| | Registry Key | Value Name | Value Data |
 | HKEY_CLASSES_ROOT\CLSID\{49FF1FD4-A32F-6EA1-FB36-EDD7AE45A9F2} | | |
 | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | registry cleaner | %SYSTEMDRIVE%\progra~1\regist~1\regclean .exe |
 | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | soproc_sorefregsoalertwxlitennaj | rundll32 shell32.dll,shellexec_rundll %S YSTEMDRIVE%\progra~1\softwa~1\soproc .exe -pack sorefregsoalertwxlitennaj |
 | HKEY_CURRENT_USER\Software\Registry Cleaner\Registry Cleaner\1.0\Setti ngs | | |
 | HKEY_CURRENT_USER\Software\Registry Cleaner\Registry Cleaner\1.0\Setti ngs | id | 03222008 |
 | HKEY_CURRENT_USER\Software\Registry Cleaner\Registry Cleaner\1.0\Setti ngs | prevah | [reg_dword, value: 00030130] |
 | HKEY_CURRENT_USER\Software\Registry Cleaner\Registry Cleaner\1.0\Setti ngs | prevfh | [reg_dword, value: 0002014a] |
 | HKEY_CURRENT_USER\Software\Registry Cleaner\Registry Cleaner\1.0\Setti ngs | trialpath | %SYSTEMDRIVE%\progra~1\regist~1\regclean .exe |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com | machineid | [reg_binary, size: 8 bytes] |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soalertdnld\soalert__88265 | processor | sostreamer |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soalertdnld\soalert__88265\Params | | |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soalertdnld\soalert__88265\Params | cmdline | -setup |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soalertdnld\soalert__88265\Params | file | %TEMP%\sos41.tmp |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soalertdnld\soalert__88265\Params | job | soalert |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soalertdnld\soalert__88265\Params | longslowpace | y |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soalertdnld\soalert__88265\Params | package | sorefregsoalertwxlitennaj |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soalertdnld\soalert__88265\Params | url | http://adserver.sharewareonline.com/bund le/soalert.exe |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soreporter\regclean__86953 | processor | soreporter |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soreporter\regclean__86953 | state | [reg_dword, value: 00000001] |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soreporter\regclean__86953\Params | | <smachineid>69-35-11-31-6c-63-3b-0 0</smachineid>
<sbundlename >sorefregsoalertwxlitennaj</sb undlename>
<sappname>regcle an</sappname>
<saction>u seraccept</saction>
<iyear& gt;2008</iyear>
<imonth> 3</imonth>
<iday>21</ iday>
<ihour>19</ihour&g t;
<iminute>45</iminute> |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soreporter\soalert__88140 | processor | soreporter |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soreporter\soalert__88140 | state | [reg_dword, value: 00000001] |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soreporter\soalert__88140\Params | | <smachineid>69-35-11-31-6c-63-3b-0 0</smachineid>
<sbundlename >sorefregsoalertwxlitennaj</sb undlename>
<sappname>soaler t</sappname>
<saction>us eraccept</saction>
<iyear&g t;2008</iyear>
<imonth>3 </imonth>
<iday>21</i day>
<ihour>19</ihour> ;
<iminute>45</iminute> |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soreporter\weatherbug__88734 | processor | soreporter |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soreporter\weatherbug__88734 | state | [reg_dword, value: 00000001] |
 | HKEY_CURRENT_USER\Software\SoftwareOnline.com\SOProc\SoRefRegSoAlertWx LiteNnAj\soreporter\weatherbug__88734\Params | | <smachineid>69-35-11-31-6c-63-3b-0 0</smachineid>
<sbundlename >sorefregsoalertwxlitennaj</sb undlename>
<sappname>weathe rbug</sappname>
<saction> ;usercancel</saction>
<iyea r>2008</iyear>
<imonth&g t;3</imonth>
<iday>21< ;/iday>
<ihour>19</ihour >
<iminute>45</iminut |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{49FF1FD4-A32F-6EA1-FB36-EDD 7AE45A9F2} | | custom composition segment from data ser vices to xds |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{49FF1FD4-A32F-6EA1-FB36-EDD 7AE45A9F2}\InprocServer32 | | %windir%\system32\msvidctl.dll |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{49FF1FD4-A32F-6EA1-FB36-EDD 7AE45A9F2}\InprocServer32 | threadingmodel | apartment |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{49FF1FD4-A32F-6EA1-FB36-EDD 7AE45A9F2}\TypeLib | | {b0edf154-910a-11d2-b632-00c04f79498e} |
 | HKEY_LOCAL_MACHINE\Software\Licenses | | |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Licenses | {05fc536b82d671bf0} | [reg_binary, size: 124 bytes] |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Licenses | {i5fc536b82d671bf0} | [reg_binary, size: 4 bytes] |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Licenses | {k7c0db872a3f777c0} | [reg_binary, size: 260 bytes] |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Licenses | {r7c0db872a3f777c0} | [reg_binary, size: 4 bytes] |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Para meters | trappolltimemillisecs | [reg_dword, value: 00003a98] |
 | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall \Registry Cleaner | | |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall \Registry Cleaner | displayname | registry cleaner |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall \Registry Cleaner | uninstallstring | %programfiles%\registry cleaner trial\un instregclean.exe |
 | HKEY_LOCAL_MACHINE\Software\Registry Cleaner\Uninstall | | |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Registry Cleaner\Uninstall | installlog | %SYSTEMDRIVE%\progra~1\regist~1\install. log |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Registry Cleaner\Uninstall | rcuninstallpath | %SYSTEMDRIVE%\progra~1\regist~1\rcuninst all.exe |
 | HKEY_LOCAL_MACHINE\SOFTWARE\Registry Cleaner\Uninstall | soproc | %programfiles%\softwareonline\soproc.exe
|
 | HKEY_LOCAL_MACHINE\SOFTWARE\Registry Cleaner\Uninstall | unwisepath | %SYSTEMDRIVE%\progra~1\regist~1\unwise.e xe |