[code] WinPFind35 logfile created on: 3/1/2008 1:52:04 PM WinPFind35U Version 1.0.3.0 Folder = F:\Documents and Settings\Patrick\Desktop\WinPFind35u Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 511.49 Mb Total Physical Memory | 212.28 Mb Available Physical Memory | 41.50% Memory free 818.32 Mb Paging File | 544.62 Mb Available in Paging File | 66.55% Paging File free Paging file location(s): F:\pagefile.sys 336 672; %SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Program Files Drive C: | 19.10 Gb Total Space | 14.90 Gb Free Space | 77.99% Space Free | Partition Type: FAT32 D: Drive not present or media not loaded E: Drive not present or media not loaded Drive F: | 74.52 Gb Total Space | 32.53 Gb Free Space | 43.65% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded Drive I: | 189.92 Gb Total Space | 138.19 Gb Free Space | 72.76% Space Free | Partition Type: NTFS Computer Name: PATRICK-7F Current User Name: Patrick Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user [Processes - Non-Microsoft Only] applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 9/6/2007 12:28:18 PM | Attr = ] mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> Apple Inc. [Ver = 1,0,4,12 | Size = 229376 bytes | Modified Date = 7/24/2007 3:17:08 PM | Attr = ] dtsrvc.exe -> %CommonProgramFiles%\Portrait Displays\Shared\DTSRVC.exe -> [Ver = | Size = 73728 bytes | Modified Date = 6/29/2007 5:54:16 PM | Attr = ] nvsvc32.exe -> %SystemRoot%\system32\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.11.6218 | Size = 155716 bytes | Modified Date = 8/13/2007 3:14:13 PM | Attr = ] jusched.exe -> %ProgramFiles%\Java\jre1.6.0_03\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 12:11:35 AM | Attr = ] onetouch.exe -> %ProgramFiles%\Maxtor\OneTouch\Utils\OneTouch.exe -> Maxtor Corporation [Ver = 3, 0, 0, 2 | Size = 823296 bytes | Modified Date = 12/22/2004 8:21:48 AM | Attr = ] retroexpress.exe -> %ProgramFiles%\Dantz\Retrospect Express HD\RetroExpress.exe -> Dantz Development Corporation [Ver = 1.0.196.0 | Size = 6946816 bytes | Modified Date = 7/30/2004 3:47:36 PM | Attr = ] pptd40nt.exe -> %ProgramFiles%\ScanSoft\PaperPort\pptd40nt.exe -> ScanSoft, Inc. [Ver = 9.0 | Size = 57393 bytes | Modified Date = 3/17/2005 2:25:54 PM | Attr = ] brmfcwnd.exe -> %ProgramFiles%\Brother\Brmfcmon\BrMfcWnd.exe -> [Ver = 2, 0, 0, 10 | Size = 622592 bytes | Modified Date = 3/28/2006 3:48:54 PM | Attr = R ] taskswitch.exe -> %SystemRoot%\system32\TaskSwitch.exe -> [Ver = | Size = 45632 bytes | Modified Date = 3/19/2002 5:30:00 PM | Attr = ] ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.6.1.9 | Size = 267048 bytes | Modified Date = 2/19/2008 1:10:32 PM | Attr = ] acrotray.exe -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe -> Adobe Systems Inc. [Ver = 8.1.2.2008011100 | Size = 623992 bytes | Modified Date = 1/11/2008 7:54:31 PM | Attr = ] setpoint.exe -> %ProgramFiles%\Logitech\SetPoint\SetPoint.exe -> Logitech Inc. [Ver = 4.00.121 | Size = 692224 bytes | Modified Date = 4/23/2007 4:00:00 AM | Attr = ] natspeak.exe -> %ProgramFiles%\Nuance\NaturallySpeaking9\Program\natspeak.exe -> Nuance Communications, Inc. [Ver = 9.10.000.097 | Size = 2332264 bytes | Modified Date = 7/4/2007 3:04:37 PM | Attr = ] khalmnpr.exe -> %CommonProgramFiles%\Logitech\KhalShared\KHALMNPR.exe -> Logitech Inc. [Ver = 4.00.101 | Size = 56080 bytes | Modified Date = 4/11/2007 3:32:22 PM | Attr = ] brmfcmon.exe -> %ProgramFiles%\Brother\Brmfcmon\BrMfcMon.exe -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 69632 bytes | Modified Date = 3/1/2006 4:06:22 PM | Attr = ] ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.1.9 | Size = 504104 bytes | Modified Date = 2/19/2008 1:10:24 PM | Attr = ] fnplicensingservice.exe -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Modified Date = 2/29/2008 6:13:34 PM | Attr = ] devldr32.exe -> %SystemRoot%\system32\devldr32.exe -> Creative Technology Ltd. [Ver = 1, 0, 0, 17 | Size = 24064 bytes | Modified Date = 8/17/2001 4:36:42 PM | Attr = ] retrorun.exe -> %ProgramFiles%\Dantz\Retrospect Express HD\retrorun.exe -> Dantz Development Corporation [Ver = 1.0.196 | Size = 69632 bytes | Modified Date = 7/30/2004 3:47:36 PM | Attr = ] winpfind35u.exe -> %UserProfile%\Desktop\WinPFind35u\WinPFind35U.exe -> OldTimer Tools [Ver = 1.0.3.0 | Size = 310784 bytes | Modified Date = 3/1/2008 1:06:42 AM | Attr = ] [Win32 Services - Non-Microsoft Only] (Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 9/6/2007 12:28:18 PM | Attr = ] (Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> Apple Inc. [Ver = 1,0,4,12 | Size = 229376 bytes | Modified Date = 7/24/2007 3:17:08 PM | Attr = ] (dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] (DTSRVC) Portrait Displays Display Tune Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Portrait Displays\Shared\DTSRVC.exe -> [Ver = | Size = 73728 bytes | Modified Date = 6/29/2007 5:54:16 PM | Attr = ] (FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Running] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Modified Date = 2/29/2008 6:13:34 PM | Attr = ] (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\1050\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 10.50.125 | Size = 73728 bytes | Modified Date = 10/22/2004 2:24:18 AM | Attr = ] (iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.1.9 | Size = 504104 bytes | Modified Date = 2/19/2008 1:10:24 PM | Attr = ] (NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.11.6218 | Size = 155716 bytes | Modified Date = 8/13/2007 3:14:13 PM | Attr = ] (RetroExp Helper) Retrospect Express HD Restore Helper [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Dantz\Retrospect Express HD\rthlpsvc.exe -> Dantz Development Corporation [Ver = 1.0.196 | Size = 110592 bytes | Modified Date = 7/30/2004 3:47:36 PM | Attr = ] (RetroExpLauncher) Retrospect Express HD Launcher [Win32_Own | Auto | Running] -> %ProgramFiles%\Dantz\Retrospect Express HD\retrorun.exe -> Dantz Development Corporation [Ver = 1.0.196 | Size = 69632 bytes | Modified Date = 7/30/2004 3:47:36 PM | Attr = ] [Driver Services - Non-Microsoft Only] (Abiosdsk) Abiosdsk [Kernel | Disabled | Stopped] -> -> File not found (abp480n5) abp480n5 [Kernel | Disabled | Stopped] -> -> File not found (adpu160m) adpu160m [Kernel | Disabled | Stopped] -> -> File not found (AgereSoftModem) Agere Systems Soft Modem [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\AGRSM.sys -> Agere Systems [Ver = 2.1.51 2.1.51 03/04/2005 12:02:18 | Size = 1066278 bytes | Modified Date = 3/4/2005 12:02:20 PM | Attr = ] (Aha154x) Aha154x [Kernel | Disabled | Stopped] -> -> File not found (aic78u2) aic78u2 [Kernel | Disabled | Stopped] -> -> File not found (aic78xx) aic78xx [Kernel | Disabled | Stopped] -> -> File not found (AliIde) AliIde [Kernel | Disabled | Stopped] -> -> File not found (amsint) amsint [Kernel | Disabled | Stopped] -> -> File not found (asc) asc [Kernel | Disabled | Stopped] -> -> File not found (asc3350p) asc3350p [Kernel | Disabled | Stopped] -> -> File not found (asc3550) asc3550 [Kernel | Disabled | Stopped] -> -> File not found (Atdisk) Atdisk [Kernel | Disabled | Stopped] -> -> File not found (BrScnUsb) Brother USB Still Image driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\BrScnUsb.sys -> Brother Industries Ltd. [Ver = 1,0,2,1 | Size = 15295 bytes | Modified Date = 10/15/2004 12:50:20 PM | Attr = ] (cd20xrnt) cd20xrnt [Kernel | Disabled | Stopped] -> -> File not found (Changer) Changer [Kernel | System | Stopped] -> -> File not found (CmdIde) CmdIde [Kernel | Disabled | Stopped] -> -> File not found (Cpqarray) Cpqarray [Kernel | Disabled | Stopped] -> -> File not found (ctljystk) Creative SBLive! Gameport [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ctljystk.sys -> Creative Technology Ltd. [Ver = 5.1.2501.0 built by: WinDDK | Size = 3712 bytes | Modified Date = 8/17/2001 6:19:20 AM | Attr = ] (dac960nt) dac960nt [Kernel | Disabled | Stopped] -> -> File not found (DgivEcp) Team MFP Comm Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\DgivEcp.sys -> DeviceGuys, Inc. [Ver = 1.0.0.21 | Size = 38400 bytes | Modified Date = 1/29/1999 2:33:24 PM | Attr = ] (dmboot) dmboot [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 799744 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] (dmio) dmio [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 153344 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] (dmload) dmload [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmload.sys -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] (dpti2o) dpti2o [Kernel | Disabled | Stopped] -> -> File not found (emu10k) Creative SB Live! (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\emu10k1m.sys -> Creative Technology Ltd. [Ver = 5.12.01.3300 built by: WinDDK | Size = 283904 bytes | Modified Date = 8/17/2001 6:19:26 AM | Attr = ] (emu10k1) Creative Interface Manager Driver (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ctlfacem.sys -> Creative Technology Ltd. [Ver = 5.12.01.2108 built by: WinDDK | Size = 6912 bytes | Modified Date = 8/17/2001 6:19:28 AM | Attr = ] (FETNDIS) VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fetnd5.sys -> VIA Technologies, Inc. [Ver = 2.66 | Size = 27165 bytes | Modified Date = 8/17/2001 6:13:08 AM | Attr = ] (FETNDISB) VIA Rhine Family Fast Ethernet Adapter Driver Service [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\fetnd5b.sys -> VIA Technologies, Inc. [Ver = 3.32.00.0417 | Size = 42496 bytes | Modified Date = 4/14/2004 8:57:20 PM | Attr = R ] (GEARAspiWDM) GEARAspiWDM [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.0.6.1 | Size = 15664 bytes | Modified Date = 9/19/2006 3:44:04 PM | Attr = ] (GMSIPCI) GMSIPCI [Kernel | On_Demand | Stopped] -> D:\INSTALL\GMSIPCI.SYS -> File not found (hpn) hpn [Kernel | Disabled | Stopped] -> -> File not found (i2omgmt) i2omgmt [Kernel | System | Stopped] -> -> File not found (i2omp) i2omp [Kernel | Disabled | Stopped] -> -> File not found (ini910u) ini910u [Kernel | Disabled | Stopped] -> -> File not found (IntelIde) IntelIde [Kernel | Disabled | Stopped] -> -> File not found (L8042mou) SetPoint PS/2 Mouse Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\L8042mou.Sys -> Logitech Inc. [Ver = 4.00.101.00 | Size = 63248 bytes | Modified Date = 4/11/2007 3:32:38 PM | Attr = ] (lbrtfdc) lbrtfdc [Kernel | System | Stopped] -> -> File not found (LHidFilt) Logitech SetPoint KMDF HID Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\LHidFilt.Sys -> Logitech, Inc. [Ver = 4.00.101.00 | Size = 34832 bytes | Modified Date = 4/11/2007 3:32:52 PM | Attr = ] (LMouFilt) Logitech SetPoint KMDF Mouse Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\LMouFilt.Sys -> Logitech, Inc. [Ver = 4.00.101.00 | Size = 36112 bytes | Modified Date = 4/11/2007 3:32:58 PM | Attr = ] (LMouKE) SetPoint Mouse Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LMouKE.Sys -> Logitech Inc. [Ver = 4.00.101.00 | Size = 79376 bytes | Modified Date = 4/11/2007 3:33:06 PM | Attr = ] (LycoFltr) Lycosa Keyboard [Kernel | On_Demand | Stopped] -> System32\Drivers\Lycosa.sys -> File not found (mraid35x) mraid35x [Kernel | Disabled | Stopped] -> -> File not found (MXOFX) USB Storage Adapter FX (MXO) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\MXOFX.SYS -> Cypress Semiconductor [Ver = 6.01.1000.0 | Size = 32640 bytes | Modified Date = 10/10/2003 4:23:48 AM | Attr = ] (MXOPSWD) Maxtor OneTouch Security Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\mxopswd.sys -> Maxtor Corp. [Ver = 1,0,6,0 | Size = 15360 bytes | Modified Date = 10/7/2004 10:21:22 AM | Attr = ] (ntload) ntload v0.1 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\ntload.sys -> [Ver = | Size = 2752 bytes | Modified Date = 3/1/2008 12:42:18 PM | Attr = ] (nv) nv [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\nv4_mini.sys -> NVIDIA Corporation [Ver = 6.14.11.6218 | Size = 6807328 bytes | Modified Date = 8/13/2007 3:14:03 PM | Attr = ] (PCIDump) PCIDump [Kernel | System | Stopped] -> -> File not found (PCIIde) PCIIde [Kernel | Disabled | Stopped] -> -> File not found (PDCOMP) PDCOMP [Kernel | On_Demand | Stopped] -> -> File not found (PDFRAME) PDFRAME [Kernel | On_Demand | Stopped] -> -> File not found (pdiddcci) DDC/CI monitor [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\pdiddcci.sys -> Portrait Displays, Inc. [Ver = 1.00 built by: WinDDK | Size = 11776 bytes | Modified Date = 6/12/2007 11:27:00 AM | Attr = ] (PdiPorts) Portrait Displays low level device driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\PdiPorts.sys -> Portrait Displays, Inc. [Ver = 1.00 built by: WinDDK | Size = 15920 bytes | Modified Date = 11/16/2006 5:20:48 PM | Attr = ] (PDRELI) PDRELI [Kernel | On_Demand | Stopped] -> -> File not found (PDRFRAME) PDRFRAME [Kernel | On_Demand | Stopped] -> -> File not found (perc2) perc2 [Kernel | Disabled | Stopped] -> -> File not found (perc2hib) perc2hib [Kernel | Disabled | Stopped] -> -> File not found (Pivot) Pivot [Kernel | System | Running] -> %SystemRoot%\system32\drivers\pivot.sys -> Portrait Displays, Inc. [Ver = 8.21 | Size = 17465 bytes | Modified Date = 2/9/2007 12:17:18 PM | Attr = ] (pivotmou) Pivot Mouse/Pointers Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\pivotmou.sys -> Portrait Displays, Inc. [Ver = 8.21 | Size = 11323 bytes | Modified Date = 2/9/2007 12:17:16 PM | Attr = ] (Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\PxHelp20.sys -> Sonic Solutions [Ver = 3.00.56a | Size = 43528 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] (ql1080) ql1080 [Kernel | Disabled | Stopped] -> -> File not found (Ql10wnt) Ql10wnt [Kernel | Disabled | Stopped] -> -> File not found (ql12160) ql12160 [Kernel | Disabled | Stopped] -> -> File not found (ql1240) ql1240 [Kernel | Disabled | Stopped] -> -> File not found (ql1280) ql1280 [Kernel | Disabled | Stopped] -> -> File not found (Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. [Ver = 4.03.086 | Size = 20480 bytes | Modified Date = 11/13/2007 4:25:53 AM | Attr = ] (sfman) Creative SoundFont Manager Driver (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\sfmanm.sys -> Creative Technology Ltd. [Ver = 4.10.3300 | Size = 36480 bytes | Modified Date = 8/17/2001 6:19:34 AM | Attr = ] (Simbad) Simbad [Kernel | Disabled | Stopped] -> -> File not found (Sparrow) Sparrow [Kernel | Disabled | Stopped] -> -> File not found (symc810) symc810 [Kernel | Disabled | Stopped] -> -> File not found (symc8xx) symc8xx [Kernel | Disabled | Stopped] -> -> File not found (sym_hi) sym_hi [Kernel | Disabled | Stopped] -> -> File not found (sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> -> File not found (tbhsd) Tunebite High-Speed Dubbing [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\tbhsd.sys -> RapidSolution Software AG [Ver = 2, 0, 0, 0 | Size = 14464 bytes | Modified Date = 4/19/2006 5:06:24 PM | Attr = ] (TosIde) TosIde [Kernel | Disabled | Stopped] -> -> File not found (ultra) ultra [Kernel | Disabled | Stopped] -> -> File not found (viagfx) viagfx [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\vtmini.sys -> Copyright (C) VIA/S3 Graphics, Inc. [Ver = 6.14.10.0113-16.94.35.11 | Size = 134144 bytes | Modified Date = 2/3/2004 8:28:00 PM | Attr = R ] (WDICA) WDICA [Kernel | On_Demand | Stopped] -> -> File not found [Registry - Non-Microsoft Only] < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> -> -> File not found Acrobat Assistant 8.0 -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe -> Adobe Systems Inc. [Ver = 8.1.2.2008011100 | Size = 623992 bytes | Modified Date = 1/11/2008 7:54:31 PM | Attr = ] Adobe Reader Speed Launcher -> %ProgramFiles%\Adobe\Reader 8.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 8.0.0.0 | Size = 39792 bytes | Modified Date = 1/11/2008 10:16:38 PM | Attr = ] BrMfcWnd -> %ProgramFiles%\Brother\Brmfcmon\BrMfcWnd.exe -> [Ver = 2, 0, 0, 10 | Size = 622592 bytes | Modified Date = 3/28/2006 3:48:54 PM | Attr = R ] CoolSwitch -> %SystemRoot%\system32\TaskSwitch.exe -> [Ver = | Size = 45632 bytes | Modified Date = 3/19/2002 5:30:00 PM | Attr = ] IndexSearch -> %ProgramFiles%\ScanSoft\PaperPort\IndexSearch.exe -> ScanSoft, Inc. [Ver = 9.0 | Size = 40960 bytes | Modified Date = 3/17/2005 2:45:52 PM | Attr = ] iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.6.1.9 | Size = 267048 bytes | Modified Date = 2/19/2008 1:10:32 PM | Attr = ] Kernel and Hardware Abstraction Layer -> %SystemRoot%\KHALMNPR.Exe -> Logitech Inc. [Ver = 4.00.101 | Size = 56080 bytes | Modified Date = 4/11/2007 3:32:22 PM | Attr = ] Logitech Hardware Abstraction Layer -> %SystemRoot%\KHALMNPR.Exe -> Logitech Inc. [Ver = 4.00.101 | Size = 56080 bytes | Modified Date = 4/11/2007 3:32:22 PM | Attr = ] MaxtorOneTouch -> %ProgramFiles%\Maxtor\OneTouch\Utils\OneTouch.exe -> Maxtor Corporation [Ver = 3, 0, 0, 2 | Size = 823296 bytes | Modified Date = 12/22/2004 8:21:48 AM | Attr = ] MSDrive -> %SystemRoot%\system32\drvwav.dll -> [Ver = | Size = 103936 bytes | Modified Date = 3/1/2008 12:29:34 PM | Attr = ] PaperPort PTD -> %ProgramFiles%\ScanSoft\PaperPort\pptd40nt.exe -> ScanSoft, Inc. [Ver = 9.0 | Size = 57393 bytes | Modified Date = 3/17/2005 2:25:54 PM | Attr = ] QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.4.1 | Size = 385024 bytes | Modified Date = 1/31/2008 11:13:08 PM | Attr = ] RetroExpress -> %ProgramFiles%\Dantz\Retrospect Express HD\RetroExpress.exe -> Dantz Development Corporation [Ver = 1.0.196.0 | Size = 6946816 bytes | Modified Date = 7/30/2004 3:47:36 PM | Attr = ] SetDefPrt -> %ProgramFiles%\Brother\Brmfl06a\BrStDvPt.exe -> Brother Industories, Ltd. [Ver = 1, 0, 1, 2 | Size = 49152 bytes | Modified Date = 1/26/2005 6:02:22 PM | Attr = ] SSBkgdUpdate -> %CommonProgramFiles%\Scansoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe -> Scansoft, Inc. [Ver = 1, 0, 0, 6 | Size = 155648 bytes | Modified Date = 9/29/2003 4:00:20 PM | Attr = ] SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_03\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 12:11:35 AM | Attr = ] < OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> IMAIL-> Installed = 1 -> MAPI-> Installed = 1 -> MSFS-> Installed = 1 -> < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> updateMgr -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe -> File not found < All Users Startup Folder > -> F:\Documents and Settings\All Users\Start Menu\Programs\Startup -> %AllUsersProfile%\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk -> %CommonProgramFiles%\Adobe\Calibration\Adobe Gamma Loader.exe -> Adobe Systems, Inc. [Ver = 1, 0, 0, 1 | Size = 113664 bytes | Modified Date = 11/4/1999 3:06:48 PM | Attr = ] %AllUsersProfile%\Start Menu\Programs\Startup\Logitech SetPoint.lnk -> %ProgramFiles%\Logitech\SetPoint\SetPoint.exe -> Logitech Inc. [Ver = 4.00.121 | Size = 692224 bytes | Modified Date = 4/23/2007 4:00:00 AM | Attr = ] < Patrick Startup Folder > -> F:\Documents and Settings\Patrick\Start Menu\Programs\Startup -> %UserProfile%\Start Menu\Programs\Startup\Dragon NaturallySpeaking.lnk -> %ProgramFiles%\Nuance\NaturallySpeaking9\Program\natspeak.exe -> Nuance Communications, Inc. [Ver = 9.10.000.097 | Size = 2332264 bytes | Modified Date = 7/4/2007 3:04:37 PM | Attr = ] %UserProfile%\Start Menu\Programs\Startup\Webshots.lnk -> %ProgramFiles%\Webshots\Launcher.exe -> [Ver = | Size = 45056 bytes | Modified Date = 12/19/2005 11:37:18 AM | Attr = ] < SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad -> {a5e2f611-2610-487a-a541-9a3ba3a9c68b} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\Installer\{a5e2f611-2610-487a-a541-9a3ba3a9c68b}\ServicePrx.dll [ServicePrx] -> [Ver = | Size = 14374 bytes | Modified Date = 3/1/2008 12:29:31 PM | Attr = RHS] {a6537a26-77fd-42d4-9947-c3406e62b832} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\Installer\{a6537a26-77fd-42d4-9947-c3406e62b832}\zip.dll [zip] -> [Ver = | Size = 38438 bytes | Modified Date = 3/1/2008 12:29:36 PM | Attr = RHS] < ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> {0B52C7EC-D1A3-4054-923C-DD12567F28B1} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\byxuuvs.dll [] -> [Ver = | Size = 35328 bytes | Modified Date = 3/1/2008 12:28:40 PM | Attr = ] < SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> byxuuvs -> %SystemRoot%\system32\byxuuvs.dll -> [Ver = | Size = 35328 bytes | Modified Date = 3/1/2008 12:28:40 PM | Attr = ] < CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> < CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < HOSTS File > (734 bytes) -> F:\WINDOWS\System32\drivers\etc\Hosts -> < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.msn.com/ -> HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\Local Page -> F:\WINDOWS\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: Main\\Start Page -> http://www.msnbc.com/ -> HKEY_CURRENT_USER\: ProxyEnable -> 0 -> < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 1 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Adobe Systems Incorporated [Ver = 8.0.0.2006102200 | Size = 62080 bytes | Modified Date = 10/22/2006 11:08:42 PM | Attr = ] {0B52C7EC-D1A3-4054-923C-DD12567F28B1} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\byxuuvs.dll [Reg Error: Value does not exist or could not be read.] -> [Ver = | Size = 35328 bytes | Modified Date = 3/1/2008 12:28:40 PM | Attr = ] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 501136 bytes | Modified Date = 9/25/2007 12:11:33 AM | Attr = ] {7E74B279-FC5B-43C5-BD8B-C25E725279E0} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\vtutu.dll [Reg Error: Value does not exist or could not be read.] -> [Ver = | Size = 321024 bytes | Modified Date = 3/1/2008 1:47:03 PM | Attr = ] {AE7CD045-E861-484f-8273-0445EE161910} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [Adobe PDF Conversion Toolbar Helper] -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 10:47:03 PM | Attr = ] < Internet Explorer Bars [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {182EC0BE-5110-49C8-A062-BEB1D02A220B} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 10:47:03 PM | Attr = ] < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> {3F5A62E2-51F2-11D3-A075-CC7364CAE42A} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\wscmp.dll [&WinSec Toolbar] -> [Ver = | Size = 230912 bytes | Modified Date = 3/1/2008 1:43:04 PM | Attr = ] {47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 10:47:03 PM | Attr = ] < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 10:47:03 PM | Attr = ] WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn\yt.dll [Yahoo! Toolbar] -> File not found < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 12:11:34 AM | Attr = ] {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} [HKEY_CURRENT_USER] -> %ProgramFiles%\Java\jre1.6.0_03\bin\ssv.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 501136 bytes | Modified Date = 9/25/2007 12:11:33 AM | Attr = ] < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 12:11:34 AM | Attr = ] < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> Append to existing PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 10:47:03 PM | Attr = ] Convert link target to Adobe PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 10:47:03 PM | Attr = ] Convert link target to existing PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 10:47:03 PM | Attr = ] Convert selected links to Adobe PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 10:47:03 PM | Attr = ] Convert selected links to existing PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 10:47:03 PM | Attr = ] Convert selection to Adobe PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 10:47:03 PM | Attr = ] Convert selection to existing PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 10:47:03 PM | Attr = ] Convert to Adobe PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 10:47:03 PM | Attr = ] < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {FAED1671-BA20-4BC7-A277-9140CE46D5AA} -> (VIA Rhine II Fast Ethernet Adapter) -> < Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] -> %ProgramFiles%\Bonjour\mdnsNSP.dll -> Apple Inc. [Ver = 1,0,4,12 | Size = 147456 bytes | Modified Date = 7/24/2007 3:17:08 PM | Attr = ] < Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab[Java Plug-in 1.5.0_06] -> {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab[Java Plug-in 1.5.0_09] -> {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab[Java Plug-in 1.5.0_11] -> {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab[Java Plug-in 1.6.0_01] -> {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab[Java Plug-in 1.6.0_02] -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> [Registry - Additional Scans - Non-Microsoft Only] < BotCheck > -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\DefaultLaunchPermission -> (binary data) -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineLaunchRestriction -> (binary data) -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineAccessRestriction -> (binary data) -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableDCOM -> Y -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{A50398B8-9075-4FBF-A7A1-456BF21937AD} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{AD65A69D-3831-40D7-9629-9B0B50A93843} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{0040D221-54A1-11D1-9DE0-006097042D69} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\\System.EnterpriseServices.Thunk.dll -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirstRunDisabled -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> -> Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ not found. -> -> Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ not found. -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ -> -> *Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] F:\WINDOWS\system32\vtutu.dll -> %SystemRoot%\system32\vtutu.dll -> [Ver = | Size = 321024 bytes | Modified Date = 3/1/2008 1:47:03 PM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Bounds -> (binary data) -> *Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> kerberos -> %SystemRoot%\system32\kerberos.dll -> Microsoft Corporation [Ver = 5.1.2600.2698 (xpsp_sp2_gdr.050614-1522) | Size = 295936 bytes | Modified Date = 6/15/2005 11:49:30 AM | Attr = ] msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] schannel -> %SystemRoot%\system32\schannel.dll -> Microsoft Corporation [Ver = 5.1.2600.3126 (xpsp_sp2_gdr.070425-0226) | Size = 144896 bytes | Modified Date = 4/25/2007 8:21:15 AM | Attr = ] wdigest -> %SystemRoot%\system32\wdigest.dll -> Microsoft Corporation [Ver = 5.1.2600.2874 (xpsp_sp2_gdr.060323-1516) | Size = 49152 bytes | Modified Date = 3/23/2006 10:37:50 PM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\ImpersonatePrivilegeUpgradeToolHasRun -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\LsaPid -> 664 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\SecureBoot -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\auditbaseobjects -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\crashonauditfail -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\disabledomaincreds -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\everyoneincludesanonymous -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fipsalgorithmpolicy -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\forceguest -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fullprivilegeauditing -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\limitblankpassworduse -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\lmcompatibilitylevel -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nodefaultadminowner -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nolmhash -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymous -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymoussam -> 1 -> *Notification Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Notification Packages -> scecli -> %SystemRoot%\system32\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 180224 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\ -> -> *ProviderOrder* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\\ProviderOrder -> Windows NT Access Provider -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\\ProviderPath -> F:\WINDOWS\system32\ntmarta.dll [%SystemRoot%\system32\ntmarta.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 118784 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\\Pattern -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\\GrafBlumGroup -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\\Lookup -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminclientsec -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminserversec -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\\SkewMatrix -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\\SSOURL -> http://www.passport.com -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\\Time -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Name -> Digest -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Comment -> Digest SSPI Authentication Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Capabilities -> 16464 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\RpcId -> 65535 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\TokenSize -> 65535 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Time -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Name -> DPA -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Comment -> DPA Security Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Capabilities -> 55 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\RpcId -> 17 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\TokenSize -> 768 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Time -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Name -> MSN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Comment -> MSN Security Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Capabilities -> 55 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\RpcId -> 18 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\TokenSize -> 768 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Time -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> F:\WINDOWS\system32\svchost.exe [%SystemRoot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 52539 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> F:\WINDOWS\system32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> F:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\Network Diagnostic\xpnetdiag.exe -> F:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> Microsoft Corporation [Ver = 5.1.2600.2946 (xpsp.060706-0011) | Size = 557568 bytes | Modified Date = 7/6/2006 2:49:52 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> F:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\F:\Program Files\TVU Player\TVUPlayer.exe -> F:\Program Files\TVU Player\TVUPlayer.exe [F:\Program Files\TVU Player\TVUPlayer.exe:*:Enabled:TVUPlayer] -> TVU Networks [Ver = 2,2,0,0 | Size = 487424 bytes | Modified Date = 8/4/2006 2:03:28 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\F:\Program Files\Mozilla Firefox\firefox.exe -> F:\Program Files\Mozilla Firefox\firefox.exe [F:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox] -> Mozilla Corporation [Ver = 1.8.1.12: 2008020121 | Size = 7655024 bytes | Modified Date = 2/8/2008 10:19:19 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\F:\Program Files\Participatory Culture Foundation\Democracy Player\Democracy_Downloader.exe -> F:\Program Files\Participatory Culture Foundation\Democracy Player\Democracy_Downloader.exe [F:\Program Files\Participatory Culture Foundation\Democracy Player\Democracy_Downloader.exe:*:Enabled:Democracy_Downloader] -> [Ver = | Size = 9882046 bytes | Modified Date = 6/21/2007 10:58:40 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\Network Diagnostic\xpnetdiag.exe -> F:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> Microsoft Corporation [Ver = 5.1.2600.2946 (xpsp.060706-0011) | Size = 557568 bytes | Modified Date = 7/6/2006 2:49:52 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\F:\Program Files\Java\jre1.6.0_01\bin\javaw.exe -> F:\Program Files\Java\jre1.6.0_01\bin\javaw.exe [F:\Program Files\Java\jre1.6.0_01\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 135168 bytes | Modified Date = 3/13/2007 11:31:28 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\F:\Program Files\Participatory Culture Foundation\Miro\Miro_Downloader.exe -> F:\Program Files\Participatory Culture Foundation\Miro\Miro_Downloader.exe [F:\Program Files\Participatory Culture Foundation\Miro\Miro_Downloader.exe:*:Enabled:Miro_Downloader] -> [Ver = | Size = 4138882 bytes | Modified Date = 1/10/2008 3:26:16 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\F:\Program Files\Joost\xulrunner\tvprunner.exe -> F:\Program Files\Joost\xulrunner\tvprunner.exe [F:\Program Files\Joost\xulrunner\tvprunner.exe:*:Enabled:tvprunner] -> Joost Technologies B.V. [Ver = 1.9a5pre: 2007112910 | Size = 2560672 bytes | Modified Date = 11/29/2007 4:01:26 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\F:\Program Files\SopCast\adv\SopAdver.exe -> F:\Program Files\SopCast\adv\SopAdver.exe [F:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver] -> www.sopcast.com [Ver = 2, 0, 4, 0 | Size = 567384 bytes | Modified Date = 12/13/2007 1:33:12 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\F:\Program Files\SopCast\SopCast.exe -> F:\Program Files\SopCast\SopCast.exe [F:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application] -> www.sopcast.com [Ver = 2.0.4.1212 | Size = 1888256 bytes | Modified Date = 12/13/2007 1:37:56 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\F:\Program Files\SopCast\sopvod.exe -> F:\Program Files\SopCast\sopvod.exe [F:\Program Files\SopCast\sopvod.exe:*:Enabled:sopvod] -> [Ver = | Size = 1427560 bytes | Modified Date = 12/13/2007 1:33:04 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\F:\Program Files\Bonjour\mDNSResponder.exe -> F:\Program Files\Bonjour\mDNSResponder.exe [F:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> Apple Inc. [Ver = 1,0,4,12 | Size = 229376 bytes | Modified Date = 7/24/2007 3:17:08 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\F:\Program Files\iTunes\iTunes.exe -> F:\Program Files\iTunes\iTunes.exe [F:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> Apple Inc. [Ver = 7.6.1.9 | Size = 19897640 bytes | Modified Date = 2/19/2008 1:10:26 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\F:\DOCUME~1\Patrick\LOCALS~1\Temp\win27.exe -> F:\DOCUME~1\Patrick\LOCALS~1\Temp\win27.exe [F:\DOCUME~1\Patrick\LOCALS~1\Temp\win27.exe:*:Enabled:win27] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> F:\WINDOWS\system32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> F:\WINDOWS\system32\wuauserv.dll [F:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Modified Date = 8/4/2004 6:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\ not found. -> -> Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\ not found. -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable -> 0 -> [Files/Folders - Created Within 30 days] cdr4_xp.sys -> %SystemRoot%\System32\drivers\cdr4_xp.sys -> Sonic Solutions [Ver = 8.0.0.212 | Size = 9336 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] cdralw2k.sys -> %SystemRoot%\System32\drivers\cdralw2k.sys -> Sonic Solutions [Ver = 8.0.0.212 | Size = 9464 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] PxHelp20.sys -> %SystemRoot%\System32\drivers\PxHelp20.sys -> Sonic Solutions [Ver = 3.00.56a | Size = 43528 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] byxuuvs.dll -> %SystemRoot%\System32\byxuuvs.dll -> [Ver = | Size = 35328 bytes | Modified Date = 3/1/2008 12:28:40 PM | Attr = ] cbxurom.dll -> %SystemRoot%\System32\cbxurom.dll -> [Ver = | Size = 35328 bytes | Modified Date = 3/1/2008 12:30:29 PM | Attr = ] drvwav.dll -> %SystemRoot%\System32\drvwav.dll -> [Ver = | Size = 103936 bytes | Modified Date = 3/1/2008 12:29:34 PM | Attr = ] drvwavr.dll -> %SystemRoot%\System32\drvwavr.dll -> [Ver = | Size = 15360 bytes | Modified Date = 3/1/2008 12:29:34 PM | Attr = ] ntload.sys -> %SystemRoot%\System32\ntload.sys -> [Ver = | Size = 2752 bytes | Modified Date = 3/1/2008 12:42:18 PM | Attr = ] opnoonk.dll -> %SystemRoot%\System32\opnoonk.dll -> [Ver = | Size = 35328 bytes | Modified Date = 3/1/2008 12:29:02 PM | Attr = ] px.dll -> %SystemRoot%\System32\px.dll -> Sonic Solutions [Ver = 4.0.36.500 | Size = 551672 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] pxafs.dll -> %SystemRoot%\System32\pxafs.dll -> Sonic Solutions [Ver = 4.0.36.500 | Size = 129784 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] pxcpya64.exe -> %SystemRoot%\System32\pxcpya64.exe -> Sonic Solutions [Ver = 1.00.44B | Size = 66296 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] pxcpyi64.exe -> %SystemRoot%\System32\pxcpyi64.exe -> Sonic Solutions [Ver = 1.00.44B | Size = 120056 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] pxdrv.dll -> %SystemRoot%\System32\pxdrv.dll -> Sonic Solutions [Ver = 1.02.09a | Size = 518904 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] pxhpinst.exe -> %SystemRoot%\System32\pxhpinst.exe -> Sonic Solutions [Ver = 3.00.64a | Size = 72440 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] pxinsa64.exe -> %SystemRoot%\System32\pxinsa64.exe -> Sonic Solutions [Ver = 3.00.64a | Size = 64760 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] pxinsi64.exe -> %SystemRoot%\System32\pxinsi64.exe -> Sonic Solutions [Ver = 3.00.64a | Size = 118520 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] pxmas.dll -> %SystemRoot%\System32\pxmas.dll -> Sonic Solutions [Ver = 4.0.36.500 | Size = 187128 bytes | Modified Date = 1/4/2008 3:58:48 PM | Attr = ] pxsfs.dll -> %SystemRoot%\System32\pxsfs.dll -> Sonic Solutions [Ver = 4.0.36.500 | Size = 1628920 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] pxwave.dll -> %SystemRoot%\System32\pxwave.dll -> Sonic Solutions [Ver = 4.0.36.500 | Size = 379640 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] QuickTime.qts -> %SystemRoot%\System32\QuickTime.qts -> Apple Inc. [Ver = 7.4.1 | Size = 57344 bytes | Modified Date = 1/31/2008 11:13:18 PM | Attr = ] QuickTimeVR.qtx -> %SystemRoot%\System32\QuickTimeVR.qtx -> Apple Inc. [Ver = 7.4.1 | Size = 90112 bytes | Modified Date = 1/31/2008 11:13:18 PM | Attr = ] sex1.ico -> %SystemRoot%\System32\sex1.ico -> [Ver = | Size = 3262 bytes | Modified Date = 3/1/2008 12:31:54 PM | Attr = ] sex2.ico -> %SystemRoot%\System32\sex2.ico -> [Ver = | Size = 3262 bytes | Modified Date = 3/1/2008 12:32:28 PM | Attr = ] ututv.ini -> %SystemRoot%\System32\ututv.ini -> [Ver = | Size = 7126 bytes | Modified Date = 3/1/2008 1:51:14 PM | Attr = HS] ututv.ini2 -> %SystemRoot%\System32\ututv.ini2 -> [Ver = | Size = 6789 bytes | Modified Date = 3/1/2008 1:50:06 PM | Attr = HS] vtutu.dll -> %SystemRoot%\System32\vtutu.dll -> [Ver = | Size = 321024 bytes | Modified Date = 3/1/2008 1:47:03 PM | Attr = ] vxblock.dll -> %SystemRoot%\System32\vxblock.dll -> Sonic Solutions [Ver = 1.00.83a | Size = 88824 bytes | Modified Date = 1/4/2008 3:58:46 PM | Attr = ] winexy32.dll -> %SystemRoot%\System32\winexy32.dll -> [Ver = | Size = 23552 bytes | Modified Date = 3/1/2008 12:29:16 PM | Attr = ] winupdate.exe -> %SystemRoot%\System32\winupdate.exe -> [Ver = | Size = 87040 bytes | Modified Date = 3/1/2008 12:29:27 PM | Attr = ] wscmp.dll -> %SystemRoot%\System32\wscmp.dll -> [Ver = | Size = 230912 bytes | Modified Date = 3/1/2008 1:43:04 PM | Attr = ] yayyvwv.dll -> %SystemRoot%\System32\yayyvwv.dll -> [Ver = | Size = 39936 bytes | Modified Date = 3/1/2008 12:29:20 PM | Attr = ] ztvunacev2.dll -> %SystemRoot%\System32\ztvunacev2.dll -> [Ver = | Size = 75264 bytes | Modified Date = 6/9/2006 | Attr = ] ztvunrar3.dll -> %SystemRoot%\System32\ztvunrar3.dll -> [Ver = | Size = 156160 bytes | Modified Date = 6/9/2006 | Attr = ] QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 2/15/2008 4:21:20 PM | Attr = ] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 3/1/2008 12:42:14 PM | Attr = H ] unvise32.exe -> %SystemRoot%\unvise32.exe -> MindVision Software [Ver = 3.1.1 | Size = 86016 bytes | Modified Date = 12/17/1999 9:13:04 AM | Attr = ] [Files Created - Additional Folder Scans - Non-Microsoft Only] Adobe -> %AllUsersProfile%\Application Data\Adobe -> [Folder | Created Date = 2/19/2008 3:54:29 PM | Attr = ] FLEXnet -> %AllUsersProfile%\Application Data\FLEXnet -> [Folder | Created Date = 2/29/2008 6:13:39 PM | Attr = ] DivX -> %AppData%\DivX -> [Folder | Created Date = 2/18/2008 11:11:35 AM | Attr = ] PCF-VLC -> %AppData%\PCF-VLC -> [Folder | Created Date = 2/24/2008 7:25:01 PM | Attr = ] Updater5 -> %UserProfile%\My Documents\Updater5 -> [Folder | Created Date = 2/29/2008 6:14:41 PM | Attr = ] Adobe Acrobat 8 Professional.lnk -> %AllUsersProfile%\Desktop\Adobe Acrobat 8 Professional.lnk -> [Ver = | Size = 1736 bytes | Modified Date = 3/1/2008 12:10:20 PM | Attr = ] Adobe Reader 8.lnk -> %AllUsersProfile%\Desktop\Adobe Reader 8.lnk -> [Ver = | Size = 1729 bytes | Modified Date = 2/19/2008 3:54:44 PM | Attr = ] iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [Ver = | Size = 1804 bytes | Modified Date = 2/23/2008 2:02:15 AM | Attr = ] QuickTime Player.lnk -> %AllUsersProfile%\Desktop\QuickTime Player.lnk -> [Ver = | Size = 1604 bytes | Modified Date = 2/16/2008 11:53:13 AM | Attr = ] Adobe Acrobat 8 Professional -> %UserProfile%\Desktop\Adobe Acrobat 8 Professional -> [Folder | Created Date = 2/24/2008 4:34:13 PM | Attr = ] BDSM galleries.URL -> %UserProfile%\Desktop\BDSM galleries.URL -> [Ver = | Size = 59 bytes | Modified Date = 3/1/2008 12:52:17 PM | Attr = ] Now download WinPFind35u.doc -> %UserProfile%\Desktop\Now download WinPFind35u.doc -> [Ver = | Size = 26624 bytes | Modified Date = 3/1/2008 1:50:24 PM | Attr = ] PicoZip.lnk -> %UserProfile%\Desktop\PicoZip.lnk -> [Ver = | Size = 616 bytes | Modified Date = 2/3/2008 1:01:06 AM | Attr = ] Uncensored porn.URL -> %UserProfile%\Desktop\Uncensored porn.URL -> [Ver = | Size = 59 bytes | Modified Date = 3/1/2008 12:52:48 PM | Attr = ] WinPFind35u -> %UserProfile%\Desktop\WinPFind35u -> [Folder | Created Date = 3/1/2008 1:51:04 PM | Attr = ] WinPFind35u.exe -> %UserProfile%\Desktop\WinPFind35u.exe -> [Ver = | Size = 482000 bytes | Modified Date = 3/1/2008 1:46:59 PM | Attr = ] Macrovision Shared -> %CommonProgramFiles%\Macrovision Shared -> [Folder | Created Date = 2/29/2008 6:13:33 PM | Attr = ] [Files/Folders - Modified Within 30 days] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 3/1/2008 1:45:42 PM | Attr = R ] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 3/1/2008 12:42:46 PM | Attr = ] byxuuvs.dll -> %SystemRoot%\System32\byxuuvs.dll -> [Ver = | Size = 35328 bytes | Modified Date = 3/1/2008 12:28:40 PM | Attr = ] CatRoot2 -> %SystemRoot%\System32\CatRoot2 -> [Folder | Modified Date = 2/12/2008 3:26:54 PM | Attr = ] 13 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> cbxurom.dll -> %SystemRoot%\System32\cbxurom.dll -> [Ver = | Size = 35328 bytes | Modified Date = 3/1/2008 12:30:29 PM | Attr = ] dllcache -> %SystemRoot%\System32\dllcache -> [Folder | Modified Date = 2/13/2008 3:01:30 AM | Attr = RHS] drivers -> %SystemRoot%\System32\drivers -> [Folder | Modified Date = 2/16/2008 11:37:51 AM | Attr = ] DRVSTORE -> %SystemRoot%\System32\DRVSTORE -> [Folder | Modified Date = 2/1/2008 10:14:02 AM | Attr = ] drvwav.dll -> %SystemRoot%\System32\drvwav.dll -> [Ver = | Size = 103936 bytes | Modified Date = 3/1/2008 12:29:34 PM | Attr = ] drvwavr.dll -> %SystemRoot%\System32\drvwavr.dll -> [Ver = | Size = 15360 bytes | Modified Date = 3/1/2008 12:29:34 PM | Attr = ] FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [Ver = | Size = 123728 bytes | Modified Date = 3/1/2008 12:15:10 PM | Attr = ] ntload.sys -> %SystemRoot%\System32\ntload.sys -> [Ver = | Size = 2752 bytes | Modified Date = 3/1/2008 12:42:18 PM | Attr = ] opnoonk.dll -> %SystemRoot%\System32\opnoonk.dll -> [Ver = | Size = 35328 bytes | Modified Date = 3/1/2008 12:29:02 PM | Attr = ] perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [Ver = | Size = 52880 bytes | Modified Date = 3/1/2008 12:45:56 PM | Attr = ] perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [Ver = | Size = 380658 bytes | Modified Date = 3/1/2008 12:45:56 PM | Attr = ] PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [Ver = | Size = 439988 bytes | Modified Date = 3/1/2008 12:45:56 PM | Attr = ] QuickTime.qts -> %SystemRoot%\System32\QuickTime.qts -> Apple Inc. [Ver = 7.4.1 | Size = 57344 bytes | Modified Date = 1/31/2008 11:13:18 PM | Attr = ] QuickTimeVR.qtx -> %SystemRoot%\System32\QuickTimeVR.qtx -> Apple Inc. [Ver = 7.4.1 | Size = 90112 bytes | Modified Date = 1/31/2008 11:13:18 PM | Attr = ] sex1.ico -> %SystemRoot%\System32\sex1.ico -> [Ver = | Size = 3262 bytes | Modified Date = 3/1/2008 12:31:54 PM | Attr = ] sex2.ico -> %SystemRoot%\System32\sex2.ico -> [Ver = | Size = 3262 bytes | Modified Date = 3/1/2008 12:32:28 PM | Attr = ] ututv.ini -> %SystemRoot%\System32\ututv.ini -> [Ver = | Size = 7126 bytes | Modified Date = 3/1/2008 1:51:14 PM | Attr = HS] ututv.ini2 -> %SystemRoot%\System32\ututv.ini2 -> [Ver = | Size = 6789 bytes | Modified Date = 3/1/2008 1:50:06 PM | Attr = HS] vtutu.dll -> %SystemRoot%\System32\vtutu.dll -> [Ver = | Size = 321024 bytes | Modified Date = 3/1/2008 1:47:03 PM | Attr = ] winexy32.dll -> %SystemRoot%\System32\winexy32.dll -> [Ver = | Size = 23552 bytes | Modified Date = 3/1/2008 12:29:16 PM | Attr = ] winupdate.exe -> %SystemRoot%\System32\winupdate.exe -> [Ver = | Size = 87040 bytes | Modified Date = 3/1/2008 12:29:27 PM | Attr = ] wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [Ver = | Size = 13646 bytes | Modified Date = 3/1/2008 12:42:27 PM | Attr = ] wscmp.dll -> %SystemRoot%\System32\wscmp.dll -> [Ver = | Size = 230912 bytes | Modified Date = 3/1/2008 1:43:04 PM | Attr = ] yayyvwv.dll -> %SystemRoot%\System32\yayyvwv.dll -> [Ver = | Size = 39936 bytes | Modified Date = 3/1/2008 12:29:20 PM | Attr = ] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 2/12/2008 3:26:40 PM | Attr = H ] 3 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 3/1/2008 12:41:37 PM | Attr = S] Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 2/29/2008 6:06:23 PM | Attr = R S] imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 2/13/2008 3:01:25 AM | Attr = ] inf -> %SystemRoot%\inf -> [Folder | Modified Date = 2/13/2008 3:01:31 AM | Attr = H ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 3/1/2008 12:29:35 PM | Attr = HS] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 3/1/2008 1:50:45 PM | Attr = ] QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 2/15/2008 4:21:20 PM | Attr = ] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 3/1/2008 12:42:14 PM | Attr = H ] Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 2/23/2008 4:00:50 AM | Attr = ] repair -> %SystemRoot%\repair -> [Folder | Modified Date = 3/1/2008 4:01:03 AM | Attr = ] system32 -> %SystemRoot%\system32 -> [Folder | Modified Date = 3/1/2008 1:47:05 PM | Attr = ] Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 2/1/2008 11:07:52 AM | Attr = S] Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 3/1/2008 1:47:16 PM | Attr = ] Webica.ini -> %SystemRoot%\Webica.ini -> [Ver = | Size = 99 bytes | Modified Date = 2/22/2008 2:05:31 PM | Attr = ] win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 862 bytes | Modified Date = 2/6/2008 7:51:30 PM | Attr = ] WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 2/29/2008 6:07:34 PM | Attr = ] AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [Ver = | Size = 284 bytes | Modified Date = 2/27/2008 9:50:02 AM | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 3/1/2008 12:41:48 PM | Attr = H ] qmgr0.dat -> F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [Ver = | Size = 4232 bytes | Modified Date = 2/12/2008 3:26:55 PM | Attr = ] qmgr1.dat -> F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [Ver = | Size = 4617 bytes | Modified Date = 2/12/2008 3:26:55 PM | Attr = ] _is10B.exe -> F:\Documents and Settings\Patrick\Local Settings\Temp\_is10B.exe -> Macrovision Corporation [Ver = 12.0.58849 | Size = 455600 bytes | Modified Date = 1/20/2007 5:46:42 AM | Attr = R ] _is541.exe -> F:\Documents and Settings\Patrick\Local Settings\Temp\_is541.exe -> Macrovision Corporation [Ver = 12.0.49974 | Size = 455600 bytes | Modified Date = 5/24/2006 11:10:42 AM | Attr = R ] 61 F:\Documents and Settings\Patrick\Local Settings\Temp\*.tmp files -> F:\Documents and Settings\Patrick\Local Settings\Temp\*.tmp -> BrMfcWnd.exe -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon\BrMfcWnd.exe -> [Ver = 2, 0, 0, 10 | Size = 622592 bytes | Modified Date = 3/28/2006 3:48:54 PM | Attr = R ] BrMfimon.exe -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon\BrMfimon.exe -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 204800 bytes | Modified Date = 2/22/2006 9:00:20 AM | Attr = ] BrccMCtl.exe -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\BrccMCtl.exe -> Brother Industries, Ltd. [Ver = 3, 0, 83, 83 | Size = 339968 bytes | Modified Date = 4/6/2006 9:11:02 PM | Attr = ] BrCCStoFix.exe -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\BrCCStoFix.exe -> Brother Industries, Ltd. [Ver = 1, 0, 2, 1 | Size = 49152 bytes | Modified Date = 6/18/2004 9:55:10 PM | Attr = ] BrCtrCen.exe -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\BrCtrCen.exe -> Brother Industries, Ltd. [Ver = 3, 0, 8, 2 | Size = 61440 bytes | Modified Date = 4/10/2006 2:58:06 PM | Attr = ] AXDIST.EXE -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\WebUpdate\AXDIST.EXE -> Microsoft Corporation [Ver = 4.71.0030.1 | Size = 803680 bytes | Modified Date = 1/28/2000 12:19:24 PM | Attr = ] WSH.EXE -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\WebUpdate\WSH.EXE -> Microsoft Corporation [Ver = 5.0.531.7 | Size = 574688 bytes | Modified Date = 1/28/2000 12:19:26 PM | Attr = ] BrmfcwndBul.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndBul.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 516096 bytes | Modified Date = 3/3/2006 6:26:42 PM | Attr = ] BrmfcwndChn.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndChn.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 1 | Size = 512000 bytes | Modified Date = 3/3/2006 8:56:06 PM | Attr = ] BrmfcwndCze.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndCze.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 512000 bytes | Modified Date = 3/11/2006 4:25:02 PM | Attr = ] BrmfcwndDan.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndDan.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 512000 bytes | Modified Date = 3/6/2006 2:35:34 PM | Attr = ] BrmfcwndDut.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndDut.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 1 | Size = 512000 bytes | Modified Date = 3/6/2006 4:33:04 PM | Attr = ] BrmfcwndEng.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndEng.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 512000 bytes | Modified Date = 3/6/2006 2:33:12 PM | Attr = ] BrmfcwndFin.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndFin.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 516096 bytes | Modified Date = 2/16/2006 6:43:28 PM | Attr = ] BrmfcwndFre.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndFre.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 516096 bytes | Modified Date = 2/14/2006 3:54:08 PM | Attr = ] BrmfcwndGer.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndGer.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 516096 bytes | Modified Date = 2/14/2006 4:43:58 PM | Attr = ] BrmfcwndHun.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndHun.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 516096 bytes | Modified Date = 3/7/2006 8:49:56 AM | Attr = ] BrmfcwndIta.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndIta.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 516096 bytes | Modified Date = 3/11/2006 3:41:22 PM | Attr = ] BrmfcwndJpn.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndJpn.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 512000 bytes | Modified Date = 3/6/2006 2:28:50 PM | Attr = ] BrmfcwndNor.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndNor.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 512000 bytes | Modified Date = 3/11/2006 3:47:12 PM | Attr = ] BrmfcwndPol.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndPol.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 516096 bytes | Modified Date = 3/6/2006 5:27:34 PM | Attr = ] BrmfcwndPor.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndPor.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 516096 bytes | Modified Date = 2/16/2006 2:30:54 PM | Attr = ] BrmfcwndRom.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndRom.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 516096 bytes | Modified Date = 3/3/2006 7:30:06 PM | Attr = ] BrmfcwndRus.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndRus.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 516096 bytes | Modified Date = 3/7/2006 10:14:02 AM | Attr = ] BrmfcwndSpa.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndSpa.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 3 | Size = 512000 bytes | Modified Date = 4/5/2006 4:08:26 PM | Attr = R ] BrmfcwndSwe.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BrmfcwndSwe.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 0 | Size = 516096 bytes | Modified Date = 3/11/2006 4:01:56 PM | Attr = ] BroSNMP.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Brmfcmon_Protect\BroSNMP.dll -> Brother Industries, Ltd. [Ver = 1, 0, 0, 1 | Size = 69632 bytes | Modified Date = 2/23/2006 4:15:04 PM | Attr = ] brccbul.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccbul.dll -> Brother Industries, Ltd. [Ver = 3, 0, 3, 3 | Size = 106496 bytes | Modified Date = 4/1/2006 12:16:54 PM | Attr = ] brccchn.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccchn.dll -> Brother Industries, Ltd. [Ver = 3, 0, 4, 4 | Size = 86016 bytes | Modified Date = 4/6/2006 8:14:12 PM | Attr = ] brcccze.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brcccze.dll -> Brother Industries, Ltd. [Ver = 3, 0, 3, 3 | Size = 102400 bytes | Modified Date = 4/1/2006 12:15:44 PM | Attr = ] brccdan.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccdan.dll -> Brother Industries, Ltd. [Ver = 3, 0, 3, 3 | Size = 102400 bytes | Modified Date = 4/1/2006 12:18:10 PM | Attr = ] brccDCtl.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccDCtl.dll -> Brother Industries, Ltd. [Ver = 3, 0, 53, 53 | Size = 638976 bytes | Modified Date = 4/3/2006 8:06:40 PM | Attr = ] brccdut.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccdut.dll -> Brother Industries, Ltd. [Ver = 3, 0, 4, 4 | Size = 106496 bytes | Modified Date = 4/7/2006 11:59:38 AM | Attr = ] brcceng.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brcceng.dll -> Brother Industries, Ltd. [Ver = 3, 0, 4, 4 | Size = 102400 bytes | Modified Date = 4/1/2006 12:21:34 PM | Attr = ] brccFCtl.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccFCtl.dll -> Brother Industries, Ltd. [Ver = 3, 0, 12, 41 | Size = 143360 bytes | Modified Date = 3/28/2006 9:22:08 PM | Attr = ] brccfile.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccfile.dll -> Brother Industries, Ltd. [Ver = 3, 0, 0, 0 | Size = 61440 bytes | Modified Date = 1/27/2006 7:09:08 PM | Attr = ] brccfin.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccfin.dll -> Brother Industries, Ltd. [Ver = 3, 0, 5, 5 | Size = 102400 bytes | Modified Date = 4/7/2006 12:07:14 PM | Attr = ] brccfre.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccfre.dll -> Brother Industries, Ltd. [Ver = 3, 0, 4, 4 | Size = 106496 bytes | Modified Date = 4/7/2006 10:17:30 AM | Attr = ] brccger.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccger.dll -> Brother Industries, Ltd. [Ver = 3, 0, 3, 3 | Size = 106496 bytes | Modified Date = 4/1/2006 12:24:30 PM | Attr = ] brcchun.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brcchun.dll -> Brother Industries, Ltd. [Ver = 3, 0, 4, 4 | Size = 106496 bytes | Modified Date = 4/7/2006 12:03:16 PM | Attr = ] brccimg.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccimg.dll -> Brother Industries, Ltd. [Ver = 3, 0, 0, 0 | Size = 4861952 bytes | Modified Date = 2/13/2006 3:53:46 PM | Attr = ] brccita.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccita.dll -> Brother Industries, Ltd. [Ver = 3, 0, 3, 3 | Size = 110592 bytes | Modified Date = 4/1/2006 12:26:58 PM | Attr = ] brccjpn.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccjpn.dll -> Brother Industries, Ltd. [Ver = 3, 0, 3, 3 | Size = 90112 bytes | Modified Date = 3/31/2006 6:56:44 PM | Attr = ] brccnor.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccnor.dll -> Brother Industries, Ltd. [Ver = 3, 0, 4, 4 | Size = 102400 bytes | Modified Date = 4/7/2006 12:01:40 PM | Attr = ] brccpol.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccpol.dll -> Brother Industries, Ltd. [Ver = 3, 0, 3, 3 | Size = 102400 bytes | Modified Date = 4/1/2006 12:29:28 PM | Attr = ] brccpor.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccpor.dll -> Brother Industries, Ltd. [Ver = 3, 0, 3, 3 | Size = 106496 bytes | Modified Date = 4/1/2006 12:30:42 PM | Attr = ] brccrom.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccrom.dll -> Brother Industries, Ltd. [Ver = 3, 0, 4, 4 | Size = 106496 bytes | Modified Date = 4/7/2006 12:04:52 PM | Attr = ] brccrus.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccrus.dll -> Brother Industries, Ltd. [Ver = 3, 0, 3, 3 | Size = 106496 bytes | Modified Date = 4/1/2006 12:33:40 PM | Attr = ] brccspa.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccspa.dll -> Brother Industries, Ltd. [Ver = 3, 0, 3, 3 | Size = 106496 bytes | Modified Date = 4/1/2006 12:35:00 PM | Attr = ] brccsrch.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccsrch.dll -> Brother Industries, Ltd. [Ver = 3, 0, 1, 2 | Size = 24576 bytes | Modified Date = 2/10/2006 6:14:58 PM | Attr = ] brccswe.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccswe.dll -> Brother Industries, Ltd. [Ver = 3, 0, 3, 3 | Size = 102400 bytes | Modified Date = 4/1/2006 12:36:16 PM | Attr = ] brcctwn.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brcctwn.dll -> Brother Industries, Ltd. [Ver = 3, 0, 1, 1 | Size = 28672 bytes | Modified Date = 3/9/2006 9:35:56 PM | Attr = ] brccusa.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccusa.dll -> Brother Industries, Ltd. [Ver = 3, 0, 4, 4 | Size = 102400 bytes | Modified Date = 4/1/2006 12:21:56 PM | Attr = ] brccwia.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\brccwia.dll -> Brother Industries, Ltd. [Ver = 3, 0, 1, 1 | Size = 57344 bytes | Modified Date = 3/9/2006 9:36:02 PM | Attr = ] BrImgPDF.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\BrImgPDF.dll -> Brother Industries,LTD. [Ver = 1, 0, 0, 1 | Size = 40960 bytes | Modified Date = 4/9/2004 1:47:46 PM | Attr = ] lfawd12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lfawd12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 23040 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] lfbmp12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lfbmp12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 30720 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] LFCMP12n.DLL -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\LFCMP12n.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.073 | Size = 360448 bytes | Modified Date = 7/5/2005 | Attr = ] lfeps12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lfeps12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 37888 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] lffax12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lffax12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 73728 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] lflma12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lflma12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 29184 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] lflmb12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lflmb12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 31744 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] lfmsp12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lfmsp12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 19456 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] lfpcx12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lfpcx12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 26112 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] Lfpng12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\Lfpng12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.073 | Size = 182784 bytes | Modified Date = 7/5/2005 | Attr = ] LFPNM12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\LFPNM12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 31232 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] lftif12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lftif12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 141312 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] lfwfx12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lfwfx12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 19968 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] lfwmf12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lfwmf12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 49664 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] lfwpg12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lfwpg12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 20992 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] LTDIS12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\LTDIS12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 259584 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] ltefx12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\ltefx12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 208384 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] ltfil12n.DLL -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\ltfil12n.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.073 | Size = 131584 bytes | Modified Date = 7/5/2005 | Attr = ] ltimg12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\ltimg12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 164864 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] ltkrn12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\ltkrn12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 406016 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] lttwn12n.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\lttwn12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 35840 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] LTWND12n.DLL -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\LTWND12n.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.068 | Size = 30208 bytes | Modified Date = 6/30/2003 12:00:02 AM | Attr = ] maxutil.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\maxutil.dll -> ScanSoft, Inc. [Ver = 9.0 | Size = 106544 bytes | Modified Date = 3/9/2004 5:25:34 PM | Attr = ] pperr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\pperr.dll -> ScanSoft, Inc. [Ver = 9.0 | Size = 81966 bytes | Modified Date = 3/9/2004 5:23:26 PM | Attr = ] BRLFX05A.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\PCFAX\BRLFX05A.dll -> Brother Industries Ltd. [Ver = 1.00 | Size = 7168 bytes | Modified Date = 4/13/2005 1:00:00 AM | Attr = ] BROFX05A.DLL -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\PCFAX\BROFX05A.DLL -> Brother Industries Ltd. [Ver = 1.01 built by: WinDDK | Size = 174592 bytes | Modified Date = 3/2/2006 1:01:00 AM | Attr = ] BRUFX05A.DLL -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\PCFAX\BRUFX05A.DLL -> Brother Industries Ltd. [Ver = 1.01 built by: WinDDK | Size = 163840 bytes | Modified Date = 3/2/2006 1:01:00 AM | Attr = ] RsmgrStr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\bul\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.211 | Size = 53248 bytes | Modified Date = 1/17/2006 6:28:28 PM | Attr = R ] rsmgrstr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\chn\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.207 | Size = 36864 bytes | Modified Date = 8/23/2004 4:20:48 PM | Attr = ] RsmgrStr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\cze\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.207 | Size = 53248 bytes | Modified Date = 10/30/2004 11:01:14 AM | Attr = ] rsmgrstr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\dan\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/21/2005 3:08:08 PM | Attr = ] rsmgrstr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\dut\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/21/2005 3:08:44 PM | Attr = ] RsmgrStr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\eng\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/17/2005 7:00:08 PM | Attr = ] RsmgrStr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\fin\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.210 | Size = 49152 bytes | Modified Date = 10/26/2005 1:09:02 PM | Attr = ] rsmgrstr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\fre\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/21/2005 3:09:14 PM | Attr = ] rsmgrstr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\ger\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.210 | Size = 40960 bytes | Modified Date = 10/21/2005 3:09:34 PM | Attr = ] RsmgrStr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\hun\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.207 | Size = 53248 bytes | Modified Date = 10/30/2004 9:27:20 AM | Attr = ] rsmgrstr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\ita\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/21/2005 3:09:52 PM | Attr = ] RsmgrStr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\jpn\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.209 | Size = 49152 bytes | Modified Date = 6/14/2005 4:45:12 PM | Attr = ] rsmgrstr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\nor\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/21/2005 3:10:12 PM | Attr = ] RsmgrStr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\pol\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.207 | Size = 53248 bytes | Modified Date = 10/30/2004 11:48:14 AM | Attr = R ] rsmgrstr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\por\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/21/2005 3:10:34 PM | Attr = ] RsmgrStr.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\RsmgLang\rom\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.211 | Size = 53248 bytes | Modified Date = 1/19/2006 2:33:12 PM | Attr = R ] BrTwdLNG.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\TwainLang\BrTwdLNG.dll -> Brother Industries, Ltd. [Ver = 3, 4, 9, 1 | Size = 81920 bytes | Modified Date = 12/16/2005 3:27:22 PM | Attr = ] ISSetup.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{8CEF3E3D-B8DF-4D7C-A7BE-4BCD63A19F92}\ISSetup.dll -> Macrovision Corporation [Ver = 12.0.49974 | Size = 552214 bytes | Modified Date = 10/16/2007 1:40:00 AM | Attr = R ] _Setup.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{8CEF3E3D-B8DF-4D7C-A7BE-4BCD63A19F92}\_Setup.dll -> Macrovision Corporation [Ver = 12.0.49974 | Size = 164784 bytes | Modified Date = 5/17/2006 10:21:04 AM | Attr = R ] ISSetup.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{ED05BE38-2831-4743-9107-366E01A27821}\ISSetup.dll -> Macrovision Corporation [Ver = 12.0.58849 | Size = 546582 bytes | Modified Date = 4/23/2007 8:20:28 PM | Attr = R ] _Setup.dll -> F:\Documents and Settings\Patrick\Local Settings\Temp\{ED05BE38-2831-4743-9107-366E01A27821}\_Setup.dll -> Macrovision Corporation [Ver = 12.0.49974 | Size = 385968 bytes | Modified Date = 5/17/2006 10:21:04 AM | Attr = R ] Perflib_Perfdata_138.dat -> F:\Documents and Settings\Patrick\Local Settings\Temp\Perflib_Perfdata_138.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/1/2008 12:42:06 PM | Attr = ] 61 F:\Documents and Settings\Patrick\Local Settings\Temp\*.tmp files -> F:\Documents and Settings\Patrick\Local Settings\Temp\*.tmp -> {AC76BA86-1033-F400-7760-000000000003}.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{AC76BA86-1033-F400-7760-000000000003}.ini -> [Ver = | Size = 1657 bytes | Modified Date = 3/1/2008 12:10:16 PM | Attr = ] {AC76BA86-7AD7-1033-7B44-A81200000003}.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{AC76BA86-7AD7-1033-7B44-A81200000003}.ini -> [Ver = | Size = 729 bytes | Modified Date = 2/19/2008 3:54:01 PM | Attr = ] 61 F:\Documents and Settings\Patrick\Local Settings\Temp\*.tmp files -> F:\Documents and Settings\Patrick\Local Settings\Temp\*.tmp -> brcc_bul.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_bul.ini -> [Ver = | Size = 1076 bytes | Modified Date = 2/14/2006 8:17:14 PM | Attr = ] brcc_chn.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_chn.ini -> [Ver = | Size = 1070 bytes | Modified Date = 2/14/2006 8:17:26 PM | Attr = ] brcc_cze.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_cze.ini -> [Ver = | Size = 1074 bytes | Modified Date = 2/14/2006 8:26:06 PM | Attr = ] brcc_dan.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_dan.ini -> [Ver = | Size = 1074 bytes | Modified Date = 2/14/2006 8:17:44 PM | Attr = ] brcc_dut.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_dut.ini -> [Ver = | Size = 1074 bytes | Modified Date = 2/14/2006 8:17:52 PM | Attr = ] brcc_eng.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_eng.ini -> [Ver = | Size = 1073 bytes | Modified Date = 2/14/2006 8:17:58 PM | Attr = ] brcc_fin.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_fin.ini -> [Ver = | Size = 1075 bytes | Modified Date = 2/14/2006 8:18:06 PM | Attr = ] brcc_fre.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_fre.ini -> [Ver = | Size = 1075 bytes | Modified Date = 2/14/2006 8:18:12 PM | Attr = ] brcc_ger.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_ger.ini -> [Ver = | Size = 1075 bytes | Modified Date = 2/14/2006 8:18:20 PM | Attr = ] brcc_hun.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_hun.ini -> [Ver = | Size = 1076 bytes | Modified Date = 2/14/2006 8:18:26 PM | Attr = ] brcc_ita.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_ita.ini -> [Ver = | Size = 1074 bytes | Modified Date = 2/14/2006 8:18:32 PM | Attr = ] brcc_jpn.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_jpn.ini -> [Ver = | Size = 1073 bytes | Modified Date = 2/14/2006 8:18:40 PM | Attr = ] brcc_nor.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_nor.ini -> [Ver = | Size = 1074 bytes | Modified Date = 2/14/2006 8:18:54 PM | Attr = ] brcc_pol.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_pol.ini -> [Ver = | Size = 1075 bytes | Modified Date = 2/14/2006 8:19:40 PM | Attr = ] brcc_por.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_por.ini -> [Ver = | Size = 1074 bytes | Modified Date = 2/14/2006 8:19:46 PM | Attr = ] brcc_rom.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_rom.ini -> [Ver = | Size = 1072 bytes | Modified Date = 2/14/2006 8:19:52 PM | Attr = ] brcc_rus.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_rus.ini -> [Ver = | Size = 1078 bytes | Modified Date = 2/14/2006 8:20:00 PM | Attr = ] brcc_spa.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_spa.ini -> [Ver = | Size = 1073 bytes | Modified Date = 2/14/2006 8:20:06 PM | Attr = ] brcc_swe.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_swe.ini -> [Ver = | Size = 1074 bytes | Modified Date = 2/14/2006 8:20:12 PM | Attr = ] brcc_usa.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ClassicStyle\brcc_usa.ini -> [Ver = | Size = 1073 bytes | Modified Date = 2/14/2006 8:14:06 PM | Attr = ] brcc_bul.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_bul.ini -> [Ver = | Size = 1156 bytes | Modified Date = 2/15/2006 1:17:06 PM | Attr = ] brcc_chn.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_chn.ini -> [Ver = | Size = 1150 bytes | Modified Date = 2/22/2006 6:26:24 PM | Attr = ] brcc_cze.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_cze.ini -> [Ver = | Size = 1153 bytes | Modified Date = 2/14/2006 8:24:52 PM | Attr = ] brcc_dan.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_dan.ini -> [Ver = | Size = 1153 bytes | Modified Date = 2/14/2006 8:16:40 PM | Attr = ] brcc_dut.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_dut.ini -> [Ver = | Size = 1152 bytes | Modified Date = 2/14/2006 8:16:34 PM | Attr = ] brcc_eng.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_eng.ini -> [Ver = | Size = 1152 bytes | Modified Date = 2/14/2006 8:16:26 PM | Attr = ] brcc_fin.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_fin.ini -> [Ver = | Size = 1153 bytes | Modified Date = 2/14/2006 8:16:20 PM | Attr = ] brcc_fre.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_fre.ini -> [Ver = | Size = 1153 bytes | Modified Date = 2/14/2006 8:16:10 PM | Attr = ] brcc_ger.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_ger.ini -> [Ver = | Size = 1152 bytes | Modified Date = 2/14/2006 8:16:04 PM | Attr = ] brcc_hun.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_hun.ini -> [Ver = | Size = 1152 bytes | Modified Date = 2/14/2006 8:15:56 PM | Attr = ] brcc_ita.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_ita.ini -> [Ver = | Size = 1151 bytes | Modified Date = 2/14/2006 8:15:48 PM | Attr = ] brcc_jpn.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_jpn.ini -> [Ver = | Size = 1152 bytes | Modified Date = 2/14/2006 8:15:42 PM | Attr = ] brcc_nor.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_nor.ini -> [Ver = | Size = 1153 bytes | Modified Date = 2/14/2006 8:15:34 PM | Attr = ] brcc_pol.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_pol.ini -> [Ver = | Size = 1156 bytes | Modified Date = 2/14/2006 8:15:26 PM | Attr = ] brcc_por.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_por.ini -> [Ver = | Size = 1151 bytes | Modified Date = 2/14/2006 8:15:16 PM | Attr = ] brcc_rom.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_rom.ini -> [Ver = | Size = 1152 bytes | Modified Date = 2/14/2006 8:15:08 PM | Attr = ] brcc_rus.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_rus.ini -> [Ver = | Size = 1157 bytes | Modified Date = 2/14/2006 8:14:50 PM | Attr = ] brcc_spa.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_spa.ini -> [Ver = | Size = 1151 bytes | Modified Date = 2/14/2006 8:14:42 PM | Attr = ] brcc_swe.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_swe.ini -> [Ver = | Size = 1152 bytes | Modified Date = 2/14/2006 8:14:34 PM | Attr = ] brcc_usa.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{7ACE950B-C99C-4939-A485-AF7E35E24C64}\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\ControlCenter\skin\ModernStyle\brcc_usa.ini -> [Ver = | Size = 1152 bytes | Modified Date = 2/14/2006 8:14:00 PM | Attr = ] _isdel.ini -> F:\Documents and Settings\Patrick\Local Settings\Temp\{8CEF3E3D-B8DF-4D7C-A7BE-4BCD63A19F92}\_isdel.ini -> [Ver = | Size = 282 bytes | Modified Date = 1/27/2008 11:43:46 AM | Attr = ] [Files Modified - Additional Folder Scans - Non-Microsoft Only] Adobe -> %AllUsersProfile%\Application Data\Adobe -> [Folder | Modified Date = 3/1/2008 12:03:23 PM | Attr = ] DIGStream -> %AllUsersProfile%\Application Data\DIGStream -> [Folder | Modified Date = 2/6/2008 10:42:25 PM | Attr = ] FLEXnet -> %AllUsersProfile%\Application Data\FLEXnet -> [Folder | Modified Date = 2/29/2008 6:13:39 PM | Attr = ] RetroExp -> %AllUsersProfile%\Application Data\RetroExp -> [Folder | Modified Date = 3/1/2008 12:48:01 PM | Attr = ] Adobe -> %AppData%\Adobe -> [Folder | Modified Date = 2/29/2008 6:13:42 PM | Attr = ] AdobeUM -> %AppData%\AdobeUM -> [Folder | Modified Date = 2/19/2008 3:11:21 PM | Attr = ] DivX -> %AppData%\DivX -> [Folder | Modified Date = 2/18/2008 11:11:36 AM | Attr = ] PCF-VLC -> %AppData%\PCF-VLC -> [Folder | Modified Date = 2/24/2008 7:25:01 PM | Attr = ] Adobe -> %UserProfile%\Local Settings\Application Data\Adobe -> [Folder | Modified Date = 2/19/2008 3:56:16 PM | Attr = ] DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [Ver = | Size = 61952 bytes | Modified Date = 2/18/2008 11:11:30 AM | Attr = ] GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [Ver = | Size = 19800 bytes | Modified Date = 3/1/2008 12:15:38 PM | Attr = ] IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [Ver = | Size = 1578512 bytes | Modified Date = 2/1/2008 11:08:04 AM | Attr = H ] Addison.doc -> %UserProfile%\My Documents\Addison.doc -> [Ver = | Size = 22016 bytes | Modified Date = 2/15/2008 9:37:02 PM | Attr = ] Baby Shower.xls -> %UserProfile%\My Documents\Baby Shower.xls -> [Ver = | Size = 38912 bytes | Modified Date = 2/25/2008 11:45:38 AM | Attr = ] Firefox Downloads -> %UserProfile%\My Documents\Firefox Downloads -> [Folder | Modified Date = 3/1/2008 1:48:08 PM | Attr = ] Funny -> %UserProfile%\My Documents\Funny -> [Folder | Modified Date = 2/21/2008 5:16:07 PM | Attr = ] My Pictures -> %UserProfile%\My Documents\My Pictures -> [Folder | Modified Date = 2/23/2008 12:33:15 AM | Attr = R ] My Videos -> %UserProfile%\My Documents\My Videos -> [Folder | Modified Date = 2/16/2008 11:37:46 AM | Attr = R ] Retirement -> %UserProfile%\My Documents\Retirement -> [Folder | Modified Date = 2/23/2008 2:25:46 AM | Attr = ] Screensavers -> %UserProfile%\My Documents\Screensavers -> [Folder | Modified Date = 2/15/2008 10:56:01 PM | Attr = ] Updater5 -> %UserProfile%\My Documents\Updater5 -> [Folder | Modified Date = 2/29/2008 6:14:41 PM | Attr = ] Adobe Acrobat 8 Professional.lnk -> %AllUsersProfile%\Desktop\Adobe Acrobat 8 Professional.lnk -> [Ver = | Size = 1736 bytes | Modified Date = 3/1/2008 12:10:20 PM | Attr = ] Adobe Reader 8.lnk -> %AllUsersProfile%\Desktop\Adobe Reader 8.lnk -> [Ver = | Size = 1729 bytes | Modified Date = 2/19/2008 3:54:44 PM | Attr = ] iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [Ver = | Size = 1804 bytes | Modified Date = 2/23/2008 2:02:15 AM | Attr = ] Miro.lnk -> %AllUsersProfile%\Desktop\Miro.lnk -> [Ver = | Size = 1819 bytes | Modified Date = 2/3/2008 12:25:45 AM | Attr = ] QuickTime Player.lnk -> %AllUsersProfile%\Desktop\QuickTime Player.lnk -> [Ver = | Size = 1604 bytes | Modified Date = 2/16/2008 11:53:13 AM | Attr = ] Adobe Acrobat 8 Professional -> %UserProfile%\Desktop\Adobe Acrobat 8 Professional -> [Folder | Modified Date = 2/24/2008 4:34:13 PM | Attr = ] BDSM galleries.URL -> %UserProfile%\Desktop\BDSM galleries.URL -> [Ver = | Size = 59 bytes | Modified Date = 3/1/2008 12:52:17 PM | Attr = ] Microsoft Excel.lnk -> %UserProfile%\Desktop\Microsoft Excel.lnk -> [Ver = | Size = 2471 bytes | Modified Date = 2/23/2008 10:50:38 AM | Attr = ] Microsoft Word.lnk -> %UserProfile%\Desktop\Microsoft Word.lnk -> [Ver = | Size = 2473 bytes | Modified Date = 3/1/2008 1:48:39 PM | Attr = ] Now download WinPFind35u.doc -> %UserProfile%\Desktop\Now download WinPFind35u.doc -> [Ver = | Size = 26624 bytes | Modified Date = 3/1/2008 1:50:24 PM | Attr = ] PicoZip.lnk -> %UserProfile%\Desktop\PicoZip.lnk -> [Ver = | Size = 616 bytes | Modified Date = 2/3/2008 1:01:06 AM | Attr = ] Uncensored porn.URL -> %UserProfile%\Desktop\Uncensored porn.URL -> [Ver = | Size = 59 bytes | Modified Date = 3/1/2008 12:52:48 PM | Attr = ] WinPFind35u -> %UserProfile%\Desktop\WinPFind35u -> [Folder | Modified Date = 3/1/2008 1:51:04 PM | Attr = ] WinPFind35u.exe -> %UserProfile%\Desktop\WinPFind35u.exe -> [Ver = | Size = 482000 bytes | Modified Date = 3/1/2008 1:46:59 PM | Attr = ] Adobe -> %CommonProgramFiles%\Adobe -> [Folder | Modified Date = 2/29/2008 6:06:18 PM | Attr = ] Macrovision Shared -> %CommonProgramFiles%\Macrovision Shared -> [Folder | Modified Date = 2/29/2008 6:13:33 PM | Attr = ] < End of report > [/code]