[code] OTScanIt logfile created on: 3/15/2008 8:32:41 PM OTScanIt by OldTimer - Version 1.0.5.2 Folder = C:\Documents and Settings\Mark ******\Desktop\gtg\OTScanIt Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free 4.00 Gb Paging File | 3.53 Gb Available in Paging File | 88.35% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 228.13 Gb Total Space | 37.93 Gb Free Space | 16.63% Space Free | Partition Type: NTFS D: Drive not present or media not loaded Drive E: | 1023.47 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF Drive F: | 7.72 Mb Total Space | 5.98 Mb Free Space | 77.48% Space Free | Partition Type: FAT G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Drive K: | 232.83 Gb Total Space | 22.83 Gb Free Space | 9.81% Space Free | Partition Type: FAT32 Drive L: | 465.65 Gb Total Space | 367.90 Gb Free Space | 79.01% Space Free | Partition Type: FAT32 Computer Name: D1DWM691 Current User Name: Mark ****** Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users [Processes - Non-Microsoft Only] ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> MD5 = 3E47191DDAFFCDD9B28CBC50FB6499B5 | ATI Technologies Inc. [Ver = 6.14.10.4188 | Size = 512000 bytes | Modified Date = 12/20/2007 10:57:27 PM | Attr = ] ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> MD5 = 3E47191DDAFFCDD9B28CBC50FB6499B5 | ATI Technologies Inc. [Ver = 6.14.10.4188 | Size = 512000 bytes | Modified Date = 12/20/2007 10:57:27 PM | Attr = ] ccsvchst.exe -> %CommonProgramFiles%\Symantec Shared\CCSVCHST.EXE -> MD5 = A8D49668CA8BBDDF5D3D4FBD9ECFF49E | Symantec Corporation [Ver = 107.0.3.7 | Size = 149864 bytes | Modified Date = 2/14/2008 11:02:00 AM | Attr = ] lexbces.exe -> %SystemRoot%\system32\LEXBCES.EXE -> MD5 = E19C8550B4C6C67FABFFD998EACF440A | Lexmark International, Inc. [Ver = 9.45 | Size = 311296 bytes | Modified Date = 3/5/2004 12:30:48 AM | Attr = ] lexpps.exe -> %SystemRoot%\system32\LEXPPS.EXE -> MD5 = 7A48C1D07A4445F622882833CAE9AB32 | Lexmark International, Inc. [Ver = 9.45 | Size = 174592 bytes | Modified Date = 3/5/2004 12:26:20 AM | Attr = ] photoshopelementsfileagent.exe -> K:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe -> MD5 = 177FF6608B48638D4066726F3A3F8444 | [Ver = | Size = 102400 bytes | Modified Date = 9/14/2006 7:56:06 AM | Attr = ] applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> MD5 = 69DA2BB73AC426CDEEBDACC68438BA3D | Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 10/31/2007 3:09:16 PM | Attr = ] aluschedulersvc.exe -> %ProgramFiles%\Symantec\LiveUpdate\AluSchedulerSvc.exe -> MD5 = 7C813EB232C7AEFA627A12A104DDA221 | Symantec Corporation [Ver = 3.4.0.164 | Size = 243064 bytes | Modified Date = 8/31/2007 11:49:50 AM | Attr = ] ctsvccda.exe -> %SystemRoot%\system32\CTSVCCDA.EXE -> MD5 = 3C8B6609712F4FF78E521F6DCFC4032B | Creative Technology Ltd [Ver = 1.0.1.0 | Size = 44032 bytes | Modified Date = 12/13/1999 9:01:00 AM | Attr = ] crypserv.exe -> %SystemRoot%\system32\Crypserv.exe -> MD5 = 85A6662B5F12B84D599A74119F04B381 | Kenonic Controls Ltd. [Ver = 5.4.0 | Size = 52224 bytes | Modified Date = 6/29/2000 4:45:10 AM | Attr = ] dvpapi.exe -> %CommonProgramFiles%\Authentium\AntiVirus\dvpapi.exe -> MD5 = FD0E5E1107FCBC16802363D6D82281CE | Authentium, Inc. [Ver = 4,94,0,61018 | Size = 177720 bytes | Modified Date = 10/18/2006 6:16:44 PM | Attr = R ] pcctlcom.exe -> %ProgramFiles%\Trend Micro\Internet Security 12\PcCtlCom.exe -> MD5 = 30974C7E29CB115A89FFB2CCB5F89F88 | Trend Micro Incorporated. [Ver = 12.70.0.1019 | Size = 880722 bytes | Modified Date = 9/4/2006 9:54:44 PM | Attr = ] psiservice.exe -> %SystemRoot%\system32\PSIService.exe -> MD5 = 64E413BA0C529AA40C3924BBCC4153DB | [Ver = 2.0.0.1 | Size = 174656 bytes | Modified Date = 11/2/2006 9:40:12 PM | Attr = ] psiservice_2.exe -> %CommonProgramFiles%\Protexis\License Service\PsiService_2.exe -> MD5 = A6A7AD767BF5141665F5C675F671B3E1 | Protexis Inc. [Ver = 2.0.1.124 | Size = 185632 bytes | Modified Date = 7/24/2007 12:15:14 PM | Attr = ] tablet.exe -> %SystemRoot%\system32\Tablet.exe -> MD5 = 8FF10E4D5BADB180533AE7E53A28D860 | Wacom Technology, Corp. [Ver = 6.0.4-4 | Size = 1197616 bytes | Modified Date = 6/4/2007 12:52:20 PM | Attr = ] tmntsrv.exe -> %ProgramFiles%\Trend Micro\Internet Security 12\Tmntsrv.exe -> MD5 = 37C406BAC6896D504E054BBFAA120D79 | Trend Micro Incorporated. [Ver = 12.70.0.1017 | Size = 290889 bytes | Modified Date = 8/30/2005 6:30:32 PM | Attr = ] tmproxy.exe -> %ProgramFiles%\Trend Micro\Internet Security 12\tmproxy.exe -> MD5 = 949BB051485AEF6516A600F7454F0ABF | Trend Micro Inc. [Ver = 1.0.0.1135 | Size = 262215 bytes | Modified Date = 8/30/2005 6:30:34 PM | Attr = ] spysweeper.exe -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeper.exe -> Unable to obtain MD5 | Webroot Software, Inc. [Ver = 3,5,6,114 | Size = 3572592 bytes | Modified Date = 1/4/2008 8:56:52 PM | Attr = ] tabuserw.exe -> %SystemRoot%\system32\WTablet\TabUserW.exe -> MD5 = D26E69DB0FA85A58ABDFC0575291267D | Wacom Technology, Corp. [Ver = 6.0.4-4 | Size = 132656 bytes | Modified Date = 6/4/2007 12:53:00 PM | Attr = ] tablet.exe -> %SystemRoot%\system32\Tablet.exe -> MD5 = 8FF10E4D5BADB180533AE7E53A28D860 | Wacom Technology, Corp. [Ver = 6.0.4-4 | Size = 1197616 bytes | Modified Date = 6/4/2007 12:52:20 PM | Attr = ] calmain.exe -> %ProgramFiles%\Canon\CAL\CALMAIN.exe -> MD5 = 8EF654045E518AC00E52E7A1E2D3AD70 | Canon Inc. [Ver = 8, 4, 0, 1 | Size = 96370 bytes | Modified Date = 1/31/2007 3:55:42 PM | Attr = ] nmsrvc.exe -> %ProgramFiles%\Pure Networks\Network Magic\nmsrvc.exe -> MD5 = 3CB041B0C24258BDCFD0DB1B1BF95EFB | Pure Networks, Inc. [Ver = 4.0.6277.0 | Size = 321088 bytes | Modified Date = 11/1/2006 1:04:02 AM | Attr = ] tmpfw.exe -> %ProgramFiles%\Trend Micro\Internet Security 12\TmPfw.exe -> MD5 = 70EE53C6E1B5402C5CE0F12D038B0F4C | Trend Micro Inc. [Ver = 2.0.0.1135 | Size = 585792 bytes | Modified Date = 8/30/2005 6:30:34 PM | Attr = ] dvdlauncher.exe -> %ProgramFiles%\CyberLink\PowerDVD\DVDLauncher.exe -> MD5 = B3E3C57FD22E71CE20389372D972C6DC | CyberLink Corp. [Ver = 3.00.0000 | Size = 53248 bytes | Modified Date = 2/23/2005 6:19:56 PM | Attr = ] ctsysvol.exe -> %ProgramFiles%\Creative\SBAudigy\Surround Mixer\CTSysVol.exe -> MD5 = 93D27C8D2902C8F88E9B70FC20998976 | Creative Technology Ltd [Ver = 1.4.5.0 | Size = 57344 bytes | Modified Date = 9/15/2005 11:47:22 AM | Attr = ] issch.exe -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> MD5 = 583B7D111304BE63D7D9CB65482D2187 | InstallShield Software Corporation [Ver = 4, 50, 100, 33433 | Size = 81920 bytes | Modified Date = 6/10/2005 12:44:02 PM | Attr = ] pccguide.exe -> %ProgramFiles%\Trend Micro\Internet Security 12\pccguide.exe -> MD5 = 1DA0FDF5EE35C39145D464F06DC798AE | Trend Micro Incorporated. [Ver = 12.70.0.1017 | Size = 823362 bytes | Modified Date = 8/30/2005 6:30:26 PM | Attr = ] tfswctrl.exe -> %SystemRoot%\system32\dla\tfswctrl.exe -> MD5 = 352FBF618066D0CEB7DC8ECABEB1A8D7 | Sonic Solutions [Ver = 1.04.08a | Size = 122941 bytes | Modified Date = 5/31/2005 6:33:00 AM | Attr = ] pduip6600dmon.exe -> %ProgramFiles%\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe -> MD5 = 1DE937F630D060335405680299D1AEBF | CANON INC. [Ver = 3.00 | Size = 69632 bytes | Modified Date = 5/25/2005 10:35:10 AM | Attr = ] nmapp.exe -> %ProgramFiles%\Pure Networks\Network Magic\nmapp.exe -> MD5 = B151DDB3FABD308162483DDA1B865E0A | Pure Networks, Inc. [Ver = 4.0.6277.0 | Size = 321088 bytes | Modified Date = 11/1/2006 1:04:02 AM | Attr = ] ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> MD5 = 6F6493A929BC9B5762035940E825B840 | Apple Inc. [Ver = 7.6.1.9 | Size = 267048 bytes | Modified Date = 2/19/2008 2:10:32 PM | Attr = ] clclean.0001 -> %SystemDrive%\DOCUME~1\MARKHO~1\LOCALS~1\Temp\clclean.000 -> File not found ccsvchst.exe -> %CommonProgramFiles%\Symantec Shared\CCSVCHST.EXE -> MD5 = A8D49668CA8BBDDF5D3D4FBD9ECFF49E | Symantec Corporation [Ver = 107.0.3.7 | Size = 149864 bytes | Modified Date = 2/14/2008 11:02:00 AM | Attr = ] spysweeperui.exe -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeperUI.exe -> MD5 = 2B0B8C29092FB420826F5A8FD02DC081 | Webroot Software, Inc. [Ver = 5,5,7,124 | Size = 5367664 bytes | Modified Date = 1/4/2008 8:56:58 PM | Attr = ] ctdetect.exe -> %ProgramFiles%\Creative\MediaSource\Detector\CTDetect.exe -> MD5 = C744293DFBE1A3347FEC5DBFE3FD123E | Creative Technology Ltd [Ver = 3.0.2.0 | Size = 102400 bytes | Modified Date = 12/2/2004 8:23:34 PM | Attr = ] tmas_oemon.exe -> %ProgramFiles%\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe -> MD5 = 929B93FCC12782E01345657369759E7D | Trend Micro Inc. [Ver = 3.5.0.1119 | Size = 176201 bytes | Modified Date = 4/11/2006 8:39:22 PM | Attr = ] smsystemanalyzer.exe -> %ProgramFiles%\iolo\System Mechanic 6\SMSystemAnalyzer.exe -> MD5 = C8C63E4A3F91412A4CD86CB3ABCFA702 | [Ver = | Size = 557056 bytes | Modified Date = 12/20/2006 1:38:56 PM | Attr = ] creativelicensing.exe -> %CommonProgramFiles%\Creative Labs Shared\Service\CreativeLicensing.exe -> MD5 = 7DB5E3F44D797BD38B8E336CCC2E49D5 | Creative Labs [Ver = 2.65.010 | Size = 69632 bytes | Modified Date = 1/18/2006 12:07:12 PM | Attr = ] googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> MD5 = E616A6A6E91B0A86F2F6217CDE835FFE | Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 7/18/2007 5:54:45 PM | Attr = ] ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> MD5 = 1E9ED06A30FB0410CE94892F1BA6984B | Apple Inc. [Ver = 7.6.1.9 | Size = 504104 bytes | Modified Date = 2/19/2008 2:10:24 PM | Attr = ] ssu.exe -> %ProgramFiles%\Webroot\Spy Sweeper\ssu.exe -> MD5 = 52F8D97D643D83A537B7416A56B4096F | [Ver = | Size = 214384 bytes | Modified Date = 1/4/2008 8:34:36 PM | Attr = ] otscanit.exe -> %UserProfile%\Desktop\gtg\OTScanIt\OTScanIt.exe -> MD5 = 13A72F3BF831C2D2CD921B63E4C4C0E9 | OldTimer Tools [Ver = 1.0.5.2 | Size = 310784 bytes | Modified Date = 3/14/2008 2:57:26 PM | Attr = ] [Win32 Services - Non-Microsoft Only] (AdobeActiveFileMonitor5.0) Adobe Active File Monitor V5 [Win32_Own | Auto | Running] -> K:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe -> MD5 = 177FF6608B48638D4066726F3A3F8444 | [Ver = | Size = 102400 bytes | Modified Date = 9/14/2006 7:56:06 AM | Attr = ] (Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> MD5 = 69DA2BB73AC426CDEEBDACC68438BA3D | Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 10/31/2007 3:09:16 PM | Attr = ] (Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %SystemRoot%\system32\ati2evxx.exe -> MD5 = 3E47191DDAFFCDD9B28CBC50FB6499B5 | ATI Technologies Inc. [Ver = 6.14.10.4188 | Size = 512000 bytes | Modified Date = 12/20/2007 10:57:27 PM | Attr = ] (ATI Smart) ATI Smart [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\ati2sgag.exe -> MD5 = 096C9955485F2B3F910F4C503C318D74 | [Ver = 5.13.0027 | Size = 593920 bytes | Modified Date = 12/20/2007 10:05:00 PM | Attr = ] (Automatic LiveUpdate Scheduler) Automatic LiveUpdate Scheduler [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec\LiveUpdate\AluSchedulerSvc.exe -> MD5 = 7C813EB232C7AEFA627A12A104DDA221 | Symantec Corporation [Ver = 3.4.0.164 | Size = 243064 bytes | Modified Date = 8/31/2007 11:49:50 AM | Attr = ] (CCALib8) Canon Camera Access Library 8 [Win32_Own | Auto | Running] -> %ProgramFiles%\Canon\CAL\CALMAIN.exe -> MD5 = 8EF654045E518AC00E52E7A1E2D3AD70 | Canon Inc. [Ver = 8, 4, 0, 1 | Size = 96370 bytes | Modified Date = 1/31/2007 3:55:42 PM | Attr = ] (ccEvtMgr) Symantec Event Manager [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\CCSVCHST.EXE -> MD5 = A8D49668CA8BBDDF5D3D4FBD9ECFF49E | Symantec Corporation [Ver = 107.0.3.7 | Size = 149864 bytes | Modified Date = 2/14/2008 11:02:00 AM | Attr = ] (ccSetMgr) Symantec Settings Manager [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\CCSVCHST.EXE -> MD5 = A8D49668CA8BBDDF5D3D4FBD9ECFF49E | Symantec Corporation [Ver = 107.0.3.7 | Size = 149864 bytes | Modified Date = 2/14/2008 11:02:00 AM | Attr = ] (CLTNetCnService) Symantec Lic NetConnect service [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\CCSVCHST.EXE -> MD5 = A8D49668CA8BBDDF5D3D4FBD9ECFF49E | Symantec Corporation [Ver = 107.0.3.7 | Size = 149864 bytes | Modified Date = 2/14/2008 11:02:00 AM | Attr = ] (comHost) COM Host [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\VAScanner\comHost.exe -> MD5 = 75A69CA9998577F8B2BE8695040E5DF4 | Symantec Corporation [Ver = 3.0.0.71 | Size = 55640 bytes | Modified Date = 8/22/2007 3:21:30 AM | Attr = ] (Creative Labs Licensing Service) Creative Labs Licensing Service [Win32_Own | On_Demand | Running] -> %CommonProgramFiles%\Creative Labs Shared\Service\CreativeLicensing.exe -> MD5 = 7DB5E3F44D797BD38B8E336CCC2E49D5 | Creative Labs [Ver = 2.65.010 | Size = 69632 bytes | Modified Date = 1/18/2006 12:07:12 PM | Attr = ] (Creative Service for CDROM Access) Creative Service for CDROM Access [Win32_Own | Auto | Running] -> %SystemRoot%\system32\CTSVCCDA.EXE -> MD5 = 3C8B6609712F4FF78E521F6DCFC4032B | Creative Technology Ltd [Ver = 1.0.1.0 | Size = 44032 bytes | Modified Date = 12/13/1999 9:01:00 AM | Attr = ] (Crypkey License) Crypkey License [Win32_Own | Auto | Running] -> %SystemRoot%\system32\Crypserv.exe -> MD5 = 85A6662B5F12B84D599A74119F04B381 | Kenonic Controls Ltd. [Ver = 5.4.0 | Size = 52224 bytes | Modified Date = 6/29/2000 4:45:10 AM | Attr = ] (dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\dmadmin.exe -> MD5 = 554C7CB178FE3BD12450B81AD63ADBC3 | Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] (dvpapi) dvpapi [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Authentium\AntiVirus\dvpapi.exe -> MD5 = FD0E5E1107FCBC16802363D6D82281CE | Authentium, Inc. [Ver = 4,94,0,61018 | Size = 177720 bytes | Modified Date = 10/18/2006 6:16:44 PM | Attr = R ] (gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> MD5 = 751C1D2CA2ABF4A9F5A6B8D7D45B907C | Google [Ver = 2.0.734.29932.beta | Size = 138168 bytes | Modified Date = 2/1/2007 10:03:34 AM | Attr = ] (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> MD5 = 1CF03C69B49ACB70C722DF92755C0C8C | Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 12:41:10 AM | Attr = ] (Imapi Helper) Imapi Helper [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Alex Feinman\ISO Recorder\ImapiHelper.exe -> MD5 = 1ACAD13923E467E473C3EC503223F983 | Alex Feinman [Ver = 1.0.0.0 | Size = 163840 bytes | Modified Date = 1/5/2006 12:06:02 AM | Attr = ] (iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> MD5 = 1E9ED06A30FB0410CE94892F1BA6984B | Apple Inc. [Ver = 7.6.1.9 | Size = 504104 bytes | Modified Date = 2/19/2008 2:10:24 PM | Attr = ] (LexBceS) LexBce Server [Win32_Own | Auto | Running] -> %SystemRoot%\system32\LEXBCES.EXE -> MD5 = E19C8550B4C6C67FABFFD998EACF440A | Lexmark International, Inc. [Ver = 9.45 | Size = 311296 bytes | Modified Date = 3/5/2004 12:30:48 AM | Attr = ] (LiveUpdate) LiveUpdate [Win32_Shared | On_Demand | Stopped] -> %ProgramFiles%\Symantec\LiveUpdate\LuComServer_3_4.EXE -> MD5 = 63ED50A6ED61829C2DEF5B733D258A05 | Symantec Corporation [Ver = 3.4.0.162 | Size = 3192184 bytes | Modified Date = 8/23/2007 4:35:22 PM | Attr = ] (LiveUpdate Notice) LiveUpdate Notice [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\CCSVCHST.EXE -> MD5 = A8D49668CA8BBDDF5D3D4FBD9ECFF49E | Symantec Corporation [Ver = 107.0.3.7 | Size = 149864 bytes | Modified Date = 2/14/2008 11:02:00 AM | Attr = ] (NetSvc) Intel NCS NetService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Intel\PROSetWired\NCS\Sync\NetSvc.exe -> MD5 = 9DA26B773BD04B867A8E9F427CD048FC | Intel(R) Corporation [Ver = 2.2.7.0 | Size = 147456 bytes | Modified Date = 11/19/2004 1:26:40 PM | Attr = ] (nmraapache) Pure Networks Net2Go Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe -> MD5 = 13350DDD0976CEB5F125396C7BFB05B4 | Pure Networks, Inc. [Ver = 2.0.54 | Size = 12800 bytes | Modified Date = 10/14/2006 8:21:04 PM | Attr = ] (nmservice) Pure Networks Network Magic Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Pure Networks\Network Magic\nmsrvc.exe -> MD5 = 3CB041B0C24258BDCFD0DB1B1BF95EFB | Pure Networks, Inc. [Ver = 4.0.6277.0 | Size = 321088 bytes | Modified Date = 11/1/2006 1:04:02 AM | Attr = ] (PcCtlCom) Trend Micro Central Control Component [Win32_Own | Auto | Running] -> %ProgramFiles%\Trend Micro\Internet Security 12\PcCtlCom.exe -> MD5 = 30974C7E29CB115A89FFB2CCB5F89F88 | Trend Micro Incorporated. [Ver = 12.70.0.1019 | Size = 880722 bytes | Modified Date = 9/4/2006 9:54:44 PM | Attr = ] (ProtexisLicensing) ProtexisLicensing [Win32_Own | Auto | Running] -> %SystemRoot%\system32\PSIService.exe -> MD5 = 64E413BA0C529AA40C3924BBCC4153DB | [Ver = 2.0.0.1 | Size = 174656 bytes | Modified Date = 11/2/2006 9:40:12 PM | Attr = ] (PSI_SVC_2) Protexis Licensing V2 [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Protexis\License Service\PsiService_2.exe -> MD5 = A6A7AD767BF5141665F5C675F671B3E1 | Protexis Inc. [Ver = 2.0.1.124 | Size = 185632 bytes | Modified Date = 7/24/2007 12:15:14 PM | Attr = ] (Symantec Core LC) Symantec Core LC [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\CCPD-LC\symlcsvc.exe -> MD5 = FA2F6A8849219B16460BF44F9D1F3AA7 | [Ver = | Size = 1251720 bytes | Modified Date = 3/10/2008 9:51:31 PM | Attr = ] (TabletService) TabletService [Win32_Own | Auto | Running] -> %SystemRoot%\system32\Tablet.exe -> MD5 = 8FF10E4D5BADB180533AE7E53A28D860 | Wacom Technology, Corp. [Ver = 6.0.4-4 | Size = 1197616 bytes | Modified Date = 6/4/2007 12:52:20 PM | Attr = ] (Tmntsrv) Trend Micro Real-time Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Trend Micro\Internet Security 12\Tmntsrv.exe -> MD5 = 37C406BAC6896D504E054BBFAA120D79 | Trend Micro Incorporated. [Ver = 12.70.0.1017 | Size = 290889 bytes | Modified Date = 8/30/2005 6:30:32 PM | Attr = ] (TmPfw) Trend Micro Personal Firewall [Win32_Own | Auto | Running] -> %ProgramFiles%\Trend Micro\Internet Security 12\TmPfw.exe -> MD5 = 70EE53C6E1B5402C5CE0F12D038B0F4C | Trend Micro Inc. [Ver = 2.0.0.1135 | Size = 585792 bytes | Modified Date = 8/30/2005 6:30:34 PM | Attr = ] (tmproxy) Trend Micro Proxy Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Trend Micro\Internet Security 12\tmproxy.exe -> MD5 = 949BB051485AEF6516A600F7454F0ABF | Trend Micro Inc. [Ver = 1.0.0.1135 | Size = 262215 bytes | Modified Date = 8/30/2005 6:30:34 PM | Attr = ] (WebrootSpySweeperService) Webroot Spy Sweeper Engine [Win32_Own | Auto | Running] -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeper.exe -> Unable to obtain MD5 | Webroot Software, Inc. [Ver = 3,5,6,114 | Size = 3572592 bytes | Modified Date = 1/4/2008 8:56:52 PM | Attr = ] [Registry - Non-Microsoft Only] < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> -> -> File not found ATIPTA -> %ProgramFiles%\ATI Technologies\ATI Control Panel\atiptaxx.exe -> MD5 = 8824078BDA1635639AAE125D24B85383 | ATI Technologies, Inc. [Ver = 6.14.10.5160 | Size = 344064 bytes | Modified Date = 8/5/2005 11:05:00 PM | Attr = ] BuildBU -> %SystemDrive%\dell\bldbubg.exe -> MD5 = 5954C0A3D5FFADBE17AA7530C66E90AA | [Ver = | Size = 61440 bytes | Modified Date = 1/18/2006 11:47:54 AM | Attr = ] ccApp -> %CommonProgramFiles%\Symantec Shared\CCAPP.EXE -> MD5 = E67200B6EF51BBF60C14C64D60FAD482 | Symantec Corporation [Ver = 107.0.3.7 | Size = 51048 bytes | Modified Date = 2/14/2008 11:01:56 AM | Attr = ] CTSysVol -> %ProgramFiles%\Creative\SBAudigy\Surround Mixer\CTSysVol.exe -> MD5 = 93D27C8D2902C8F88E9B70FC20998976 | Creative Technology Ltd [Ver = 1.4.5.0 | Size = 57344 bytes | Modified Date = 9/15/2005 11:47:22 AM | Attr = ] dla -> %SystemRoot%\system32\dla\tfswctrl.exe -> MD5 = 352FBF618066D0CEB7DC8ECABEB1A8D7 | Sonic Solutions [Ver = 1.04.08a | Size = 122941 bytes | Modified Date = 5/31/2005 6:33:00 AM | Attr = ] DVDLauncher -> %ProgramFiles%\CyberLink\PowerDVD\DVDLauncher.exe -> MD5 = B3E3C57FD22E71CE20389372D972C6DC | CyberLink Corp. [Ver = 3.00.0000 | Size = 53248 bytes | Modified Date = 2/23/2005 6:19:56 PM | Attr = ] IntelMeM -> %ProgramFiles%\Intel\Modem Event Monitor\IntelMEM.exe -> MD5 = BC02E491E88492B02363CE1B384FF7A7 | Intel Corporation [Ver = 0, 1, 0, 10 | Size = 221184 bytes | Modified Date = 9/3/2003 10:12:44 PM | Attr = ] ISUSPM Startup -> %CommonProgramFiles%\InstallShield\UpdateService\ISUSPM.exe -> MD5 = 9E109B03018763FDCB075CE74547BE22 | InstallShield Software Corporation [Ver = 4, 50, 100, 33433 | Size = 249856 bytes | Modified Date = 6/10/2005 12:44:02 PM | Attr = ] ISUSScheduler -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> MD5 = 583B7D111304BE63D7D9CB65482D2187 | InstallShield Software Corporation [Ver = 4, 50, 100, 33433 | Size = 81920 bytes | Modified Date = 6/10/2005 12:44:02 PM | Attr = ] iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> MD5 = 6F6493A929BC9B5762035940E825B840 | Apple Inc. [Ver = 7.6.1.9 | Size = 267048 bytes | Modified Date = 2/19/2008 2:10:32 PM | Attr = ] MBMon -> %SystemRoot%\system32\CTMBHA.DLL -> MD5 = EFF8CB80ACD8A2C94DCC06ABCD946260 | [Ver = 1.0.1.22 | Size = 1345520 bytes | Modified Date = 5/19/2005 10:54:00 AM | Attr = ] nmapp -> %ProgramFiles%\Pure Networks\Network Magic\nmapp.exe -> MD5 = B151DDB3FABD308162483DDA1B865E0A | Pure Networks, Inc. [Ver = 4.0.6277.0 | Size = 321088 bytes | Modified Date = 11/1/2006 1:04:02 AM | Attr = ] osCheck -> %ProgramFiles%\Norton Internet Security\osCheck.exe -> MD5 = 91535A86F6BD48BACCC3D58E6653456A | Symantec Corporation [Ver = 15.0.0.178 | Size = 714608 bytes | Modified Date = 8/25/2007 12:53:28 AM | Attr = ] pccguide.exe -> %ProgramFiles%\Trend Micro\Internet Security 12\pccguide.exe -> MD5 = 1DA0FDF5EE35C39145D464F06DC798AE | Trend Micro Incorporated. [Ver = 12.70.0.1017 | Size = 823362 bytes | Modified Date = 8/30/2005 6:30:26 PM | Attr = ] PDUiP6600DMon -> %ProgramFiles%\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe -> MD5 = 1DE937F630D060335405680299D1AEBF | CANON INC. [Ver = 3.00 | Size = 69632 bytes | Modified Date = 5/25/2005 10:35:10 AM | Attr = ] SpySweeper -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeperUI.exe -> MD5 = 2B0B8C29092FB420826F5A8FD02DC081 | Webroot Software, Inc. [Ver = 5,5,7,124 | Size = 5367664 bytes | Modified Date = 1/4/2008 8:56:58 PM | Attr = ] < OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> IMAIL-> Installed = 1 -> MAPI-> Installed = 1 -> MSFS-> Installed = 1 -> < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> Creative Detector -> %ProgramFiles%\Creative\MediaSource\Detector\CTDetect.exe -> MD5 = C744293DFBE1A3347FEC5DBFE3FD123E | Creative Technology Ltd [Ver = 3.0.2.0 | Size = 102400 bytes | Modified Date = 12/2/2004 8:23:34 PM | Attr = ] OE_OEM -> %ProgramFiles%\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe -> MD5 = 929B93FCC12782E01345657369759E7D | Trend Micro Inc. [Ver = 3.5.0.1119 | Size = 176201 bytes | Modified Date = 4/11/2006 8:39:22 PM | Attr = ] SetDefaultMIDI -> %SystemRoot%\MIDIDEF.EXE -> MD5 = 702A697091F0C47AF6BDAE2A35E2C248 | Creative Technology Ltd [Ver = 2, 9, 0, 4 | Size = 24576 bytes | Modified Date = 12/22/2004 7:40:02 PM | Attr = ] SMSystemAnalyzer -> %ProgramFiles%\iolo\System Mechanic 6\SMSystemAnalyzer.exe -> MD5 = C8C63E4A3F91412A4CD86CB3ABCFA702 | [Ver = | Size = 557056 bytes | Modified Date = 12/20/2006 1:38:56 PM | Attr = ] swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> MD5 = E616A6A6E91B0A86F2F6217CDE835FFE | Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 7/18/2007 5:54:45 PM | Attr = ] < Run [HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\] > -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> Creative Detector -> %ProgramFiles%\Creative\MediaSource\Detector\CTDetect.exe -> MD5 = C744293DFBE1A3347FEC5DBFE3FD123E | Creative Technology Ltd [Ver = 3.0.2.0 | Size = 102400 bytes | Modified Date = 12/2/2004 8:23:34 PM | Attr = ] OE_OEM -> %ProgramFiles%\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe -> MD5 = 929B93FCC12782E01345657369759E7D | Trend Micro Inc. [Ver = 3.5.0.1119 | Size = 176201 bytes | Modified Date = 4/11/2006 8:39:22 PM | Attr = ] SetDefaultMIDI -> %SystemRoot%\MIDIDEF.EXE -> MD5 = 702A697091F0C47AF6BDAE2A35E2C248 | Creative Technology Ltd [Ver = 2, 9, 0, 4 | Size = 24576 bytes | Modified Date = 12/22/2004 7:40:02 PM | Attr = ] SMSystemAnalyzer -> %ProgramFiles%\iolo\System Mechanic 6\SMSystemAnalyzer.exe -> MD5 = C8C63E4A3F91412A4CD86CB3ABCFA702 | [Ver = | Size = 557056 bytes | Modified Date = 12/20/2006 1:38:56 PM | Attr = ] swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> MD5 = E616A6A6E91B0A86F2F6217CDE835FFE | Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 7/18/2007 5:54:45 PM | Attr = ] < Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup -> < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> %AllUsersProfile%\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk -> %CommonProgramFiles%\Adobe\Calibration\Adobe Gamma Loader.exe -> MD5 = C2FF17734176CD15221C10044EF0BA1A | Adobe Systems, Inc. [Ver = 1, 0, 0, 1 | Size = 113664 bytes | Modified Date = 10/11/2000 7:08:00 PM | Attr = ] %AllUsersProfile%\Start Menu\Programs\Startup\dlbcserv.lnk -> %ProgramFiles%\Dell Photo Printer 720\dlbcserv.exe -> MD5 = D0D1B7429881A2F0465D73E1403B513D | [Ver = 1.0.0.1 | Size = 315392 bytes | Modified Date = 1/9/2005 7:42:54 AM | Attr = ] %AllUsersProfile%\Start Menu\Programs\Startup\HotSync Manager.lnk -> %ProgramFiles%\Handspring\Hotsync.exe -> MD5 = F8FB2CA91F25D3EAA2CAE2F0B55FEC54 | PalmSource, Inc [Ver = 6.0.1 | Size = 471040 bytes | Modified Date = 6/9/2004 2:16:08 PM | Attr = ] < Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> < Mark ****** Startup Folder > -> C:\Documents and Settings\Mark ******\Start Menu\Programs\Startup -> < AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktopNetwork3.dll -> MD5 = EC49D64A0F8806710D978764CE3688C3 | [Ver = | Size = 110592 bytes | Modified Date = 1/18/2006 12:20:45 PM | Attr = ] *MultiFile Done* -> -> < SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005] > -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> AtiExtEvent -> %SystemRoot%\system32\ati2evxx.dll -> MD5 = 6C253F61D585CFA2B57CBD95464EC208 | ATI Technologies Inc. [Ver = 6.14.10.4176 | Size = 122880 bytes | Modified Date = 12/20/2007 10:58:55 PM | Attr = ] WRNotifier -> %SystemRoot%\system32\WRLogonNtf.dll -> MD5 = 9BA2293EFC229743D76BF7637E07DF44 | Webroot Software, Inc. [Ver = 3,5,6,114 | Size = 219504 bytes | Modified Date = 1/4/2008 8:34:36 PM | Attr = ] < CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\\{17492023-C23A-453E-A040-C7C580BBF700} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\InstallVisualStyle -> C:\WINDOWS\Resources\Themes\Royale\Royale.mss [C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles] -> File not found HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\InstallTheme -> C:\WINDOWS\Resources\Themes\Royale.the [C:\WINDOWS\Resources\Themes\Royale.theme] -> File not found < CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place0 -> ::{C55C499D-3518-44a1-998E-796AC5FC989D} -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place1 -> 8 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place2 -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place3 -> 5 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place4 -> 17 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005] > -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\ -> -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\ -> -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place0 -> ::{C55C499D-3518-44a1-998E-796AC5FC989D} -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place1 -> 8 -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place2 -> 0 -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place3 -> 5 -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place4 -> 17 -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < HOSTS File > (734 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\Default_Search_URL -> http://www.google.com/ie -> HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://www.google.com/ie -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\Default_Page_URL -> http://www.google.com/ig/dell?hl=en -> HKEY_CURRENT_USER\: Main\\Search Bar -> http://www.google.com/ie -> HKEY_CURRENT_USER\: Main\\Search Page -> http://www.google.com -> HKEY_CURRENT_USER\: Main\\Start Page -> http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_home -> HKEY_CURRENT_USER\: Search\\SearchAssistant -> http://www.google.com/ie -> HKEY_CURRENT_USER\: SearchURL\\ -> http://www.google.com/search?q=%s[Reg Error: Value provider does not exist or could not be read.] -> HKEY_CURRENT_USER\: ProxyEnable -> 0 -> HKEY_CURRENT_USER\: ProxyOverride -> 127.0.0.1 -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: Main\\Default_Page_URL -> http://www.google.com/ig/dell?hl=en -> HKEY_USERS\.DEFAULT\: Main\\Start Page -> http://www.google.com/ig/dell?hl=en -> HKEY_USERS\.DEFAULT\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: Main\\Default_Page_URL -> http://www.google.com/ig/dell?hl=en -> HKEY_USERS\S-1-5-18\: Main\\Start Page -> http://www.google.com/ig/dell?hl=en -> HKEY_USERS\S-1-5-18\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\] > -> -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\: Main\\Default_Page_URL -> http://www.google.com/ig/dell?hl=en -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\: Main\\Search Bar -> http://www.google.com/ie -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\: Main\\Search Page -> http://www.google.com -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\: Main\\Start Page -> http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_home -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\: Search\\SearchAssistant -> http://www.google.com/ie -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\: SearchURL\\ -> http://www.google.com/search?q=%s[Reg Error: Value provider does not exist or could not be read.] -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\: ProxyEnable -> 0 -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\: ProxyOverride -> 127.0.0.1 -> < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 1 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 3 domain(s) found. -> turbotax.com .[https] -> Trusted sites -> xara.com .[*] -> Trusted sites -> xaraonline.com .[*] -> Trusted sites -> < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\] > -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 3 domain(s) found. -> turbotax.com .[https] -> Trusted sites -> xara.com .[*] -> Trusted sites -> xaraonline.com .[*] -> Trusted sites -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\] > -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Unable to obtain MD5 | Adobe Systems Incorporated [Ver = 8.0.0.2006102200 | Size = 62080 bytes | Modified Date = 10/23/2006 12:08:42 AM | Attr = ] {5CA3D70E-1895-11CF-8E15-001234567890} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\dla\tfswshx.dll [DriveLetterAccess] -> MD5 = ECBB15757C8DFCB1D23685FC2B96B898 | Sonic Solutions [Ver = 1.04.08a | Size = 118844 bytes | Modified Date = 5/31/2005 6:33:00 AM | Attr = ] {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [Reg Error: Value does not exist or could not be read.] -> MD5 = 6BC066FCC66BB0EE33A618EBC65683D5 | Symantec Corporation [Ver = 2008.2.0.84 | Size = 316784 bytes | Modified Date = 8/24/2007 11:51:56 PM | Attr = ] {6D53EC84-6AAE-4787-AEEE-F4628F01010C} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Symantec Shared\IDS\IPSBHO.dll [Symantec Intrusion Prevention] -> MD5 = FA3E00177B57D5B2BF058D560931D750 | Symantec Corporation [Ver = 8.2.0.86 | Size = 116088 bytes | Modified Date = 3/10/2008 9:57:12 PM | Attr = ] {AA58ED58-01DD-4d91-8333-CF10577473F7} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar5.dll [Google Toolbar Helper] -> MD5 = 6319F2D4708DBCAE37CFA03DA10782C0 | Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2403392 bytes | Modified Date = 1/20/2007 12:55:32 AM | Attr = R ] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll [Google Toolbar Notifier BHO] -> MD5 = 1DC47CA76A0FFEAA25B45DE5706F2115 | Google Inc. [Ver = 2, 0, 301, 7164 | Size = 325048 bytes | Modified Date = 7/18/2007 5:54:43 PM | Attr = ] {CA6319C0-31B7-401E-A518-A07C3DB8F777} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\GoogleAFE\GoogleAE.dll [CBrowserHelperObject Object] -> Unable to obtain MD5 | Google [Ver = 1.0.0.1 | Size = 90112 bytes | Modified Date = 12/8/2005 4:00:34 PM | Attr = ] < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> {2318C2B1-4965-11d4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar5.dll [&Google] -> MD5 = 6319F2D4708DBCAE37CFA03DA10782C0 | Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2403392 bytes | Modified Date = 1/20/2007 12:55:32 AM | Attr = R ] {327C2873-E90D-4c37-AA9D-10AC9BABA46C} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Canon\Easy-WebPrint\Toolband.dll [Easy-WebPrint] -> MD5 = 3D3A15D5F7C44868FF26C2A73377D7EE | [Ver = 2, 5, 1, 6 | Size = 405504 bytes | Modified Date = 8/26/2004 12:27:32 PM | Attr = ] {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [Show Norton Toolbar] -> MD5 = 6BC066FCC66BB0EE33A618EBC65683D5 | Symantec Corporation [Ver = 2008.2.0.84 | Size = 316784 bytes | Modified Date = 8/24/2007 11:51:56 PM | Attr = ] < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar5.dll [&Google] -> MD5 = 6319F2D4708DBCAE37CFA03DA10782C0 | Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2403392 bytes | Modified Date = 1/20/2007 12:55:32 AM | Attr = R ] WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar5.dll [&Google] -> MD5 = 6319F2D4708DBCAE37CFA03DA10782C0 | Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2403392 bytes | Modified Date = 1/20/2007 12:55:32 AM | Attr = R ] WebBrowser\\{4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [Show Norton Toolbar] -> MD5 = 6BC066FCC66BB0EE33A618EBC65683D5 | Symantec Corporation [Ver = 2008.2.0.84 | Size = 316784 bytes | Modified Date = 8/24/2007 11:51:56 PM | Attr = ] < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\] > -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar5.dll [&Google] -> MD5 = 6319F2D4708DBCAE37CFA03DA10782C0 | Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2403392 bytes | Modified Date = 1/20/2007 12:55:32 AM | Attr = R ] WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar5.dll [&Google] -> MD5 = 6319F2D4708DBCAE37CFA03DA10782C0 | Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2403392 bytes | Modified Date = 1/20/2007 12:55:32 AM | Attr = R ] WebBrowser\\{4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [Show Norton Toolbar] -> MD5 = 6BC066FCC66BB0EE33A618EBC65683D5 | Symantec Corporation [Ver = 2008.2.0.84 | Size = 316784 bytes | Modified Date = 8/24/2007 11:51:56 PM | Attr = ] < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [] -> File not found < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> E&xport to Microsoft Excel -> %SystemDrive%\PROGRA~1\MICROS~4\Office12\EXCEL.EXE -> File not found Easy-WebPrint Add To Print List -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> MD5 = 1DB4789F18D94EF7028109FCD0888E52 | [Ver = 2, 5, 1, 6 | Size = 200704 bytes | Modified Date = 8/26/2004 12:26:36 PM | Attr = ] Easy-WebPrint High Speed Print -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> MD5 = 1DB4789F18D94EF7028109FCD0888E52 | [Ver = 2, 5, 1, 6 | Size = 200704 bytes | Modified Date = 8/26/2004 12:26:36 PM | Attr = ] Easy-WebPrint Preview -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> MD5 = 1DB4789F18D94EF7028109FCD0888E52 | [Ver = 2, 5, 1, 6 | Size = 200704 bytes | Modified Date = 8/26/2004 12:26:36 PM | Attr = ] Easy-WebPrint Print -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> MD5 = 1DB4789F18D94EF7028109FCD0888E52 | [Ver = 2, 5, 1, 6 | Size = 200704 bytes | Modified Date = 8/26/2004 12:26:36 PM | Attr = ] < Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found < Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\] > -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\] > -> HKEY_USERS\S-1-5-21-2109104683-3805700953-4194988199-1005\Software\Microsoft\Internet Explorer\MenuExt\ -> E&xport to Microsoft Excel -> %SystemDrive%\PROGRA~1\MICROS~4\Office12\EXCEL.EXE -> File not found Easy-WebPrint Add To Print List -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> MD5 = 1DB4789F18D94EF7028109FCD0888E52 | [Ver = 2, 5, 1, 6 | Size = 200704 bytes | Modified Date = 8/26/2004 12:26:36 PM | Attr = ] Easy-WebPrint High Speed Print -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> MD5 = 1DB4789F18D94EF7028109FCD0888E52 | [Ver = 2, 5, 1, 6 | Size = 200704 bytes | Modified Date = 8/26/2004 12:26:36 PM | Attr = ] Easy-WebPrint Preview -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> MD5 = 1DB4789F18D94EF7028109FCD0888E52 | [Ver = 2, 5, 1, 6 | Size = 200704 bytes | Modified Date = 8/26/2004 12:26:36 PM | Attr = ] Easy-WebPrint Print -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> MD5 = 1DB4789F18D94EF7028109FCD0888E52 | [Ver = 2, 5, 1, 6 | Size = 200704 bytes | Modified Date = 8/26/2004 12:26:36 PM | Attr = ] < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {5514F759-4EC8-41B8-9BD1-CCDD2A2C123E} -> (Westell WireSpeed Dual Connect Modem) -> {95DDF218-C683-4340-97B2-4BB0FAEDADEF} -> (Intel(R) PRO/100 VE Network Connection) -> < Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found pure-go:{4746C79A-2042-4332-8650-48966E44ABA8} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Pure Networks Shared\puresp3.dll[CPureGoProtoInfo Object] -> MD5 = 227EE4793C6AED4C24C3F45AEDE1ED36 | Pure Networks, Inc. [Ver = 4.0.6305.0 | Size = 71232 bytes | Modified Date = 11/9/2006 2:37:38 AM | Attr = ] < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {02BCC737-B171-4746-94C9-0D8A0B2C0089}[HKEY_LOCAL_MACHINE] -> http://office.microsoft.com/templates/ieawsdc.cab[Microsoft Office Template and Media Control] -> {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}[HKEY_LOCAL_MACHINE] -> http://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab[Office Genuine Advantage Validation Tool] -> {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}[HKEY_LOCAL_MACHINE] -> http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab[CKAVWebScan Object] -> {17492023-C23A-453E-A040-C7C580BBF700}[HKEY_LOCAL_MACHINE] -> http://go.microsoft.com/fwlink/?linkid=39204[Windows Genuine Advantage Validation Tool] -> {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B}[HKEY_LOCAL_MACHINE] -> http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.4.4.cab[DownloadManager Control] -> {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}[HKEY_LOCAL_MACHINE] -> http://office.microsoft.com/officeupdate/content/opuc3.cab[Office Update Installation Engine] -> {459E93B6-150E-45D5-8D4B-45C66FC035FE}[HKEY_LOCAL_MACHINE] -> http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx[get_atlcom Class] -> {6414512B-B978-451D-A0D8-FCFDF33E833C}[HKEY_LOCAL_MACHINE] -> http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138114010296[WUWebControl Class] -> {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}[HKEY_LOCAL_MACHINE] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1142794898406[MUWebControl Class] -> {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B}[HKEY_LOCAL_MACHINE] -> http://launch.gamespyarcade.com/software/launch/alaunch.cab[Reg Error: Key does not exist or could not be opened.] -> {819F8533-D935-4183-B692-587F8D56AC3C}[HKEY_LOCAL_MACHINE] -> http://www.iolo.com/threatcenter/App/ocx/AVCheckUp.ocx[iolo.AV.OnlineVirusScanner] -> {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}[HKEY_LOCAL_MACHINE] -> http://www.adobe.com/products/acrobat/nos/gp.cab[get_atlcom Class] -> {D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> Microsoft XML Parser for Java[HKEY_LOCAL_MACHINE] -> file://C:\WINDOWS\Java\classes\xmldso.cab[Reg Error: Key does not exist or could not be opened.] -> [Files/Folders - Created Within 90 days] ATI -> %SystemDrive%\ATI -> [Folder | Created Date = 1/18/2008 1:02:43 AM | Attr = ] Avenger -> %SystemDrive%\Avenger -> [Folder | Created Date = 3/15/2008 12:25:40 PM | Attr = ] Deckard -> %SystemDrive%\Deckard -> [Folder | Created Date = 3/15/2008 4:22:44 AM | Attr = ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> Unable to obtain MD5 | [Ver = | Size = 3219279872 bytes | Created Date = 3/13/2008 3:07:59 PM | Attr = HS] install.dat -> %SystemDrive%\install.dat -> MD5 = 0305366B4AF178DAD5E04F42D43DADB5 | [Ver = | Size = 164 bytes | Created Date = 3/13/2008 10:02:47 AM | Attr = ] System32 -> %SystemDrive%\System32 -> [Folder | Created Date = 3/12/2008 8:55:08 PM | Attr = ] Temp -> %SystemDrive%\Temp -> [Folder | Created Date = 3/9/2008 7:03:15 PM | Attr = ] VundoFix Backups -> %SystemDrive%\VundoFix Backups -> [Folder | Created Date = 3/12/2008 7:44:25 PM | Attr = ] WTablet -> %SystemDrive%\WTablet -> [Folder | Created Date = 3/9/2008 10:48:11 PM | Attr = ] Samhid.sys -> %SystemRoot%\System32\drivers\Samhid.sys -> MD5 = 71CEC3F79B3E921D417CB8E541FFF10A | [Ver = | Size = 7548 bytes | Created Date = 1/17/2008 10:00:38 PM | Attr = ] SSFS0BB9.sys -> %SystemRoot%\System32\drivers\SSFS0BB9.sys -> MD5 = D3AD8D2E550B262694B024D1EB1EFFFC | Webroot Software Inc (www.webroot.com) [Ver = 3.5.6.114 | Size = 20336 bytes | Created Date = 3/13/2008 10:05:15 AM | Attr = ] sshrmd.sys -> %SystemRoot%\System32\drivers\sshrmd.sys -> MD5 = 4D0E7A4BEFAD963D3AECFAC12FDEFF16 | Webroot Software Inc (www.webroot.com) [Ver = 3.5.6.114 | Size = 21872 bytes | Created Date = 3/13/2008 10:05:15 AM | Attr = ] ssidrv.sys -> %SystemRoot%\System32\drivers\ssidrv.sys -> MD5 = 43EEDDC9B9B8ACCDB4A914BA893C73DE | Webroot Software Inc (www.webroot.com) [Ver = 3.5.6.114 | Size = 163696 bytes | Created Date = 3/13/2008 10:05:15 AM | Attr = ] sskbfd.sys -> %SystemRoot%\System32\drivers\sskbfd.sys -> MD5 = 8564BC9598BE1705477B7FA61D657C2B | Webroot Software Inc (www.webroot.com) [Ver = 3.5.6.114 | Size = 23920 bytes | Created Date = 3/13/2008 10:05:15 AM | Attr = ] SYMEVENT.CAT -> %SystemRoot%\System32\drivers\SYMEVENT.CAT -> MD5 = CCF19EB963474EE4BA9F4F554BC140F1 | [Ver = | Size = 10740 bytes | Created Date = 3/10/2008 8:42:07 PM | Attr = ] SYMEVENT.INF -> %SystemRoot%\System32\drivers\SYMEVENT.INF -> MD5 = 6DAB88588D60317DDBFFBB7601BD5988 | [Ver = | Size = 805 bytes | Created Date = 3/10/2008 8:42:05 PM | Attr = ] SYMEVENT.SYS -> %SystemRoot%\System32\drivers\SYMEVENT.SYS -> MD5 = 9E4188476848B2EF86F9C44D5164E724 | Symantec Corporation [Ver = 12.5.2.1 | Size = 123952 bytes | Created Date = 3/10/2008 8:42:05 PM | Attr = ] wacommousefilter.sys -> %SystemRoot%\System32\drivers\wacommousefilter.sys -> MD5 = 427A8BC96F16C40DF81C2D2F4EDD32DD | Wacom Technology [Ver = 1.2.0002.0 | Size = 11312 bytes | Created Date = 2/27/2008 5:03:11 PM | Attr = ] wacomvhid.sys -> %SystemRoot%\System32\drivers\wacomvhid.sys -> MD5 = 73E6F16A1F187D71FB26AF308551E54A | Wacom Technology [Ver = 2.8.0000.0 | Size = 12848 bytes | Created Date = 2/27/2008 5:03:11 PM | Attr = ] WacomVKHid.sys -> %SystemRoot%\System32\drivers\WacomVKHid.sys -> MD5 = 889459833432B161CB99CFDF84A1A9BB | Wacom Technology [Ver = 1.1.0000.0 | Size = 11440 bytes | Created Date = 2/27/2008 5:04:48 PM | Attr = ] amdpcom32.dll -> %SystemRoot%\System32\amdpcom32.dll -> MD5 = F86FB57625E38AEB8CC3CB7551D58B4F | Advanced Micro Devices, Inc. [Ver = 6.14.10.0001 | Size = 46080 bytes | Created Date = 12/20/2007 10:24:07 PM | Attr = ] ati2sgag.exe -> %SystemRoot%\System32\ati2sgag.exe -> MD5 = 096C9955485F2B3F910F4C503C318D74 | [Ver = 5.13.0027 | Size = 593920 bytes | Created Date = 1/18/2008 1:03:55 AM | Attr = ] ATIDEMGX.dll -> %SystemRoot%\System32\ATIDEMGX.dll -> MD5 = A5E4D5C197D3810146459D1DC7A6EF75 | Advanced Micro Devices, Inc. [Ver = 2.0.2910.39885 | Size = 368640 bytes | Created Date = 12/20/2007 11:09:31 PM | Attr = ] atioglx2.dll -> %SystemRoot%\System32\atioglx2.dll -> MD5 = E623B2DA2E80FB90A91031AFFAB0EF97 | ATI Technologies Inc. [Ver = 6.14.10.7275 | Size = 9826304 bytes | Created Date = 12/20/2007 10:53:18 PM | Attr = ] atiok3x2.dll -> %SystemRoot%\System32\atiok3x2.dll -> MD5 = BF6410AA8BC877C1AFF2AE9FFD36D78B | ATI Technologies Inc. [Ver = 6.14.10.7275 | Size = 159744 bytes | Created Date = 12/20/2007 10:15:04 PM | Attr = ] ativva5x.dat -> %SystemRoot%\System32\ativva5x.dat -> MD5 = 31B434EDEC919137787CABF10E76266B | [Ver = | Size = 3107788 bytes | Created Date = 12/20/2007 10:35:44 PM | Attr = ] ativva6x.dat -> %SystemRoot%\System32\ativva6x.dat -> MD5 = C23E3A4C7004D634A5C2E02841B3E3D4 | [Ver = | Size = 887724 bytes | Created Date = 12/20/2007 10:35:44 PM | Attr = ] ativvaxx.dat -> %SystemRoot%\System32\ativvaxx.dat -> MD5 = 31B434EDEC919137787CABF10E76266B | [Ver = | Size = 3107788 bytes | Created Date = 12/20/2007 10:35:44 PM | Attr = ] CreateDir.exe -> %SystemRoot%\System32\CreateDir.exe -> MD5 = 46532B778119553442EB3AE82315DAEE | [Ver = 1, 0, 0, 1 | Size = 192512 bytes | Created Date = 1/17/2008 10:00:27 PM | Attr = ] DLLAV32.dll -> %SystemRoot%\System32\DLLAV32.dll -> MD5 = 7775978DA5DC07CCCAA79B1FB712C780 | PoINT Software & Systems GmbH [Ver = 6, 0, 0, 108 | Size = 487424 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLAV32.lib -> %SystemRoot%\System32\DLLAV32.lib -> MD5 = B542E1BBB193304986A2782E96919D3C | [Ver = | Size = 14182 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLCDA32.dll -> %SystemRoot%\System32\DLLCDA32.dll -> MD5 = 3CF5D6F462D385BF3A26BA60A0459F67 | PoINT Software & Systems GmbH [Ver = 3, 3, 0, 70 | Size = 114688 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLCDF32.dll -> %SystemRoot%\System32\DLLCDF32.dll -> MD5 = 435EBFA51632D4ACC7368F751597A86C | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 24 | Size = 61440 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLCPY32.dll -> %SystemRoot%\System32\DLLCPY32.dll -> MD5 = 5E2532A48ABB83BAA9D19E3500B45380 | PoINT Software & Systems GmbH [Ver = 3, 7, 0, 136 | Size = 94208 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLDEV32.dll -> %SystemRoot%\System32\DLLDEV32.dll -> MD5 = 6AC20E21984B912F6982FFEF8EBBEB13 | PoINT Software & Systems GmbH [Ver = 3, 7, 0, 254 | Size = 163840 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLDEV32i.dll -> %SystemRoot%\System32\DLLDEV32i.dll -> MD5 = A0193025F23F4509C561D3358F4A149F | [Ver = 3, 7, 0, 12 | Size = 120200 bytes | Created Date = 2/24/2008 9:24:05 AM | Attr = ] DLLDIR32.dll -> %SystemRoot%\System32\DLLDIR32.dll -> MD5 = 9B108B6A630027763CD9EB28AB06992B | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 10 | Size = 32768 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLDRV32.dll -> %SystemRoot%\System32\DLLDRV32.dll -> MD5 = 3B588D13B0C68F4AD341342B8B244725 | PoINT Software & Systems GmbH [Ver = 3, 7, 0, 332 | Size = 151552 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLIMG32.dll -> %SystemRoot%\System32\DLLIMG32.dll -> MD5 = 1903B46D93ED6E1ED5A41954FA21870F | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 10 | Size = 45056 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLIO32.dll -> %SystemRoot%\System32\DLLIO32.dll -> MD5 = A7CC0D4909C673704484EA735642DBA8 | PoINT Software & Systems GmbH [Ver = 3, 1, 0, 86 | Size = 53248 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLISO32.dll -> %SystemRoot%\System32\DLLISO32.dll -> MD5 = D41CD97D3A7B3DAF632C9335710162A0 | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 11 | Size = 32768 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLIX.dll -> %SystemRoot%\System32\DLLIX.dll -> MD5 = 82D1CAC671A80EB542B4428F072D7548 | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 7 | Size = 24576 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLMSC32.dll -> %SystemRoot%\System32\DLLMSC32.dll -> MD5 = 69C3A42D62622DC14200D2F0531B7171 | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 11 | Size = 32768 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLPNT32.dll -> %SystemRoot%\System32\DLLPNT32.dll -> MD5 = C6CC1155A6CDAE463E9085727383C6D6 | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 44 | Size = 36864 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLPRF32.dll -> %SystemRoot%\System32\DLLPRF32.dll -> MD5 = 32D596876B43B44FC4A2BFCC379CE6D2 | PoINT Software & Systems GmbH [Ver = 3, 1, 0, 34 | Size = 49152 bytes | Created Date = 2/24/2008 9:24:45 AM | Attr = ] DLLPRJ32.dll -> %SystemRoot%\System32\DLLPRJ32.dll -> MD5 = B4455EF6F773C790ECBAAD93F719C1FE | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 17 | Size = 53248 bytes | Created Date = 2/24/2008 9:24:46 AM | Attr = ] DLLPTL32.dll -> %SystemRoot%\System32\DLLPTL32.dll -> MD5 = BE5E9E3646D1EC21B9CD75895FE90B36 | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 23 | Size = 65536 bytes | Created Date = 2/24/2008 9:24:46 AM | Attr = ] DLLRD32.dll -> %SystemRoot%\System32\DLLRD32.dll -> MD5 = 8EF0C1253D47A158D3023F1292A5E293 | PoINT Software & Systems GmbH [Ver = 2, 1, 0, 104 | Size = 40960 bytes | Created Date = 2/24/2008 9:24:46 AM | Attr = ] DLLRES32.dll -> %SystemRoot%\System32\DLLRES32.dll -> MD5 = 63E34A8666D80101F6DC8CC9CC61685A | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 143 | Size = 188416 bytes | Created Date = 2/24/2008 9:24:46 AM | Attr = ] DLLTPO32.dll -> %SystemRoot%\System32\DLLTPO32.dll -> MD5 = B2BCA1AAACFD7C7656F58ECF5C6569AC | PoINT Software & Systems GmbH [Ver = 3, 1, 0, 31 | Size = 57344 bytes | Created Date = 2/24/2008 9:24:46 AM | Attr = ] E447EDAD8A.sys -> %SystemRoot%\System32\E447EDAD8A.sys -> MD5 = D4C190B84A5168863D6D97D9E7FAC244 | [Ver = | Size = 168 bytes | Created Date = 2/24/2008 5:44:59 PM | Attr = RHS] FDRdriver.dll -> %SystemRoot%\System32\FDRdriver.dll -> MD5 = 5E81F4F16894EC37B4072E5CEA9402C3 | Jess Technology Co., Ltd. [Ver = 1, 2, 0, 1 | Size = 77824 bytes | Created Date = 1/17/2008 10:00:38 PM | Attr = ] FDRpage.dll -> %SystemRoot%\System32\FDRpage.dll -> MD5 = 2A7B1B373168D307573DD5295476FC8A | [Ver = 1, 0, 0, 0 | Size = 487424 bytes | Created Date = 1/17/2008 10:00:37 PM | Attr = ] Kaspersky Lab -> %SystemRoot%\System32\Kaspersky Lab -> [Folder | Created Date = 3/15/2008 1:17:38 PM | Attr = ] 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> KGyGaAvL.sys -> %SystemRoot%\System32\KGyGaAvL.sys -> MD5 = 0F07374DEB5BA2311841E9BE54E45E0B | [Ver = | Size = 1682 bytes | Created Date = 2/24/2008 5:44:59 PM | Attr = HS] MAGIX -> %SystemRoot%\System32\MAGIX -> [Folder | Created Date = 2/24/2008 9:23:09 AM | Attr = ] mgxoschk.dll -> %SystemRoot%\System32\mgxoschk.dll -> MD5 = 52A424D73031C2C66FDA15FA9AB07F9D | MAGIX AG [Ver = 1, 37, 0, 241 | Size = 700416 bytes | Created Date = 2/24/2008 9:23:09 AM | Attr = ] mnnmp.ini -> %SystemRoot%\System32\mnnmp.ini -> MD5 = 58875579C080DF9EB23DEB8234EA4624 | [Ver = | Size = 2878 bytes | Created Date = 3/12/2008 9:02:09 PM | Attr = HS] MRT.INI -> %SystemRoot%\System32\MRT.INI -> MD5 = 8107BBF0E420BED39BC3490B2FF9F555 | [Ver = | Size = 127 bytes | Created Date = 3/12/2008 10:24:10 PM | Attr = ] MXRestore.exe -> %SystemRoot%\System32\MXRestore.exe -> MD5 = 2E519B13BBF346314B2833226ED748A0 | MAGIX AG [Ver = 2, 0, 5, 9 | Size = 430080 bytes | Created Date = 2/24/2008 9:24:46 AM | Attr = ] New Folder -> %SystemRoot%\System32\New Folder -> [Folder | Created Date = 3/9/2008 10:42:14 PM | Attr = ] QuickTime.qts -> %SystemRoot%\System32\QuickTime.qts -> MD5 = 2BAFF55F023EFB5A2F15EF5C9B7E5C35 | Apple Inc. [Ver = 7.4.1 | Size = 57344 bytes | Created Date = 2/1/2008 12:13:18 AM | Attr = ] QuickTimeVR.qtx -> %SystemRoot%\System32\QuickTimeVR.qtx -> MD5 = 74358270B25669C3A96C5673E61AA943 | Apple Inc. [Ver = 7.4.1 | Size = 90112 bytes | Created Date = 2/1/2008 12:13:18 AM | Attr = ] S32EVNT1.DLL -> %SystemRoot%\System32\S32EVNT1.DLL -> MD5 = 35A78813765364C5B46411A40AF6E559 | Symantec Corporation [Ver = 12.5.2.2 | Size = 60800 bytes | Created Date = 3/10/2008 8:42:11 PM | Attr = ] sam.ini -> %SystemRoot%\System32\sam.ini -> MD5 = C8427A543F673CEF710946BA56D9B567 | [Ver = | Size = 180 bytes | Created Date = 1/17/2008 10:02:26 PM | Attr = ] ssiefr.EXE -> %SystemRoot%\System32\ssiefr.EXE -> MD5 = 0AC2D082F667BB9340231CC90D41D60A | Webroot Software Inc (www.webroot.com) [Ver = 3.5.6.114 | Size = 16240 bytes | Created Date = 3/13/2008 10:04:53 AM | Attr = ] STRING32.dll -> %SystemRoot%\System32\STRING32.dll -> MD5 = B331F90A8198EBC93AFB6511D76891F4 | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 20 | Size = 32768 bytes | Created Date = 2/24/2008 9:24:46 AM | Attr = ] Tablet.exe -> %SystemRoot%\System32\Tablet.exe -> MD5 = 8FF10E4D5BADB180533AE7E53A28D860 | Wacom Technology, Corp. [Ver = 6.0.4-4 | Size = 1197616 bytes | Created Date = 2/27/2008 5:03:07 PM | Attr = ] TTI32.dll -> %SystemRoot%\System32\TTI32.dll -> MD5 = 1DA32728F808D41F380193B6B21B14C2 | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 2 | Size = 24576 bytes | Created Date = 2/24/2008 9:24:46 AM | Attr = ] TTIC32.dll -> %SystemRoot%\System32\TTIC32.dll -> MD5 = AB024EFED92D5A91DDCC9577FD5A3A9C | PoINT Software & Systems GmbH [Ver = 3, 0, 0, 2 | Size = 24576 bytes | Created Date = 2/24/2008 9:24:46 AM | Attr = ] unvckami.ini -> %SystemRoot%\System32\unvckami.ini -> MD5 = 5B6D6A844DE682801D936CE5BEB48FA3 | [Ver = | Size = 1318352 bytes | Created Date = 3/10/2008 8:34:07 PM | Attr = HS] VundoFixSVC.exe -> %SystemRoot%\System32\VundoFixSVC.exe -> MD5 = 09F56AC1B2A7550F967DECCAB2612680 | Atribune.org [Ver = 1.00.0003 | Size = 24576 bytes | Created Date = 3/12/2008 8:50:25 PM | Attr = ] WacomTablet.cpl -> %SystemRoot%\System32\WacomTablet.cpl -> MD5 = 8BA56CFA2CABC297C50BA81609B7A4C3 | Wacom Technology, Corp. [Ver = 6.0.4-4 | Size = 3483184 bytes | Created Date = 2/27/2008 5:05:08 PM | Attr = ] WacomTablet.znc -> %SystemRoot%\System32\WacomTablet.znc -> MD5 = B08ED7647B2F6E5E6641CB0DC6620666 | [Ver = | Size = 1887859 bytes | Created Date = 2/27/2008 5:05:09 PM | Attr = ] Wintab32.dll -> %SystemRoot%\System32\Wintab32.dll -> MD5 = 14F11F5AD339EE83B34EAD215108712E | Wacom Technology, Corp. [Ver = 6.0.4-4 | Size = 124464 bytes | Created Date = 2/27/2008 5:03:08 PM | Attr = ] WRLogonNtf.dll -> %SystemRoot%\System32\WRLogonNtf.dll -> MD5 = 9BA2293EFC229743D76BF7637E07DF44 | Webroot Software, Inc. [Ver = 3,5,6,114 | Size = 219504 bytes | Created Date = 3/13/2008 10:05:09 AM | Attr = ] wrlzma.dll -> %SystemRoot%\System32\wrlzma.dll -> MD5 = AD701873F240FF13C877038BE7D2C6EA | [Ver = | Size = 26480 bytes | Created Date = 3/13/2008 10:04:54 AM | Attr = ] WTablet -> %SystemRoot%\System32\WTablet -> [Folder | Created Date = 2/27/2008 5:03:10 PM | Attr = ] ativpsrm.bin -> %SystemRoot%\ativpsrm.bin -> MD5 = D41D8CD98F00B204E9800998ECF8427E | [Ver = | Size = 0 bytes | Created Date = 1/18/2008 1:07:05 AM | Attr = ] cdplayer.ini -> %SystemRoot%\cdplayer.ini -> MD5 = 767A2ACC2FA58455F0EDFA007CB2013F | [Ver = | Size = 25 bytes | Created Date = 1/25/2008 9:30:41 PM | Attr = ] CleaningLab.INI -> %SystemRoot%\CleaningLab.INI -> MD5 = D41D8CD98F00B204E9800998ECF8427E | [Ver = | Size = 0 bytes | Created Date = 2/24/2008 11:19:17 AM | Attr = ] cookies.ini -> %SystemRoot%\cookies.ini -> MD5 = 9F5CF38A55993E61D498F48CE8BBDFE0 | [Ver = | Size = 161 bytes | Created Date = 3/13/2008 10:20:10 AM | Attr = ] ERDNT -> %SystemRoot%\ERDNT -> [Folder | Created Date = 3/15/2008 4:24:36 AM | Attr = ] eReg.dat -> %SystemRoot%\eReg.dat -> MD5 = AC44553E0D31576AED940D634BC77A1C | [Ver = | Size = 763 bytes | Created Date = 1/18/2008 8:54:17 PM | Attr = ] mgxoschk.ini -> %SystemRoot%\mgxoschk.ini -> MD5 = 9E94B7FF5A49FD116814E0590CDD2A83 | [Ver = | Size = 5937 bytes | Created Date = 2/24/2008 9:23:09 AM | Attr = ] pskt.ini -> %SystemRoot%\pskt.ini -> MD5 = 16CE98F45D05079F9A6D1405BEE12653 | [Ver = | Size = 22 bytes | Created Date = 3/10/2008 7:59:48 PM | Attr = ] QTFont.for -> %SystemRoot%\QTFont.for -> MD5 = E1034D757709F37F2D1EBD96D5EAD02B | [Ver = | Size = 1409 bytes | Created Date = 1/18/2008 1:00:25 AM | Attr = ] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> MD5 = DBA91CD5A3A68302967C03213E52BDE8 | [Ver = | Size = 54156 bytes | Created Date = 1/18/2008 1:00:25 AM | Attr = H ] WRSetup.dll -> %SystemRoot%\WRSetup.dll -> MD5 = C6CB3DF1220A239FB69FC9CD0AFB412D | Webroot Software, Inc. [Ver = 5,5,7,124 | Size = 1526640 bytes | Created Date = 3/13/2008 10:04:53 AM | Attr = ] Norton Internet Security - Run Full System Scan - Mark ******.job -> %SystemRoot%\tasks\Norton Internet Security - Run Full System Scan - Mark ******.job -> MD5 = A997B06097B4B053559D3B17A5163842 | [Ver = | Size = 634 bytes | Created Date = 3/10/2008 9:12:59 PM | Attr = ] [Files/Folders - Modified Within 90 days] ATI -> %SystemDrive%\ATI -> [Folder | Modified Date = 1/18/2008 1:02:43 AM | Attr = ] Avenger -> %SystemDrive%\Avenger -> [Folder | Modified Date = 3/15/2008 12:28:41 PM | Attr = ] Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 3/15/2008 3:07:28 AM | Attr = ] Deckard -> %SystemDrive%\Deckard -> [Folder | Modified Date = 3/15/2008 4:22:44 AM | Attr = ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> Unable to obtain MD5 | [Ver = | Size = 3219279872 bytes | Modified Date = 3/15/2008 6:35:32 PM | Attr = HS] install.dat -> %SystemDrive%\install.dat -> MD5 = 0305366B4AF178DAD5E04F42D43DADB5 | [Ver = | Size = 164 bytes | Modified Date = 3/13/2008 10:02:49 AM | Attr = ] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 3/15/2008 12:38:41 PM | Attr = ] System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 3/15/2008 4:25:20 AM | Attr = HS] System32 -> %SystemDrive%\System32 -> [Folder | Modified Date = 3/12/2008 8:55:08 PM | Attr = ] Temp -> %SystemDrive%\Temp -> [Folder | Modified Date = 3/9/2008 7:03:15 PM | Attr = ] VundoFix Backups -> %SystemDrive%\VundoFix Backups -> [Folder | Modified Date = 3/13/2008 12:30:07 AM | Attr = ] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 3/15/2008 6:37:12 PM | Attr = ] WTablet -> %SystemDrive%\WTablet -> [Folder | Modified Date = 3/9/2008 10:48:11 PM | Attr = ] ati2mtag.sys -> %SystemRoot%\System32\dllcache\ati2mtag.sys -> MD5 = E51AA5ADF535C847072C0AED3E642912 | ATI Technologies Inc. [Ver = 6.14.10.6764 | Size = 2843136 bytes | Modified Date = 12/20/2007 11:53:20 PM | Attr = ] ati2erec.dll -> %SystemRoot%\System32\drivers\ati2erec.dll -> MD5 = 6AC759330F9BE1F54839A1D653929EE6 | ATI Technologies Inc. [Ver = 1.0.0.12 | Size = 49152 bytes | Modified Date = 12/20/2007 10:17:25 PM | Attr = ] ati2mtag.sys -> %SystemRoot%\System32\drivers\ati2mtag.sys -> MD5 = E51AA5ADF535C847072C0AED3E642912 | ATI Technologies Inc. [Ver = 6.14.10.6764 | Size = 2843136 bytes | Modified Date = 12/20/2007 11:53:20 PM | Attr = ] coh_mon.cat -> %SystemRoot%\System32\drivers\coh_mon.cat -> MD5 = 4C4565CB893EBE52163F421EB074ED74 | [Ver = | Size = 10537 bytes | Modified Date = 1/15/2008 9:54:42 AM | Attr = ] COH_Mon.inf -> %SystemRoot%\System32\drivers\COH_Mon.inf -> MD5 = F3C0C48B56BD53958D6D59C2E2011649 | [Ver = | Size = 706 bytes | Modified Date = 1/15/2008 5:28:00 AM | Attr = ] COH_Mon.sys -> %SystemRoot%\System32\drivers\COH_Mon.sys -> MD5 = 4ECDE31D8CF3C342BEF518AF954F513B | Symantec Corporation [Ver = 6,1,4,10 | Size = 23904 bytes | Modified Date = 1/12/2008 6:32:00 PM | Attr = ] SSFS0BB9.sys -> %SystemRoot%\System32\drivers\SSFS0BB9.sys -> MD5 = D3AD8D2E550B262694B024D1EB1EFFFC | Webroot Software Inc (www.webroot.com) [Ver = 3.5.6.114 | Size = 20336 bytes | Modified Date = 1/4/2008 8:34:34 PM | Attr = ] sshrmd.sys -> %SystemRoot%\System32\drivers\sshrmd.sys -> MD5 = 4D0E7A4BEFAD963D3AECFAC12FDEFF16 | Webroot Software Inc (www.webroot.com) [Ver = 3.5.6.114 | Size = 21872 bytes | Modified Date = 1/4/2008 8:34:34 PM | Attr = ] ssidrv.sys -> %SystemRoot%\System32\drivers\ssidrv.sys -> MD5 = 43EEDDC9B9B8ACCDB4A914BA893C73DE | Webroot Software Inc (www.webroot.com) [Ver = 3.5.6.114 | Size = 163696 bytes | Modified Date = 1/4/2008 8:34:34 PM | Attr = ] sskbfd.sys -> %SystemRoot%\System32\drivers\sskbfd.sys -> MD5 = 8564BC9598BE1705477B7FA61D657C2B | Webroot Software Inc (www.webroot.com) [Ver = 3.5.6.114 | Size = 23920 bytes | Modified Date = 1/4/2008 8:34:36 PM | Attr = ] SYMEVENT.CAT -> %SystemRoot%\System32\drivers\SYMEVENT.CAT -> MD5 = CCF19EB963474EE4BA9F4F554BC140F1 | [Ver = | Size = 10740 bytes | Modified Date = 3/13/2008 12:21:26 AM | Attr = ] SYMEVENT.INF -> %SystemRoot%\System32\drivers\SYMEVENT.INF -> MD5 = 6DAB88588D60317DDBFFBB7601BD5988 | [Ver = | Size = 805 bytes | Modified Date = 3/13/2008 12:21:26 AM | Attr = ] SYMEVENT.SYS -> %SystemRoot%\System32\drivers\SYMEVENT.SYS -> MD5 = 9E4188476848B2EF86F9C44D5164E724 | Symantec Corporation [Ver = 12.5.2.1 | Size = 123952 bytes | Modified Date = 3/13/2008 12:21:25 AM | Attr = ] amdpcom32.dll -> %SystemRoot%\System32\amdpcom32.dll -> MD5 = F86FB57625E38AEB8CC3CB7551D58B4F | Advanced Micro Devices, Inc. [Ver = 6.14.10.0001 | Size = 46080 bytes | Modified Date = 12/20/2007 10:24:07 PM | Attr = ] ati2cqag.dll -> %SystemRoot%\System32\ati2cqag.dll -> MD5 = 5C9AD3B9FF8A024AB44A23E88E02AA12 | ATI Technologies Inc. [Ver = 6.14.10.0361 | Size = 499712 bytes | Modified Date = 12/20/2007 10:11:47 PM | Attr = ] ati2dvag.dll -> %SystemRoot%\System32\ati2dvag.dll -> MD5 = EDE354AA631F8664E59CCE0E22E0244F | ATI Technologies Inc. [Ver = 6.14.10.6764 | Size = 272384 bytes | Modified Date = 12/20/2007 11:08:18 PM | Attr = ] ati2edxx.dll -> %SystemRoot%\System32\ati2edxx.dll -> MD5 = 5F9031EF8EAEE880104999D11C6A154D | ATI Technologies, Inc. [Ver = 6, 14, 10, 2513 | Size = 43520 bytes | Modified Date = 12/20/2007 10:59:09 PM | Attr = ] ati2evxx.dll -> %SystemRoot%\System32\ati2evxx.dll -> MD5 = 6C253F61D585CFA2B57CBD95464EC208 | ATI Technologies Inc. [Ver = 6.14.10.4176 | Size = 122880 bytes | Modified Date = 12/20/2007 10:58:55 PM | Attr = ] ati2evxx.exe -> %SystemRoot%\System32\ati2evxx.exe -> MD5 = 3E47191DDAFFCDD9B28CBC50FB6499B5 | ATI Technologies Inc. [Ver = 6.14.10.4188 | Size = 512000 bytes | Modified Date = 12/20/2007 10:57:27 PM | Attr = ] Ati2mdxx.exe -> %SystemRoot%\System32\Ati2mdxx.exe -> MD5 = 7EA8D1B729992823B835CD9EF790FC50 | ATI Technologies, Inc. [Ver = 6, 14, 10, 2495 | Size = 26112 bytes | Modified Date = 12/20/2007 10:59:17 PM | Attr = ] ati2sgag.exe -> %SystemRoot%\System32\ati2sgag.exe -> MD5 = 096C9955485F2B3F910F4C503C318D74 | [Ver = 5.13.0027 | Size = 593920 bytes | Modified Date = 12/20/2007 10:05:00 PM | Attr = ] ati3duag.dll -> %SystemRoot%\System32\ati3duag.dll -> MD5 = F10807DDAEE359BC262435036A559407 | ATI Technologies Inc. [Ver = 6.14.10.0555 | Size = 3120640 bytes | Modified Date = 12/20/2007 10:47:35 PM | Attr = ] ATIDDC.DLL -> %SystemRoot%\System32\ATIDDC.DLL -> MD5 = 1E0D860475520374B5ED7DECD6148580 | ATI Technologies Inc. [Ver = 6.14.10.8 | Size = 53248 bytes | Modified Date = 12/20/2007 10:56:27 PM | Attr = ] ATIDEMGX.dll -> %SystemRoot%\System32\ATIDEMGX.dll -> MD5 = A5E4D5C197D3810146459D1DC7A6EF75 | Advanced Micro Devices, Inc. [Ver = 2.0.2910.39885 | Size = 368640 bytes | Modified Date = 12/20/2007 11:09:31 PM | Attr = ] atiiiexx.dll -> %SystemRoot%\System32\atiiiexx.dll -> MD5 = E72A769E0711B0971C31D55264AF15B7 | ATI Technologies Inc. [Ver = 6.14.10.4005 | Size = 307200 bytes | Modified Date = 12/20/2007 11:02:40 PM | Attr = ] atikvmag.dll -> %SystemRoot%\System32\atikvmag.dll -> MD5 = D7CFE817AE431E313EFEE3ADE129A175 | ATI Technologies Inc. [Ver = 6.14.10.0070 | Size = 385024 bytes | Modified Date = 12/20/2007 10:20:17 PM | Attr = ] atioglx2.dll -> %SystemRoot%\System32\atioglx2.dll -> MD5 = E623B2DA2E80FB90A91031AFFAB0EF97 | ATI Technologies Inc. [Ver = 6.14.10.7275 | Size = 9826304 bytes | Modified Date = 12/20/2007 10:53:18 PM | Attr = ] atioglxx.dll -> %SystemRoot%\System32\atioglxx.dll -> MD5 = 0EEC798E5747350DFB0BB65C17BFD3EF | ATI Technologies Inc. [Ver = 6.14.10.7275 | Size = 5435392 bytes | Modified Date = 12/20/2007 10:20:47 PM | Attr = ] atiok3x2.dll -> %SystemRoot%\System32\atiok3x2.dll -> MD5 = BF6410AA8BC877C1AFF2AE9FFD36D78B | ATI Technologies Inc. [Ver = 6.14.10.7275 | Size = 159744 bytes | Modified Date = 12/20/2007 10:15:04 PM | Attr = ] atipdlxx.dll -> %SystemRoot%\System32\atipdlxx.dll -> MD5 = 5AB9C462CC34528C7E8D9DAC10212456 | ATI Technologies, Inc. [Ver = 6, 14, 10, 2527 | Size = 147456 bytes | Modified Date = 12/20/2007 10:59:39 PM | Attr = ] atitvo32.dll -> %SystemRoot%\System32\atitvo32.dll -> MD5 = A583595D4103BF45AC661A58A737BF40 | ATI Technologies Inc. [Ver = 6.14.10.4200 | Size = 17408 bytes | Modified Date = 12/20/2007 10:18:12 PM | Attr = ] ativva5x.dat -> %SystemRoot%\System32\ativva5x.dat -> MD5 = 31B434EDEC919137787CABF10E76266B | [Ver = | Size = 3107788 bytes | Modified Date = 12/20/2007 10:35:44 PM | Attr = ] ativva6x.dat -> %SystemRoot%\System32\ativva6x.dat -> MD5 = C23E3A4C7004D634A5C2E02841B3E3D4 | [Ver = | Size = 887724 bytes | Modified Date = 12/20/2007 10:35:44 PM | Attr = ] ativvaxx.dat -> %SystemRoot%\System32\ativvaxx.dat -> MD5 = 31B434EDEC919137787CABF10E76266B | [Ver = | Size = 3107788 bytes | Modified Date = 12/20/2007 10:35:44 PM | Attr = ] ativvaxx.dll -> %SystemRoot%\System32\ativvaxx.dll -> MD5 = 687DAD9F28DCCD39657E95EE4E91EE75 | ATI Technologies Inc. [Ver = 6.14.10.0178 | Size = 1661696 bytes | Modified Date = 12/20/2007 10:36:04 PM | Attr = ] CatRoot2 -> %SystemRoot%\System32\CatRoot2 -> [Folder | Modified Date = 3/15/2008 6:47:33 PM | Attr = ] 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> DirectX -> %SystemRoot%\System32\DirectX -> [Folder | Modified Date = 1/15/2008 8:22:11 PM | Attr = ] dllcache -> %SystemRoot%\System32\dllcache -> [Folder | Modified Date = 2/27/2008 5:04:49 PM | Attr = RHS] drivers -> %SystemRoot%\System32\drivers -> [Folder | Modified Date = 3/15/2008 12:25:40 PM | Attr = ] E447EDAD8A.sys -> %SystemRoot%\System32\E447EDAD8A.sys -> MD5 = D4C190B84A5168863D6D97D9E7FAC244 | [Ver = | Size = 168 bytes | Modified Date = 3/15/2008 7:01:09 PM | Attr = RHS] FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> MD5 = 98780E4D5FB7F917BDA8E2BF8452D31F | [Ver = | Size = 1324096 bytes | Modified Date = 3/9/2008 1:58:18 PM | Attr = ] FxsTmp -> %SystemRoot%\System32\FxsTmp -> [Folder | Modified Date = 2/14/2008 10:09:45 PM | Attr = ] Kaspersky Lab -> %SystemRoot%\System32\Kaspersky Lab -> [Folder | Modified Date = 3/15/2008 1:17:38 PM | Attr = ] KGyGaAvL.sys -> %SystemRoot%\System32\KGyGaAvL.sys -> MD5 = 0F07374DEB5BA2311841E9BE54E45E0B | [Ver = | Size = 1682 bytes | Modified Date = 3/15/2008 7:01:17 PM | Attr = HS] MAGIX -> %SystemRoot%\System32\MAGIX -> [Folder | Modified Date = 2/24/2008 9:24:56 AM | Attr = ] MediaServerDump -> %SystemRoot%\System32\MediaServerDump -> [Folder | Modified Date = 1/5/2008 7:16:05 PM | Attr = ] mnnmp.ini -> %SystemRoot%\System32\mnnmp.ini -> MD5 = 58875579C080DF9EB23DEB8234EA4624 | [Ver = | Size = 2878 bytes | Modified Date = 3/15/2008 12:22:54 PM | Attr = HS] MRT.INI -> %SystemRoot%\System32\MRT.INI -> MD5 = 8107BBF0E420BED39BC3490B2FF9F555 | [Ver = | Size = 127 bytes | Modified Date = 3/12/2008 10:24:10 PM | Attr = ] New Folder -> %SystemRoot%\System32\New Folder -> [Folder | Modified Date = 3/9/2008 10:42:14 PM | Attr = ] Oemdspif.dll -> %SystemRoot%\System32\Oemdspif.dll -> MD5 = 3E850C2551F4798A4CD7E8C255BAE6B9 | ATI Technologies, Inc. [Ver = 6.15.0201 | Size = 122880 bytes | Modified Date = 12/20/2007 10:59:26 PM | Attr = ] perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> MD5 = C91003B9CA885B1DCD64A65BC9D7D191 | [Ver = | Size = 63860 bytes | Modified Date = 3/9/2008 2:03:29 PM | Attr = ] perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> MD5 = 1C8D318751214E9F62B2EA8E4D6D99AE | [Ver = | Size = 405310 bytes | Modified Date = 3/9/2008 2:03:30 PM | Attr = ] PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> MD5 = C4DFC29CA11FB56E35690F333AEA8EE8 | [Ver = | Size = 477404 bytes | Modified Date = 3/9/2008 2:03:27 PM | Attr = ] QuickTime.qts -> %SystemRoot%\System32\QuickTime.qts -> MD5 = 2BAFF55F023EFB5A2F15EF5C9B7E5C35 | Apple Inc. [Ver = 7.4.1 | Size = 57344 bytes | Modified Date = 2/1/2008 12:13:18 AM | Attr = ] QuickTimeVR.qtx -> %SystemRoot%\System32\QuickTimeVR.qtx -> MD5 = 74358270B25669C3A96C5673E61AA943 | Apple Inc. [Ver = 7.4.1 | Size = 90112 bytes | Modified Date = 2/1/2008 12:13:18 AM | Attr = ] ReinstallBackups -> %SystemRoot%\System32\ReinstallBackups -> [Folder | Modified Date = 2/27/2008 5:05:05 PM | Attr = ] Restore -> %SystemRoot%\System32\Restore -> [Folder | Modified Date = 3/15/2008 4:25:20 AM | Attr = ] S32EVNT1.DLL -> %SystemRoot%\System32\S32EVNT1.DLL -> MD5 = 35A78813765364C5B46411A40AF6E559 | Symantec Corporation [Ver = 12.5.2.2 | Size = 60800 bytes | Modified Date = 3/13/2008 12:21:25 AM | Attr = ] sam.ini -> %SystemRoot%\System32\sam.ini -> MD5 = C8427A543F673CEF710946BA56D9B567 | [Ver = | Size = 180 bytes | Modified Date = 1/17/2008 10:02:26 PM | Attr = ] ssiefr.EXE -> %SystemRoot%\System32\ssiefr.EXE -> MD5 = 0AC2D082F667BB9340231CC90D41D60A | Webroot Software Inc (www.webroot.com) [Ver = 3.5.6.114 | Size = 16240 bytes | Modified Date = 1/4/2008 8:34:34 PM | Attr = ] unvckami.ini -> %SystemRoot%\System32\unvckami.ini -> MD5 = 5B6D6A844DE682801D936CE5BEB48FA3 | [Ver = | Size = 1318352 bytes | Modified Date = 3/13/2008 10:19:27 AM | Attr = HS] VundoFixSVC.exe -> %SystemRoot%\System32\VundoFixSVC.exe -> MD5 = 09F56AC1B2A7550F967DECCAB2612680 | Atribune.org [Ver = 1.00.0003 | Size = 24576 bytes | Modified Date = 3/12/2008 8:50:25 PM | Attr = ] wbem -> %SystemRoot%\System32\wbem -> [Folder | Modified Date = 2/28/2008 6:57:43 AM | Attr = ] wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> MD5 = 9E5EDAAF67EA91BA0B776D476D63D294 | [Ver = | Size = 2206 bytes | Modified Date = 3/15/2008 6:39:10 PM | Attr = ] WRLogonNtf.dll -> %SystemRoot%\System32\WRLogonNtf.dll -> MD5 = 9BA2293EFC229743D76BF7637E07DF44 | Webroot Software, Inc. [Ver = 3,5,6,114 | Size = 219504 bytes | Modified Date = 1/4/2008 8:34:36 PM | Attr = ] wrlzma.dll -> %SystemRoot%\System32\wrlzma.dll -> MD5 = AD701873F240FF13C877038BE7D2C6EA | [Ver = | Size = 26480 bytes | Modified Date = 1/4/2008 8:34:36 PM | Attr = ] WTablet -> %SystemRoot%\System32\WTablet -> [Folder | Modified Date = 2/27/2008 5:03:10 PM | Attr = ] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 2/13/2008 4:25:03 AM | Attr = H ] assembly -> %SystemRoot%\assembly -> [Folder | Modified Date = 3/10/2008 8:57:39 PM | Attr = R S] ativpsrm.bin -> %SystemRoot%\ativpsrm.bin -> MD5 = D41D8CD98F00B204E9800998ECF8427E | [Ver = | Size = 0 bytes | Modified Date = 1/18/2008 1:07:05 AM | Attr = ] bootstat.dat -> %SystemRoot%\bootstat.dat -> MD5 = 6A2CB42966136854F4464516FBB4AE72 | [Ver = | Size = 2048 bytes | Modified Date = 3/15/2008 6:35:56 PM | Attr = S] cdplayer.ini -> %SystemRoot%\cdplayer.ini -> MD5 = 767A2ACC2FA58455F0EDFA007CB2013F | [Ver = | Size = 25 bytes | Modified Date = 1/25/2008 9:30:41 PM | Attr = ] CleaningLab.INI -> %SystemRoot%\CleaningLab.INI -> MD5 = D41D8CD98F00B204E9800998ECF8427E | [Ver = | Size = 0 bytes | Modified Date = 2/24/2008 11:19:17 AM | Attr = ] cookies.ini -> %SystemRoot%\cookies.ini -> MD5 = 9F5CF38A55993E61D498F48CE8BBDFE0 | [Ver = | Size = 161 bytes | Modified Date = 3/13/2008 10:20:11 AM | Attr = ] Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 3/15/2008 1:17:43 PM | Attr = S] ERDNT -> %SystemRoot%\ERDNT -> [Folder | Modified Date = 3/15/2008 4:24:36 AM | Attr = ] eReg.dat -> %SystemRoot%\eReg.dat -> MD5 = AC44553E0D31576AED940D634BC77A1C | [Ver = | Size = 763 bytes | Modified Date = 1/18/2008 11:01:52 PM | Attr = ] EyeCand3.INI -> %SystemRoot%\EyeCand3.INI -> MD5 = FD03887A0472641D175A6462B76E080D | [Ver = | Size = 373248 bytes | Modified Date = 2/8/2008 4:32:43 PM | Attr = ] Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 3/8/2008 10:41:48 AM | Attr = R S] ie7updates -> %SystemRoot%\ie7updates -> [Folder | Modified Date = 2/14/2008 4:02:14 AM | Attr = ] inf -> %SystemRoot%\inf -> [Folder | Modified Date = 3/15/2008 1:17:38 PM | Attr = H ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 3/15/2008 3:07:28 AM | Attr = HS] mgxoschk.ini -> %SystemRoot%\mgxoschk.ini -> MD5 = 9E94B7FF5A49FD116814E0590CDD2A83 | [Ver = | Size = 5937 bytes | Modified Date = 2/24/2008 9:23:09 AM | Attr = ] Microsoft.NET -> %SystemRoot%\Microsoft.NET -> [Folder | Modified Date = 2/8/2008 10:16:47 AM | Attr = ] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 3/9/2008 1:59:51 PM | Attr = ] pskt.ini -> %SystemRoot%\pskt.ini -> MD5 = 16CE98F45D05079F9A6D1405BEE12653 | [Ver = | Size = 22 bytes | Modified Date = 3/13/2008 1:13:50 AM | Attr = ] QTFont.for -> %SystemRoot%\QTFont.for -> MD5 = E1034D757709F37F2D1EBD96D5EAD02B | [Ver = | Size = 1409 bytes | Modified Date = 1/18/2008 1:00:25 AM | Attr = ] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> MD5 = DBA91CD5A3A68302967C03213E52BDE8 | [Ver = | Size = 54156 bytes | Modified Date = 3/15/2008 6:38:31 PM | Attr = H ] Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 3/15/2008 6:37:33 PM | Attr = ] ShellNew -> %SystemRoot%\ShellNew -> [Folder | Modified Date = 2/29/2008 4:02:23 PM | Attr = ] SysMech6.INI -> %SystemRoot%\SysMech6.INI -> MD5 = 7907741EC4F5B4AFEDCC124B5498E1E8 | [Ver = | Size = 1504 bytes | Modified Date = 3/13/2008 7:51:54 PM | Attr = ] system32 -> %SystemRoot%\system32 -> [Folder | Modified Date = 3/15/2008 8:07:11 PM | Attr = ] Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 3/10/2008 9:12:59 PM | Attr = S] Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 3/15/2008 8:32:34 PM | Attr = ] win.ini -> %SystemRoot%\win.ini -> MD5 = 99B41628405D501F87C73393AC0F2F94 | [Ver = | Size = 814 bytes | Modified Date = 3/15/2008 6:47:19 PM | Attr = ] WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 2/10/2008 8:42:30 AM | Attr = ] WRSetup.dll -> %SystemRoot%\WRSetup.dll -> MD5 = C6CB3DF1220A239FB69FC9CD0AFB412D | Webroot Software, Inc. [Ver = 5,5,7,124 | Size = 1526640 bytes | Modified Date = 1/4/2008 8:56:58 PM | Attr = ] AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> MD5 = 6155D839A4F823EEC18D5E0B0D5F55D1 | [Ver = | Size = 284 bytes | Modified Date = 3/13/2008 11:18:22 PM | Attr = ] Norton Internet Security - Run Full System Scan - Mark ******.job -> %SystemRoot%\tasks\Norton Internet Security - Run Full System Scan - Mark ******.job -> MD5 = A997B06097B4B053559D3B17A5163842 | [Ver = | Size = 634 bytes | Modified Date = 3/10/2008 9:12:59 PM | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> MD5 = F1A6CD5ADAAB953A6764EA364E17BFB8 | [Ver = | Size = 6 bytes | Modified Date = 3/15/2008 6:36:05 PM | Attr = H ] qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> Unable to obtain MD5 | [Ver = | Size = 13826 bytes | Modified Date = 3/15/2008 6:38:51 PM | Attr = ] qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> Unable to obtain MD5 | [Ver = | Size = 13826 bytes | Modified Date = 3/15/2008 6:38:51 PM | Attr = ] data.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data\data.dat -> MD5 = 03887595A957A86FD4C2E5C61F21329E | [Ver = | Size = 3804 bytes | Modified Date = 3/27/2006 12:50:49 PM | Attr = ] opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data\opa11.dat -> MD5 = BBAD5B8BBBF19CA2C5EFF76C1C1ABD8B | [Ver = | Size = 11078 bytes | Modified Date = 2/4/2006 9:37:45 PM | Attr = ] opa12.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data\opa12.dat -> MD5 = 0E7E24ED21BD5DA96B0D882D5A043AD4 | [Ver = | Size = 8206 bytes | Modified Date = 11/5/2006 11:09:22 AM | Attr = ] CalMRU.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\CalMRU.dat -> MD5 = 434A4EC51E926F038E30F043E153D24A | [Ver = | Size = 2060 bytes | Modified Date = 1/1/2007 8:39:41 PM | Attr = ] wkcalcat.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wkcalcat.dat -> MD5 = AA563914D536084370039886074AE4C7 | [Ver = | Size = 16384 bytes | Modified Date = 1/29/2006 5:16:32 PM | Attr = ] wklntsk1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wklntsk1.dat -> MD5 = E310AD8E86105A618DD5B892D6CC47DF | [Ver = | Size = 201230 bytes | Modified Date = 2/28/2008 8:43:40 PM | Attr = ] ActivationGui.dll -> C:\Documents and Settings\Mark ******\Local Settings\Temp\clclean.0001.dir.0000\ActivationGui.dll -> MD5 = 88AED0A31F3F487AB67E784AC1DB36C3 | Creative Technology Ltd. [Ver = 2.1.1.0 | Size = 204800 bytes | Modified Date = 3/15/2008 12:31:42 PM | Attr = ] ApiExShell.dll -> C:\Documents and Settings\Mark ******\Local Settings\Temp\clclean.0001.dir.0000\ApiExShell.dll -> MD5 = B016E0A04E5727002578F17C1F22F038 | Creative Technology Ltd. [Ver = 2.1.1.0 | Size = 77824 bytes | Modified Date = 3/15/2008 12:31:42 PM | Attr = ] 3 C:\Documents and Settings\Mark ******\Local Settings\Temp\clclean.0001.dir.0000\*.tmp files -> C:\Documents and Settings\Mark ******\Local Settings\Temp\clclean.0001.dir.0000\*.tmp -> ActivationGui.dll -> C:\Documents and Settings\Mark ******\Local Settings\Temp\clclean.0001.dir.0001\ActivationGui.dll -> MD5 = 88AED0A31F3F487AB67E784AC1DB36C3 | Creative Technology Ltd. [Ver = 2.1.1.0 | Size = 204800 bytes | Modified Date = 3/15/2008 6:38:36 PM | Attr = ] ApiExShell.dll -> C:\Documents and Settings\Mark ******\Local Settings\Temp\clclean.0001.dir.0001\ApiExShell.dll -> MD5 = B016E0A04E5727002578F17C1F22F038 | Creative Technology Ltd. [Ver = 2.1.1.0 | Size = 77824 bytes | Modified Date = 3/15/2008 6:38:36 PM | Attr = ] 3 C:\Documents and Settings\Mark ******\Local Settings\Temp\clclean.0001.dir.0001\*.tmp files -> C:\Documents and Settings\Mark ******\Local Settings\Temp\clclean.0001.dir.0001\*.tmp -> [CatchMe Rootkit Scan by GMER] < Windows folder & sub-folders > scanning hidden processes ... IPC error: 2 The system cannot find the file specified. scanning hidden services & system hive ... scanning hidden registry entries ... [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher] "TracesProcessed"=dword:00000065 scanning hidden files ... C:\WINDOWS\system32\Thumbs.db:encryptable 0 bytes C:\WINDOWS\Thumbs.db:encryptable 0 bytes C:\WINDOWS\Help\Thumbs.db:encryptable 0 bytes C:\WINDOWS\Web\Thumbs.db:encryptable 0 bytes C:\WINDOWS\ehome\Thumbs.db:encryptable 0 bytes scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 47 < Document and Settings folder & sub folders > scanning hidden files ... IPC error: 2 The system cannot find the file specified. C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\3895E30A.TMP 0 bytes C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\A5AAAED6.TMP 0 bytes C:\Documents and Settings\All Users\Application Data\TEMP:054B9966 98 bytes C:\Documents and Settings\All Users\Application Data\TEMP:FF566C71 120 bytes C:\Documents and Settings\All Users\Documents\My Pictures\Landscapes - GalleryPlayer\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\All Users\Documents\My Pictures\Masterpieces - GalleryPlayer\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\All Users\Documents\My Pictures\Nature - GalleryPlayer\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\All Users\Documents\My Videos\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Application Data\Microsoft\eHome\mcl_images\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Application Data\Microsoft\Themes\canvas\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Application Data\Microsoft\Themes\virtual shades\virtualshades\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Application Data\Newsbin\Newsbin.nbi:Version 8 bytes C:\Documents and Settings\Mark ******\Application Data\Newsbin\Newsbin.nbi.bak:Version 8 bytes C:\Documents and Settings\Mark ******\Desktop\Album Covers\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\artistry web\gradient_page3_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\artistry web\gradient_page4_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\artsy stuff\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\handyman web\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\HIP Clients\Donnas Desserts\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\HIP Clients\Kane Chamber\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Art in the Wilds 2\Art in the Wilds\portfolio_page1_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Art in the Wilds 2\Art in the Wilds\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Art in the Wilds 2\Artist Application_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Art in the Wilds 2\artist app_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Art in the Wilds 2\index_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Art in the Wilds 2\pastel_page5_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Art in the Wilds 2\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\artinthewildsonmycomputer\aboutus_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\artinthewildsonmycomputer\artist app_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\artinthewildsonmycomputer\food_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\artinthewildsonmycomputer\index_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\artinthewildsonmycomputer\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\artinthewildsonmycomputer\pastel_page3_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\artinthewildsonmycomputer\pastel_page5_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\business forms\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\businesscard examples\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\hiplogo file\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Kane Chamber stuff\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Leadership McKean\Deco_page4green_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Leadership McKean\Deco_page4_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Leadership McKean\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\logo examples\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\test pages\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\test pages\Traveller_page1_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\test pages\Traveller_page5_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\testnavbar\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\lumberjacks nav menu_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\kids menu_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\pictures to fool around with\3d graphics\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\pictures to fool around with\banners\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\pictures to fool around with\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\pictures to fool around with\nav buttons to play with\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\pictures to fool around with\possible nav buttons\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\pictures to fool around with\gallery photos\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\pictures to fool around with\history photos\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\Web photo gallery\Lumberjacks Web Gallery\index (6)\media\photobook\medium\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\xara 3d\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\events_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\index_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\My Documents\My Web Pages\Traveller_page5_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\My Web Pages\history_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\My Web Pages\Lumberjacks_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\My Web Pages\photos_files\Photos\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\My Web Pages\photos_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\My Web Pages\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Lumberjacks website\navigation110406\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\lumberphoto\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\corry website project\scifi_page1_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\corry website project\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\corry website project\index_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\corrycontract\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\dangelo\Corvette_page4_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\dangelo\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Donna's Desserts Invoices\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\donnasdessertsonmycomputer\images\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\donnasdessertsonmycomputer\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\photoexamples\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\PRIDE web\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Pride Web 2\sabre_page3_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Pride Web 2\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\two scoops web\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\two scoops web\two scoops testing website3\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\two scoops web\two scoops testing website4\images\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\two scoops web\two scoops testing website4\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\two scoops web\Guardian_page1_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\****** Internet Productions\yesterday web\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\editables\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\nerjam\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\New Folder\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\PICTURES\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\Pioneer screens\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\plug-ins\albord10\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\plug-ins\freebies\Freebies\images\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\predator\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\charger\Avic Screens\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Desktop\charger\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Favorites\Premier Complete Wet End - Side Discharge 1.5 Complete Wet Ends Spa Pumps www.PoolDeals.com.url:favicon 894 bytes C:\Documents and Settings\Mark ******\Favorites\Metal Detecting Forums, Auctions + More - Treasure Quest.url:favicon 1150 bytes C:\Documents and Settings\Mark ******\Favorites\Microsoft FrontPage Techniques.url:favicon 1150 bytes C:\Documents and Settings\Mark ******\Local Settings\Application Data\Microsoft\ehome\Image.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Local Settings\Application Data\Microsoft\ehome\musicThumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\Local Settings\Application Data\Microsoft\ehome\Video.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Battlefield 2\LogoCache\www.game-monitor.com\server-stat-image\4\FFFFFF\000000\0000FF\000000\67.18.2.10:16567.jpg 20 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\Bad for Good- The Very Best of the Scorpions\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\D-A-D\Riskin' It All\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\Doro und Warlock Diskographie\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\Four the Hard Way\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\Jon Oliva's Pain\Tage Mahal\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\Mama's Boys\Plug It In\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\Michael Monroe\Whatcha Want\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\Perfect Timing\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\Poetic Justice\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\Rhino Bucket\Get Used to It\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\The Four Horsemen\Nobody Said It Was Easy\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\The Very Best of Rainbow\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music Bad Bitrate\Ugly Kid Joe\The Very Best of Ugly Kid Joe- As Ugly as It Gets\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\1980_01_01\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_03_26\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_04_03\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_04_09\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_04_14\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_04_21\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_04_21\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_05_12\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_05_20\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_05_22\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_05_23\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_05_26\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_06_11\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_07_02\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_07_02\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_07_17\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_08_06\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_08_06\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_08_10\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_08_12\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_08_12\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_09_01\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_09_01\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_09_15\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_09_16\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_09_17\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_09_18\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_09_23\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_11_11\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_11_12\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_12_04\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_12_05\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_12_06\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_12_23\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_12_24\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_12_24\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2005_12_28\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_01_08\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_01_16\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_10_10\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_10_24\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_10_29\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_11_03\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_11_04\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_11_06\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_11_08\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_11_20\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_12_21\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_12_29\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_01_06\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_03_17\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_06_15\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_06_22\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\Copy of 1980_01_01\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\Copy of 2005_03_26\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\Copy of 2005_04_03\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\Copy of 2005_04_09\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\Copy of 2005_04_14\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\Microsoft Clip Organizer\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\Screenshot Studio Files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\Vacation Pictures\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_02_24\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_06_23\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_03_14\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_03_15\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_03_17\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_03_18\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_03_21\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_03_23\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_04_11\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_04_30\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_06_10\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_07_03\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_07_11\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_08_02\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_08_09\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_08_24\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_09_05\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2006_09_12\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_06_26\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_06_27\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_07_14\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_07_20\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_07_21\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_08_04\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_08_11\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_08_12\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_08_16\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_08_18\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_08_25\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_08_31\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_09_07\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_09_07\Wedding Photos\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_11_10\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_11_13\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_11_15\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_12_08\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_12_13\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_12_14\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_12_15\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_12_16\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_12_22\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures\2007_12_30\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\2005_04_04\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\2005_04_04\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\2005_06_09\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\2005_07_14\STITCH_0624\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\2005_07_14\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\2005_10_30\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\2006_05_22\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\Microsoft Clip Organizer\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\Microsoft Clip Organizer\XaraInfo\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\Movies\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\photos for printing\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\Picture\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Pictures no slideshow\Pureed Meals\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\Simpsons Movie\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\A Scanner Darkly\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\American Pie Naked Mile\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\Beer League\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\BeerFest\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\Clerks 2\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\Click\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\DaVinci Code\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\ehthumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\Eragon\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\The 300\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\The Descent\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\The Devil Wears Prada\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\Tokyo Drift\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\Transformers\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\Van Wilder 2\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\Wickerman\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Movies\X-Men 3\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\TV Series\Billie Piper\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Videos\TV Series\DR Who\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Web Pages\history_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Web Pages\index_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Web Pages\photos_files\Photos\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Web Pages\photos_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Web Pages\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Web Pages\Lumberjacks_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Historical Project\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\****** Internet Productions\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Radio Holly\The Go-Go's\Beauty and the Beat\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Downloaded Program Updates\ElementsIconSuite\Elements Icon Suite\Icons\PNG\Drives\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Downloaded Program Updates\ElementsIconSuite\Elements Icon Suite\Icons\PNG\File Types\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Downloaded Program Updates\ElementsIconSuite\Elements Icon Suite\Icons\PNG\Folders\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Downloaded Program Updates\ElementsIconSuite\Elements Icon Suite\Icons\PNG\Hardware\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Downloaded Program Updates\ElementsIconSuite\Elements Icon Suite\Icons\PNG\Misc & System\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Downloaded Program Updates\ElementsIconSuite\Elements Icon Suite\Icons\PNG\Old Icons\Folders\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Downloaded Program Updates\ElementsIconSuite\Elements Icon Suite\Icons\PNG\Old Icons\Longhorn Folders\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Downloaded Program Updates\ElementsIconSuite\Elements Icon Suite\Icons\PNG\Old Icons\Snow Drives\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\ebay pictures\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Events_files\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Lizzy Borden\Appointment with Death\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Lost Horizon\Awakening the World\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Lynch Mob\Lynch Mob\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Lynch Mob\Wicked Sensation\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Metallica\Master of Puppets\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Metallica\Metallic Attack_ The Ultimate Tribute\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Metallica\Reload\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Sister Whiskey\Sister Whiskey (Liquor & Poker)\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Skew Siskin\Skew Sisken\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Electric Angels\Electric Angels\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder\Backstreet Symphony\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder\Robert Johnson's Tombstone\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder\The Magnificent Seventh!\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder albums\The Thrill of It All\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder albums\Behind Closed Doors\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder albums\Laughing on Judgement Day\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder albums\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder albums\Thunder - Live At Rock City\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder albums\Thunder - Live At The Bedford Arms\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder albums\Thunder - Live Circuit [Japan]\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder albums\Thunder - Open The Window - Shut The Door\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder albums\Thunder - The X-Mas Show Live\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder albums\Thunder - They Think It's All Acoustic\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder albums\Thunder - They Think It's Over... It's now\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Thunder albums\Thunder - X-Mas Show 2006\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Too Tall Jones\Bipolar\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Tora Tora\Wild America\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Candlebox\Candlebox\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Coheed & Cambria\Good Apollo, I'm Burning Star IV, Volume One\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Coheed & Cambria\In Keeping Secrets of Silent Earth- 3 Disc 1\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Contraband\Contraband\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\D-A-D\No Fuel Left for the Pilgrims\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\D-A-D\Riskin' It All\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Damn Yankees\Damn Yankees\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Danger Danger\Cockroach(Paul Laine)\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Danger Danger\Danger Danger\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Danger Danger\Dawn\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Danger Danger\Four the Hard Way\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Danger Danger\Live And Nude\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Danger Danger\Screw It\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Danger Danger\Ted Poley\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Danger Danger\The Return of the Great Gildersleeves\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Dangerous Toys\Dangerous Toys\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Avantasia\Lost in Space Part 1\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Avantasia\Lost in Space Part 2\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Helloween\Better Than Raw\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Honeymoon Suite\Racing After Midnight\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Bang Tango\Ready to Go\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Black 'N Blue\Black 'N Blue\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Black 'N Blue\In Heat\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Black 'N Blue\Nasty Nasty\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Black 'N Blue\Ultimate Collection\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Black 'N Blue\Without Love\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Britny Fox\Bite Down Hard\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Bruce Dickinson\Balls to Picasso\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Buckcherry\15\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Buckcherry\Buckcherry\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Buckcherry\Time Bomb\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Deep Purple\Slaves and Masters\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Deep Purple\The House of Blue Light\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Dirty Looks\Cool from the Wire\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Fastway\Bad Bad Girls\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Fastway\Fastway\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Fastway\Say What You Will_ Live\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Fastway\Trick Or Treat\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Firehouse\Firehouse\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Gilby Clarke\Swag\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Gotthard\Dial Hard\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Hanoi Rocks\Oriental Beat\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Hanoi Rocks\Twelve Shots on the Rocks\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\A Matter of Life and Death\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Dance of Death\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Eddie's Archive Disc 6\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Eddie's Archive Disc 9\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Iron Maiden - The First Ten Years [10 CD Set]\Disc 01\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Iron Maiden - The First Ten Years [10 CD Set]\Disc 02\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Iron Maiden - The First Ten Years [10 CD Set]\Disc 03\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Iron Maiden - The First Ten Years [10 CD Set]\Disc 04\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Iron Maiden - The First Ten Years [10 CD Set]\Disc 05\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Iron Maiden - The First Ten Years [10 CD Set]\Disc 06\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Iron Maiden - The First Ten Years [10 CD Set]\Disc 07\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Iron Maiden - The First Ten Years [10 CD Set]\Disc 08\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Iron Maiden - The First Ten Years [10 CD Set]\Disc 09\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Iron Maiden - The First Ten Years [10 CD Set]\Disc 10\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Iron Maiden - The First Ten Years [10 CD Set]\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Seventh Son of a Seventh Son\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\The Best Of The Beast [UK]\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Iron Maiden\Virtual XI\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Joan Jett & the Blackhearts\Fit to Be Tied- Great Hits by Joan Jett and the Blackhearts\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Jon Oliva's Pain\Tage Mahal\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Michael Monroe\Whatcha Want\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Michael Schenker Group\M.S.G\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Michael Schenker Group\Perfect Timing\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Michael Schenker Group\The Essential Michael Schenker Group\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Motorpsychos\Piston Whipped\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Quireboys\A Bit of What You Fancy\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Rhino Bucket\Get Used to It\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Rhino Bucket\Rhino Bucket\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Ride The Sky\New Protection\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Robin Mcauley\Business As Usual\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Son of a Bitch\Victim You\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Spread Eagle\Spread Eagle\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Steve Stevens\Atomic Playboys\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\UFO\Walk on Water\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Unruly Child\Waiting for the Sun\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Various Artists\This Is '80s Hair Metal Disc 1\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Various Artists\This Is '80s Hair Metal Disc 2\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Various Artists\This Is '80s Hair Metal Disc 3\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Virgin Steele\Hymns To Victory\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Virgin Steele\The Book of Burning\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Waysted\Save Your Prayers [Bonus Tracks]\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Waysted\The Good The Bad The Waysted\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\White Lion\Mane Attraction\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Y&T\Earthshaker\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Y&T\In Rock We Trust\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Y&T\One Hot Night\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Y&T\Struck Down\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Y&T\The Best of Y&T (1981-1985)\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Y&T\Unearthed, Vol. 1\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Y&T\Unearthed, Vol. 2\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Y&T\Yesterday & Today\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Tesla\Mechanical Resonance\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\The Almighty\Powertrippin'\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\The Babys\Anthology\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\The Babys\The Best of the Babys\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Accept\Death Row\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Accept\Metal Heart\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Accept\Objection Overruled\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Accept\Restless and Wild-Balls to the Wall\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\ACCEPT - discography (1979-2001)\ACCEPT - 1982 - Best of Accept\Covers\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\ACCEPT - discography (1979-2001)\ACCEPT - 1982 - Hungry years\Covers\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\ACCEPT - discography (1979-2001)\ACCEPT - 1982 - Restless And Wild\Covers\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\ACCEPT - discography (1979-2001)\ACCEPT - 1983 - Balls to the wall\Covers\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\ACCEPT - discography (1979-2001)\ACCEPT - 1985 - Live in Japan\Covers\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\ACCEPT - discography (1979-2001)\ACCEPT - 1986 - Russian Roulette\Covers\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\ACCEPT - discography (1979-2001)\ACCEPT - 1990 - Staying a Life\Covers\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\ACCEPT - discography (1979-2001)\ACCEPT - Metal Masters\Covers\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1981 - For Those About To Rock\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1974 - High Voltage (Australian)\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1976 - Dirty Deeds Done Dirt Cheap\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1976 - High Voltage\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1977 - Let There Be Rock\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1978 - If You Want Blood, You've Got It\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1978 - Powerage\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1979 - Highway To Hell\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1980 - Back in Black\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1983 - Flick Of The Switch\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1984 - '74 Jailbreak\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1985 - Fly On The Wall\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1986 - Who Made Who\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1988 - Blow Up Your Video\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1990 - The Razors Edge\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1995 - Ballbreaker\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\1997 - Bonfire box set\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\2000 - Stiff Upper Lip\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\acdc total\Shockingly_Rare-(2006)-PLM\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Kick Axe\Vices\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Kick Axe\Welcome to the Club\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Kix\Blow My Fuse\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Krokus\Metal Rendez-Vous\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Krokus\Rock the Block\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Krokus\Round 13\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Krokus\The Dirty Dozen\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Lillian Axe\Out of the Darkness, Into the Light (1987-89)\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\The Clarks\Someday Maybe\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\The McAuley-Schenker Group\M.S.G. [Impact-MCA]\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\The Michael Schenker Group\The Michael Schenker Group\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Helix\Back for Another Taste\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Helix\Half Alive\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Helix\Helix\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Scorpions\Bad for Good- The Very Best of the Scorpions\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Scorpions\Humanity Hour, Vol. 1\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Scorpions\Unbreakable\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Rose Tattoo\Scarred For Life\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Rough Cutt\Rough Cutt_Rough Cutt Wants You!\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Saxon\Solid Ball of Rock\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Saxon\Wheels of Steel-Strong Arm of the Law Disc 1\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\My Music\Saxon\Wheels of Steel-Strong Arm of the Law Disc 2\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\New Folder\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Newsbin Download\Helloween - Keeper Of The Seven Keys (Disc1)\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Newsbin Download\Stormwarrior\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Newsbin Download\hells belles\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Newsbin Download\Saxon - Strong Arm Of The Law\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Newsbin Download\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Mark ******\My Documents\Untitled Gallery\Thumbs.db:encryptable 0 bytes scan completed successfully hidden files: 1604 < End of report > [/code]