0

Im new to this site but I found out that alot of people recieved help here. I have a Windows Vista laptop that cant access the internet right now due to this Virus so I am using another system to do research. Can someone help me please in removing this? I currently have Trend Micro but it is finding no Viruses on my system. I know that it is still there due to my system not working properly. Please lend some assistance?
~Hellius

2
Contributors
5
Replies
6
Views
8 Years
Discussion Span
Last Post by Godsp3ed
0

Download Malwarebytes' Anti-Malware to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Else Download the Updates Manually Here
* Once the program has loaded, select Perform full scan, then click Scan.
* Make sure all applications including browsers are closed during the scan and you are preferably not in safe mode
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad, Save the Logfile.
* Immediately Reboot he computer

*Now download TrendMicro HijackThis
*Install it, Run it and click on 'Run a scan and save a logfile'
*After the scan you will get a notepad window with the scan results, Save it.
* Post both the MBAM and HJT logs back here.

0

This is the log from RMin:

----------------------------------------------------------------------------------------------------
Version 8.0.0.902
----------------------------------------------------------------------------------------------------
Engine: 3.0.0.850
----------------------------------------------------------------------------------------------------
Start of Scan
6/19/2009 3:31:27 PM

Your System Information :
CPU: Intel Pentium
IE: 7.0.6001.18000
MEMORY FREE: 2008932
MEMORY TOTAL: 2097152
VIRTUAL FREE: 1972112
VIRTUAL TOTAL: 2097024
Windows Vista 6.0 (6001) Service Pack 1.0
----------------------------------------------------------------------------------------------------
Running processes: Process ID
----------------------------------------------------------------------------------------------------
[System Process] 0
System 4
smss.exe 452
csrss.exe 576
wininit.exe 620
csrss.exe 628
services.exe 668
lsass.exe 680
lsm.exe 688
winlogon.exe 768
svchost.exe 900
svchost.exe 984
svchost.exe 1040
svchost.exe 1088
svchost.exe 1240
svchost.exe 1268
svchost.exe 1300
audiodg.exe 1356
SLsvc.exe 1384
wlanext.exe 1640
spoolsv.exe 1740
svchost.exe 1764
TMBMSRV.exe 612
AppleMobileDeviceService.exe 684
BlueSoleilCS.exe 1008
mDNSResponder.exe 1148
LSSrvc.exe 1600
McciCMService.exe 340
svchost.exe 2184
BLService.exe 2216
RichVideo.exe 2244
SeaPort.exe 2264
SfCtlCom.exe 2328
svchost.exe 2436
TmProxy.exe 2492
taskeng.exe 2708
svchost.exe 2780
SearchIndexer.exe 2840
XAudio.exe 2892
TmPfw.exe 2972
taskeng.exe 3212
BsHelpCS.exe 3392
taskeng.exe 3428
dwm.exe 3652
explorer.exe 3696
igfxtray.exe 2316
hkcmd.exe 2192
igfxpers.exe 740
QPService.exe 1232
igfxsrvc.exe 1852
QLBCTRL.exe 3756
jusched.exe 3896
hpwuSchd2.exe 1652
HPWAMain.exe 3424
McciTrayApp.exe 3964
BtTray.exe 3936
wmdSync.exe 3056
UfSeAgnt.exe 3556
LightScribeControlPanel.exe 4008
msnmsgr.exe 3632
ehtray.exe 1924
wmpnscfg.exe 4048
TMAS_OEMon.exe 3088
ONENOTEM.EXE 3104
wmpnetwk.exe 3872
hpqwmiex.exe 2204
WmiPrvSE.exe 4264
svchost.exe 4580
WiFiMsg.exe 4912
Com4QLBEx.exe 5208
HpqToaster.exe 5244
HPHC_Service.exe 6124
taskeng.exe 2292
WUDFHost.exe 2432
WmiPrvSE.exe 4000
RegMech.exe 5644
----------------------------------------------------------------------------------------------------
Sections Scanned:
----------------------------------------------------------------------------------------------------
SL - 1
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Installer.exe
Value : (default) = C:\Program Files\Atheros\Installer.exe
Parsed : c:\program files\atheros\installer.exe

SL - 2
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\bigint.js
Value : Path = "C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\Escalator\bigint.js"
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\escalator\bigint.js

SL - 3
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckAuth.html
Value : Path = "C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\CheckAuth.html"
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\checkauth.html

SL - 4
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckAuth.html.1
Value : Path = "C:\Program Files\ATT-SST\OCB\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\ConnectivityFlow\Flow\CheckAuth.html"
Parsed : c:\program files\att-sst\ocb\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\connectivityflow\flow\checkauth.html

SL - 5
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckAuth_Logic.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\CheckAuth_Logic.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\checkauth_logic.html

SL - 6
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckCable.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\CheckCable.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\checkcable.html

SL - 7
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckCable_StepOne.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\CheckCable_StepOne.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\checkcable_stepone.html

SL - 8
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckCable_StepTwo.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\CheckCable_StepTwo.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\checkcable_steptwo.html

SL - 9
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckLights.html
Value : Path = "C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\CheckLights.html"
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\checklights.html

SL - 10
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckLights.html.1
Value : Path = "C:\Program Files\ATT-SST\OCB\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\ConnectivityFlow\Flow\CheckLights.html"
Parsed : c:\program files\att-sst\ocb\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\connectivityflow\flow\checklights.html

SL - 11
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckLights_Logic.html
Value : Path = "C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\CheckLights_Logic.html"
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\checklights_logic.html

SL - 12
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckLights_Logic.html.1
Value : Path = "C:\Program Files\ATT-SST\OCB\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\ConnectivityFlow\Flow\CheckLights_Logic.html"
Parsed : c:\program files\att-sst\ocb\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\connectivityflow\flow\checklights_logic.html

SL - 13
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckModem.html
Value : Path = "C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\CheckModem.html"
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\checkmodem.html

SL - 14
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckModem.html.1
Value : Path = "C:\Program Files\ATT-SST\OCB\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\ConnectivityFlow\Flow\CheckModem.html"
Parsed : c:\program files\att-sst\ocb\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\connectivityflow\flow\checkmodem.html

SL - 15
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckModem_Logic.html
Value : Path = "C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\CheckModem_Logic.html"
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\checkmodem_logic.html

SL - 16
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CheckModem_Logic.html.1
Value : Path = "C:\Program Files\ATT-SST\OCB\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\ConnectivityFlow\Flow\CheckModem_Logic.html"
Parsed : c:\program files\att-sst\ocb\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\connectivityflow\flow\checkmodem_logic.html

SL - 17
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\code_sequential.js
Value : Path = "C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\Escalator\code_sequential.js"
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\escalator\code_sequential.js

SL - 18
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\ConfirmTest.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\ConfirmTest.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\confirmtest.html

SL - 19
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\ConfirmTest_Logic.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\ConfirmTest_Logic.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\confirmtest_logic.html

SL - 20
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\ConnTest.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\ConnTest.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\conntest.html

SL - 21
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\ConnTest_Fail.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\ConnTest_Fail.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\conntest_fail.html

SL - 22
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\ConnTest_Logic.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\ConnTest_Logic.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\conntest_logic.html

SL - 23
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\ConnTest_Pass.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\ConnTest_Pass.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\conntest_pass.html

SL - 24
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CreateProfiles.html
Value : Path = "C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\CreateProfiles.html"
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\createprofiles.html

SL - 25
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\CreateProfiles.html.1
Value : Path = "C:\Program Files\ATT-SST\OCB\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\ConnectivityFlow\Flow\CreateProfiles.html"
Parsed : c:\program files\att-sst\ocb\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\connectivityflow\flow\createprofiles.html

SL - 26
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\Encoder.xsd
Value : Path = "C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\Escalator\Encoder.xsd"
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\escalator\encoder.xsd

SL - 27
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\Encoder.xsd.1
Value : Path = "C:\Program Files\ATT-SST\OCB\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\Escalator\Encoder.xsd"
Parsed : c:\program files\att-sst\ocb\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\escalator\encoder.xsd

SL - 28
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\escalator.htm
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\Escalator\escalator.htm
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\escalator\escalator.htm

SL - 29
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\footer.htm
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\Escalator\footer.htm
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\escalator\footer.htm

SL - 30
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\index.html
Value : Path = "C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\help\en\index.html"
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\help\en\index.html

SL - 31
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\index.html.1
Value : Path = "C:\Program Files\ATT-SST\OCB\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\help\en\index.html"
Parsed : c:\program files\att-sst\ocb\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\help\en\index.html

SL - 32
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\IPReleaseRenew.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\IPReleaseRenew.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\ipreleaserenew.html

SL - 33
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\IPReleaseRenew_Logic.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\IPReleaseRenew_Logic.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\ipreleaserenew_logic.html

SL - 34
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\NetworkCheck.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\NetworkCheck.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\networkcheck.html

SL - 35
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\NetworkCheck_Logic.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\NetworkCheck_Logic.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\networkcheck_logic.html

SL - 36
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\NetworkCheck_SelectNIC.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\NetworkCheck_SelectNIC.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\networkcheck_selectnic.html

SL - 37
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\NetworkRestore.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\NetworkRestore.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\networkrestore.html

SL - 38
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\NetworkRestore_Failed.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\NetworkRestore_Failed.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\networkrestore_failed.html

SL - 39
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\NetworkRestore_Logic.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\NetworkRestore_Logic.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\networkrestore_logic.html

SL - 40
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\Null_Logic.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\Null_Logic.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\null_logic.html

SL - 41
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\PerformReboot.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\PerformReboot.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\performreboot.html

SL - 42
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\PerformReboot_Progress.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\PerformReboot_Progress.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\performreboot_progress.html

SL - 43
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\promptForElevation.htm
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\Escalator\promptForElevation.htm
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\escalator\promptforelevation.htm

SL - 44
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\PromptForElevation.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\PromptForElevation.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\promptforelevation.html

SL - 45
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\ProxyCheck.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\ProxyCheck.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\proxycheck.html

SL - 46
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\ProxyCheck_Logic.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\ProxyCheck_Logic.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\proxycheck_logic.html

SL - 47
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\ProxyCheck_Restore.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\ProxyCheck_Restore.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\proxycheck_restore.html

SL - 48
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\ProxyCheck_RestoreFailed.html
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\ConnectivityFlow\Flow\ProxyCheck_RestoreFailed.html
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\connectivityflow\flow\proxycheck_restorefailed.html

SL - 49
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\ServiceConfig.xml
Value : Path = "C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\Escalator\ServiceConfig.xml"
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\escalator\serviceconfig.xml

SL - 50
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\ServiceConfig.xml.1
Value : Path = "C:\Program Files\ATT-SST\OCB\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\Escalator\ServiceConfig.xml"
Parsed : c:\program files\att-sst\ocb\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\escalator\serviceconfig.xml

SL - 51
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\Start.htm
Value : Path = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\Escalator\Start.htm
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\escalator\start.htm

SL - 52
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\toc.html
Value : Path = "C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\help\en\toc.html"
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab\help\en\toc.html

SL - 53
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\toc.html.1
Value : Path = "C:\Program Files\ATT-SST\OCB\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\help\en\toc.html"
Parsed : c:\program files\att-sst\ocb\41500bd3-91c3-4bfd-a1a6-4cd7eaa78267\help\en\toc.html

SL - 54
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InstallHelper.exe\Uninstall\ATT-SST\Content Files
Value : Entry7 = C:\Program Files\ATT-SST\OCB\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab
Parsed : c:\program files\att-sst\ocb\3bbff8dd-a96d-4cca-b3d8-4ba77ddeb3ab

SL - 55
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mdminstallersystem-heroes_screensaver.scr
Value : (default) = C:\Program Files\Genome Id V1.2\heroes_screensaver.scr
Parsed : c:\program files\genome id v1.2\heroes_screensaver.scr

RI - 56
Location: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Value : Common Documents = %PUBLIC%\Documents
Parsed : c:\users\public\documents

RI - 57
Location: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Value : {3D644C9B-1FB8-4f30-9B45-F670235F79C0} = %PUBLIC%\Downloads
Parsed : c:\users\public\downloads

SP - 58
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Windows\Microsoft.NET\Framework\v1.0.3705\vsavb7rt.dll = 00001000
Parsed : c:\windows\microsoft.net\framework\v1.0.3705\vsavb7rt.dll

SP - 59
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Windows\Microsoft.NET\Framework\v1.0.3705\system.enterpriseservices.dll = 00001000
Parsed : c:\windows\microsoft.net\framework\v1.0.3705\system.enterpriseservices.dll

SP - 60
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorrc.dll = 00001000
Parsed : c:\windows\microsoft.net\framework\v1.0.3705\mscorrc.dll

SP - 61
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscordbi.dll = 00001000
Parsed : c:\windows\microsoft.net\framework\v1.0.3705\mscordbi.dll

SP - 62
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorsec.dll = 00001000
Parsed : c:\windows\microsoft.net\framework\v1.0.3705\mscorsec.dll

SP - 63
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Windows\Microsoft.NET\Framework\v1.0.3705\system.configuration.install.dll = 00001000
Parsed : c:\windows\microsoft.net\framework\v1.0.3705\system.configuration.install.dll

SP - 64
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Windows\Microsoft.NET\Framework\v1.0.3705\microsoft.vsa.vb.codedomprocessor.dll = 00001000
Parsed : c:\windows\microsoft.net\framework\v1.0.3705\microsoft.vsa.vb.codedomprocessor.dll

SP - 65
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Windows\Microsoft.NET\Framework\v1.0.3705\wminet_utils.dll = 00001000
Parsed : c:\windows\microsoft.net\framework\v1.0.3705\wminet_utils.dll

SP - 66
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Windows\Microsoft.NET\Framework\v1.0.3705\microsoft.jscript.dll = 00001000
Parsed : c:\windows\microsoft.net\framework\v1.0.3705\microsoft.jscript.dll

SP - 67
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Windows\Microsoft.NET\Framework\v1.0.3705\diasymreader.dll = 00001000
Parsed : c:\windows\microsoft.net\framework\v1.0.3705\diasymreader.dll

SP - 68
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Windows\Microsoft.NET\Framework\v1.0.3705\iehost.dll = 00001000
Parsed : c:\windows\microsoft.net\framework\v1.0.3705\iehost.dll

SP - 69
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Windows\Microsoft.NET\Framework\v1.0.3705\system.data.dll = 00001000
Parsed : c:\windows\microsoft.net\framework\v1.0.3705\system.data.dll

SP - 70
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\Norton Internet Security\Engine\16.0.0.125\SymAdLog.dll = 00000001
Parsed : c:\program files\norton internet security\engine\16.0.0.125\symadlog.dll

SP - 71
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\Norton Internet Security\Engine\16.0.0.125\SymAddIn.xml = 00000001
Parsed : c:\program files\norton internet security\engine\16.0.0.125\symaddin.xml

SP - 72
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\Norton Internet Security\Engine\16.0.0.125\SymAddIn.dat = 00000001
Parsed : c:\program files\norton internet security\engine\16.0.0.125\symaddin.dat

SP - 73
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\Norton Internet Security\Engine\16.0.0.125\SymMcCmd.dll = 00000001
Parsed : c:\program files\norton internet security\engine\16.0.0.125\symmccmd.dll

SP - 74
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\Norton Internet Security\Engine\16.0.0.125\MceEULA.dll = 00000001
Parsed : c:\program files\norton internet security\engine\16.0.0.125\mceeula.dll

SP - 75
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\Hewlett-Packard\Digital Imaging\hpis\temp\Install.wse.exe = 00000001
Parsed : c:\program files\hewlett-packard\digital imaging\hpis\temp\install.wse.exe

SP - 76
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\Hewlett-Packard\Digital Imaging\hpis\temp\config.ini = 00000001
Parsed : c:\program files\hewlett-packard\digital imaging\hpis\temp\config.ini

SP - 77
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\Hewlett-Packard\Digital Imaging\hpis\temp\templates.zip = 00000001
Parsed : c:\program files\hewlett-packard\digital imaging\hpis\temp\templates.zip

SP - 78
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.exe = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.exe

SP - 79
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\iPodService.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\ipodservice.dll

SP - 80
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\da.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\da.lproj\ipodservicelocalized.dll

SP - 81
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\de.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\de.lproj\ipodservicelocalized.dll

SP - 82
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\en.lproj\ipodservicelocalized.dll

SP - 83
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\es.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\es.lproj\ipodservicelocalized.dll

SP - 84
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\fi.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\fi.lproj\ipodservicelocalized.dll

SP - 85
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\fr.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\fr.lproj\ipodservicelocalized.dll

SP - 86
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\it.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\it.lproj\ipodservicelocalized.dll

SP - 87
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\ja.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\ja.lproj\ipodservicelocalized.dll

SP - 88
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\ko.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\ko.lproj\ipodservicelocalized.dll

SP - 89
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\nb.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\nb.lproj\ipodservicelocalized.dll

SP - 90
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\nl.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\nl.lproj\ipodservicelocalized.dll

SP - 91
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\ru.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\ru.lproj\ipodservicelocalized.dll

SP - 92
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\sv.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\sv.lproj\ipodservicelocalized.dll

SP - 93
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\zh_cn.lproj\ipodservicelocalized.dll

SP - 94
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\iPod\bin\iPodService.Resources\zh_TW.lproj\iPodServiceLocalized.dll = 80000000
Parsed : c:\program files\ipod\bin\ipodservice.resources\zh_tw.lproj\ipodservicelocalized.dll

SUP - 95
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Value : HPAdvisor = C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
Parsed : c:\program files\hewlett-packard\hp advisor\hpadvisor.exe

SUP - 96
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Value : Uniblue RegistryBooster 2009 = c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
Parsed : c:\program files\uniblue\registrybooster\startregistrybooster.exe

ARP - 97
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Genome Id V1.2
Value : DisplayIcon = C:\Program Files\Genome Id V1.2\heroes_screensaver.scr
Parsed : c:\program files\genome id v1.2\heroes_screensaver.scr

ARP - 98
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HDMI
Value : InstallLocation = C:\Program Files\Intel\Intel Quick Resume Technology
Parsed : c:\program files\intel\intel quick resume technology

ARP - 99
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00203668-8170-44A0-BE44-B632FA4D780F}
Value : InstallSource = C:\Users\Administrator\AppData\Local\NOS\Adobe AIR Installer\
Parsed : c:\users\administrator\appdata\local\nos\adobe air installer

ARP - 100
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160070}
Value : InstallSource = C:\Users\Administrator\AppData\LocalLow\Sun\Java\jre1.6.0_07\
Parsed : c:\users\administrator\appdata\locallow\sun\java\jre1.6.0_07

ARP - 101
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{352310C3-E46B-42D3-8F32-54721FDD72D9}
Value : InstallSource = C:\hp\tmp\src\bits\Commonbits\
Parsed : c:\hp\tmp\src\bits\commonbits

ARP - 102
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
Value : InstallSource = C:\Windows\SoftwareDistribution\Download\d261ac122901a09fbb3161480ae64e69\img\
Parsed : c:\windows\softwaredistribution\download\d261ac122901a09fbb3161480ae64e69\img

ARP - 103
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{57A5AEC1-97FC-474D-92C4-908FCC2253D4}
Value : InstallLocation = C:\Program Files\Hewlett-Packard\HP Customer Experience Enhancements
Parsed : c:\program files\hewlett-packard\hp customer experience enhancements

ARP - 104
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{57A5AEC1-97FC-474D-92C4-908FCC2253D4}
Value : InstallSource = c:\HP\tmp\src\
Parsed : c:\hp\tmp\src

ARP - 105
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6423EF83-6E1D-4D22-A36F-689CD19FD4D2}
Value : InstallSource = C:\hp\tmp\src\bits\Commonbits\
Parsed : c:\hp\tmp\src\bits\commonbits

ARP - 106
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}
Value : InstallLocation = C:\Program Files\Norton Internet Security\Engine\16.0.0.125\
Parsed : c:\program files\norton internet security\engine\16.0.0.125

ARP - 107
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}
Value : InstallSource = C:\Program Files\Norton Internet Security\Branding\
Parsed : c:\program files\norton internet security\branding

ARP - 108
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{846DDADA-0239-4B67-A6B1-33658863793B}
Value : InstallSource = c:\HP\tmp\src\
Parsed : c:\hp\tmp\src

ARP - 109
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Value : InstallSource = c:\7e04c93646fac70c59738d926c7982\
Parsed : c:\7e04c93646fac70c59738d926c7982

ARP - 110
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Value : InstallSource = c:\560c8561adda528d6b689e72f83437\
Parsed : c:\560c8561adda528d6b689e72f83437

ARP - 111
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{96384578-C6A2-4EC6-92CD-B62A60713040}
Value : InstallSource = c:\hp\tmp\src\bits\
Parsed : c:\hp\tmp\src\bits

ARP - 112
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Value : InstallSource = c:\9212202ef9935b9c8239c5\
Parsed : c:\9212202ef9935b9c8239c5

ARP - 113
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DC24971E-1946-445D-8A82-CE685433FA7D}
Value : InstallLocation = C:\Program Files\Realtek Semiconductor Corp.\Realtek USB 2.0 Card Reader
Parsed : c:\program files\realtek semiconductor corp.\realtek usb 2.0 card reader

ARP - 114
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Users\Administrator\AppData\Roaming\Microsoft\Installer\{B6D0B141-B2BE-4DD0-B08F-B9186F3E36B3}\ =
Parsed : c:\users\administrator\appdata\roaming\microsoft\installer\{b6d0b141-b2be-4dd0-b08f-b9186f3e36b3}

ARP - 115
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Users\Administrator\AppData\Roaming\Microsoft\Installer\ =
Parsed : c:\users\administrator\appdata\roaming\microsoft\installer

ARP - 116
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Users\Administrator\AppData\Roaming\Macromedia\ = 1
Parsed : c:\users\administrator\appdata\roaming\macromedia

ARP - 117
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Users\Administrator\AppData\Roaming\Macromedia\Shockwave Player\ = 1
Parsed : c:\users\administrator\appdata\roaming\macromedia\shockwave player

ARP - 118
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Windows\Installer\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\ =
Parsed : c:\windows\installer\{5db1df0c-aabc-4362-8a6d-cefdfb036e41}

ARP - 119
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Family\ =
Parsed : c:\program files\cyberlink\power2go\menus\family

ARP - 120
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Family\Audio\ =
Parsed : c:\program files\cyberlink\power2go\menus\family\audio

ARP - 121
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Family\Background\ =
Parsed : c:\program files\cyberlink\power2go\menus\family\background

ARP - 122
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Family\Button\ =
Parsed : c:\program files\cyberlink\power2go\menus\family\button

ARP - 123
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Family\Fontstyle\ =
Parsed : c:\program files\cyberlink\power2go\menus\family\fontstyle

ARP - 124
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Family\Frame\ =
Parsed : c:\program files\cyberlink\power2go\menus\family\frame

ARP - 125
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Family\Highlight\ =
Parsed : c:\program files\cyberlink\power2go\menus\family\highlight

ARP - 126
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Family\Layout\ =
Parsed : c:\program files\cyberlink\power2go\menus\family\layout

ARP - 127
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Family\Motion\ =
Parsed : c:\program files\cyberlink\power2go\menus\family\motion

ARP - 128
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Family\PCBG\ =
Parsed : c:\program files\cyberlink\power2go\menus\family\pcbg

ARP - 129
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Family\Text\ =
Parsed : c:\program files\cyberlink\power2go\menus\family\text

ARP - 130
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Party\ =
Parsed : c:\program files\cyberlink\power2go\menus\party

ARP - 131
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Party\Audio\ =
Parsed : c:\program files\cyberlink\power2go\menus\party\audio

ARP - 132
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Party\Background\ =
Parsed : c:\program files\cyberlink\power2go\menus\party\background

ARP - 133
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Party\Button\ =
Parsed : c:\program files\cyberlink\power2go\menus\party\button

ARP - 134
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Party\Fontstyle\ =
Parsed : c:\program files\cyberlink\power2go\menus\party\fontstyle

ARP - 135
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Party\Frame\ =
Parsed : c:\program files\cyberlink\power2go\menus\party\frame

ARP - 136
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Party\Highlight\ =
Parsed : c:\program files\cyberlink\power2go\menus\party\highlight

ARP - 137
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Party\Layout\ =
Parsed : c:\program files\cyberlink\power2go\menus\party\layout

ARP - 138
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Party\Motion\ =
Parsed : c:\program files\cyberlink\power2go\menus\party\motion

ARP - 139
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Party\PCBG\ =
Parsed : c:\program files\cyberlink\power2go\menus\party\pcbg

ARP - 140
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Party\Text\ =
Parsed : c:\program files\cyberlink\power2go\menus\party\text

ARP - 141
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Romance\ =
Parsed : c:\program files\cyberlink\power2go\menus\romance

ARP - 142
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Romance\Audio\ =
Parsed : c:\program files\cyberlink\power2go\menus\romance\audio

ARP - 143
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Romance\Background\ =
Parsed : c:\program files\cyberlink\power2go\menus\romance\background

ARP - 144
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Romance\Button\ =
Parsed : c:\program files\cyberlink\power2go\menus\romance\button

ARP - 145
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Romance\Fontstyle\ =
Parsed : c:\program files\cyberlink\power2go\menus\romance\fontstyle

ARP - 146
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Romance\Frame\ =
Parsed : c:\program files\cyberlink\power2go\menus\romance\frame

ARP - 147
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Romance\Highlight\ =
Parsed : c:\program files\cyberlink\power2go\menus\romance\highlight

ARP - 148
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Romance\Layout\ =
Parsed : c:\program files\cyberlink\power2go\menus\romance\layout

ARP - 149
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Romance\Motion\ =
Parsed : c:\program files\cyberlink\power2go\menus\romance\motion

ARP - 150
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Romance\PCBG\ =
Parsed : c:\program files\cyberlink\power2go\menus\romance\pcbg

ARP - 151
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Romance\Text\ =
Parsed : c:\program files\cyberlink\power2go\menus\romance\text

ARP - 152
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Sports\ =
Parsed : c:\program files\cyberlink\power2go\menus\sports

ARP - 153
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Sports\Audio\ =
Parsed : c:\program files\cyberlink\power2go\menus\sports\audio

ARP - 154
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Sports\Background\ =
Parsed : c:\program files\cyberlink\power2go\menus\sports\background

ARP - 155
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Sports\Button\ =
Parsed : c:\program files\cyberlink\power2go\menus\sports\button

ARP - 156
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Sports\Fontstyle\ =
Parsed : c:\program files\cyberlink\power2go\menus\sports\fontstyle

ARP - 157
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Sports\Frame\ =
Parsed : c:\program files\cyberlink\power2go\menus\sports\frame

ARP - 158
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Sports\Highlight\ =
Parsed : c:\program files\cyberlink\power2go\menus\sports\highlight

ARP - 159
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Sports\Layout\ =
Parsed : c:\program files\cyberlink\power2go\menus\sports\layout

ARP - 160
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Sports\Motion\ =
Parsed : c:\program files\cyberlink\power2go\menus\sports\motion

ARP - 161
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Sports\PCBG\ =
Parsed : c:\program files\cyberlink\power2go\menus\sports\pcbg

ARP - 162
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Cyberlink\Power2Go\Menus\Sports\Text\ =
Parsed : c:\program files\cyberlink\power2go\menus\sports\text

ARP - 163
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas

ARP - 164
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\Audio\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\audio

ARP - 165
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\background\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\background

ARP - 166
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\Button\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\button

ARP - 167
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\Effect\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\effect

ARP - 168
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\FirstPlay\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\firstplay

ARP - 169
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\fontstyle\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\fontstyle

ARP - 170
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\frame\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\frame

ARP - 171
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\highlight\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\highlight

ARP - 172
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\LayerTemplate\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\layertemplate

ARP - 173
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\LayerTemplate\LayerTemplate1\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\layertemplate\layertemplate1

ARP - 174
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\LayerTemplate\LayerTemplate2\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\layertemplate\layertemplate2

ARP - 175
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\LayerTemplate\LayerTemplate3\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\layertemplate\layertemplate3

ARP - 176
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\LayerTemplate\LayerTemplate4\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\layertemplate\layertemplate4

ARP - 177
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\LayerTemplate\LayerTemplate5\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\layertemplate\layertemplate5

ARP - 178
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\LayerTemplate\LayerTemplate6\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\layertemplate\layertemplate6

ARP - 179
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\layout\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\layout

ARP - 180
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\MMotion\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\mmotion

ARP - 181
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\Motion\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\motion

ARP - 182
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\pcbg\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\pcbg

ARP - 183
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\TemplateThumb\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\templatethumb

ARP - 184
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\Blue Xmas\text\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\blue xmas\text

ARP - 185
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion

ARP - 186
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\Audio\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\audio

ARP - 187
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\background\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\background

ARP - 188
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\Button\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\button

ARP - 189
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\Effect\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\effect

ARP - 190
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\FirstPlay\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\firstplay

ARP - 191
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\fontstyle\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\fontstyle

ARP - 192
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\frame\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\frame

ARP - 193
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\highlight\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\highlight

ARP - 194
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\LayerTemplate\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\layertemplate

ARP - 195
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\LayerTemplate\LayerTemplate1\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\layertemplate\layertemplate1

ARP - 196
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\LayerTemplate\LayerTemplate2\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\layertemplate\layertemplate2

ARP - 197
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\LayerTemplate\LayerTemplate3\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\layertemplate\layertemplate3

ARP - 198
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\LayerTemplate\LayerTemplate4\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\layertemplate\layertemplate4

ARP - 199
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\LayerTemplate\LayerTemplate5\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\layertemplate\layertemplate5

ARP - 200
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\LayerTemplate\LayerTemplate6\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\layertemplate\layertemplate6

ARP - 201
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\layout\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\layout

ARP - 202
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\MMotion\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\mmotion

ARP - 203
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\Motion\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\motion

ARP - 204
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\pcbg\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\pcbg

ARP - 205
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\TemplateThumb\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\templatethumb

ARP - 206
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Menus\E-Motion\text\ =
Parsed : c:\program files\cyberlink\powerdirector\menus\e-motion\text

ARP - 207
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Styles\Fast\ =
Parsed : c:\program files\cyberlink\powerdirector\styles\fast

ARP - 208
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Styles\Slow\ =
Parsed : c:\program files\cyberlink\powerdirector\styles\slow

ARP - 209
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Styles\Sports\ =
Parsed : c:\program files\cyberlink\powerdirector\styles\sports

ARP - 210
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Styles\Sports\CellSlideShow\ =
Parsed : c:\program files\cyberlink\powerdirector\styles\sports\cellslideshow

ARP - 211
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Styles\Xmas\ =
Parsed : c:\program files\cyberlink\powerdirector\styles\xmas

ARP - 212
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\CyberLink\PowerDirector\Styles\Xmas\CellSlideShow\ =
Parsed : c:\program files\cyberlink\powerdirector\styles\xmas\cellslideshow

ARP - 213
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Users\Administrator\AppData\Roaming\Microsoft\Installer\{082702D5-5DD8-4600-BCE5-48B15174687F}\ =
Parsed : c:\users\administrator\appdata\roaming\microsoft\installer\{082702d5-5dd8-4600-bce5-48b15174687f}

ARP - 214
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Hewlett-Packard\ESU for Microsoft Vista\ =
Parsed : c:\program files\hewlett-packard\esu for microsoft vista

ARP - 215
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Hewlett-Packard\ESU for Microsoft Vista\HotFix\x86\ =
Parsed : c:\program files\hewlett-packard\esu for microsoft vista\hotfix\x86

ARP - 216
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Hewlett-Packard\ESU for Microsoft Vista\HotFix\ =
Parsed : c:\program files\hewlett-packard\esu for microsoft vista\hotfix

ARP - 217
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Hewlett-Packard\ESU for Microsoft Vista\HotFix\x64\ =
Parsed : c:\program files\hewlett-packard\esu for microsoft vista\hotfix\x64

ARP - 218
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Windows\Installer\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}\ =
Parsed : c:\windows\installer\{4fc670eb-5f02-4b07-90db-022b86bfefd0}

ARP - 219
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Windows\Installer\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}\ =
Parsed : c:\windows\installer\{23f3da62-2d9e-4a69-b8d5-be8e9e148092}

ARP - 220
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Windows\Installer\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}\ =
Parsed : c:\windows\installer\{9867824a-c86d-4a83-8f3c-e7a86be0afd3}

ARP - 221
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Windows\Installer\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}\ =
Parsed : c:\windows\installer\{051b9612-4d82-42ac-8c63-cd2dcedc1cb3}

ARP - 222
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Windows\Installer\{CDD849CF-7442-466F-B026-8C93990A7C3C}\ =
Parsed : c:\windows\installer\{cdd849cf-7442-466f-b026-8c93990a7c3c}

ARP - 223
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : c:\Program Files\Microsoft Silverlight\2.0.31005.0\ =
Parsed : c:\program files\microsoft silverlight\2.0.31005.0

ARP - 224
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : c:\Program Files\Microsoft Silverlight\2.0.31005.0\fr\ =
Parsed : c:\program files\microsoft silverlight\2.0.31005.0\fr

ARP - 225
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : c:\Program Files\Microsoft Silverlight\2.0.31005.0\it\ =
Parsed : c:\program files\microsoft silverlight\2.0.31005.0\it

ARP - 226
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : c:\Program Files\Microsoft Silverlight\2.0.31005.0\de\ =
Parsed : c:\program files\microsoft silverlight\2.0.31005.0\de

ARP - 227
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : c:\Program Files\Microsoft Silverlight\2.0.31005.0\es\ =
Parsed : c:\program files\microsoft silverlight\2.0.31005.0\es

ARP - 228
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : c:\Program Files\Microsoft Silverlight\2.0.31005.0\zh-Hans\ =
Parsed : c:\program files\microsoft silverlight\2.0.31005.0\zh-hans

ARP - 229
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : c:\Program Files\Microsoft Silverlight\2.0.31005.0\zh-Hant\ =
Parsed : c:\program files\microsoft silverlight\2.0.31005.0\zh-hant

ARP - 230
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : c:\Program Files\Microsoft Silverlight\2.0.31005.0\ja\ =
Parsed : c:\program files\microsoft silverlight\2.0.31005.0\ja

ARP - 231
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : c:\Program Files\Microsoft Silverlight\2.0.31005.0\ko\ =
Parsed : c:\program files\microsoft silverlight\2.0.31005.0\ko

ARP - 232
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Hewlett-Packard\Digital Imaging\hpis\temp\ =
Parsed : c:\program files\hewlett-packard\digital imaging\hpis\temp

ARP - 233
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Value : C:\Program Files\Hewlett-Packard\Digital Imaging\hpis\ =
Parsed : c:\program files\hewlett-packard\digital imaging\hpis

FX - 234
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.0\OpenWithList
Value : default =
Parsed :

FX - 235
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.1\OpenWithList
Value : default =
Parsed :

FX - 236
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.696]\OpenWithList
Value : default =
Parsed :

FX - 237
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\OpenWithList
Value : default =
Parsed :

FX - 238
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx\OpenWithList
Value : default =
Parsed :

FX - 239
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DTS-MoNG\OpenWithList
Value : default =
Parsed :

FX - 240
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DVDRip-Morsan(SweSub)\OpenWithList
Value : default =
Parsed :

FX - 241
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srt\OpenWithList
Value : default =
Parsed :

FX - 242
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.uccapilog\OpenWithList
Value : default =
Parsed :

FX - 243
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\OpenWithList
Value : default = OpenWithList
Parsed :

PS - 244
Location: C:\ProgramData\Microsoft\Windows\Start Menu\PAV\Personal Antivirus.lnk
Value : Shortcut = c:\program files\pav\pav.exe
Parsed : c:\program files\pav\pav.exe

PS - 245
Location: C:\ProgramData\Microsoft\Windows\Start Menu\PAV\Uninstall.lnk
Value : Shortcut = c:\program files\pav\pav.exe
Parsed : c:\program files\pav\pav.exe

PS - 246
Location: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Neverwinter Nights 2\Mask of the Betrayer\ Manual.lnk
Value : Shortcut = c:\program files\atari\neverwinter nights 2\documentation\motb_manual.pdf
Parsed : c:\program files\atari\neverwinter nights 2\documentation\motb_manual.pdf

PS - 247
Location: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Neverwinter Nights 2\Mask of the Betrayer\Readme.lnk
Value : Shortcut = c:\program files\atari\neverwinter nights 2\documentation\motb_readme.rtf
Parsed : c:\program files\atari\neverwinter nights 2\documentation\motb_readme.rtf

CC - 248
Location: HKEY_CLASSES_ROOT\Applications\uTorrent.exe\shell\open\command
Value : (default) = "C:\Program Files\uTorrent\uTorrent.exe" "%1"
Parsed : c:\program files\utorrent\utorrent.exe

CC - 249
Location: HKEY_CLASSES_ROOT\Applications\vlc.exe\shell\open\command
Value : (default) = "C:\Users\Hellius\Desktop\VLC\vlc.exe" "%1"
Parsed : c:\users\hellius\desktop\vlc\vlc.exe

CC - 250
Location: HKEY_CLASSES_ROOT\CLSID\{12BEF447-D278-4EED-B3E1-09CDF7E4C126}\InprocServer32
Value : (default) = C:\Program Files\Norton Internet Security\Engine\16.0.0.125\MceEULA.dll
Parsed : c:\program files\norton internet security\engine\16.0.0.125\mceeula.dll

CC - 251
Location: HKEY_CLASSES_ROOT\CLSID\{2060435E-AB52-49E1-A2EA-5D31645887CF}\InprocServer32
Value : (default) = C:\Windows\system32\SynCtrl.dll
Parsed : c:\windows\system32\synctrl.dll

CC - 252
Location: HKEY_CLASSES_ROOT\CLSID\{2060435E-AB52-49E1-A2EA-5D31645887CF}\ToolboxBitmap32
Value : (default) = C:\Windows\system32\SynCtrl.dll, 103
Parsed : c:\windows\system32\synctrl.dll

CC - 253
Location: HKEY_CLASSES_ROOT\CLSID\{206D8F65-689B-40D0-8F07-8D974CD8884B}\InprocServer32
Value : (default) = C:\Windows\system32\SynCtrl.dll
Parsed : c:\windows\system32\synctrl.dll

CC - 254
Location: HKEY_CLASSES_ROOT\CLSID\{206D8F65-689B-40D0-8F07-8D974CD8884B}\ToolboxBitmap32
Value : (default) = C:\Windows\system32\SynCtrl.dll, 118
Parsed : c:\windows\system32\synctrl.dll

CC - 255
Location: HKEY_CLASSES_ROOT\CLSID\{248AFB1A-27C4-4A30-BF45-6544146648BC}\InprocServer32
Value : (default) = C:\Windows\system32\SynCOM.dll
Parsed : c:\windows\system32\syncom.dll

CC - 256
Location: HKEY_CLASSES_ROOT\CLSID\{248AFB1A-27C4-4A30-BF45-6544146648BC}\ToolboxBitmap32
Value : (default) = C:\Windows\system32\SynCOM.dll, 201
Parsed : c:\windows\system32\syncom.dll

CC - 257
Location: HKEY_CLASSES_ROOT\CLSID\{6B75345B-AA36-438A-BBE6-4078B4C6984D}\ToolboxBitmap32
Value : (default) = C:\Develop\HPSU_4_6\HpsuInstall\HP Common MM\_source\HPDeviceDetection.dll, 130
Parsed : c:\develop\hpsu_4_6\hpsuinstall\hp common mm\_source\hpdevicedetection.dll

CC - 258
Location: HKEY_CLASSES_ROOT\CLSID\{7EA9A8FA-F5D2-49E1-99E8-C26EE07FCEEB}
Value : LocalizedString = @C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\Office.\osetupui.dll,-200
Parsed : c:\program files\common files\microsoft shared\office12\office setup controller\office.\osetupui.dll

CC - 259
Location: HKEY_CLASSES_ROOT\CLSID\{9345312C-D098-4BB1-B2B2-D529EB995173}\InprocServer32
Value : (default) = C:\Windows\system32\SynCOM.dll
Parsed : c:\windows\system32\syncom.dll

CC - 260
Location: HKEY_CLASSES_ROOT\CLSID\{9345312C-D098-4BB1-B2B2-D529EB995173}\ToolboxBitmap32
Value : (default) = C:\Windows\system32\SynCOM.dll, 201
Parsed : c:\windows\system32\syncom.dll

CC - 261
Location: HKEY_CLASSES_ROOT\CLSID\{9C042297-D1CD-4F0D-B1AB-9F48AD6A6DFF}\InprocServer32
Value : (default) = C:\Windows\system32\SynCOM.dll
Parsed : c:\windows\system32\syncom.dll

CC - 262
Location: HKEY_CLASSES_ROOT\CLSID\{9C042297-D1CD-4F0D-B1AB-9F48AD6A6DFF}\ToolboxBitmap32
Value : (default) = C:\Windows\system32\SynCOM.dll, 201
Parsed : c:\windows\system32\syncom.dll

CC - 263
Location: HKEY_CLASSES_ROOT\CLSID\{a220a2df-406f-4d68-9b62-995669ae0c92}\InprocServer32
Value : (default) = C:\Windows\system32\SynCtrl.dll
Parsed : c:\windows\system32\synctrl.dll

CC - 264
Location: HKEY_CLASSES_ROOT\CLSID\{a220a2df-406f-4d68-9b62-995669ae0c92}\ToolboxBitmap32
Value : (default) = C:\Windows\system32\SynCtrl.dll, 105
Parsed : c:\windows\system32\synctrl.dll

CC - 265
Location: HKEY_CLASSES_ROOT\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\ToolboxBitmap32
Value : (default) = C:\Develop\HPSU_4_6\HpsuInstall\HP Common MM\_source\RulesEngine.dll, 202
Parsed : c:\develop\hpsu_4_6\hpsuinstall\hp common mm\_source\rulesengine.dll

CC - 266
Location: HKEY_CLASSES_ROOT\CLSID\{E0C6335D-27F8-424B-A5C2-561291A902A0}\InprocServer32
Value : (default) = C:\Windows\system32\SynCOM.dll
Parsed : c:\windows\system32\syncom.dll

CC - 267
Location: HKEY_CLASSES_ROOT\CLSID\{E0C6335D-27F8-424B-A5C2-561291A902A0}\ToolboxBitmap32
Value : (default) = C:\Windows\system32\SynCOM.dll, 201
Parsed : c:\windows\system32\syncom.dll

CC - 268
Location: HKEY_CLASSES_ROOT\CLSID\{F418EBA0-6A10-4482-AC2B-2D10C807073A}\InprocServer32
Value : (default) = C:\Windows\system32\SynCtrl.dll
Parsed : c:\windows\system32\synctrl.dll

CC - 269
Location: HKEY_CLASSES_ROOT\CLSID\{F418EBA0-6A10-4482-AC2B-2D10C807073A}\ToolboxBitmap32
Value : (default) = C:\Windows\system32\SynCtrl.dll, 101
Parsed : c:\windows\system32\synctrl.dll

CC - 270
Location: HKEY_CLASSES_ROOT\CLSID\{F51C15D4-3D0A-4DBA-A095-EBCC09F24DA2}\InprocServer32
Value : (default) = C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YMERemote.dll
Parsed : c:\progra~1\yahoo!\companion\installs\cpn\ymeremote.dll

CC - 271
Location: HKEY_CLASSES_ROOT\dat_auto_file\shell\open\command
Value : (default) = "C:\Program Files\uTorrent\uTorrent.exe" "%1"
Parsed : c:\program files\utorrent\utorrent.exe

CC - 272
Location: HKEY_CLASSES_ROOT\dinerdash4SavedGame\Shell\Open\Command
Value : (default) = "C:\Program Files\HP Games\Diner Dash Hometown Hero\Diner Dash - Hometown Hero-WT.exe %1"
Parsed : c:\program files\hp games\diner dash hometown hero\diner dash

CC - 273
Location: HKEY_CLASSES_ROOT\ed2k\DefaultIcon
Value : (default) = C:\Program Files\eMule\eMule.exe,0
Parsed : c:\program files\emule\emule.exe

CC - 274
Location: HKEY_CLASSES_ROOT\ed2k\shell\open\command
Value : (default) = "C:\Program Files\eMule\eMule.exe" "%1"
Parsed : c:\program files\emule\emule.exe

CC - 275
Location: HKEY_CLASSES_ROOT\rmvb_auto_file\shell\open\command
Value : (default) = "C:\Users\Hellius\Desktop\VLC\vlc.exe" "%1"
Parsed : c:\users\hellius\desktop\vlc\vlc.exe

CC - 276
Location: HKEY_CLASSES_ROOT\TypeLib\{283C8576-0726-4DBC-9609-3F855162009A}\1.0\0\win32
Value : (default) = c:\Program Files\Microsoft Silverlight\npctrl.1.0.30716.0.dll
Parsed : c:\program files\microsoft silverlight\npctrl.1.0.30716.0.dll

CC - 277
Location: HKEY_CLASSES_ROOT\TypeLib\{37EF9BBE-16CF-41B4-ADB1-4AE61963A354}\1.0\HELPDIR
Value : (default) = C:\Program Files\Common Files\Microsoft Shared\Database Replication\
Parsed : c:\program files\common files\microsoft shared\database replication

CC - 278
Location: HKEY_CLASSES_ROOT\TypeLib\{6F1D1C70-4B8A-4273-808E-5FB78E797702}\1.0\0\win32
Value : (default) = C:\Program Files\Windows Live\Messenger\msnmsgr.exe\10
Parsed : c:\program files\windows live\messenger\msnmsgr.exe\10

CC - 279
Location: HKEY_CLASSES_ROOT\TypeLib\{819BBC18-F054-4F88-82D8-88F29F311135}\1.0\0\win32
Value : (default) = C:\Program Files\Norton Internet Security\Engine\16.0.0.125\MceEULA.dll
Parsed : c:\program files\norton internet security\engine\16.0.0.125\mceeula.dll

CC - 280
Location: HKEY_CLASSES_ROOT\TypeLib\{819BBC18-F054-4F88-82D8-88F29F311135}\1.0\HELPDIR
Value : (default) = C:\Program Files\Norton Internet Security\Engine\16.0.0.125\
Parsed : c:\program files\norton internet security\engine\16.0.0.125

CC - 281
Location: HKEY_CLASSES_ROOT\TypeLib\{82D70786-7968-46EA-836D-203AEBCA4481}\1.0\0\win32
Value : (default) = C:\Windows\system32\SynCtrl.dll
Parsed : c:\windows\system32\synctrl.dll

CC - 282
Location: HKEY_CLASSES_ROOT\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}\1.0\0\win32
Value : (default) = C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YMERemote.dll
Parsed : c:\progra~1\yahoo!\companion\installs\cpn\ymeremote.dll

CC - 283
Location: HKEY_CLASSES_ROOT\TypeLib\{C89361FC-B7A8-405F-8329-DCAB7592E579}\1.0\HELPDIR
Value : (default) = C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\AREN\
Parsed : c:\program files\common files\microsoft shared\translat\aren

CC - 284
Location: HKEY_CLASSES_ROOT\TypeLib\{E2489565-2CE5-4690-9111-76E79A9F6CCD}\2.0\0\win32
Value : (default) = C:\Windows\system32\SynCOM.dll
Parsed : c:\windows\system32\syncom.dll

CC - 285
Location: HKEY_CLASSES_ROOT\uTorrent\shell\open\command
Value : (default) = "C:\Program Files\uTorrent\uTorrent.exe" "%1"
Parsed : c:\program files\utorrent\utorrent.exe

CC - 286
Location: HKEY_CLASSES_ROOT\VirtualStore\MACHINE\SOFTWARE\Xfire
Value : (default) = C:\Program Files\Xfire
Parsed : c:\program files\xfire

CC - 287
Location: HKEY_CLASSES_ROOT\virtualvillagers3SavedGame\Shell\Open\Command
Value : (default) = "C:\Program Files\HP Games\Virtual Villagers - The Secret City\Virtual Villagers - The Secret City-WT.exe %1"
Parsed : c:\program files\hp games\virtual villagers - the secret city\virtual villagers

DEEP - 288
Location: HKEY_USERS\S-1-5-21-1821147234-265528868-179954347-1002\Software\Microsoft\MediaPlayer\Preferences
Value : TrackFoldersDirectories6 = C:\Users\Public\Recorded TV\
Parsed : c:\users\public\recorded tv

DEEP - 289
Location: HKEY_USERS\S-1-5-21-1821147234-265528868-179954347-1002\Software\Microsoft\MediaPlayer\Preferences
Value : CurrentBackgroundScanFolder = C:\Users\Hellius\Downloads\Meat Loaf\Bat Out Of Hell III_ The Monster Is Loos
Parsed : c:\users\hellius\downloads\meat loaf\bat out of hell iii_ the monster is loos

DEEP - 290
Location: HKEY_USERS\S-1-5-21-1821147234-265528868-179954347-1002\Software\Microsoft\Windows\CurrentVersion\Run
Value : HPADVISOR = C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
Parsed : c:\program files\hewlett-packard\hp advisor\hpadvisor.exe

DEEP - 291
Location: HKEY_USERS\S-1-5-21-1821147234-265528868-179954347-1002\Software\Yahoo\pager\profiles\Skins
Value : Default_SkinDir = C:\PROGRA~1\Yahoo!\MESSEN~1\skins\Default
Parsed : c:\progra~1\yahoo!\messen~1\skins\default

DEEP - 292
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemExit\.Current
Value : (default) = C:\Users\Hellius\Music\Windows Sounds\Close.wav
Parsed : c:\users\hellius\music\windows sounds\close.wav

DEEP - 293
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemExit\.Modified
Value : (default) = C:\Users\Hellius\Music\Windows Sounds\Close.wav
Parsed : c:\users\hellius\music\windows sounds\close.wav

DEEP - 294
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\WindowsLogon\.Current
Value : (default) = C:\Users\Hellius\Desktop\Open2.wav
Parsed : c:\users\hellius\desktop\open2.wav

DEEP - 295
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\WindowsLogon\.Modified
Value : (default) = C:\Users\Hellius\Desktop\Open2.wav
Parsed : c:\users\hellius\desktop\open2.wav

DEEP - 296
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\iTunes\iTunes_Complete\.Modified
Value : (default) = C:\Program Files\iTunes\iTunes.Resources\complete.wav
Parsed : c:\program files\itunes\itunes.resources\complete.wav

DEEP - 297
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\iTunes\iTunes_PageLoadComplete\.Modified
Value : (default) = C:\Program Files\iTunes\iTunes.Resources\axloadcomplete.wav
Parsed : c:\program files\itunes\itunes.resources\axloadcomplete.wav

DEEP - 298
Location: HKEY_CURRENT_USER\Software\Audacity\Audacity\RecentFiles
Value : file1 = C:\Users\Hellius\Music\Stratovarius - The Abyss Of Your Eyes.mp3
Parsed : c:\users\hellius\music\stratovarius

DEEP - 299
Location: HKEY_CURRENT_USER\Software\Audacity\Audacity\RecentFiles
Value : file2 = C:\Users\Hellius\Music\J-Kwon - Tipsy.mp3
Parsed : c:\users\hellius\music\j-kwon

DEEP - 300
Location: HKEY_CURRENT_USER\Software\Audacity\Audacity\RecentFiles
Value : file3 = C:\Users\Hellius\Music\Downloads\16 - J-Kwon - Tipsy.mp3
Parsed : c:\users\hellius\music\downloads\16

DEEP - 301
Location: HKEY_CURRENT_USER\Software\Audacity\Audacity\RecentFiles
Value : file4 = C:\Users\Hellius\Music\Rehab - Sittin at a Bar.mp3
Parsed : c:\users\hellius\music\rehab

DEEP - 302
Location: HKEY_CURRENT_USER\Software\Audacity\Audacity\RecentFiles
Value : file5 = C:\Users\Hellius\Videos\Comp Turn off.wma
Parsed : c:\users\hellius\videos\comp turn off.wma

DEEP - 303
Location: HKEY_CURRENT_USER\Software\CDisplay
Value : LastDir = C:\Users\Hellius\Desktop\Jhonen Vasquez\Jhonen Vasquez\Misc
Parsed : c:\users\hellius\desktop\jhonen vasquez\jhonen vasquez\misc

DEEP - 304
Location: HKEY_CURRENT_USER\Software\CDisplay\RecentPages
Value : 0000 = C:\Users\Hellius\Desktop\Jhonen Vasquez\Jhonen Vasquez\Misc\Everything Can Be Beaten.cbr
Parsed : c:\users\hellius\desktop\jhonen vasquez\jhonen vasquez\misc\everything can be beaten.cbr

DEEP - 305
Location: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{37DFB563-7F4F-4695-8FB7-0D54352899E3}
Value : AppPath = C:\Users\Hellius\AppData\Roaming\IMVUClient
Parsed : c:\users\hellius\appdata\roaming\imvuclient

DEEP - 306
Location: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
Value : url1 = C:\Users\Hellius\Downloads\Stephen King Movies
Parsed : c:\users\hellius\downloads\stephen king movies

DEEP - 307
Location: HKEY_CURRENT_USER\Software\Microsoft\Keyboard\Native Media Players\QuickTime Player
Value : ExePath = C:\Program Files\QuickT
Parsed : c:\program files\quickt

DEEP - 308
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\RecentFileList
Value : File0 = C:\Users\Hellius\Videos\Comp Turn off.wma
Parsed : c:\users\hellius\videos\comp turn off.wma

DEEP - 309
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\RecentFileList
Value : File1 = C:\Users\Hellius\Downloads\Loreena McKennitt-9 albums-mp3\1997 Book of secrets\The Book of Secrets\The Book of Secrets\Loreena McKennitt - 03 - Skellig.mp3
Parsed : c:\users\hellius\downloads\loreena mckennitt-9 albums-mp3\1997 book of secrets\the book of secrets\the book of secrets\loreena mckennitt

DEEP - 310
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\RecentFileList
Value : File2 = C:\Users\Hellius\Downloads\Stephen King Movies\Nightshift Collection Vol 1 & 2 - The Woman In The Room & Boogeyman.avi
Parsed : c:\users\hellius\downloads\stephen king movies\nightshift collection vol 1 & 2

DEEP - 311
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\RecentFileList
Value : File3 = C:\Users\Hellius\Videos\Wanted (2008) [DVDRip-H.264 - AC3 5.1] [ENG].mp3
Parsed : c:\users\hellius\videos\wanted (2008) [dvdrip-h.264

DEEP - 312
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\RecentFileList
Value : File4 = C:\Users\Hellius\Music\Timo Kotipelto - Sleep well.mp3
Parsed : c:\users\hellius\music\timo kotipelto

DEEP - 313
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\RecentFileList
Value : File5 = C:\Users\Hellius\Music\Stratovarius - Chasing Shadows.mp3
Parsed : c:\users\hellius\music\stratovarius

DEEP - 314
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\RecentFileList
Value : File6 = C:\Users\Hellius\Music\Downloads\Kotipelto - Serenity - Sleep Well - 2007 -.mp3
Parsed : c:\users\hellius\music\downloads\kotipelto

DEEP - 315
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Settings
Value : SaveAsDir = C:\Users\Hellius\Music\Playlists
Parsed : c:\users\hellius\music\playlists

DEEP - 316
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Value : CurrentBackgroundScanFolder = C:\Users\Public\Pictures\Sample Pictures
Parsed : c:\users\public\pictures\sample pictures

DEEP - 317
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Value : TrackFoldersDirectories6 = C:\Users\Public\Recorded TV\
Parsed : c:\users\public\recorded tv

DEEP - 318
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
Value : Shortcut1 = C:\Users\Hellius\Desktop\Windows Media Player.lnk
Parsed : c:\users\hellius\desktop\windows media player.lnk

DEEP - 319
Location: HKEY_CURRENT_USER\Software\Microsoft\MM20
Value : ImportDirAllMedia = C:\Users\Hellius\Documents\Youcam\
Parsed : c:\users\hellius\documents\youcam

DEEP - 320
Location: HKEY_CURRENT_USER\Software\Microsoft\MPEG2Demultiplexer
Value : WriteCaptureDir = c:\dm.capture\
Parsed : c:\dm.capture

DEEP - 321
Location: HKEY_CURRENT_USER\Software\Microsoft\MSNMessenger\PerPassportSettings\101068905
Value : MessageLogPath = C:\Users\Hellius\Documents\My Received Files\estrawman101068905\History
Parsed : c:\users\hellius\documents\my received files\estrawman101068905\history

DEEP - 322
Location: HKEY_CURRENT_USER\Software\Microsoft\MSNMessenger\PerPassportSettings\700582889
Value : MessageLogPath = C:\Users\Hellius\Documents\My Received Files\hellius700582889\History
Parsed : c:\users\hellius\documents\my received files\hellius700582889\history

DEEP - 323
Location: HKEY_CURRENT_USER\Software\Microsoft\MSNMessenger\PerPassportSettings\722147281
Value : MessageLogPath = C:\Users\Hellius\Documents\My Received Files\slaveofmyownheart722147281\History
Parsed : c:\users\hellius\documents\my received files\slaveofmyownheart722147281\history

DEEP - 324
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List
Value : File1 = C:\Users\Hellius\Pictures\Untitled.jpg
Parsed : c:\users\hellius\pictures\untitled.jpg

DEEP - 325
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List
Value : File2 = C:\Users\Hellius\Pictures\w00tn

0

Please do as requested in my previous post so that i may help assisting you in this matter :)

0

I have recieved offline help and my computer has been fixed, Thank you for your help.

0

I have recieved offline help and my computer has been fixed, Thank you for your help.

Thats Great :)

This question has already been answered. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.