d,00,41,\
00,33,00,36,00,38,00,2d,00,36,00,44,00,43,00,36,00,42,00,43,00,41,00,30,00,\
45,00,33,00,31,00,34,00,7d,00,00,00
"Publisher"="Eastman Kodak Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000a79
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,43,00,33,00,35,00,34,00,43,00,39,00,42,\
00,36,00,2d,00,41,00,34,00,45,00,30,00,2d,00,34,00,42,00,42,00,30,00,2d,00,\
41,00,33,00,36,00,38,00,2d,00,36,00,44,00,43,00,36,00,42,00,43,00,41,00,30,\
00,45,00,33,00,31,00,34,00,7d,00,00,00
"URLInfoAbout"="http://www.Kodak.com"
"URLUpdateInfo"="_"
"VersionMajor"=dword:00000003
"VersionMinor"=dword:00000003
"WindowsInstaller"=dword:00000001
"Version"=dword:03030000
"Language"=dword:00000000
"DisplayName"="SFR"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}]
"DisplayIcon"="C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.1.4322\\ndpsetup.ico"
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="1.1.4322"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20071202"
"InstallLocation"=""
"InstallSource"="C:\\DELL\\6w650\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,58,00,7b,00,43,00,42,00,32,00,46,00,37,00,45,00,44,00,\
44,00,2d,00,39,00,44,00,31,00,46,00,2d,00,34,00,33,00,43,00,31,00,2d,00,39,\
00,30,00,46,00,43,00,2d,00,34,00,46,00,35,00,32,00,45,00,41,00,45,00,31,00,\
37,00,32,00,41,00,31,00,7d,00,00,00
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Microsoft"
"Readme"=hex(2):66,00,69,00,6c,00,65,00,3a,00,2f,00,2f,00,43,00,3a,00,5c,00,57,\
00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,\
73,00,6f,00,66,00,74,00,2e,00,4e,00,45,00,54,00,5c,00,46,00,72,00,61,00,6d,\
00,65,00,77,00,6f,00,72,00,6b,00,5c,00,76,00,31,00,2e,00,31,00,2e,00,34,00,\
33,00,32,00,32,00,5c,00,31,00,30,00,33,00,33,00,5c,00,52,00,65,00,70,00,61,\
00,69,00,72,00,52,00,65,00,64,00,69,00,73,00,74,00,2e,00,68,00,74,00,6d,00,\
00,00
"Size"=""
"EstimatedSize"=dword:000114c7
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,58,00,7b,00,43,00,42,00,32,00,46,00,37,00,45,00,44,\
00,44,00,2d,00,39,00,44,00,31,00,46,00,2d,00,34,00,33,00,43,00,31,00,2d,00,\
39,00,30,00,46,00,43,00,2d,00,34,00,46,00,35,00,32,00,45,00,41,00,45,00,31,\
00,37,00,32,00,41,00,31,00,7d,00,00,00
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000001
"WindowsInstaller"=dword:00000001
"Version"=dword:010110e2
"Language"=dword:00000409
"DisplayName"="Microsoft .NET Framework 1.1"
"SystemComponent"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D15E9DB5-6BEB-4534-901E-80C0A29BAB97}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0001"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\Sysext\\Essadpt\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,44,00,31,00,35,00,45,00,39,00,44,00,42,00,\
35,00,2d,00,36,00,42,00,45,00,42,00,2d,00,34,00,35,00,33,00,34,00,2d,00,39,\
00,30,00,31,00,45,00,2d,00,38,00,30,00,43,00,30,00,41,00,32,00,39,00,42,00,\
41,00,42,00,39,00,37,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000242
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,44,00,31,00,35,00,45,00,39,00,44,00,42,\
00,35,00,2d,00,36,00,42,00,45,00,42,00,2d,00,34,00,35,00,33,00,34,00,2d,00,\
39,00,30,00,31,00,45,00,2d,00,38,00,30,00,43,00,30,00,41,00,32,00,39,00,42,\
00,41,00,42,00,39,00,37,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESSAdpt"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D32470A1-B10C-4059-BA53-CF0486F68EBC}]
"DisplayIcon"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\$SETUP_10009_2a677\\Setup.exe,0"
"DisplayName"="Kodak EasyShare software"
"NoModify"=dword:00000000
"NoRemove"=dword:00000000
"NoRepair"=dword:00000000
"UninstallString"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\$SETUP_10009_2a677\\Setup.exe /APR-REMOVE"
"ModifyPath"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\$SETUP_10009_2a677\\Setup.exe /APR-MODIFY"
"URLUpdateInfo"="http://www.kodak.com/go/easyshare"
"Publisher"="Eastman Kodak Company"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D55DA406-3031-42AB-B7C4-2183C00803F3}]
"ServicePrefixName"="Radialpoint"
"ProductNameInstalled"="Freedom"
"CompanyNameInstalled"="Zero Knowledge"
"ApplicationNameInstalled"="SafeConnect"
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="8.0.27"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090602"
"InstallLocation"="C:\\Program Files\\Verizon\\Verizon Internet Security Suite\\"
"InstallSource"="C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,44,00,35,00,35,00,44,00,41,00,34,00,30,00,\
36,00,2d,00,33,00,30,00,33,00,31,00,2d,00,34,00,32,00,41,00,42,00,2d,00,42,\
00,37,00,43,00,34,00,2d,00,32,00,31,00,38,00,33,00,43,00,30,00,30,00,38,00,\
30,00,33,00,46,00,33,00,7d,00,00,00
"Publisher"="Verizon"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00003526
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,44,00,35,00,35,00,44,00,41,00,34,00,30,\
00,36,00,2d,00,33,00,30,00,33,00,31,00,2d,00,34,00,32,00,41,00,42,00,2d,00,\
42,00,37,00,43,00,34,00,2d,00,32,00,31,00,38,00,33,00,43,00,30,00,30,00,38,\
00,30,00,33,00,46,00,33,00,7d,00,00,00
"URLInfoAbout"="http://www.Radialpoint.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000008
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0800001b
"Language"=dword:00000409
"DisplayName"="RPS SafeConnect"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D64DCF1C-7A95-49A4-BAFA-C42B5CF6B8B6}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="3.0.0.0000"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,63,00,6f,\
00,6d,00,00,00
"HelpTelephone"=" "
"InstallDate"="20020930"
"InstallLocation"=""
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"SystemComponent"=dword:00000001
"URLInfoAbout"="http://www.microsoft.com"
"URLUpdateInfo"="http://www.microsoft.com"
"VersionMajor"=dword:00000003
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:03000000
"Language"=dword:00000409
"DisplayName"="Works Suite OS Pack"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D6DE02C7-1F47-11D4-9515-00105AE4B89A}]
"AuthorizedCDFPrefix"=""
"Comments"="Jasc Software Inc"
"Contact"="Customer Support Department"
"DisplayVersion"="7.05.0000"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6a,00,61,00,73,00,63,00,2e,00,63,00,6f,00,6d,00,2f,00,73,00,75,00,70,\
00,70,00,6f,00,72,00,74,00,32,00,2e,00,61,00,73,00,70,00,00,00
"HelpTelephone"="1-952-930-9171"
"InstallDate"="20030911"
"InstallLocation"=""
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,44,00,36,00,44,00,45,00,30,00,32,00,43,00,\
37,00,2d,00,31,00,46,00,34,00,37,00,2d,00,31,00,31,00,44,00,34,00,2d,00,39,\
00,35,00,31,00,35,00,2d,00,30,00,30,00,31,00,30,00,35,00,41,00,45,00,34,00,\
42,00,38,00,39,00,41,00,7d,00,00,00
"Publisher"="Jasc Software Inc"
"Readme"=hex(2):52,00,65,00,61,00,64,00,6d,00,65,00,2e,00,64,00,6f,00,63,00,00,\
00
"Size"=""
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,44,00,36,00,44,00,45,00,30,00,32,00,43,\
00,37,00,2d,00,31,00,46,00,34,00,37,00,2d,00,31,00,31,00,44,00,34,00,2d,00,\
39,00,35,00,31,00,35,00,2d,00,30,00,30,00,31,00,30,00,35,00,41,00,45,00,34,\
00,42,00,38,00,39,00,41,00,7d,00,00,00
"URLInfoAbout"="http://www.jasc.com"
"URLUpdateInfo"="http://www.jasc.com/patches.asp?"
"VersionMajor"=dword:00000007
"VersionMinor"=dword:00000005
"WindowsInstaller"=dword:00000001
"Version"=dword:07050000
"Language"=dword:00000409
"DisplayName"="Paint Shop Pro 7"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DCDC8E79-4600-4C02-9824-CD3BB8971D4E}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{DCDC8E79-4600-4C02-9824-CD3BB8971D4E}\\Setup.exe\" -l0x9 -L0x9anything"
"DisplayName"=""
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{DCDC8E79-4600-4C02-9824-CD3BB8971D4E}\\setup.ilg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E646DCF0-5A68-11D5-B229-002078017FBF}]
"DisplayIcon"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,\
00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,44,00,69,00,67,00,69,00,74,00,\
61,00,6c,00,20,00,4c,00,69,00,6e,00,65,00,20,00,44,00,65,00,74,00,65,00,63,\
00,74,00,5c,00,44,00,4c,00,47,00,2e,00,65,00,78,00,65,00,00,00
"Publisher"="BVRP Software, Inc"
"DisplayVersion"="1.06.2"
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000006
"InstallLocation"="C:\\Program Files\\Digital Line Detect"
"Language"=dword:00000009
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{E646DCF0-5A68-11D5-B229-002078017FBF}\\setup.exe\" -l0x9 ControlPanelAnyText"
"DisplayName"="Digital Line Detect"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{E646DCF0-5A68-11D5-B229-002078017FBF}\\setup.ilg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F2D0C1B1-80FF-46F9-BA61-33B01A07FAFC}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0003"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\ESS\\HLPCCTR\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,46,00,32,00,44,00,30,00,43,00,31,00,42,00,\
31,00,2d,00,38,00,30,00,46,00,46,00,2d,00,34,00,36,00,46,00,39,00,2d,00,42,\
00,41,00,36,00,31,00,2d,00,33,00,33,00,42,00,30,00,31,00,41,00,30,00,37,00,\
46,00,41,00,46,00,43,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=hex(2):5f,00,00,00
"Size"=""
"EstimatedSize"=dword:00000051
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,46,00,32,00,44,00,30,00,43,00,31,00,42,\
00,31,00,2d,00,38,00,30,00,46,00,46,00,2d,00,34,00,36,00,46,00,39,00,2d,00,\
42,00,41,00,36,00,31,00,2d,00,33,00,33,00,42,00,30,00,31,00,41,00,30,00,37,\
00,46,00,41,00,46,00,43,00,7d,00,00,00
"URLInfoAbout"="http://www.Kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="HLPCCTR"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F573B950-CC14-4E55-8F29-F054485E11AA}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="8.0.27"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090602"
"InstallLocation"="C:\\Program Files\\Verizon\\Verizon Internet Security Suite\\"
"InstallSource"="C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,46,00,35,00,37,00,33,00,42,00,39,00,35,00,\
30,00,2d,00,43,00,43,00,31,00,34,00,2d,00,34,00,45,00,35,00,35,00,2d,00,38,\
00,46,00,32,00,39,00,2d,00,46,00,30,00,35,00,34,00,34,00,38,00,35,00,45,00,\
31,00,31,00,41,00,41,00,7d,00,00,00
"Publisher"="Verizon"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000a9c
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,46,00,35,00,37,00,33,00,42,00,39,00,35,\
00,30,00,2d,00,43,00,43,00,31,00,34,00,2d,00,34,00,45,00,35,00,35,00,2d,00,\
38,00,46,00,32,00,39,00,2d,00,46,00,30,00,35,00,34,00,34,00,38,00,35,00,45,\
00,31,00,31,00,41,00,41,00,7d,00,00,00
"URLInfoAbout"="http://www.Radialpoint.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000008
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0800001b
"Language"=dword:00000409
"DisplayName"="RPS Diagnostic Utility"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}]
"AuthorizedCDFPrefix"=""
"Comments"="Your Comments"
"Contact"="Customer Support Department"
"DisplayVersion"="3.00.0007.0000"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,79,00,6f,00,75,00,72,00,63,00,6f,00,6d,00,70,00,61,00,6e,00,79,00,2e,\
00,63,00,6f,00,6d,00,2f,00,68,00,65,00,6c,00,70,00,00,00
"HelpTelephone"="1-555-555-4505"
"InstallDate"="20040408"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\OTTBP\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,46,00,37,00,31,00,37,00,36,00,30,00,43,00,\
44,00,2d,00,30,00,46,00,38,00,42,00,2d,00,34,00,44,00,43,00,43,00,2d,00,42,\
00,37,00,42,00,37,00,2d,00,36,00,42,00,32,00,32,00,33,00,43,00,43,00,33,00,\
38,00,34,00,33,00,43,00,7d,00,00,00
"Publisher"="Eastman Kodak Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:000003be
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,46,00,37,00,31,00,37,00,36,00,30,00,43,\
00,44,00,2d,00,30,00,46,00,38,00,42,00,2d,00,34,00,44,00,43,00,43,00,2d,00,\
42,00,37,00,42,00,37,00,2d,00,36,00,42,00,32,00,32,00,33,00,43,00,43,00,33,\
00,38,00,34,00,33,00,43,00,7d,00,00,00
"URLInfoAbout"="http://www.yourcompany.com"
"URLUpdateInfo"="http://www.yourcompany.com/updateinfo"
"VersionMajor"=dword:00000003
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:03000007
"Language"=dword:00000000
"DisplayName"="OTtBP"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F90DA605-4E92-11D4-A319-00104BCAB4AB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F91E1833-2D7C-4725-B98A-C779FEC41946}]
"AuthorizedCDFPrefix"=""
"Comments"="None"
"Contact"="Customer Support Department"
"DisplayVersion"="2003.2.92.0"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,65,00,61,00,72,00,74,00,68,00,6c,00,69,00,6e,\
00,6b,00,2e,00,6e,00,65,00,74,00,00,00
"HelpTelephone"="1-800-EARTHLINK"
"InstallDate"="20030916"
"InstallLocation"=""
"InstallSource"="C:\\Program Files\\EarthLink Setup\\Windows\\access\\"
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="EarthLink, Inc."
"Readme"=""
"Size"=""
"EstimatedSize"=dword:000003ad
"SystemComponent"=dword:00000001
"URLInfoAbout"="http://www.earthlink.net"
"URLUpdateInfo"="http://www.earthlink.net/home/software"
"VersionMajor"=dword:000007d3
"VersionMinor"=dword:00000002
"WindowsInstaller"=dword:00000001
"Version"=dword:d302005c
"Language"=dword:00000409
"DisplayName"="EarthLink MDAC"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}]
"AuthorizedCDFPrefix"=""
"Comments"="Go to http://support.dell.com."
"Contact"="Dell Support"
"DisplayVersion"="1.00.00"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,73,00,75,00,70,00,\
70,00,6f,00,72,00,74,00,2e,00,64,00,65,00,6c,00,6c,00,2e,00,63,00,6f,00,6d,\
00,00,00
"HelpTelephone"="0"
"InstallDate"="20030911"
"InstallLocation"=""
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Dell"
"Readme"=""
"Size"=""
"SystemComponent"=dword:00000001
"URLInfoAbout"="http://www.dell.com"
"URLUpdateInfo"="http://support.dell.com"
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:01000000
"Language"=dword:00000409
"DisplayName"="Banctec Service Agreement"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FC93A5F4-45D4-4C19-AF79-808794229BE9}]
"UninstallString"="RunDll32 C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\engine\\6\\INTEL3~1\\Ctor.dll,LaunchSetup \"C:\\Program Files\\InstallShield Installation Information\\{FC93A5F4-45D4-4C19-AF79-808794229BE9}\\SETUP.EXE\" -l0x9 "
"DisplayName"="Family Tree Maker"
"LogFile"="C:\\Program Files\\InstallShield Installation Information\\{FC93A5F4-45D4-4C19-AF79-808794229BE9}\\setup.ilg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FEDE2483-87B7-44C1-A5BB-D75AEB8B6340}]
"AuthorizedCDFPrefix"=""
"Comments"="_"
"Contact"="_"
"DisplayVersion"="4.00.0000.0000"
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6b,00,6f,00,64,00,61,00,6b,00,2e,00,63,00,6f,00,6d,00,2f,00,67,00,6f,\
00,2f,00,65,00,61,00,73,00,79,00,73,00,68,00,61,00,72,00,65,00,73,00,75,00,\
70,00,70,00,6f,00,72,00,74,00,00,00
"HelpTelephone"="_"
"InstallDate"="20041019"
"InstallLocation"=""
"InstallSource"="C:\\Documents and Settings\\All Users\\Application Data\\Kodak\\EasyShareSetup\\ESS\\ESSEMAIL\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,46,00,45,00,44,00,45,00,32,00,34,00,38,00,\
33,00,2d,00,38,00,37,00,42,00,37,00,2d,00,34,00,34,00,43,00,31,00,2d,00,41,\
00,35,00,42,00,42,00,2d,00,44,00,37,00,35,00,41,00,45,00,42,00,38,00,42,00,\
36,00,33,00,34,00,30,00,7d,00,00,00
"Publisher"="EASTMAN KODAK Company"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00000095
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,46,00,45,00,44,00,45,00,32,00,34,00,38,\
00,33,00,2d,00,38,00,37,00,42,00,37,00,2d,00,34,00,34,00,43,00,31,00,2d,00,\
41,00,35,00,42,00,42,00,2d,00,44,00,37,00,35,00,41,00,45,00,42,00,38,00,42,\
00,36,00,33,00,34,00,30,00,7d,00,00,00
"URLInfoAbout"="http://www.kodak.com"
"URLUpdateInfo"="http://www.kodak.com/go/easysharesw"
"VersionMajor"=dword:00000004
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:04000000
"Language"=dword:00000000
"DisplayName"="ESSEMAIL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FFE078E6-0288-4405-B26D-05D38F20295E}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="8.0.27"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20090602"
"InstallLocation"="C:\\Program Files\\Verizon\\Verizon Internet Security Suite\\"
"InstallSource"="C:\\Program Files\\InstallShield Installation Information\\{4CB90CB9-DD58-4CCC-A053-08FA70A42941}\\"
"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\
00,65,00,20,00,2f,00,49,00,7b,00,46,00,46,00,45,00,30,00,37,00,38,00,45,00,\
36,00,2d,00,30,00,32,00,38,00,38,00,2d,00,34,00,34,00,30,00,35,00,2d,00,42,\
00,32,00,36,00,44,00,2d,00,30,00,35,00,44,00,33,00,38,00,46,00,32,00,30,00,\
32,00,39,00,35,00,45,00,7d,00,00,00
"Publisher"="Verizon"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:000000ec
"SystemComponent"=dword:00000001
"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\
78,00,65,00,20,00,2f,00,49,00,7b,00,46,00,46,00,45,00,30,00,37,00,38,00,45,\
00,36,00,2d,00,30,00,32,00,38,00,38,00,2d,00,34,00,34,00,30,00,35,00,2d,00,\
42,00,32,00,36,00,44,00,2d,00,30,00,35,00,44,00,33,00,38,00,46,00,32,00,30,\
00,32,00,39,00,35,00,45,00,7d,00,00,00
"URLInfoAbout"="http://www.Radialpoint.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000008
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0800001b
"Language"=dword:00000409
"DisplayName"="RPS Burn"

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PowerTeacher Gradebook]
"DisplayName"="PowerTeacher Gradebook"
"UninstallString"="C:\\WINDOWS\\system32\\javaws.exe -uninstall \"http://powerschool.dragon.k12.pa.us:7880/powerschool-gradebook/lib/powerschool-gradebook.jar\""
"DisplayIcon"="C:\\WINDOWS\\system32\\javaws.exe"

km2357
2009-08-20, 21:13
I'd like for you to download the following reg file (link below and be sure to save it to your Desktop) and merge it into your Registry. It will fix your Add/Remove Programs so that if in the future you have to run ComboFix again (hopefully you'll never have to), it (ComboFix) won't end up removing your Change/Remove buttons. Before running/merging the regfix, be sure to run ERUNT first to backup your Registry.

Thanks to sUBs for his help and for the regfix.

Note: This regfix is for jlauv's computer only! Do not run it on your computer.

Let me know when you've downloaded and ran the regfix, so I can remove the link.


LINK REMOVED


Once the file is downloaded, double-click add_remove.reg on your Desktop. When it asks if you want to merge the info to the registry, hit YES/OK. Reboot the computer.


Let me know if you have any problems.

jlauv
2009-08-21, 03:47
I downloaded and installed the add_remove.reg on my computer.

Everything seems fine with the reboot.

The computer seems to be running well, and the web browser works great.

Is there anything else that I should do? (Like should I delete the items in the Combofix quarantine?)

km2357
2009-08-21, 07:06
Downloading and merging that reg file was the last thing I wanted you to do.

If there are no more problems, then you are good to go. :bigthumb:

You can delete RSIT.exe, the C:\RSIT folder, and the two RSIT Logs.

You can delete GMER.zip, GMER.exe, and the GMER Log.

You can delete lookreg.bat, lookreg.txt, and the add_remove.reg file as well.

To remove ComboFix, do the following:

Go to Start > Run - type in ComboFix /u & click OK

Empty your Recycle Bin.


Please take the time to read my All Clean Post.

Please follow these simple steps in order to keep your computer clean and secure:

This is a good time to clear your existing system restore points and establish a new clean restore point

Go to Start > All Programs > Accessories > System Tools > System Restore
Select Create a restore point, and Ok it.
Next, go to Start > Run and type in cleanmgr
Make sure the C:\ drive is selected and click OK. If your computer's Hard Drive is not located on C:, change it to the correct drive letter then click OK.
Select the More options tab
Choose the option to clean up system restore and OK it.
This will remove all restore points except the new one you just created..

Clearing your restore points is not something you should do on a regular basis. Normally, this process only needs to be done after clearing out an infestation of malware.


Make your Internet Explorer more secure This can be done by following these simple instructions: From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub frames across different domains to Prompt When all these settings have been made, click on the OK button.
If it asks you if you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Set correct settings for files that should be hidden in Windows XP
Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
If unchecked please checkHide protected operating system files (Recommended)
If necessary check "Display content of system folders"
If necessary Uncheck Hide file extensions for known file types.
Click OK

Use An Antivirus Software and Keep It Updated - It is very important that your computer has an antivirus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperative that you update your antivirus software at least once a day. If you do not update your antivirus software, then it will not be able to catch any of the new variants that may come out.
Visit Microsoft's Update Site Frequently It is important that you visit Microsoft Updates (http://update.microsoft.com/) regularly. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Install SpywareBlaster SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
Computer Safety on line Anti Malware (http://forum.malwareremoval.com/viewtopic.php?p=54#54)
Use the hosts file: Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate web pages. We can customize a hosts file so that it blocks certain web pages. However, it can slow down certain computers. This is why using a hosts file is optional. Download mvps hosts file (http://www.mvps.org/winhelp2002/hosts.htm) Make sure you read the instructions on how to install the hosts file. There is a good tutorial HERE (http://www.bleepingcomputer.com/forums/tutorial51.html) If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button on the task bar at the bottom of your screen Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then doubleclick it. On the dropdown box, change the setting from automatic to manual. Click ok..
Use an alternative instant messenger program.Trillian (http://www.trillian.cc/) and Miranda IM (http://www.miranda-im.com/) These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
Please read Tony Klein's excellent article: How I got Infected in the First Place (http://forums.subratam.org/index.php?showtopic=5931)
Please read Understanding Spyware, Browser Hijackers, and Dialers (http://www.bleepingcomputer.com/forums/tutorial41.html)
Please read Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/tutorial82.html)
If you are using Internet Explorer, please consider using an alternate browser: Mozilla's Firefox (http://www.mozilla.org/products/firefox) or
Opera (http://www.opera.com/download/).
If you decide to use either FireFox or Opera, it is very important that you keep them up to date and check frequently for updates of the browser of your choice.
Update all these programs regularly Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
If your computer was infected by a website, a program, IM, MSN, or p2p, check this site because it is Time To Fight Back (http://spyware-free.us/2006/01/time-to-fight-back.html). Follow these steps and your potential for being infected again will reduce dramatically.

Here's a good website to read about Malware prevention:

http://users.telenet.be/bluepatchy/miekiemoes/prevention.html

Good luck!

Please reply one last time so that I know you have read my post and this thread can be closed.

jlauv
2009-08-22, 07:36
I followed the directions in your last post.

Thanks for all of your help!!!

I greatly appreciate all the time that you spent in fixing my machine!:thanks:

km2357
2009-08-22, 19:18
You're welcome. I'm glad I was able to help you out. :)

Good luck and safe surfing.