ok, after some analysis it seems neither is correct, the added entry or the oep.
the missing entry is away from msvbvm60.dll, perhaps it's decryption routine, or some sort on code injection routine.
I think if the author of the product spent his time enhancing his product more than the time he spent to over-protect it, that would have been much much better for him.I cannot imagine that a little program to change some entries in registry, or do things that freeware program does, can have such protection.