[code] OTScanIt logfile created on: 4/15/2008 4:00:56 PM OTScanIt by OldTimer - Version 1.0.9.0 Folder = C:\Documents and Settings\Florin\Desktop\OTscan it\OTScanIt Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 1.41 Gb Available Physical Memory | 70.52% Memory free 3.85 Gb Paging File | 3.28 Gb Available in Paging File | 85.34% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 92.41 Gb Total Space | 30.05 Gb Free Space | 32.52% Space Free | Partition Type: NTFS D: Drive not present or media not loaded Drive E: | 65.80 Gb Total Space | 28.68 Gb Free Space | 43.58% Space Free | Partition Type: NTFS Drive F: | 97.66 Gb Total Space | 42.26 Gb Free Space | 43.27% Space Free | Partition Type: NTFS Drive G: | 42.21 Gb Total Space | 21.06 Gb Free Space | 49.90% Space Free | Partition Type: NTFS H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: STINGACIU Current User Name: Florin Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users [Processes - Non-Microsoft Only] ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> ATI Technologies Inc. [Ver = 6.14.10.4183 | Size = 495616 bytes | Modified Date = 12/4/2007 10:53:58 PM | Attr = ] smc.exe -> %ProgramFiles%\Symantec\Symantec Endpoint Protection\Smc.exe -> Symantec Corporation [Ver = 11.0.1000.1091 | Size = 2569600 bytes | Modified Date = 12/18/2007 8:03:08 PM | Attr = ] ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> ATI Technologies Inc. [Ver = 6.14.10.4183 | Size = 495616 bytes | Modified Date = 12/4/2007 10:53:58 PM | Attr = ] ccsvchst.exe -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.3.6.2 | Size = 108392 bytes | Modified Date = 11/9/2007 4:15:18 PM | Attr = ] photoshopelementsfileagent.exe -> %ProgramFiles%\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe -> [Ver = | Size = 102400 bytes | Modified Date = 9/14/2006 8:56:06 AM | Attr = ] applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 9/6/2007 1:28:18 PM | Attr = ] mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> Apple Inc. [Ver = 1,0,4,12 | Size = 229376 bytes | Modified Date = 7/24/2007 4:17:08 PM | Attr = ] ctsvccda.exe -> %SystemRoot%\system32\CTsvcCDA.EXE -> Creative Technology Ltd [Ver = 1.0.1.0 | Size = 44032 bytes | Modified Date = 12/13/1999 1:01:00 AM | Attr = ] dkservice.exe -> %ProgramFiles%\Diskeeper Corporation\Diskeeper\DkService.exe -> Diskeeper Corporation [Ver = 10.0.593.0 | Size = 765952 bytes | Modified Date = 11/23/2005 8:58:04 AM | Attr = ] lssrvc.exe -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> Hewlett-Packard Company [Ver = 1.4.105.1 | Size = 49152 bytes | Modified Date = 6/20/2006 9:08:48 PM | Attr = ] pnkbstra.exe -> %SystemRoot%\system32\PnkBstrA.exe -> [Ver = | Size = 66872 bytes | Modified Date = 9/21/2007 11:48:34 PM | Attr = ] rtvscan.exe -> %ProgramFiles%\Symantec\Symantec Endpoint Protection\Rtvscan.exe -> Symantec Corporation [Ver = 11.0.1000.1112 | Size = 2189240 bytes | Modified Date = 12/18/2007 10:08:08 PM | Attr = ] smcgui.exe -> %ProgramFiles%\Symantec\Symantec Endpoint Protection\SmcGui.exe -> Symantec Corporation [Ver = 11.0.1000.1091 | Size = 1643904 bytes | Modified Date = 12/18/2007 8:03:10 PM | Attr = ] cthelper.exe -> %SystemRoot%\system32\CTHELPER.EXE -> Creative Technology Ltd [Ver = 1, 0, 0, 2 | Size = 24576 bytes | Modified Date = 7/2/2002 6:56:00 PM | Attr = ] ctnotify.exe -> %ProgramFiles%\Creative\ShareDLL\CTNotify.exe -> Creative Technology Ltd. [Ver = 2.00.05.0 | Size = 191488 bytes | Modified Date = 12/26/2001 2:00:00 AM | Attr = ] mediadet.exe -> %ProgramFiles%\Creative\ShareDLL\Mediadet.exe -> Creative Technology Ltd. [Ver = 2.00.08.0 | Size = 167424 bytes | Modified Date = 7/23/2002 10:00:00 AM | Attr = ] hpztsb10.exe -> %SystemRoot%\system32\spool\drivers\w32x86\3\hpztsb10.exe -> HP [Ver = 2.323.0.0 | Size = 172032 bytes | Modified Date = 1/13/2006 8:13:02 PM | Attr = ] mom.exe -> %ProgramFiles%\ATI Technologies\ATI.ACE\Core-Static\MOM.exe -> Advanced Micro Devices Inc. [Ver = 2.0.0.0 | Size = 49152 bytes | Modified Date = 7/17/2007 12:13:56 PM | Attr = ] tsnp2std.exe -> %SystemRoot%\tsnp2std.exe -> SONIX [Ver = 1, 1, 3, 9 | Size = 258048 bytes | Modified Date = 1/5/2007 6:12:58 PM | Attr = ] vsnp2std.exe -> %SystemRoot%\vsnp2std.exe -> Sonix [Ver = 1, 1, 7, 0 | Size = 675840 bytes | Modified Date = 9/15/2006 2:21:54 PM | Attr = ] soundman.exe -> %SystemRoot%\soundman.exe -> Realtek Semiconductor Corp. [Ver = 5, 1, 0, 43 | Size = 90112 bytes | Modified Date = 8/17/2005 6:39:58 PM | Attr = ] ccapp.exe -> %CommonProgramFiles%\Symantec Shared\ccApp.exe -> Symantec Corporation [Ver = 106.3.6.2 | Size = 115560 bytes | Modified Date = 11/9/2007 4:15:34 PM | Attr = ] winampa.exe -> %ProgramFiles%\Winamp\winampa.exe -> [Ver = | Size = 37376 bytes | Modified Date = 1/15/2008 6:54:54 PM | Attr = ] ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.6.2.9 | Size = 267048 bytes | Modified Date = 3/30/2008 10:36:40 AM | Attr = ] ccc.exe -> %ProgramFiles%\ATI Technologies\ATI.ACE\Core-Static\CCC.exe -> ATI Technologies Inc. [Ver = 2.0.0.0 | Size = 49152 bytes | Modified Date = 7/17/2007 12:13:34 PM | Attr = ] lastfmhelper.exe -> %ProgramFiles%\Last.fm\LastFMHelper.exe -> Last.fm [Ver = 1.4.2.58376 | Size = 106496 bytes | Modified Date = 12/19/2007 1:04:34 PM | Attr = ] ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.2.9 | Size = 504104 bytes | Modified Date = 3/30/2008 10:36:30 AM | Attr = ] ymsgr_tray.exe -> %ProgramFiles%\Yahoo!\Messenger\Ymsgr_tray.exe -> Yahoo! Inc. [Ver = 8,1,0,0 | Size = 103928 bytes | Modified Date = 11/30/2006 10:49:06 PM | Attr = ] firefox.exe -> %ProgramFiles%\Mozilla Firefox\firefox.exe -> Mozilla Corporation [Ver = 1.8.1.13: 2008031114 | Size = 7660656 bytes | Modified Date = 3/26/2008 5:27:55 PM | Attr = ] otscanit.exe -> %UserProfile%\Desktop\OTscan it\OTScanIt\OTScanIt.exe -> OldTimer Tools [Ver = 1.0.9.0 | Size = 369152 bytes | Modified Date = 4/4/2008 12:24:38 PM | Attr = ] [Win32 Services - Non-Microsoft Only] (Adobe LM Service) Adobe LM Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Adobe Systems Shared\Service\Adobelmsvc.exe -> Adobe Systems [Ver = 2.67.010 | Size = 72704 bytes | Modified Date = 8/30/2006 1:04:58 PM | Attr = ] (Adobe Version Cue CS2) Adobe Version Cue CS2 [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe -> Adobe Systems Incorporated [Ver = 2, 0, 0, 0 | Size = 163840 bytes | Modified Date = 4/4/2005 6:58:28 PM | Attr = ] (AdobeActiveFileMonitor5.0) Adobe Active File Monitor V5 [Win32_Own | Auto | Running] -> %ProgramFiles%\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe -> [Ver = | Size = 102400 bytes | Modified Date = 9/14/2006 8:56:06 AM | Attr = ] (Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 9/6/2007 1:28:18 PM | Attr = ] (Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %SystemRoot%\system32\ati2evxx.exe -> ATI Technologies Inc. [Ver = 6.14.10.4183 | Size = 495616 bytes | Modified Date = 12/4/2007 10:53:58 PM | Attr = ] (ATI Smart) ATI Smart [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\ati2sgag.exe -> [Ver = 5.13.0027 | Size = 593920 bytes | Modified Date = 12/5/2007 3:17:00 PM | Attr = ] (Autodesk Licensing Service) Autodesk Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Autodesk Shared\Service\AdskScSrv.exe -> Autodesk [Ver = 2.70.000 | Size = 77944 bytes | Modified Date = 1/1/2007 1:38:12 PM | Attr = ] (Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> Apple Inc. [Ver = 1,0,4,12 | Size = 229376 bytes | Modified Date = 7/24/2007 4:17:08 PM | Attr = ] (ccEvtMgr) Symantec Event Manager [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.3.6.2 | Size = 108392 bytes | Modified Date = 11/9/2007 4:15:18 PM | Attr = ] (ccSetMgr) Symantec Settings Manager [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.3.6.2 | Size = 108392 bytes | Modified Date = 11/9/2007 4:15:18 PM | Attr = ] (Creative Service for CDROM Access) Creative Service for CDROM Access [Win32_Own | Auto | Running] -> %SystemRoot%\system32\CTsvcCDA.EXE -> Creative Technology Ltd [Ver = 1.0.1.0 | Size = 44032 bytes | Modified Date = 12/13/1999 1:01:00 AM | Attr = ] (Diskeeper) Diskeeper [Win32_Own | Auto | Running] -> %ProgramFiles%\Diskeeper Corporation\Diskeeper\DkService.exe -> Diskeeper Corporation [Ver = 10.0.593.0 | Size = 765952 bytes | Modified Date = 11/23/2005 8:58:04 AM | Attr = ] (dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] (gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.2.824.5515.beta | Size = 138680 bytes | Modified Date = 8/22/2007 5:03:54 PM | Attr = ] (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 12:41:10 AM | Attr = ] (idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> -> File not found (iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.2.9 | Size = 504104 bytes | Modified Date = 3/30/2008 10:36:30 AM | Attr = ] (LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> Hewlett-Packard Company [Ver = 1.4.105.1 | Size = 49152 bytes | Modified Date = 6/20/2006 9:08:48 PM | Attr = ] (LiveUpdate) LiveUpdate [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Symantec\LiveUpdate\LuComServer_3_3.EXE -> Symantec Corporation [Ver = 3.3.0.61 | Size = 3093872 bytes | Modified Date = 8/11/2007 9:05:27 PM | Attr = ] (NBService) NBService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Nero\Nero 7\Nero BackItUp\NBService.exe -> Nero AG [Ver = 2, 7, 7, 3 | Size = 792112 bytes | Modified Date = 5/24/2007 5:38:10 PM | Attr = ] (NMIndexingService) NMIndexingService [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Ahead\Lib\NMIndexingService.exe -> Nero AG [Ver = 1, 5, 13, 0 | Size = 267560 bytes | Modified Date = 6/21/2007 3:43:30 PM | Attr = ] (PnkBstrA) PnkBstrA [Win32_Own | Auto | Running] -> %SystemRoot%\system32\PnkBstrA.exe -> [Ver = | Size = 66872 bytes | Modified Date = 9/21/2007 11:48:34 PM | Attr = ] (rpcapd) Remote Packet Capture Protocol v.0 (experimental) [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\WinPcap\rpcapd.exe -> CACE Technologies [Ver = 4.0.0.1040 | Size = 92792 bytes | Modified Date = 11/6/2007 4:22:26 PM | Attr = ] (SmcService) Symantec Management Client [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec\Symantec Endpoint Protection\Smc.exe -> Symantec Corporation [Ver = 11.0.1000.1091 | Size = 2569600 bytes | Modified Date = 12/18/2007 8:03:08 PM | Attr = ] (SNAC) Symantec Network Access Control [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Symantec\Symantec Endpoint Protection\SNAC.EXE -> Symantec Corporation [Ver = 11.0.1000.1091 | Size = 234888 bytes | Modified Date = 12/18/2007 8:04:36 PM | Attr = ] (Symantec AntiVirus) Symantec Endpoint Protection [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec\Symantec Endpoint Protection\Rtvscan.exe -> Symantec Corporation [Ver = 11.0.1000.1112 | Size = 2189240 bytes | Modified Date = 12/18/2007 10:08:08 PM | Attr = ] [Registry - Non-Microsoft Only] < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> amd_dc_opt -> %ProgramFiles%\AMD\Dual-Core Optimizer\amd_dc_opt.exe [C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe] -> AMD [Ver = 1, 1, 1, 0 | Size = 77824 bytes | Modified Date = 11/17/2006 4:49:48 PM | Attr = ] ccApp -> %CommonProgramFiles%\Symantec Shared\ccApp.exe ["C:\Program Files\Common Files\Symantec Shared\ccApp.exe"] -> Symantec Corporation [Ver = 106.3.6.2 | Size = 115560 bytes | Modified Date = 11/9/2007 4:15:34 PM | Attr = ] Disc Detector -> %ProgramFiles%\Creative\ShareDLL\CTNotify.exe [C:\Program Files\Creative\ShareDLL\CtNotify.exe] -> Creative Technology Ltd. [Ver = 2.00.05.0 | Size = 191488 bytes | Modified Date = 12/26/2001 2:00:00 AM | Attr = ] EPSON Stylus Photo R200 Series -> %SystemRoot%\system32\spool\drivers\w32x86\3\E_S4I2H1.EXE [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"] -> SEIKO EPSON CORPORATION [Ver = 3.00 | Size = 99840 bytes | Modified Date = 7/8/2003 3:00:00 AM | Attr = ] HPDJ Taskbar Utility -> %SystemRoot%\system32\spool\drivers\w32x86\3\hpztsb10.exe [C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe] -> HP [Ver = 2.323.0.0 | Size = 172032 bytes | Modified Date = 1/13/2006 8:13:02 PM | Attr = ] iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> Apple Inc. [Ver = 7.6.2.9 | Size = 267048 bytes | Modified Date = 3/30/2008 10:36:40 AM | Attr = ] QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\QTTask.exe" -atboottime] -> Apple Inc. [Ver = 7.4.5 | Size = 413696 bytes | Modified Date = 3/28/2008 11:37:20 PM | Attr = ] snp2std -> %SystemRoot%\vsnp2std.exe [C:\WINDOWS\vsnp2std.exe] -> Sonix [Ver = 1, 1, 7, 0 | Size = 675840 bytes | Modified Date = 9/15/2006 2:21:54 PM | Attr = ] SoundMan -> %SystemRoot%\soundman.exe [SOUNDMAN.EXE] -> Realtek Semiconductor Corp. [Ver = 5, 1, 0, 43 | Size = 90112 bytes | Modified Date = 8/17/2005 6:39:58 PM | Attr = ] StartCCC -> %ProgramFiles%\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ["C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"] -> [Ver = | Size = 90112 bytes | Modified Date = 11/10/2006 1:35:24 PM | Attr = ] tsnp2std -> %SystemRoot%\tsnp2std.exe [C:\WINDOWS\tsnp2std.exe] -> SONIX [Ver = 1, 1, 3, 9 | Size = 258048 bytes | Modified Date = 1/5/2007 6:12:58 PM | Attr = ] UpdReg -> %SystemRoot%\Updreg.EXE [C:\WINDOWS\UpdReg.EXE] -> Creative Technology Ltd. [Ver = 1.0.2 | Size = 90112 bytes | Modified Date = 5/11/2000 1:00:00 AM | Attr = ] WinampAgent -> %ProgramFiles%\Winamp\winampa.exe ["C:\Program Files\Winamp\winampa.exe"] -> [Ver = | Size = 37376 bytes | Modified Date = 1/15/2008 6:54:54 PM | Attr = ] WINDVDPatch -> %SystemRoot%\system32\CTHELPER.EXE [CTHELPER.EXE] -> Creative Technology Ltd [Ver = 1, 0, 0, 2 | Size = 24576 bytes | Modified Date = 7/2/2002 6:56:00 PM | Attr = ] < OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> IMAIL-> Installed = 1 -> MAPI-> Installed = 1 -> MSFS-> Installed = 1 -> < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> Yahoo! Pager -> %ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe ["C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet] -> Yahoo! Inc. [Ver = 8,1,0,209 | Size = 4662776 bytes | Modified Date = 11/30/2006 10:49:04 PM | Attr = ] < Run [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> Picasa Media Detector -> %ProgramFiles%\Picasa2\PicasaMediaDetector.exe [C:\Program Files\Picasa2\PicasaMediaDetector.exe] -> File not found < Run [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> Picasa Media Detector -> %ProgramFiles%\Picasa2\PicasaMediaDetector.exe [C:\Program Files\Picasa2\PicasaMediaDetector.exe] -> File not found < Run [HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\] > -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> Yahoo! Pager -> %ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe ["C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet] -> Yahoo! Inc. [Ver = 8,1,0,209 | Size = 4662776 bytes | Modified Date = 11/30/2006 10:49:04 PM | Attr = ] < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> < Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> < Florin Startup Folder > -> C:\Documents and Settings\Florin\Start Menu\Programs\Startup -> %UserProfile%\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk -> %ProgramFiles%\ERUNT\AUTOBACK.EXE -> [Ver = | Size = 38912 bytes | Modified Date = 10/20/2005 12:04:08 PM | Attr = ] %UserProfile%\Start Menu\Programs\Startup\Last.fm Helper.lnk -> %ProgramFiles%\Last.fm\LastFMHelper.exe -> Last.fm [Ver = 1.4.2.58376 | Size = 106496 bytes | Modified Date = 12/19/2007 1:04:34 PM | Attr = ] < Sorin_Diana Startup Folder > -> C:\Documents and Settings\Sorin_Diana\Start Menu\Programs\Startup -> %SystemDrive%\Documents and Settings\Sorin_Diana\Start Menu\Programs\Startup\Last.fm Helper.lnk -> %ProgramFiles%\Last.fm\LastFMHelper.exe -> Last.fm [Ver = 1.4.2.58376 | Size = 106496 bytes | Modified Date = 12/19/2007 1:04:34 PM | Attr = ] < SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005] > -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> AtiExtEvent -> %SystemRoot%\system32\ati2evxx.dll -> ATI Technologies Inc. [Ver = 6.14.10.4176 | Size = 122880 bytes | Modified Date = 12/4/2007 10:55:20 PM | Attr = ] < CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 255 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> 67108863 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableRegistryTools -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLegacyLogonScripts -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLogoffScripts -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunLogonScriptSync -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunStartupScriptSync -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideStartupScripts -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> < CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLegacyLogonScripts -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLogoffScripts -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunLogonScriptSync -> 1 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunStartupScriptSync -> 1 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideStartupScripts -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005] > -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLegacyLogonScripts -> 0 -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLogoffScripts -> 0 -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunLogonScriptSync -> 1 -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunStartupScriptSync -> 1 -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideStartupScripts -> 0 -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> < HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: SearchURL\\ -> [Reg Error: Value provider does not exist or could not be read.] -> HKEY_CURRENT_USER\: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn2\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2006, 10, 26, 1 | Size = 440384 bytes | Modified Date = 10/26/2006 12:28:40 PM | Attr = ] HKEY_CURRENT_USER\: ProxyEnable -> 0 -> HKEY_CURRENT_USER\: ProxyOverride -> localhost;*.local -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\.DEFAULT\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> HKEY_USERS\.DEFAULT\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-18\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> HKEY_USERS\S-1-5-18\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> HKEY_USERS\S-1-5-19\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> HKEY_USERS\S-1-5-20\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\] > -> -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\: SearchURL\\ -> [Reg Error: Value provider does not exist or could not be read.] -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn2\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2006, 10, 26, 1 | Size = 440384 bytes | Modified Date = 10/26/2006 12:28:40 PM | Attr = ] HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\: ProxyEnable -> 0 -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\: ProxyOverride -> localhost;*.local -> < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 1 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 52 domain(s) found. -> < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\] > -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 52 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\] > -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. -> < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {02478D38-C3F9-4EFB-9B51-7695ECA05670} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn2\yt.dll [Yahoo! Toolbar Helper] -> Yahoo! Inc. [Ver = 2006, 10, 26, 1 | Size = 440384 bytes | Modified Date = 10/26/2006 12:28:40 PM | Attr = ] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 59032 bytes | Modified Date = 12/18/2006 4:16:41 AM | Attr = ] {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Winamp Toolbar\winamptb.dll [Winamp Toolbar BHO] -> AOL LLC [Ver = 5.1.14.2 | Size = 1185120 bytes | Modified Date = 12/13/2007 12:49:42 PM | Attr = ] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 501136 bytes | Modified Date = 9/25/2007 2:11:33 AM | Attr = ] {AE7CD045-E861-484f-8273-0445EE161910} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll [Adobe PDF Conversion Toolbar Helper] -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll [Google Toolbar Notifier BHO] -> Google Inc. [Ver = 2, 1, 615, 5858 | Size = 654832 bytes | Modified Date = 8/22/2007 5:03:56 PM | Attr = ] < Internet Explorer Bars [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {182EC0BE-5110-49C8-A062-BEB1D02A220B} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] < Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Bars [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Bars [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Bars [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Bars [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Bars [HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\] > -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> {47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Winamp Toolbar\winamptb.dll [Winamp Toolbar] -> AOL LLC [Ver = 5.1.14.2 | Size = 1185120 bytes | Modified Date = 12/13/2007 12:49:42 PM | Attr = ] {EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn2\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2006, 10, 26, 1 | Size = 440384 bytes | Modified Date = 10/26/2006 12:28:40 PM | Attr = ] < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] WebBrowser\\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Winamp Toolbar\winamptb.dll [Winamp Toolbar] -> AOL LLC [Ver = 5.1.14.2 | Size = 1185120 bytes | Modified Date = 12/13/2007 12:49:42 PM | Attr = ] WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn2\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2006, 10, 26, 1 | Size = 440384 bytes | Modified Date = 10/26/2006 12:28:40 PM | Attr = ] < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\] > -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] WebBrowser\\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Winamp Toolbar\winamptb.dll [Winamp Toolbar] -> AOL LLC [Ver = 5.1.14.2 | Size = 1185120 bytes | Modified Date = 12/13/2007 12:49:42 PM | Attr = ] WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn2\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2006, 10, 26, 1 | Size = 440384 bytes | Modified Date = 10/26/2006 12:28:40 PM | Attr = ] < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 2:11:34 AM | Attr = ] {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} [HKEY_CURRENT_USER] -> %ProgramFiles%\Java\jre1.6.0_03\bin\ssv.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 501136 bytes | Modified Date = 9/25/2007 2:11:33 AM | Attr = ] {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7}:Exec -> F:\Program Files\PacificPoker4\PacificPoker.exe [PacificPoker4] -> Cassava Ent. [Ver = 15, 0, 0, 12 | Size = 151552 bytes | Modified Date = 9/6/2007 6:16:42 PM | Attr = ] < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 2:11:34 AM | Attr = ] CmdMapping\\{94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} [HKEY_LOCAL_MACHINE] -> F:\Program Files\PacificPoker4\PacificPoker.exe [PacificPoker4] -> Cassava Ent. [Ver = 15, 0, 0, 12 | Size = 151552 bytes | Modified Date = 9/6/2007 6:16:42 PM | Attr = ] CmdMapping\\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe [Messenger Class] -> Yahoo! Inc. [Ver = 8,1,0,209 | Size = 4662776 bytes | Modified Date = 11/30/2006 10:49:04 PM | Attr = ] < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> &Winamp Toolbar Search -> %AllUsersProfile%\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.htm -> File not found Add to Windows &Live Favorites -> -> File not found Convert link target to Adobe PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert link target to existing PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert selected links to Adobe PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert selected links to existing PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert selection to Adobe PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert selection to existing PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert to Adobe PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert to existing PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Download linked FLV with GetFLV -> %ProgramFiles%\GetFLV\iemenu\DownloadLinkFLV.htm -> [Ver = | Size = 240 bytes | Modified Date = 12/8/2006 6:21:24 PM | Attr = ] < Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 2:11:34 AM | Attr = ] CmdMapping\\{94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} [HKEY_LOCAL_MACHINE] -> F:\Program Files\PacificPoker4\PacificPoker.exe [PacificPoker4] -> Cassava Ent. [Ver = 15, 0, 0, 12 | Size = 151552 bytes | Modified Date = 9/6/2007 6:16:42 PM | Attr = ] CmdMapping\\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe [Messenger Class] -> Yahoo! Inc. [Ver = 8,1,0,209 | Size = 4662776 bytes | Modified Date = 11/30/2006 10:49:04 PM | Attr = ] < Internet Explorer Menu Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\ -> &Clean Traces -> %ProgramFiles%\DAP\Privacy Package\dapcleanerie.htm -> [Ver = | Size = 1748 bytes | Modified Date = 8/31/2006 1:12:48 AM | Attr = ] &Download with &DAP -> %ProgramFiles%\DAP\dapextie.htm -> [Ver = | Size = 2020 bytes | Modified Date = 8/31/2006 1:12:48 AM | Attr = ] Add to Windows &Live Favorites -> -> File not found Download &all with DAP -> %ProgramFiles%\DAP\dapextie2.htm -> [Ver = | Size = 1041 bytes | Modified Date = 8/31/2006 1:12:48 AM | Attr = ] < Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 2:11:34 AM | Attr = ] CmdMapping\\{94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} [HKEY_LOCAL_MACHINE] -> F:\Program Files\PacificPoker4\PacificPoker.exe [PacificPoker4] -> Cassava Ent. [Ver = 15, 0, 0, 12 | Size = 151552 bytes | Modified Date = 9/6/2007 6:16:42 PM | Attr = ] CmdMapping\\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe [Messenger Class] -> Yahoo! Inc. [Ver = 8,1,0,209 | Size = 4662776 bytes | Modified Date = 11/30/2006 10:49:04 PM | Attr = ] < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\ -> &Clean Traces -> %ProgramFiles%\DAP\Privacy Package\dapcleanerie.htm -> [Ver = | Size = 1748 bytes | Modified Date = 8/31/2006 1:12:48 AM | Attr = ] &Download with &DAP -> %ProgramFiles%\DAP\dapextie.htm -> [Ver = | Size = 2020 bytes | Modified Date = 8/31/2006 1:12:48 AM | Attr = ] Add to Windows &Live Favorites -> -> File not found Download &all with DAP -> %ProgramFiles%\DAP\dapextie2.htm -> [Ver = | Size = 1041 bytes | Modified Date = 8/31/2006 1:12:48 AM | Attr = ] < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\] > -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 2:11:34 AM | Attr = ] CmdMapping\\{94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} [HKEY_LOCAL_MACHINE] -> F:\Program Files\PacificPoker4\PacificPoker.exe [PacificPoker4] -> Cassava Ent. [Ver = 15, 0, 0, 12 | Size = 151552 bytes | Modified Date = 9/6/2007 6:16:42 PM | Attr = ] CmdMapping\\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe [Messenger Class] -> Yahoo! Inc. [Ver = 8,1,0,209 | Size = 4662776 bytes | Modified Date = 11/30/2006 10:49:04 PM | Attr = ] < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\] > -> HKEY_USERS\S-1-5-21-1085031214-2147134177-725345543-1005\Software\Microsoft\Internet Explorer\MenuExt\ -> &Winamp Toolbar Search -> %AllUsersProfile%\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.htm -> File not found Add to Windows &Live Favorites -> -> File not found Convert link target to Adobe PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert link target to existing PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert selected links to Adobe PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert selected links to existing PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert selection to Adobe PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert selection to existing PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert to Adobe PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Convert to existing PDF -> %ProgramFiles%\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 231160 bytes | Modified Date = 12/18/2006 4:18:14 AM | Attr = ] Download linked FLV with GetFLV -> %ProgramFiles%\GetFLV\iemenu\DownloadLinkFLV.htm -> [Ver = | Size = 240 bytes | Modified Date = 12/8/2006 6:21:24 PM | Attr = ] < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> Extension\.spop -> %ProgramFiles%\Internet Explorer\PLUGINS\NPDocBox.dll [] -> Intertrust Technologies, Inc. [Ver = 1.0.0.32 | Size = 270336 bytes | Modified Date = 8/1/2001 6:05:42 PM | Attr = ] < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {0E76AA93-7244-4724-8531-BAD9A0D80A7F} -> () -> {C3E14318-F89C-4058-BBF7-748C9F065DAB} -> (NVIDIA nForce Networking Controller) -> < Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> NameSpace_Catalog5\Catalog_Entries\000000000001 [mdnsNSP] -> %ProgramFiles%\Bonjour\mdnsNSP.dll -> Apple Inc. [Ver = 1,0,4,12 | Size = 147456 bytes | Modified Date = 7/24/2007 4:17:08 PM | Attr = ] < Default Protocols [HKEY_USERS\.DEFAULT\] - Select to Repair > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\S-1-5-18\] - Select to Repair > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\S-1-5-19\] - Select to Repair > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\S-1-5-20\] - Select to Repair > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> bwfile-8876480:{9462A756-7B47-47BC-8C80-C34B9B80B32B} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll[BackWeb GA Pluggable Protocol] -> Logitech Inc. [Ver = Version 8.1.1 (Build 50R) | Size = 28711 bytes | Modified Date = 3/13/2007 10:01:29 PM | Attr = ] cetihpz:{CF184AD3-CDCB-4168-A3F7-8E447D129300} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\HP\hpcoretech\comp\hpuiprot.dll[CZipHandler Object] -> Hewlett-Packard Company [Ver = 2.1.4 | Size = 81920 bytes | Modified Date = 12/22/2003 8:38:40 AM | Attr = ] intu-qt2007:{026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\QuickTax 2007\ic2007pp.dll[qt2007 Pluggable Protocol Handler Class] -> Intuit Canada, a general partnership/une société en nom collectif. [Ver = 1.0.4.0 | Size = 69632 bytes | Modified Date = 1/3/2008 2:29:18 PM | Attr = ] ipp: [HKEY_LOCAL_MACHINE] -> No CLSID value msdaipp: [HKEY_LOCAL_MACHINE] -> No CLSID value < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {0A5FD7C5-A45C-49FC-ADB5-9952547D5715}[HKEY_LOCAL_MACHINE] -> http://www.creative.com/su/ocx/15026/CTSUEng.cab[Creative Software AutoUpdate] -> {14B87622-7E19-4EA8-93B3-97215F77A6BC}[HKEY_LOCAL_MACHINE] -> http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab[MessengerStatsClient Class] -> {20A60F0D-9AFA-4515-A0FD-83BD84642501}[HKEY_LOCAL_MACHINE] -> http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab[Checkers Class] -> {33564D57-0000-0010-8000-00AA00389B71}[HKEY_LOCAL_MACHINE] -> http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB[Reg Error: Key does not exist or could not be opened.] -> {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}[HKEY_LOCAL_MACHINE] -> http://office.microsoft.com/officeupdate/content/opuc3.cab[Office Update Installation Engine] -> {5C051655-FCD5-4969-9182-770EA5AA5565}[HKEY_LOCAL_MACHINE] -> http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab[Solitaire Showdown Class] -> {5D6F45B3-9043-443D-A792-115447494D24}[HKEY_LOCAL_MACHINE] -> http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab[UnoCtrl Class] -> {6414512B-B978-451D-A0D8-FCFDF33E833C}[HKEY_LOCAL_MACHINE] -> http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1156908970488[WUWebControl Class] -> {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}[HKEY_LOCAL_MACHINE] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1157302271718[MUWebControl Class] -> {8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> {9122D757-5A4F-4768-82C5-B4171D8556A7}[HKEY_LOCAL_MACHINE] -> http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab[PhotoPickConvert Class] -> {C3F79A2B-B9B4-4A66-B012-3EE46475B072}[HKEY_LOCAL_MACHINE] -> http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab[MessengerStatsClient Class] -> {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab[Java Plug-in 1.5.0_06] -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> {D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab[Shockwave Flash Object] -> {F6ACF75C-C32C-447B-9BEF-46B766368D29}[HKEY_LOCAL_MACHINE] -> http://www.creative.com/su/ocx/15026/CTPID.cab[Creative Software AutoUpdate Support Package] -> < Module Usage Keys [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/MessengerStatsPAClient.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/MessengerStatsPAClient.dll\\.Owner -> {C3F79A2B-B9B4-4A66-B012-3EE46475B072} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/MessengerStatsPAClient.dll\\{C3F79A2B-B9B4-4A66-B012-3EE46475B072} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CTPID.ocx\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CTPID.ocx\\.Owner -> {F6ACF75C-C32C-447B-9BEF-46B766368D29} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CTPID.ocx\\{F6ACF75C-C32C-447B-9BEF-46B766368D29} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CTSUEng.ocx\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CTSUEng.ocx\\.Owner -> {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CTSUEng.ocx\\{0A5FD7C5-A45C-49FC-ADB5-9952547D5715} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/GAME_UNO1.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/GAME_UNO1.dll\\.Owner -> {5D6F45B3-9043-443D-A792-115447494D24} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/GAME_UNO1.dll\\{5D6F45B3-9043-443D-A792-115447494D24} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MessengerStatsPAClient.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MessengerStatsPAClient.dll\\.Owner -> {14B87622-7E19-4EA8-93B3-97215F77A6BC} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MessengerStatsPAClient.dll\\{14B87622-7E19-4EA8-93B3-97215F77A6BC} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/msgrchkr.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/msgrchkr.dll\\.Owner -> {20A60F0D-9AFA-4515-A0FD-83BD84642501} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/msgrchkr.dll\\{20A60F0D-9AFA-4515-A0FD-83BD84642501} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/PhtPkMSN.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/PhtPkMSN.dll\\.Owner -> {9122D757-5A4F-4768-82C5-B4171D8556A7} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/PhtPkMSN.dll\\{9122D757-5A4F-4768-82C5-B4171D8556A7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SolitaireShowdown.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SolitaireShowdown.dll\\.Owner -> {5C051655-FCD5-4969-9182-770EA5AA5565} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SolitaireShowdown.dll\\{5C051655-FCD5-4969-9182-770EA5AA5565} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/opuc.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/opuc.dll\\.Owner -> {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/opuc.dll\\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/danim.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/danim.dll\\RogueSpear -> RogueSpear -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/danim.dll\\.Owner -> RogueSpear -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ddrawex.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ddrawex.dll\\RogueSpear -> RogueSpear -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ddrawex.dll\\.Owner -> RogueSpear -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/lfbmp13n.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/lfbmp13n.dll\\.Owner -> {9122D757-5A4F-4768-82C5-B4171D8556A7} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/lfbmp13n.dll\\{9122D757-5A4F-4768-82C5-B4171D8556A7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/lfcmp13n.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/lfcmp13n.dll\\.Owner -> {9122D757-5A4F-4768-82C5-B4171D8556A7} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/lfcmp13n.dll\\{9122D757-5A4F-4768-82C5-B4171D8556A7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/lfgif13n.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/lfgif13n.dll\\.Owner -> {9122D757-5A4F-4768-82C5-B4171D8556A7} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/lfgif13n.dll\\{9122D757-5A4F-4768-82C5-B4171D8556A7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/lfpng13n.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/lfpng13n.dll\\.Owner -> {9122D757-5A4F-4768-82C5-B4171D8556A7} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/lfpng13n.dll\\{9122D757-5A4F-4768-82C5-B4171D8556A7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ltdis13n.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ltdis13n.dll\\.Owner -> {9122D757-5A4F-4768-82C5-B4171D8556A7} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ltdis13n.dll\\{9122D757-5A4F-4768-82C5-B4171D8556A7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ltfil13n.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ltfil13n.dll\\.Owner -> {9122D757-5A4F-4768-82C5-B4171D8556A7} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ltfil13n.dll\\{9122D757-5A4F-4768-82C5-B4171D8556A7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ltimg13n.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ltimg13n.dll\\.Owner -> {9122D757-5A4F-4768-82C5-B4171D8556A7} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ltimg13n.dll\\{9122D757-5A4F-4768-82C5-B4171D8556A7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ltkrn13n.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ltkrn13n.dll\\.Owner -> {9122D757-5A4F-4768-82C5-B4171D8556A7} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ltkrn13n.dll\\{9122D757-5A4F-4768-82C5-B4171D8556A7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcr71.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcr71.dll\\.Owner -> Unknown Owner -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcr71.dll\\{9122D757-5A4F-4768-82C5-B4171D8556A7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/muweb.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/muweb.dll\\.Owner -> {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/muweb.dll\\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/quartz.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/quartz.dll\\RogueSpear -> RogueSpear -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/quartz.dll\\.Owner -> RogueSpear -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\\.Owner -> {6414512B-B978-451D-A0D8-FCFDF33E833C} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\\{6414512B-B978-451D-A0D8-FCFDF33E833C} -> -> [Files/Folders - Created Within 90 days] ads_err.dbf -> %SystemDrive%\ads_err.dbf -> [Ver = | Size = 2467 bytes | Created Date = 2/2/2008 5:47:46 PM | Attr = ] AROTrial.exe -> %SystemDrive%\AROTrial.exe -> Sammsoft [Ver = Advanced Registry Op | Size = 2218368 bytes | Created Date = 4/13/2008 9:32:25 AM | Attr = ] aswclear.exe -> %SystemDrive%\aswclear.exe -> Alwil Software [Ver = 1, 0, 0, 1 | Size = 230776 bytes | Created Date = 4/13/2008 10:15:10 AM | Attr = ] ComboFix -> %SystemDrive%\ComboFix -> [Folder | Created Date = 4/15/2008 3:38:34 PM | Attr = ] Deckard -> %SystemDrive%\Deckard -> [Folder | Created Date = 4/13/2008 1:16:15 PM | Attr = ] NoLopBackups -> %SystemDrive%\NoLopBackups -> [Folder | Created Date = 4/13/2008 6:43:24 PM | Attr = ] PacSteam -> %SystemDrive%\PacSteam -> [Folder | Created Date = 1/31/2008 9:57:34 PM | Attr = ] PacSteamT -> %SystemDrive%\PacSteamT -> [Folder | Created Date = 1/31/2008 9:42:02 PM | Attr = ] QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 4/13/2008 7:09:23 PM | Attr = ] _OTMoveIt -> %SystemDrive%\_OTMoveIt -> [Folder | Created Date = 4/13/2008 1:14:52 PM | Attr = ] a3d.dll -> %SystemRoot%\System32\dllcache\a3d.dll -> [Ver = 80.0.0.3 | Size = 65536 bytes | Created Date = 3/17/2008 7:40:31 AM | Attr = ] big5.nls -> %SystemRoot%\System32\dllcache\big5.nls -> [Ver = | Size = 66728 bytes | Created Date = 3/16/2008 2:36:49 AM | Attr = ] bopomofo.nls -> %SystemRoot%\System32\dllcache\bopomofo.nls -> [Ver = | Size = 82172 bytes | Created Date = 3/16/2008 2:36:50 AM | Attr = ] cap7146.sys -> %SystemRoot%\System32\dllcache\cap7146.sys -> Philips Semiconductors GmbH [Ver = 1.00 (XPClient.010817-1148) | Size = 54528 bytes | Created Date = 3/16/2008 2:36:57 AM | Attr = ] chtskf.dll -> %SystemRoot%\System32\dllcache\chtskf.dll -> [Ver = | Size = 173568 bytes | Created Date = 3/16/2008 2:36:59 AM | Attr = ] c_10001.nls -> %SystemRoot%\System32\dllcache\c_10001.nls -> [Ver = | Size = 162850 bytes | Created Date = 3/16/2008 2:36:50 AM | Attr = ] c_10002.nls -> %SystemRoot%\System32\dllcache\c_10002.nls -> [Ver = | Size = 195618 bytes | Created Date = 3/16/2008 2:36:50 AM | Attr = ] c_10003.nls -> %SystemRoot%\System32\dllcache\c_10003.nls -> [Ver = | Size = 177698 bytes | Created Date = 3/16/2008 2:36:51 AM | Attr = ] c_10004.nls -> %SystemRoot%\System32\dllcache\c_10004.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:51 AM | Attr = ] c_10005.nls -> %SystemRoot%\System32\dllcache\c_10005.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:51 AM | Attr = ] c_10008.nls -> %SystemRoot%\System32\dllcache\c_10008.nls -> [Ver = | Size = 173602 bytes | Created Date = 3/16/2008 2:36:51 AM | Attr = ] c_10021.nls -> %SystemRoot%\System32\dllcache\c_10021.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:51 AM | Attr = ] c_1047.nls -> %SystemRoot%\System32\dllcache\c_1047.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:51 AM | Attr = ] c_1140.nls -> %SystemRoot%\System32\dllcache\c_1140.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:51 AM | Attr = ] c_1141.nls -> %SystemRoot%\System32\dllcache\c_1141.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:51 AM | Attr = ] c_1142.nls -> %SystemRoot%\System32\dllcache\c_1142.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:51 AM | Attr = ] c_1143.nls -> %SystemRoot%\System32\dllcache\c_1143.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:51 AM | Attr = ] c_1144.nls -> %SystemRoot%\System32\dllcache\c_1144.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:52 AM | Attr = ] c_1145.nls -> %SystemRoot%\System32\dllcache\c_1145.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:52 AM | Attr = ] c_1146.nls -> %SystemRoot%\System32\dllcache\c_1146.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:52 AM | Attr = ] c_1147.nls -> %SystemRoot%\System32\dllcache\c_1147.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:52 AM | Attr = ] c_1148.nls -> %SystemRoot%\System32\dllcache\c_1148.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:52 AM | Attr = ] c_1149.nls -> %SystemRoot%\System32\dllcache\c_1149.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:52 AM | Attr = ] c_1361.nls -> %SystemRoot%\System32\dllcache\c_1361.nls -> [Ver = | Size = 189986 bytes | Created Date = 3/16/2008 2:36:52 AM | Attr = ] c_20000.nls -> %SystemRoot%\System32\dllcache\c_20000.nls -> [Ver = | Size = 180258 bytes | Created Date = 3/16/2008 2:36:52 AM | Attr = ] c_20001.nls -> %SystemRoot%\System32\dllcache\c_20001.nls -> [Ver = | Size = 186402 bytes | Created Date = 3/16/2008 2:36:52 AM | Attr = ] c_20002.nls -> %SystemRoot%\System32\dllcache\c_20002.nls -> [Ver = | Size = 173602 bytes | Created Date = 3/16/2008 2:36:53 AM | Attr = ] c_20003.nls -> %SystemRoot%\System32\dllcache\c_20003.nls -> [Ver = | Size = 185378 bytes | Created Date = 3/16/2008 2:36:53 AM | Attr = ] c_20004.nls -> %SystemRoot%\System32\dllcache\c_20004.nls -> [Ver = | Size = 180258 bytes | Created Date = 3/16/2008 2:36:53 AM | Attr = ] c_20005.nls -> %SystemRoot%\System32\dllcache\c_20005.nls -> [Ver = | Size = 187938 bytes | Created Date = 3/16/2008 2:36:53 AM | Attr = ] c_20105.nls -> %SystemRoot%\System32\dllcache\c_20105.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:53 AM | Attr = ] c_20106.nls -> %SystemRoot%\System32\dllcache\c_20106.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:53 AM | Attr = ] c_20107.nls -> %SystemRoot%\System32\dllcache\c_20107.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:53 AM | Attr = ] c_20108.nls -> %SystemRoot%\System32\dllcache\c_20108.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:53 AM | Attr = ] c_20269.nls -> %SystemRoot%\System32\dllcache\c_20269.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:53 AM | Attr = ] c_20273.nls -> %SystemRoot%\System32\dllcache\c_20273.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:53 AM | Attr = ] c_20277.nls -> %SystemRoot%\System32\dllcache\c_20277.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20278.nls -> %SystemRoot%\System32\dllcache\c_20278.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20280.nls -> %SystemRoot%\System32\dllcache\c_20280.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20284.nls -> %SystemRoot%\System32\dllcache\c_20284.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20285.nls -> %SystemRoot%\System32\dllcache\c_20285.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20290.nls -> %SystemRoot%\System32\dllcache\c_20290.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20297.nls -> %SystemRoot%\System32\dllcache\c_20297.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20420.nls -> %SystemRoot%\System32\dllcache\c_20420.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20423.nls -> %SystemRoot%\System32\dllcache\c_20423.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20424.nls -> %SystemRoot%\System32\dllcache\c_20424.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20833.nls -> %SystemRoot%\System32\dllcache\c_20833.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20838.nls -> %SystemRoot%\System32\dllcache\c_20838.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20871.nls -> %SystemRoot%\System32\dllcache\c_20871.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:54 AM | Attr = ] c_20880.nls -> %SystemRoot%\System32\dllcache\c_20880.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:55 AM | Attr = ] c_20924.nls -> %SystemRoot%\System32\dllcache\c_20924.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:55 AM | Attr = ] c_20932.nls -> %SystemRoot%\System32\dllcache\c_20932.nls -> [Ver = | Size = 180770 bytes | Created Date = 3/16/2008 2:36:55 AM | Attr = ] c_20936.nls -> %SystemRoot%\System32\dllcache\c_20936.nls -> [Ver = | Size = 173602 bytes | Created Date = 3/16/2008 2:36:55 AM | Attr = ] c_20949.nls -> %SystemRoot%\System32\dllcache\c_20949.nls -> [Ver = | Size = 177698 bytes | Created Date = 3/16/2008 2:36:55 AM | Attr = ] c_21025.nls -> %SystemRoot%\System32\dllcache\c_21025.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:55 AM | Attr = ] c_21027.nls -> %SystemRoot%\System32\dllcache\c_21027.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:55 AM | Attr = ] c_28596.nls -> %SystemRoot%\System32\dllcache\c_28596.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:55 AM | Attr = ] c_708.nls -> %SystemRoot%\System32\dllcache\c_708.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:56 AM | Attr = ] c_720.nls -> %SystemRoot%\System32\dllcache\c_720.nls -> [Ver = | Size = 66594 bytes | Created Date = 3/16/2008 2:36:56 AM | Attr = ] c_858.nls -> %SystemRoot%\System32\dllcache\c_858.nls -> [Ver = | Size = 66594 bytes | Created Date = 3/16/2008 2:36:56 AM | Attr = ] c_862.nls -> %SystemRoot%\System32\dllcache\c_862.nls -> [Ver = | Size = 66594 bytes | Created Date = 3/16/2008 2:36:56 AM | Attr = ] c_864.nls -> %SystemRoot%\System32\dllcache\c_864.nls -> [Ver = | Size = 66594 bytes | Created Date = 3/16/2008 2:36:56 AM | Attr = ] c_870.nls -> %SystemRoot%\System32\dllcache\c_870.nls -> [Ver = | Size = 66082 bytes | Created Date = 3/16/2008 2:36:56 AM | Attr = ] esucmd.dll -> %SystemRoot%\System32\dllcache\esucmd.dll -> SEIKO EPSON CORP. [Ver = 1.00 | Size = 31744 bytes | Created Date = 3/16/2008 2:37:10 AM | Attr = ] esuimgd.dll -> %SystemRoot%\System32\dllcache\esuimgd.dll -> SEIKO EPSON CORP. [Ver = 1.00 | Size = 57856 bytes | Created Date = 3/16/2008 2:37:10 AM | Attr = ] esunid.dll -> %SystemRoot%\System32\dllcache\esunid.dll -> SEIKO EPSON CORP. [Ver = 1.00 | Size = 45056 bytes | Created Date = 3/16/2008 2:37:10 AM | Attr = ] FP4.CAT -> %SystemRoot%\System32\dllcache\FP4.CAT -> [Ver = | Size = 31281 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] fpencode.dll -> %SystemRoot%\System32\dllcache\fpencode.dll -> [Ver = | Size = 94208 bytes | Created Date = 3/16/2008 2:37:13 AM | Attr = ] hanja.lex -> %SystemRoot%\System32\dllcache\hanja.lex -> [Ver = | Size = 108827 bytes | Created Date = 3/16/2008 2:37:18 AM | Attr = ] HPCRDP.CAT -> %SystemRoot%\System32\dllcache\HPCRDP.CAT -> [Ver = | Size = 13472 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] hwxjpn.dll -> %SystemRoot%\System32\dllcache\hwxjpn.dll -> [Ver = | Size = 13463552 bytes | Created Date = 3/16/2008 2:37:23 AM | Attr = ] IASNT4.CAT -> %SystemRoot%\System32\dllcache\IASNT4.CAT -> [Ver = | Size = 8574 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] imekr.lex -> %SystemRoot%\System32\dllcache\imekr.lex -> [Ver = | Size = 134339 bytes | Created Date = 3/16/2008 2:37:31 AM | Attr = ] imjpinst.exe -> %SystemRoot%\System32\dllcache\imjpinst.exe -> [Ver = | Size = 196665 bytes | Created Date = 3/16/2008 2:37:33 AM | Attr = ] IMS.CAT -> %SystemRoot%\System32\dllcache\IMS.CAT -> [Ver = | Size = 13753 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] imscinst.exe -> %SystemRoot%\System32\dllcache\imscinst.exe -> [Ver = | Size = 59392 bytes | Created Date = 3/16/2008 2:37:34 AM | Attr = ] korwbrkr.lex -> %SystemRoot%\System32\dllcache\korwbrkr.lex -> [Ver = | Size = 1158818 bytes | Created Date = 3/16/2008 2:37:42 AM | Attr = ] ksc.nls -> %SystemRoot%\System32\dllcache\ksc.nls -> [Ver = | Size = 47066 bytes | Created Date = 3/16/2008 2:37:43 AM | Attr = ] MAPIMIG.CAT -> %SystemRoot%\System32\dllcache\MAPIMIG.CAT -> [Ver = | Size = 399645 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] mediactr.cat -> %SystemRoot%\System32\dllcache\mediactr.cat -> [Ver = | Size = 31965 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] MSMSGS.CAT -> %SystemRoot%\System32\dllcache\MSMSGS.CAT -> [Ver = | Size = 9581 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] msn7.cat -> %SystemRoot%\System32\dllcache\msn7.cat -> [Ver = | Size = 24209 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] msn9.cat -> %SystemRoot%\System32\dllcache\msn9.cat -> [Ver = | Size = 11651 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] MSTSWEB.CAT -> %SystemRoot%\System32\dllcache\MSTSWEB.CAT -> [Ver = | Size = 7245 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] MW770.CAT -> %SystemRoot%\System32\dllcache\MW770.CAT -> [Ver = | Size = 37484 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] netfx.cat -> %SystemRoot%\System32\dllcache\netfx.cat -> [Ver = | Size = 141702 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] NT5.CAT -> %SystemRoot%\System32\dllcache\NT5.CAT -> [Ver = | Size = 2012670 bytes | Created Date = 3/16/2008 2:18:59 AM | Attr = ] NT5IIS.CAT -> %SystemRoot%\System32\dllcache\NT5IIS.CAT -> [Ver = | Size = 797189 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] NT5INF.CAT -> %SystemRoot%\System32\dllcache\NT5INF.CAT -> [Ver = | Size = 502724 bytes | Created Date = 3/16/2008 2:18:59 AM | Attr = ] NTPRINT.CAT -> %SystemRoot%\System32\dllcache\NTPRINT.CAT -> [Ver = | Size = 1086058 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] OEMBIOS.CAT -> %SystemRoot%\System32\dllcache\OEMBIOS.CAT -> [Ver = | Size = 7382 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] pintlcsa.dll -> %SystemRoot%\System32\dllcache\pintlcsa.dll -> [Ver = | Size = 175104 bytes | Created Date = 3/16/2008 2:38:05 AM | Attr = ] prc.nls -> %SystemRoot%\System32\dllcache\prc.nls -> [Ver = | Size = 83748 bytes | Created Date = 3/16/2008 2:38:07 AM | Attr = ] prcp.nls -> %SystemRoot%\System32\dllcache\prcp.nls -> [Ver = | Size = 83748 bytes | Created Date = 3/16/2008 2:38:07 AM | Attr = ] rw330ext.dll -> %SystemRoot%\System32\dllcache\rw330ext.dll -> Ricoh Co., Ltd. [Ver = 5, 0, 2419, 1 | Size = 26624 bytes | Created Date = 3/16/2008 2:38:13 AM | Attr = ] rwia001.dll -> %SystemRoot%\System32\dllcache\rwia001.dll -> Ricoh Co., Ltd. [Ver = 5, 0, 2419, 1 | Size = 79872 bytes | Created Date = 3/16/2008 2:38:13 AM | Attr = ] rwia330.dll -> %SystemRoot%\System32\dllcache\rwia330.dll -> Ricoh Co., Ltd. [Ver = 5, 0, 2419, 1 | Size = 79872 bytes | Created Date = 3/16/2008 2:38:13 AM | Attr = ] SP2.CAT -> %SystemRoot%\System32\dllcache\SP2.CAT -> [Ver = | Size = 1042903 bytes | Created Date = 3/16/2008 2:18:59 AM | Attr = ] spxcoins.dll -> %SystemRoot%\System32\dllcache\spxcoins.dll -> Perle Systems Ltd. [Ver = 1.0.0.0007 | Size = 24661 bytes | Created Date = 3/16/2008 2:19:11 AM | Attr = ] tabletpc.cat -> %SystemRoot%\System32\dllcache\tabletpc.cat -> [Ver = | Size = 110116 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] wmerrenu.cat -> %SystemRoot%\System32\dllcache\wmerrenu.cat -> [Ver = | Size = 7334 bytes | Created Date = 3/16/2008 2:19:00 AM | Attr = ] xjis.nls -> %SystemRoot%\System32\dllcache\xjis.nls -> [Ver = | Size = 28288 bytes | Created Date = 3/16/2008 2:38:42 AM | Attr = ] ctac32k.sys -> %SystemRoot%\System32\drivers\ctac32k.sys -> Creative Technology Ltd [Ver = 5.12.01.0245-1.31.0050 | Size = 127948 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] ctaud2k.sys -> %SystemRoot%\System32\drivers\ctaud2k.sys -> Creative Technology Ltd [Ver = 5.12.01.0252-1.31.0120 | Size = 837548 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] ctoss2k.sys -> %SystemRoot%\System32\drivers\ctoss2k.sys -> Creative Technology Ltd. [Ver = 5.12.01.0245-1.31.0050 | Size = 195432 bytes | Created Date = 3/17/2008 7:40:33 AM | Attr = ] ctprxy2k.sys -> %SystemRoot%\System32\drivers\ctprxy2k.sys -> Creative Technology Ltd [Ver = 5.12.01.0244-1.31.0040 | Size = 11068 bytes | Created Date = 3/17/2008 7:40:33 AM | Attr = ] ctsfm2k.sys -> %SystemRoot%\System32\drivers\ctsfm2k.sys -> Creative Technology Ltd [Ver = 5.12.01.0140-0.75.1490 (beta-release) | Size = 213860 bytes | Created Date = 3/17/2008 7:40:33 AM | Attr = ] emupia2k.sys -> %SystemRoot%\System32\drivers\emupia2k.sys -> Creative Technology Ltd [Ver = 5.12.01.0244-1.31.0040 | Size = 156604 bytes | Created Date = 3/17/2008 7:40:33 AM | Attr = ] GEARAspiWDM.sys -> %SystemRoot%\System32\drivers\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.00.07.03 | Size = 16168 bytes | Created Date = 1/29/2008 12:01:28 PM | Attr = ] ha10kx2k.sys -> %SystemRoot%\System32\drivers\ha10kx2k.sys -> Creative Technology Ltd [Ver = 5.12.01.0250-1.31.0090 | Size = 998004 bytes | Created Date = 3/17/2008 7:40:33 AM | Attr = ] SYMEVENT.CAT -> %SystemRoot%\System32\drivers\SYMEVENT.CAT -> [Ver = | Size = 10652 bytes | Created Date = 3/16/2008 3:15:04 AM | Attr = ] SYMEVENT.INF -> %SystemRoot%\System32\drivers\SYMEVENT.INF -> [Ver = | Size = 806 bytes | Created Date = 3/16/2008 3:15:04 AM | Attr = ] SYMEVENT.SYS -> %SystemRoot%\System32\drivers\SYMEVENT.SYS -> Symantec Corporation [Ver = 12.4.0.24 | Size = 136496 bytes | Created Date = 3/16/2008 3:15:04 AM | Attr = ] SysPlant.sys -> %SystemRoot%\System32\drivers\SysPlant.sys -> Symantec Corporation [Ver = 11.0.1000.1091 | Size = 91008 bytes | Created Date = 3/16/2008 3:15:16 AM | Attr = ] 4codedecoder.dll -> %SystemRoot%\System32\4codedecoder.dll -> dicas digital image coding GmbH [Ver = 1,11,0,3 | Size = 282624 bytes | Created Date = 4/12/2008 7:53:00 AM | Attr = ] a3d.dll -> %SystemRoot%\System32\a3d.dll -> [Ver = 80.0.0.3 | Size = 65536 bytes | Created Date = 3/17/2008 7:40:31 AM | Attr = ] AC3API.DLL -> %SystemRoot%\System32\AC3API.DLL -> Creative Technology Ltd [Ver = 5.12.01.0244-1.31.0040 | Size = 53248 bytes | Created Date = 3/17/2008 7:40:31 AM | Attr = ] audiocodec.dll -> %SystemRoot%\System32\audiocodec.dll -> dicas digital image coding GmbH [Ver = 1,3,0,3 | Size = 577536 bytes | Created Date = 4/12/2008 7:53:00 AM | Attr = ] BMXBkpCtrlState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> %SystemRoot%\System32\BMXBkpCtrlState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> [Ver = | Size = 29808 bytes | Created Date = 3/17/2008 8:35:59 AM | Attr = ] BMXCtrlState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> %SystemRoot%\System32\BMXCtrlState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> [Ver = | Size = 29808 bytes | Created Date = 3/17/2008 8:35:59 AM | Attr = ] BMXState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> %SystemRoot%\System32\BMXState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> [Ver = | Size = 17500 bytes | Created Date = 3/17/2008 8:35:59 AM | Attr = ] BMXStateBkp-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> %SystemRoot%\System32\BMXStateBkp-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> [Ver = | Size = 17500 bytes | Created Date = 3/17/2008 8:35:59 AM | Attr = ] COMMONFX.DLL -> %SystemRoot%\System32\COMMONFX.DLL -> Creative Technology Ltd [Ver = 5.12.01.0244-1.31.0040 | Size = 110592 bytes | Created Date = 3/17/2008 7:40:31 AM | Attr = ] CT1MGM.ROM -> %SystemRoot%\System32\CT1MGM.ROM -> [Ver = | Size = 1048576 bytes | Created Date = 3/17/2008 7:40:31 AM | Attr = ] CT2MGM.SF2 -> %SystemRoot%\System32\CT2MGM.SF2 -> [Ver = | Size = 2167684 bytes | Created Date = 3/17/2008 7:40:31 AM | Attr = ] CTAGENT.DLL -> %SystemRoot%\System32\CTAGENT.DLL -> Creative Technology Ltd [Ver = 1, 0, 0, 5 | Size = 61440 bytes | Created Date = 3/17/2008 7:40:31 AM | Attr = ] CTASIO.DLL -> %SystemRoot%\System32\CTASIO.DLL -> Creative Technology Ltd [Ver = 5.12.01.0244-1.31.0040 | Size = 106496 bytes | Created Date = 3/17/2008 7:40:31 AM | Attr = ] CTBAS2W.DAT -> %SystemRoot%\System32\CTBAS2W.DAT -> [Ver = | Size = 113273 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] ctbasicw.dat -> %SystemRoot%\System32\ctbasicw.dat -> [Ver = | Size = 113373 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] ctdaught.dat -> %SystemRoot%\System32\ctdaught.dat -> [Ver = | Size = 44055 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] CTDEVCON.DLL -> %SystemRoot%\System32\CTDEVCON.DLL -> Creative Technology Ltd [Ver = 5.12.01.0244-1.31.0040 | Size = 319488 bytes | Created Date = 3/17/2008 7:40:31 AM | Attr = ] ctdlang.dat -> %SystemRoot%\System32\ctdlang.dat -> [Ver = | Size = 164044 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] CTDPROXY.DLL -> %SystemRoot%\System32\CTDPROXY.DLL -> Creative Technology Ltd [Ver = 5.12.01.0244-1.31.0040 | Size = 106496 bytes | Created Date = 3/17/2008 7:40:31 AM | Attr = ] CTEMUPIA.DLL -> %SystemRoot%\System32\CTEMUPIA.DLL -> Creative Technology Ltd [Ver = 5.12.01.0244-1.31.0040 | Size = 36864 bytes | Created Date = 3/17/2008 7:40:31 AM | Attr = ] CTOSUSER.DLL -> %SystemRoot%\System32\CTOSUSER.DLL -> Creative Technology Ltd [Ver = 5.12.01.0244-1.31.0040 | Size = 155648 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] CTSBLFX.DLL -> %SystemRoot%\System32\CTSBLFX.DLL -> Creative Technology Ltd [Ver = 5.12.01.0244-1.31.0040 | Size = 643072 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] CTSPKHLP.DLL -> %SystemRoot%\System32\CTSPKHLP.DLL -> Creative Technology Ltd [Ver = 1, 0, 0, 2 | Size = 28672 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] ctstatic.dat -> %SystemRoot%\System32\ctstatic.dat -> [Ver = | Size = 179669 bytes | Created Date = 3/17/2008 7:40:33 AM | Attr = ] default.ecw -> %SystemRoot%\System32\default.ecw -> [Ver = | Size = 2259067 bytes | Created Date = 3/17/2008 7:40:33 AM | Attr = ] DEFAULT.SFM -> %SystemRoot%\System32\DEFAULT.SFM -> [Ver = | Size = 59 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] DEFAULT4.SFM -> %SystemRoot%\System32\DEFAULT4.SFM -> [Ver = | Size = 59 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] DEFAULT8.SFM -> %SystemRoot%\System32\DEFAULT8.SFM -> [Ver = | Size = 59 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] dllzaac.dll -> %SystemRoot%\System32\dllzaac.dll -> zplane.development [Ver = 1, 0, 0, 0 | Size = 233472 bytes | Created Date = 4/12/2008 7:53:00 AM | Attr = ] DVCState-{00000004-00000000-00000008-00001102-00000002-80641102}.dat -> %SystemRoot%\System32\DVCState-{00000004-00000000-00000008-00001102-00000002-80641102}.dat -> [Ver = | Size = 24 bytes | Created Date = 3/17/2008 8:35:59 AM | Attr = ] DVCStateBkp-{00000004-00000000-00000008-00001102-00000002-80641102}.dat -> %SystemRoot%\System32\DVCStateBkp-{00000004-00000000-00000008-00001102-00000002-80641102}.dat -> [Ver = | Size = 24 bytes | Created Date = 3/17/2008 8:35:59 AM | Attr = ] EAXAC3.DLL -> %SystemRoot%\System32\EAXAC3.DLL -> Creative Labs [Ver = 1.12 | Size = 77824 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] GEARAspi.dll -> %SystemRoot%\System32\GEARAspi.dll -> GEAR Software Inc. [Ver = 2.1.1.1 | Size = 107368 bytes | Created Date = 1/29/2008 12:02:30 PM | Attr = ] KILL.INI -> %SystemRoot%\System32\KILL.INI -> [Ver = | Size = 180 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] KILLAPPS.EXE -> %SystemRoot%\System32\KILLAPPS.EXE -> [Ver = | Size = 49152 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] logonui.exe.manifest -> %SystemRoot%\System32\logonui.exe.manifest -> [Ver = | Size = 488 bytes | Created Date = 3/16/2008 2:33:03 AM | Attr = RH ] mp4filelib.dll -> %SystemRoot%\System32\mp4filelib.dll -> dicas digital image coding GmbH [Ver = 2,3,0,1 | Size = 217088 bytes | Created Date = 4/12/2008 7:53:00 AM | Attr = ] ncpa.cpl.manifest -> %SystemRoot%\System32\ncpa.cpl.manifest -> [Ver = | Size = 749 bytes | Created Date = 3/16/2008 2:32:57 AM | Attr = RH ] nwc.cpl.manifest -> %SystemRoot%\System32\nwc.cpl.manifest -> [Ver = | Size = 749 bytes | Created Date = 3/16/2008 2:32:57 AM | Attr = RH ] OPENAL32.DLL -> %SystemRoot%\System32\OPENAL32.DLL -> Creative Technology Ltd [Ver = 5.12.01.0244-1.31.0040 | Size = 135168 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] PIAPROXY.DLL -> %SystemRoot%\System32\PIAPROXY.DLL -> Creative Technology Ltd [Ver = 5.12.01.0244-1.31.0040 | Size = 110592 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] QuickTime.qts -> %SystemRoot%\System32\QuickTime.qts -> Apple Inc. [Ver = 7.4.5 | Size = 57344 bytes | Created Date = 3/28/2008 11:37:26 PM | Attr = ] QuickTimeVR.qtx -> %SystemRoot%\System32\QuickTimeVR.qtx -> Apple Inc. [Ver = 7.4.5 | Size = 90112 bytes | Created Date = 3/28/2008 11:37:26 PM | Attr = ] REGPLIB.EXE -> %SystemRoot%\System32\REGPLIB.EXE -> [Ver = | Size = 36864 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] S32EVNT1.DLL -> %SystemRoot%\System32\S32EVNT1.DLL -> Symantec Corporation [Ver = 12.4.0.25 | Size = 60808 bytes | Created Date = 3/16/2008 3:15:04 AM | Attr = ] sapi.cpl.manifest -> %SystemRoot%\System32\sapi.cpl.manifest -> [Ver = | Size = 749 bytes | Created Date = 3/16/2008 2:32:57 AM | Attr = RH ] SFMS32.DLL -> %SystemRoot%\System32\SFMS32.DLL -> Creative Technology Ltd [Ver = 5.12.01.0140-0.75.1490 (beta-release) | Size = 270336 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] spxcoins.dll -> %SystemRoot%\System32\spxcoins.dll -> Perle Systems Ltd. [Ver = 1.0.0.0007 | Size = 24661 bytes | Created Date = 3/16/2008 2:19:11 AM | Attr = ] streamio.dll -> %SystemRoot%\System32\streamio.dll -> dicas digital image coding GmbH [Ver = 1,4,0,1 | Size = 57344 bytes | Created Date = 4/12/2008 7:53:00 AM | Attr = ] Taskill.exe -> %SystemRoot%\System32\Taskill.exe -> [Ver = | Size = 6656 bytes | Created Date = 2/2/2008 5:53:24 PM | Attr = ] wuaucpl.cpl.manifest -> %SystemRoot%\System32\wuaucpl.cpl.manifest -> [Ver = | Size = 749 bytes | Created Date = 3/16/2008 2:32:57 AM | Attr = RH ] xvidcore.dll -> %SystemRoot%\System32\xvidcore.dll -> [Ver = | Size = 761856 bytes | Created Date = 4/11/2008 5:03:52 PM | Attr = ] xvidvfw.dll -> %SystemRoot%\System32\xvidvfw.dll -> [Ver = | Size = 135168 bytes | Created Date = 4/11/2008 5:03:52 PM | Attr = ] Crash Damage 2005 -> %SystemRoot%\Crash Damage 2005 -> [Folder | Created Date = 2/11/2008 7:29:22 AM | Attr = ] 9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> crash.ini -> %SystemRoot%\crash.ini -> [Ver = | Size = 49 bytes | Created Date = 2/9/2008 11:25:18 AM | Attr = ] CTDCRES.DLL -> %SystemRoot%\CTDCRES.DLL -> Creative Technology Ltd [Ver = 1, 0, 0, 1 | Size = 49152 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] CTDV10K1.CDF -> %SystemRoot%\CTDV10K1.CDF -> [Ver = | Size = 3373917 bytes | Created Date = 3/17/2008 7:40:31 AM | Attr = ] DEVREG.DLL -> %SystemRoot%\DEVREG.DLL -> Creative Technology Ltd [Ver = 1.00.00.0018-1.00.0180 | Size = 94208 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] ERDNT -> %SystemRoot%\ERDNT -> [Folder | Created Date = 4/13/2008 1:16:46 PM | Attr = ] fdsv.exe -> %SystemRoot%\fdsv.exe -> Smallfrogs Studio [Ver = 1.0.0.10 | Size = 73728 bytes | Created Date = 4/13/2008 7:09:22 PM | Attr = ] grep.exe -> %SystemRoot%\grep.exe -> [Ver = | Size = 80412 bytes | Created Date = 4/13/2008 7:09:22 PM | Attr = ] iun6002.exe -> %SystemRoot%\iun6002.exe -> Indigo Rose Corporation [Ver = 6.0.0.3 | Size = 720896 bytes | Created Date = 2/9/2008 11:24:11 AM | Attr = ] MIDIDEF.EXE -> %SystemRoot%\MIDIDEF.EXE -> Creative Technology Ltd [Ver = 2, 8, 2, 0 | Size = 61440 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] Nircmd.exe -> %SystemRoot%\Nircmd.exe -> NirSoft [Ver = 2.05 | Size = 28160 bytes | Created Date = 4/13/2008 7:09:22 PM | Attr = ] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Created Date = 3/16/2008 2:45:50 AM | Attr = ] privacy_danger -> %SystemRoot%\privacy_danger -> [Folder | Created Date = 4/12/2008 4:11:19 PM | Attr = ] PSCONV.EXE -> %SystemRoot%\PSCONV.EXE -> [Ver = | Size = 184320 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Created Date = 4/9/2008 7:23:11 AM | Attr = ] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Created Date = 4/9/2008 7:23:11 AM | Attr = H ] READREG.EXE -> %SystemRoot%\READREG.EXE -> Creative Technology Limited [Ver = 1, 5, 0, 9 | Size = 176128 bytes | Created Date = 3/17/2008 7:40:32 AM | Attr = ] sed.exe -> %SystemRoot%\sed.exe -> [Ver = | Size = 98816 bytes | Created Date = 4/13/2008 7:09:22 PM | Attr = ] SWFConverter.INI -> %SystemRoot%\SWFConverter.INI -> [Ver = | Size = 37 bytes | Created Date = 4/11/2008 5:03:58 PM | Attr = ] swreg.exe -> %SystemRoot%\swreg.exe -> SteelWerX [Ver = 3.0.0.0 | Size = 161792 bytes | Created Date = 4/13/2008 7:09:22 PM | Attr = ] swsc.exe -> %SystemRoot%\swsc.exe -> SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Created Date = 4/13/2008 7:09:22 PM | Attr = ] swxcacls.exe -> %SystemRoot%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 4/13/2008 7:09:22 PM | Attr = ] TSearch.INI -> %SystemRoot%\TSearch.INI -> [Ver = | Size = 1816 bytes | Created Date = 3/26/2008 6:00:04 PM | Attr = ] VFind.exe -> %SystemRoot%\VFind.exe -> [Ver = | Size = 49152 bytes | Created Date = 4/13/2008 7:09:22 PM | Attr = ] WindowsShell.Manifest -> %SystemRoot%\WindowsShell.Manifest -> [Ver = | Size = 749 bytes | Created Date = 3/16/2008 2:32:57 AM | Attr = RH ] zip.exe -> %SystemRoot%\zip.exe -> [Ver = | Size = 68096 bytes | Created Date = 4/13/2008 7:09:22 PM | Attr = ] {00000004-00000000-00000008-00001102-00000002-80641102}.BAK -> %SystemRoot%\{00000004-00000000-00000008-00001102-00000002-80641102}.BAK -> [Ver = | Size = 3376060 bytes | Created Date = 3/17/2008 3:51:29 PM | Attr = ] {00000004-00000000-00000008-00001102-00000002-80641102}.CDF -> %SystemRoot%\{00000004-00000000-00000008-00001102-00000002-80641102}.CDF -> [Ver = | Size = 3376060 bytes | Created Date = 3/17/2008 3:51:28 PM | Attr = ] ?????????????????????????????????i -> %SystemRoot%\㩃䑜捯浵湥獴愠摮匠瑥楴杮屳汆牯湩䅜灰楬慣楴湯䐠瑡屡楗慮灭坜湩浡⹰湩i -> [Ver = | Size = 145 bytes | Modified Date = 3/26/2008 8:17:31 AM | Attr = ] ????????????????? -> %SystemRoot%\㩃停潲牧浡䘠汩獥坜湩浡屰楗慮灭椮楮 -> [Ver = | Size = 145 bytes | Modified Date = 12/20/2007 12:10:28 AM | Attr = ] [Files Created - Additional Folder Scans - Non-Microsoft Only] Ahead -> %AllUsersProfile%\Application Data\Ahead -> [Folder | Created Date = 3/15/2008 8:40:34 PM | Attr = ] Avg7 -> %AllUsersProfile%\Application Data\Avg7 -> [Folder | Created Date = 3/16/2008 3:04:34 AM | Attr = ] Intuit Canada -> %AllUsersProfile%\Application Data\Intuit Canada -> [Folder | Created Date = 3/9/2008 8:28:45 PM | Attr = ] Nero -> %AllUsersProfile%\Application Data\Nero -> [Folder | Created Date = 3/15/2008 8:37:42 PM | Attr = ] noteborq -> %AllUsersProfile%\Application Data\noteborq -> [Folder | Created Date = 4/11/2008 4:49:13 PM | Attr = ] Subliminal Flash -> %AllUsersProfile%\Application Data\Subliminal Flash -> [Folder | Created Date = 3/16/2008 1:42:05 AM | Attr = ] Symantec -> %AllUsersProfile%\Application Data\Symantec -> [Folder | Created Date = 3/16/2008 3:11:19 AM | Attr = ] WLInstaller -> %AllUsersProfile%\Application Data\WLInstaller -> [Folder | Created Date = 4/8/2008 5:50:55 PM | Attr = ] Ahead -> %AppData%\Ahead -> [Folder | Created Date = 4/12/2008 8:05:33 AM | Attr = ] com.kennettnet.MusicRescue.plist -> %AppData%\com.kennettnet.MusicRescue.plist -> [Ver = | Size = 3232 bytes | Created Date = 1/18/2008 5:14:48 PM | Attr = ] com.kennettnet.MusicRescueProfiles.plist -> %AppData%\com.kennettnet.MusicRescueProfiles.plist -> [Ver = | Size = 194066 bytes | Created Date = 1/18/2008 5:14:47 PM | Attr = ] CopyTrans -> %AppData%\CopyTrans -> [Folder | Created Date = 2/28/2008 5:49:30 PM | Attr = ] Eltima Software -> %AppData%\Eltima Software -> [Folder | Created Date = 4/11/2008 4:32:40 PM | Attr = ] Moyea -> %AppData%\Moyea -> [Folder | Created Date = 4/11/2008 4:37:48 PM | Attr = ] TmpRecentIcons -> %AppData%\TmpRecentIcons -> [Folder | Created Date = 4/11/2008 6:36:00 PM | Attr = ] Winamp -> %AppData%\Winamp -> [Folder | Created Date = 3/25/2008 9:02:57 AM | Attr = ] IsolatedStorage -> %UserProfile%\Local Settings\Application Data\IsolatedStorage -> [Folder | Created Date = 4/11/2008 4:56:14 PM | Attr = ] Sony Ericsson -> %UserProfile%\Local Settings\Application Data\Sony Ericsson -> [Folder | Created Date = 2/10/2008 5:50:24 PM | Attr = ] Steam -> %UserProfile%\Local Settings\Application Data\Steam -> [Folder | Created Date = 1/31/2008 9:40:07 PM | Attr = ] Symantec -> %UserProfile%\Local Settings\Application Data\Symantec -> [Folder | Created Date = 3/16/2008 11:50:21 PM | Attr = ] aaa1.mp3 -> %UserProfile%\My Documents\aaa1.mp3 -> [Ver = | Size = 415868 bytes | Created Date = 2/20/2008 8:29:22 PM | Attr = ] Adobe -> %UserProfile%\My Documents\Adobe -> [Folder | Created Date = 3/21/2008 2:50:46 PM | Attr = ] antro -> %UserProfile%\My Documents\antro -> [Folder | Created Date = 3/6/2008 10:11:42 AM | Attr = ] Cambrian 543 mya.doc -> %UserProfile%\My Documents\Cambrian 543 mya.doc -> [Ver = | Size = 26112 bytes | Created Date = 3/5/2008 8:28:25 PM | Attr = ] clip0001.avi -> %UserProfile%\My Documents\clip0001.avi -> [Ver = | Size = 24636936 bytes | Created Date = 2/16/2008 4:58:06 PM | Attr = ] clip0002.avi -> %UserProfile%\My Documents\clip0002.avi -> [Ver = | Size = 9002 bytes | Created Date = 3/6/2008 5:37:08 PM | Attr = ] clip0003.avi -> %UserProfile%\My Documents\clip0003.avi -> [Ver = | Size = 33256742 bytes | Created Date = 3/6/2008 5:37:50 PM | Attr = ] clip0004.avi -> %UserProfile%\My Documents\clip0004.avi -> [Ver = | Size = 16145080 bytes | Created Date = 3/6/2008 5:41:38 PM | Attr = ] clip0005.avi -> %UserProfile%\My Documents\clip0005.avi -> [Ver = | Size = 6341048 bytes | Created Date = 3/6/2008 5:43:41 PM | Attr = ] clip0006.avi -> %UserProfile%\My Documents\clip0006.avi -> [Ver = | Size = 38453032 bytes | Created Date = 3/6/2008 5:45:43 PM | Attr = ] clip0007.avi -> %UserProfile%\My Documents\clip0007.avi -> [Ver = | Size = 4923812 bytes | Created Date = 3/6/2008 5:53:39 PM | Attr = ] NeroVision -> %UserProfile%\My Documents\NeroVision -> [Folder | Created Date = 4/12/2008 8:05:33 AM | Attr = ] QuickTime Player.lnk -> %AllUsersProfile%\Desktop\QuickTime Player.lnk -> [Ver = | Size = 1604 bytes | Created Date = 4/9/2008 3:52:46 PM | Attr = ] Windows Live Messenger .lnk -> %AllUsersProfile%\Desktop\Windows Live Messenger .lnk -> [Ver = | Size = 1827 bytes | Created Date = 4/8/2008 5:51:59 PM | Attr = ] Antro rough work.zip -> %UserProfile%\Desktop\Antro rough work.zip -> [Ver = | Size = 700514 bytes | Created Date = 4/4/2008 8:57:25 AM | Attr = ] appleipod.bat -> %UserProfile%\Desktop\appleipod.bat -> [Ver = | Size = 246 bytes | Created Date = 4/9/2008 4:23:43 PM | Attr = ] backups -> %UserProfile%\Desktop\backups -> [Folder | Created Date = 4/13/2008 1:12:52 PM | Attr = ] ComboFix.exe -> %UserProfile%\Desktop\ComboFix.exe -> [Ver = | Size = 1698889 bytes | Created Date = 4/13/2008 7:05:50 PM | Attr = ] Counter Strike 1.6 Non Steam.lnk -> %UserProfile%\Desktop\Counter Strike 1.6 Non Steam.lnk -> [Ver = | Size = 749 bytes | Created Date = 4/12/2008 9:27:53 AM | Attr = ] ddd -> %UserProfile%\Desktop\ddd -> [Folder | Created Date = 4/11/2008 4:48:47 PM | Attr = ] dss.exe -> %UserProfile%\Desktop\dss.exe -> [Ver = 3, 2, 8, 1 | Size = 686630 bytes | Created Date = 4/13/2008 1:15:49 PM | Attr = ] erunt-setup.exe -> %UserProfile%\Desktop\erunt-setup.exe -> Lars Hederer [Ver = | Size = 791393 bytes | Created Date = 4/13/2008 6:56:49 PM | Attr = ] ERUNT.lnk -> %UserProfile%\Desktop\ERUNT.lnk -> [Ver = | Size = 592 bytes | Created Date = 4/13/2008 6:57:21 PM | Attr = ] fix.reg -> %UserProfile%\Desktop\fix.reg -> [Ver = | Size = 127 bytes | Created Date = 4/13/2008 6:59:22 PM | Attr = ] Florin.exe -> %UserProfile%\Desktop\Florin.exe -> Trend Micro Inc. [Ver = 2.00.0002 | Size = 401720 bytes | Created Date = 4/13/2008 1:31:43 PM | Attr = ] gfpro.exe -> %UserProfile%\Desktop\gfpro.exe -> GetFLV, Inc. [Ver = | Size = 5476592 bytes | Created Date = 4/12/2008 7:55:19 AM | Attr = ] HiJackThis.exe -> %UserProfile%\Desktop\HiJackThis.exe -> Trend Micro Inc. [Ver = 2.00.0002 | Size = 401720 bytes | Created Date = 4/12/2008 11:57:42 PM | Attr = ] install_asm_en.exe -> %UserProfile%\Desktop\install_asm_en.exe -> Locussoftcorp LTD [Ver = 1.0.8.0 | Size = 462616 bytes | Created Date = 4/11/2008 6:38:54 PM | Attr = ] Lab chem.docx -> %UserProfile%\Desktop\Lab chem.docx -> [Ver = | Size = 12576 bytes | Created Date = 4/10/2008 3:36:31 PM | Attr = ] New Microsoft Word Document.doc -> %UserProfile%\Desktop\New Microsoft Word Document.doc -> [Ver = | Size = 27648 bytes | Created Date = 4/3/2008 8:32:41 PM | Attr = ] New Microsoft Word Document1.doc -> %UserProfile%\Desktop\New Microsoft Word Document1.doc -> [Ver = | Size = 37376 bytes | Created Date = 4/13/2008 6:37:31 PM | Attr = ] NoLop.exe -> %UserProfile%\Desktop\NoLop.exe -> PunkTools [Ver = 3.00.0052 | Size = 40448 bytes | Created Date = 4/13/2008 6:36:29 PM | Attr = ] Other -> %UserProfile%\Desktop\Other -> [Folder | Created Date = 4/1/2008 8:48:05 PM | Attr = ] OTMoveIt2.exe -> %UserProfile%\Desktop\OTMoveIt2.exe -> OldTimer Tools [Ver = 1.0.4.1 | Size = 291840 bytes | Created Date = 4/13/2008 1:13:53 PM | Attr = ] OTscan it -> %UserProfile%\Desktop\OTscan it -> [Folder | Created Date = 4/15/2008 3:57:42 PM | Attr = ] OTScanIt.exe -> %UserProfile%\Desktop\OTScanIt.exe -> [Ver = | Size = 540250 bytes | Created Date = 4/15/2008 3:57:12 PM | Attr = ] swf_video_converter.exe -> %UserProfile%\Desktop\swf_video_converter.exe -> Eltima Software [Ver = 3.0.20.77 | Size = 4583830 bytes | Created Date = 4/12/2008 7:52:14 AM | Attr = ] untitled.bmp -> %UserProfile%\Desktop\untitled.bmp -> [Ver = | Size = 5292054 bytes | Created Date = 4/7/2008 4:30:51 PM | Attr = ] untitled.flp -> %UserProfile%\Desktop\untitled.flp -> [Ver = | Size = 126704 bytes | Created Date = 4/14/2008 4:30:52 PM | Attr = ] Wallpapes -> %UserProfile%\Desktop\Wallpapes -> [Folder | Created Date = 4/1/2008 9:01:08 PM | Attr = ] ERUNT AutoBackup.lnk -> %UserProfile%\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk -> [Ver = | Size = 767 bytes | Created Date = 4/13/2008 6:57:30 PM | Attr = ] Last.fm Helper.lnk -> %UserProfile%\Start Menu\Programs\Startup\Last.fm Helper.lnk -> [Ver = | Size = 655 bytes | Created Date = 2/5/2008 8:22:53 AM | Attr = ] Ahead -> %CommonProgramFiles%\Ahead -> [Folder | Created Date = 3/15/2008 8:37:40 PM | Attr = ] Scanner -> %CommonProgramFiles%\Scanner -> [Folder | Created Date = 3/31/2008 5:47:52 PM | Attr = ] Symantec Shared -> %CommonProgramFiles%\Symantec Shared -> [Folder | Created Date = 3/16/2008 3:11:20 AM | Attr = ] Thraex Software -> %CommonProgramFiles%\Thraex Software -> [Folder | Created Date = 1/31/2008 9:42:02 PM | Attr = ] WindowsLiveInstaller -> %CommonProgramFiles%\WindowsLiveInstaller -> [Folder | Created Date = 4/8/2008 5:51:17 PM | Attr = HS] [Files/Folders - Modified Within 90 days] ads_err.dbf -> %SystemDrive%\ads_err.dbf -> [Ver = | Size = 2467 bytes | Modified Date = 2/2/2008 5:47:46 PM | Attr = ] AROTrial.exe -> %SystemDrive%\AROTrial.exe -> Sammsoft [Ver = Advanced Registry Op | Size = 2218368 bytes | Modified Date = 4/13/2008 9:32:33 AM | Attr = ] aswclear.exe -> %SystemDrive%\aswclear.exe -> Alwil Software [Ver = 1, 0, 0, 1 | Size = 230776 bytes | Modified Date = 4/13/2008 10:14:43 AM | Attr = ] boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 223 bytes | Modified Date = 4/12/2008 9:23:06 AM | Attr = HS] ComboFix -> %SystemDrive%\ComboFix -> [Folder | Modified Date = 4/15/2008 3:56:19 PM | Attr = ] Deckard -> %SystemDrive%\Deckard -> [Folder | Modified Date = 4/13/2008 1:16:15 PM | Attr = ] Documents and Settings -> %SystemDrive%\Documents and Settings -> [Folder | Modified Date = 2/17/2008 4:22:09 PM | Attr = ] Downloads -> %SystemDrive%\Downloads -> [Folder | Modified Date = 4/13/2008 12:52:41 PM | Attr = ] NoLopBackups -> %SystemDrive%\NoLopBackups -> [Folder | Modified Date = 4/13/2008 6:44:44 PM | Attr = ] PacSteam -> %SystemDrive%\PacSteam -> [Folder | Modified Date = 4/9/2008 4:08:47 PM | Attr = ] PacSteamT -> %SystemDrive%\PacSteamT -> [Folder | Modified Date = 1/31/2008 9:45:06 PM | Attr = ] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 4/13/2008 7:00:41 PM | Attr = ] QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 4/15/2008 3:56:16 PM | Attr = ] sqmdata00.sqm -> %SystemDrive%\sqmdata00.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/31/2008 9:43:46 AM | Attr = H ] sqmdata01.sqm -> %SystemDrive%\sqmdata01.sqm -> [Ver = | Size = 268 bytes | Modified Date = 4/1/2008 7:14:25 PM | Attr = H ] sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [Ver = | Size = 268 bytes | Modified Date = 4/4/2008 4:41:53 PM | Attr = H ] sqmdata04.sqm -> %SystemDrive%\sqmdata04.sqm -> [Ver = | Size = 268 bytes | Modified Date = 4/4/2008 9:53:56 PM | Attr = H ] sqmdata05.sqm -> %SystemDrive%\sqmdata05.sqm -> [Ver = | Size = 268 bytes | Modified Date = 4/5/2008 11:30:59 AM | Attr = H ] sqmdata06.sqm -> %SystemDrive%\sqmdata06.sqm -> [Ver = | Size = 268 bytes | Modified Date = 4/5/2008 6:24:44 PM | Attr = H ] sqmdata07.sqm -> %SystemDrive%\sqmdata07.sqm -> [Ver = | Size = 268 bytes | Modified Date = 4/7/2008 9:50:33 PM | Attr = H ] sqmdata08.sqm -> %SystemDrive%\sqmdata08.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/20/2008 6:02:29 PM | Attr = H ] sqmdata09.sqm -> %SystemDrive%\sqmdata09.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/21/2008 12:56:08 PM | Attr = H ] sqmdata10.sqm -> %SystemDrive%\sqmdata10.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/22/2008 1:41:50 PM | Attr = H ] sqmdata11.sqm -> %SystemDrive%\sqmdata11.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/22/2008 11:29:39 PM | Attr = H ] sqmdata12.sqm -> %SystemDrive%\sqmdata12.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/23/2008 12:27:51 PM | Attr = H ] sqmdata13.sqm -> %SystemDrive%\sqmdata13.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/24/2008 5:18:17 PM | Attr = H ] sqmdata14.sqm -> %SystemDrive%\sqmdata14.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/26/2008 6:01:57 PM | Attr = H ] sqmdata15.sqm -> %SystemDrive%\sqmdata15.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/26/2008 10:53:15 PM | Attr = H ] sqmdata16.sqm -> %SystemDrive%\sqmdata16.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/30/2008 11:40:42 AM | Attr = H ] sqmdata17.sqm -> %SystemDrive%\sqmdata17.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/30/2008 1:57:07 PM | Attr = H ] sqmdata18.sqm -> %SystemDrive%\sqmdata18.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/30/2008 7:44:05 PM | Attr = H ] sqmdata19.sqm -> %SystemDrive%\sqmdata19.sqm -> [Ver = | Size = 268 bytes | Modified Date = 3/30/2008 10:29:39 PM | Attr = H ] sqmnoopt00.sqm -> %SystemDrive%\sqmnoopt00.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/31/2008 9:43:46 AM | Attr = H ] sqmnoopt01.sqm -> %SystemDrive%\sqmnoopt01.sqm -> [Ver = | Size = 244 bytes | Modified Date = 4/1/2008 7:14:25 PM | Attr = H ] sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [Ver = | Size = 244 bytes | Modified Date = 4/4/2008 4:41:53 PM | Attr = H ] sqmnoopt04.sqm -> %SystemDrive%\sqmnoopt04.sqm -> [Ver = | Size = 244 bytes | Modified Date = 4/4/2008 9:53:56 PM | Attr = H ] sqmnoopt05.sqm -> %SystemDrive%\sqmnoopt05.sqm -> [Ver = | Size = 244 bytes | Modified Date = 4/5/2008 11:30:59 AM | Attr = H ] sqmnoopt06.sqm -> %SystemDrive%\sqmnoopt06.sqm -> [Ver = | Size = 244 bytes | Modified Date = 4/5/2008 6:24:44 PM | Attr = H ] sqmnoopt07.sqm -> %SystemDrive%\sqmnoopt07.sqm -> [Ver = | Size = 244 bytes | Modified Date = 4/7/2008 9:50:33 PM | Attr = H ] sqmnoopt08.sqm -> %SystemDrive%\sqmnoopt08.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/20/2008 6:02:29 PM | Attr = H ] sqmnoopt09.sqm -> %SystemDrive%\sqmnoopt09.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/21/2008 12:56:08 PM | Attr = H ] sqmnoopt10.sqm -> %SystemDrive%\sqmnoopt10.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/22/2008 1:41:50 PM | Attr = H ] sqmnoopt11.sqm -> %SystemDrive%\sqmnoopt11.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/22/2008 11:29:39 PM | Attr = H ] sqmnoopt12.sqm -> %SystemDrive%\sqmnoopt12.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/23/2008 12:27:51 PM | Attr = H ] sqmnoopt13.sqm -> %SystemDrive%\sqmnoopt13.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/24/2008 5:18:17 PM | Attr = H ] sqmnoopt14.sqm -> %SystemDrive%\sqmnoopt14.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/26/2008 6:01:57 PM | Attr = H ] sqmnoopt15.sqm -> %SystemDrive%\sqmnoopt15.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/26/2008 10:53:15 PM | Attr = H ] sqmnoopt16.sqm -> %SystemDrive%\sqmnoopt16.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/30/2008 11:40:42 AM | Attr = H ] sqmnoopt17.sqm -> %SystemDrive%\sqmnoopt17.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/30/2008 1:57:07 PM | Attr = H ] sqmnoopt18.sqm -> %SystemDrive%\sqmnoopt18.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/30/2008 7:44:05 PM | Attr = H ] sqmnoopt19.sqm -> %SystemDrive%\sqmnoopt19.sqm -> [Ver = | Size = 244 bytes | Modified Date = 3/30/2008 10:29:39 PM | Attr = H ] System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 4/13/2008 1:16:37 PM | Attr = HS] Temp -> %SystemDrive%\Temp -> [Folder | Modified Date = 4/11/2008 4:57:03 PM | Attr = ] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 4/15/2008 3:56:17 PM | Attr = ] _OTMoveIt -> %SystemDrive%\_OTMoveIt -> [Folder | Modified Date = 4/13/2008 1:14:52 PM | Attr = ] etc -> %SystemRoot%\System32\drivers\etc -> [Folder | Modified Date = 4/15/2008 3:47:03 PM | Attr = ] hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [Ver = | Size = 27 bytes | Modified Date = 4/15/2008 3:47:03 PM | Attr = ] GEARAspiWDM.sys -> %SystemRoot%\System32\drivers\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.00.07.03 | Size = 16168 bytes | Modified Date = 1/29/2008 12:01:28 PM | Attr = ] SYMEVENT.CAT -> %SystemRoot%\System32\drivers\SYMEVENT.CAT -> [Ver = | Size = 10652 bytes | Modified Date = 3/16/2008 3:15:12 AM | Attr = ] SYMEVENT.INF -> %SystemRoot%\System32\drivers\SYMEVENT.INF -> [Ver = | Size = 806 bytes | Modified Date = 3/16/2008 3:15:12 AM | Attr = ] SYMEVENT.SYS -> %SystemRoot%\System32\drivers\SYMEVENT.SYS -> Symantec Corporation [Ver = 12.4.0.24 | Size = 136496 bytes | Modified Date = 3/16/2008 3:15:12 AM | Attr = ] UMDF -> %SystemRoot%\System32\drivers\UMDF -> [Folder | Modified Date = 3/6/2008 9:53:11 AM | Attr = ] Msft_User_WpdMtpDr_01_00_00.Wdf -> %SystemRoot%\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf -> [Ver = | Size = 0 bytes | Modified Date = 3/6/2008 9:53:11 AM | Attr = H ] WpsHelper.sys -> %SystemRoot%\System32\drivers\WpsHelper.sys -> Symantec Corporation [Ver = 11.0.717.804 | Size = 50536 bytes | Modified Date = 3/25/2008 4:15:22 PM | Attr = ] $winnt$.inf -> %SystemRoot%\System32\$winnt$.inf -> [Ver = | Size = 288 bytes | Modified Date = 3/16/2008 2:41:22 AM | Attr = ] 1033 -> %SystemRoot%\System32\1033 -> [Folder | Modified Date = 3/15/2008 10:08:25 PM | Attr = ] 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> amcompat.tlb -> %SystemRoot%\System32\amcompat.tlb -> [Ver = | Size = 16832 bytes | Modified Date = 3/16/2008 2:34:07 AM | Attr = ] BMXBkpCtrlState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> %SystemRoot%\System32\BMXBkpCtrlState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> [Ver = | Size = 29808 bytes | Modified Date = 4/15/2008 3:45:40 PM | Attr = ] BMXCtrlState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> %SystemRoot%\System32\BMXCtrlState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> [Ver = | Size = 29808 bytes | Modified Date = 4/15/2008 3:45:40 PM | Attr = ] BMXState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> %SystemRoot%\System32\BMXState-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> [Ver = | Size = 17500 bytes | Modified Date = 4/15/2008 3:45:40 PM | Attr = ] BMXStateBkp-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> %SystemRoot%\System32\BMXStateBkp-{00000004-00000000-00000008-00001102-00000002-80641102}.rfx -> [Ver = | Size = 17500 bytes | Modified Date = 4/15/2008 3:45:40 PM | Attr = ] CatRoot -> %SystemRoot%\System32\CatRoot -> [Folder | Modified Date = 4/9/2008 4:32:23 PM | Attr = ] CatRoot2 -> %SystemRoot%\System32\CatRoot2 -> [Folder | Modified Date = 4/15/2008 3:54:59 PM | Attr = ] cdplayer.exe.manifest -> %SystemRoot%\System32\cdplayer.exe.manifest -> [Ver = | Size = 749 bytes | Modified Date = 3/16/2008 2:32:57 AM | Attr = RH ] CmdLineExt03.dll -> %SystemRoot%\System32\CmdLineExt03.dll -> [Ver = | Size = 43520 bytes | Modified Date = 4/12/2008 9:26:54 AM | Attr = ] Com -> %SystemRoot%\System32\Com -> [Folder | Modified Date = 3/17/2008 12:53:56 AM | Attr = ] config -> %SystemRoot%\System32\config -> [Folder | Modified Date = 4/15/2008 3:45:02 PM | Attr = ] CONFIG.NT -> %SystemRoot%\System32\CONFIG.NT -> [Ver = | Size = 2577 bytes | Modified Date = 4/13/2008 1:26:09 PM | Attr = ] Defaults -> %SystemRoot%\System32\Defaults -> [Folder | Modified Date = 3/17/2008 7:41:02 AM | Attr = ] dllcache -> %SystemRoot%\System32\dllcache -> [Folder | Modified Date = 3/17/2008 7:41:03 AM | Attr = RHS] drivers -> %SystemRoot%\System32\drivers -> [Folder | Modified Date = 4/15/2008 3:56:17 PM | Attr = ] DRVSTORE -> %SystemRoot%\System32\DRVSTORE -> [Folder | Modified Date = 4/8/2008 5:52:02 PM | Attr = ] DVCState-{00000004-00000000-00000008-00001102-00000002-80641102}.dat -> %SystemRoot%\System32\DVCState-{00000004-00000000-00000008-00001102-00000002-80641102}.dat -> [Ver = | Size = 24 bytes | Modified Date = 4/15/2008 3:45:40 PM | Attr = ] DVCStateBkp-{00000004-00000000-00000008-00001102-00000002-80641102}.dat -> %SystemRoot%\System32\DVCStateBkp-{00000004-00000000-00000008-00001102-00000002-80641102}.dat -> [Ver = | Size = 24 bytes | Modified Date = 4/15/2008 3:45:40 PM | Attr = ] emptyregdb.dat -> %SystemRoot%\System32\emptyregdb.dat -> [Ver = | Size = 23348 bytes | Modified Date = 3/16/2008 2:31:50 AM | Attr = ] GEARAspi.dll -> %SystemRoot%\System32\GEARAspi.dll -> GEAR Software Inc. [Ver = 2.1.1.1 | Size = 107368 bytes | Modified Date = 1/29/2008 12:02:30 PM | Attr = ] ias -> %SystemRoot%\System32\ias -> [Folder | Modified Date = 3/16/2008 2:33:33 AM | Attr = ] icsxml -> %SystemRoot%\System32\icsxml -> [Folder | Modified Date = 3/15/2008 10:08:54 PM | Attr = ] logonui.exe.manifest -> %SystemRoot%\System32\logonui.exe.manifest -> [Ver = | Size = 488 bytes | Modified Date = 3/16/2008 2:33:03 AM | Attr = RH ] ncpa.cpl.manifest -> %SystemRoot%\System32\ncpa.cpl.manifest -> [Ver = | Size = 749 bytes | Modified Date = 3/16/2008 2:32:57 AM | Attr = RH ] npp -> %SystemRoot%\System32\npp -> [Folder | Modified Date = 3/15/2008 10:12:38 PM | Attr = ] nscompat.tlb -> %SystemRoot%\System32\nscompat.tlb -> [Ver = | Size = 23392 bytes | Modified Date = 3/16/2008 2:34:06 AM | Attr = ] nwc.cpl.manifest -> %SystemRoot%\System32\nwc.cpl.manifest -> [Ver = | Size = 749 bytes | Modified Date = 3/16/2008 2:32:57 AM | Attr = RH ] oobe -> %SystemRoot%\System32\oobe -> [Folder | Modified Date = 3/16/2008 2:32:42 AM | Attr = ] perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [Ver = | Size = 96858 bytes | Modified Date = 4/6/2008 8:54:00 AM | Attr = ] perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [Ver = | Size = 504414 bytes | Modified Date = 4/6/2008 8:54:00 AM | Attr = ] PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [Ver = | Size = 612944 bytes | Modified Date = 4/6/2008 8:54:00 AM | Attr = ] QuickTime.qts -> %SystemRoot%\System32\QuickTime.qts -> Apple Inc. [Ver = 7.4.5 | Size = 57344 bytes | Modified Date = 3/28/2008 11:37:26 PM | Attr = ] QuickTimeVR.qtx -> %SystemRoot%\System32\QuickTimeVR.qtx -> Apple Inc. [Ver = 7.4.5 | Size = 90112 bytes | Modified Date = 3/28/2008 11:37:26 PM | Attr = ] ReinstallBackups -> %SystemRoot%\System32\ReinstallBackups -> [Folder | Modified Date = 3/17/2008 7:40:57 AM | Attr = ] Restore -> %SystemRoot%\System32\Restore -> [Folder | Modified Date = 4/13/2008 1:16:37 PM | Attr = ] S32EVNT1.DLL -> %SystemRoot%\System32\S32EVNT1.DLL -> Symantec Corporation [Ver = 12.4.0.25 | Size = 60808 bytes | Modified Date = 3/16/2008 3:15:12 AM | Attr = ] sapi.cpl.manifest -> %SystemRoot%\System32\sapi.cpl.manifest -> [Ver = | Size = 749 bytes | Modified Date = 3/16/2008 2:32:57 AM | Attr = RH ] settings.sfm -> %SystemRoot%\System32\settings.sfm -> [Ver = | Size = 1072 bytes | Modified Date = 4/15/2008 3:45:40 PM | Attr = ] settingsbkup.sfm -> %SystemRoot%\System32\settingsbkup.sfm -> [Ver = | Size = 1072 bytes | Modified Date = 4/15/2008 3:45:40 PM | Attr = ] Setup -> %SystemRoot%\System32\Setup -> [Folder | Modified Date = 3/15/2008 10:13:23 PM | Attr = ] usmt -> %SystemRoot%\System32\usmt -> [Folder | Modified Date = 3/15/2008 10:13:15 PM | Attr = ] vsconfig.xml -> %SystemRoot%\System32\vsconfig.xml -> [Ver = | Size = 352218 bytes | Modified Date = 3/16/2008 3:00:25 AM | Attr = H ] wbem -> %SystemRoot%\System32\wbem -> [Folder | Modified Date = 3/16/2008 11:23:43 PM | Attr = ] WindowsLogon.manifest -> %SystemRoot%\System32\WindowsLogon.manifest -> [Ver = | Size = 488 bytes | Modified Date = 3/16/2008 2:33:03 AM | Attr = RH ] wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [Ver = | Size = 2228 bytes | Modified Date = 4/15/2008 3:47:26 PM | Attr = ] wuaucpl.cpl.manifest -> %SystemRoot%\System32\wuaucpl.cpl.manifest -> [Ver = | Size = 749 bytes | Modified Date = 3/16/2008 2:32:57 AM | Attr = RH ] zllictbl.dat -> %SystemRoot%\System32\zllictbl.dat -> [Ver = | Size = 4212 bytes | Modified Date = 3/12/2008 3:59:56 PM | Attr = H ] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 4/9/2008 11:47:23 AM | Attr = H ] 9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> $MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Modified Date = 3/16/2008 3:09:47 AM | Attr = H ] .agf377_file_store_32 -> %SystemRoot%\.agf377_file_store_32 -> [Folder | Modified Date = 3/21/2008 12:12:57 AM | Attr = ] .jagex_cache_32 -> %SystemRoot%\.jagex_cache_32 -> [Folder | Modified Date = 4/6/2008 5:34:23 PM | Attr = ] .silabclient_store_32 -> %SystemRoot%\.silabclient_store_32 -> [Folder | Modified Date = 3/26/2008 5:29:09 PM | Attr = ] AppPatch -> %SystemRoot%\AppPatch -> [Folder | Modified Date = 3/15/2008 10:13:08 PM | Attr = ] bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 4/15/2008 3:46:26 PM | Attr = S] Crash Damage 2005 -> %SystemRoot%\Crash Damage 2005 -> [Folder | Modified Date = 2/11/2008 7:29:22 AM | Attr = ] crash.ini -> %SystemRoot%\crash.ini -> [Ver = | Size = 49 bytes | Modified Date = 2/9/2008 11:25:18 AM | Attr = ] Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 4/13/2008 1:31:35 PM | Attr = S] Driver Cache -> %SystemRoot%\Driver Cache -> [Folder | Modified Date = 3/15/2008 10:07:32 PM | Attr = ] EHome -> %SystemRoot%\EHome -> [Folder | Modified Date = 3/15/2008 10:13:01 PM | Attr = ] ERDNT -> %SystemRoot%\ERDNT -> [Folder | Modified Date = 4/15/2008 3:44:50 PM | Attr = ] Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 3/28/2008 9:06:09 AM | Attr = R S] Help -> %SystemRoot%\Help -> [Folder | Modified Date = 3/16/2008 9:26:53 PM | Attr = ] ie7updates -> %SystemRoot%\ie7updates -> [Folder | Modified Date = 2/14/2008 12:27:08 AM | Attr = ] ime -> %SystemRoot%\ime -> [Folder | Modified Date = 3/15/2008 10:13:01 PM | Attr = ] imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 3/17/2008 12:58:18 AM | Attr = ] inf -> %SystemRoot%\inf -> [Folder | Modified Date = 4/15/2008 6:06:05 AM | Attr = H ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 4/11/2008 10:44:57 PM | Attr = HS] Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Modified Date = 3/16/2008 3:05:54 AM | Attr = ] iun6002.exe -> %SystemRoot%\iun6002.exe -> Indigo Rose Corporation [Ver = 6.0.0.3 | Size = 720896 bytes | Modified Date = 2/9/2008 11:21:40 AM | Attr = ] Media -> %SystemRoot%\Media -> [Folder | Modified Date = 3/17/2008 7:40:09 AM | Attr = ] msagent -> %SystemRoot%\msagent -> [Folder | Modified Date = 3/17/2008 5:12:42 AM | Attr = ] mui -> %SystemRoot%\mui -> [Folder | Modified Date = 3/15/2008 10:13:01 PM | Attr = ] NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [Ver = | Size = 116 bytes | Modified Date = 4/15/2008 8:53:00 AM | Attr = ] ODBCINST.INI -> %SystemRoot%\ODBCINST.INI -> [Ver = | Size = 4161 bytes | Modified Date = 3/16/2008 2:33:55 AM | Attr = ] peernet -> %SystemRoot%\peernet -> [Folder | Modified Date = 3/15/2008 10:12:49 PM | Attr = ] popcinfo.dat -> %SystemRoot%\popcinfo.dat -> [Ver = | Size = 89 bytes | Modified Date = 3/23/2008 6:58:58 PM | Attr = H ] popcinfot.dat -> %SystemRoot%\popcinfot.dat -> [Ver = | Size = 16 bytes | Modified Date = 3/22/2008 12:47:49 PM | Attr = ] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 4/15/2008 3:39:10 PM | Attr = ] privacy_danger -> %SystemRoot%\privacy_danger -> [Folder | Modified Date = 4/12/2008 4:11:19 PM | Attr = ] pss -> %SystemRoot%\pss -> [Folder | Modified Date = 3/16/2008 2:50:29 PM | Attr = ] QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 4/9/2008 7:23:11 AM | Attr = ] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 4/15/2008 3:49:31 PM | Attr = H ] Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 3/16/2008 2:48:26 AM | Attr = ] repair -> %SystemRoot%\repair -> [Folder | Modified Date = 3/16/2008 2:41:19 AM | Attr = ] security -> %SystemRoot%\security -> [Folder | Modified Date = 3/16/2008 3:04:57 AM | Attr = ] setupapi.old -> %SystemRoot%\setupapi.old -> [Ver = | Size = 443560 bytes | Modified Date = 3/15/2008 8:36:21 PM | Attr = ] SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Modified Date = 3/16/2008 9:26:53 PM | Attr = ] SWFConverter.INI -> %SystemRoot%\SWFConverter.INI -> [Ver = | Size = 37 bytes | Modified Date = 4/11/2008 5:03:58 PM | Attr = ] system -> %SystemRoot%\system -> [Folder | Modified Date = 3/16/2008 3:04:29 AM | Attr = ] system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 243 bytes | Modified Date = 4/15/2008 3:47:17 PM | Attr = ] system32 -> %SystemRoot%\system32 -> [Folder | Modified Date = 4/15/2008 3:56:19 PM | Attr = ] Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 4/13/2008 6:44:44 PM | Attr = S] Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 4/15/2008 3:56:17 PM | Attr = ] TSearch.INI -> %SystemRoot%\TSearch.INI -> [Ver = | Size = 1816 bytes | Modified Date = 3/26/2008 6:00:04 PM | Attr = ] twain_32 -> %SystemRoot%\twain_32 -> [Folder | Modified Date = 3/15/2008 10:09:44 PM | Attr = ] Web -> %SystemRoot%\Web -> [Folder | Modified Date = 3/16/2008 2:33:06 AM | Attr = R ] win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 1023 bytes | Modified Date = 4/12/2008 9:23:06 AM | Attr = ] WindowsShell.Manifest -> %SystemRoot%\WindowsShell.Manifest -> [Ver = | Size = 749 bytes | Modified Date = 3/16/2008 2:32:57 AM | Attr = RH ] WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx -> [Ver = | Size = 316640 bytes | Modified Date = 3/16/2008 2:34:08 AM | Attr = ] {00000004-00000000-00000008-00001102-00000002-80641102}.BAK -> %SystemRoot%\{00000004-00000000-00000008-00001102-00000002-80641102}.BAK -> [Ver = | Size = 3376060 bytes | Modified Date = 4/15/2008 3:48:21 PM | Attr = ] {00000004-00000000-00000008-00001102-00000002-80641102}.CDF -> %SystemRoot%\{00000004-00000000-00000008-00001102-00000002-80641102}.CDF -> [Ver = | Size = 3376060 bytes | Modified Date = 4/15/2008 3:48:21 PM | Attr = ] ?????????????????????????????????i -> %SystemRoot%\㩃䑜捯浵湥獴愠摮匠瑥楴杮屳汆牯湩䅜灰楬慣楴湯䐠瑡屡楗慮灭坜湩浡⹰湩i -> [Ver = | Size = 145 bytes | Modified Date = 3/26/2008 8:17:31 AM | Attr = ] ????????????????? -> %SystemRoot%\㩃停潲牧浡䘠汩獥坜湩浡屰楗慮灭椮楮 -> [Ver = | Size = 145 bytes | Modified Date = 12/20/2007 12:10:28 AM | Attr = ] AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [Ver = | Size = 284 bytes | Modified Date = 4/9/2008 8:47:01 AM | Attr = ] Check Updates for Windows Live Toolbar.job -> %SystemRoot%\tasks\Check Updates for Windows Live Toolbar.job -> [Ver = | Size = 256 bytes | Modified Date = 4/15/2008 3:47:17 PM | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 4/15/2008 3:46:32 PM | Attr = H ] Filelist00001.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00001.DAT -> [Ver = | Size = 2300 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00002.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00002.DAT -> [Ver = | Size = 1308 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00003.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00003.DAT -> [Ver = | Size = 5392 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00004.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00004.DAT -> [Ver = | Size = 19384 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00005.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00005.DAT -> [Ver = | Size = 9352 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00006.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00006.DAT -> [Ver = | Size = 10672 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00007.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00007.DAT -> [Ver = | Size = 12652 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00008.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00008.DAT -> [Ver = | Size = 9088 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00009.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00009.DAT -> [Ver = | Size = 8692 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00010.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00010.DAT -> [Ver = | Size = 7636 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00011.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00011.DAT -> [Ver = | Size = 6184 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00012.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00012.DAT -> [Ver = | Size = 23212 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00013.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00013.DAT -> [Ver = | Size = 11596 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00014.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00014.DAT -> [Ver = | Size = 8824 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00015.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00015.DAT -> [Ver = | Size = 11596 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00016.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00016.DAT -> [Ver = | Size = 9484 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00017.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00017.DAT -> [Ver = | Size = 8692 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00018.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00018.DAT -> [Ver = | Size = 4468 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00019.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00019.DAT -> [Ver = | Size = 8164 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00020.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00020.DAT -> [Ver = | Size = 27172 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00021.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00021.DAT -> [Ver = | Size = 31396 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00022.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00022.DAT -> [Ver = | Size = 13972 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00023.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00023.DAT -> [Ver = | Size = 9220 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00024.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00024.DAT -> [Ver = | Size = 9220 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00025.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00025.DAT -> [Ver = | Size = 8692 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00026.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00026.DAT -> [Ver = | Size = 3412 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00027.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00027.DAT -> [Ver = | Size = 10672 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00028.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00028.DAT -> [Ver = | Size = 22420 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00029.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00029.DAT -> [Ver = | Size = 24004 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00030.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00030.DAT -> [Ver = | Size = 25984 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00031.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00031.DAT -> [Ver = | Size = 22156 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00032.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00032.DAT -> [Ver = | Size = 18856 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00033.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00033.DAT -> [Ver = | Size = 12256 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00034.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00034.DAT -> [Ver = | Size = 6448 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00035.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00035.DAT -> [Ver = | Size = 5128 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00036.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00036.DAT -> [Ver = | Size = 13444 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00037.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00037.DAT -> [Ver = | Size = 9088 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00038.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00038.DAT -> [Ver = | Size = 11992 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00039.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00039.DAT -> [Ver = | Size = 26512 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00040.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00040.DAT -> [Ver = | Size = 16216 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00041.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00041.DAT -> [Ver = | Size = 9616 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00042.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00042.DAT -> [Ver = | Size = 6316 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00043.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00043.DAT -> [Ver = | Size = 6976 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00044.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00044.DAT -> [Ver = | Size = 16744 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00045.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00045.DAT -> [Ver = | Size = 18460 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00046.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00046.DAT -> [Ver = | Size = 18724 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00047.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00047.DAT -> [Ver = | Size = 9484 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00048.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00048.DAT -> [Ver = | Size = 8824 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00049.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00049.DAT -> [Ver = | Size = 8692 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00050.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00050.DAT -> [Ver = | Size = 3412 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00051.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00051.DAT -> [Ver = | Size = 9484 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00052.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00052.DAT -> [Ver = | Size = 31924 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00053.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00053.DAT -> [Ver = | Size = 27304 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00054.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00054.DAT -> [Ver = | Size = 24400 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00055.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00055.DAT -> [Ver = | Size = 23344 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00056.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00056.DAT -> [Ver = | Size = 15820 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00057.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00057.DAT -> [Ver = | Size = 8692 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00058.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00058.DAT -> [Ver = | Size = 2356 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00059.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00059.DAT -> [Ver = | Size = 8560 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00060.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00060.DAT -> [Ver = | Size = 25720 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00061.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00061.DAT -> [Ver = | Size = 30740 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00062.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00062.DAT -> [Ver = | Size = 23212 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00063.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00063.DAT -> [Ver = | Size = 22420 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00064.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00064.DAT -> [Ver = | Size = 11332 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00065.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00065.DAT -> [Ver = | Size = 8692 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00066.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00066.DAT -> [Ver = | Size = 904 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00067.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00067.DAT -> [Ver = | Size = 7636 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00068.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00068.DAT -> [Ver = | Size = 22288 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00069.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00069.DAT -> [Ver = | Size = 27964 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00070.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00070.DAT -> [Ver = | Size = 17272 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00071.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00071.DAT -> [Ver = | Size = 9748 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00072.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00072.DAT -> [Ver = | Size = 8824 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00073.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00073.DAT -> [Ver = | Size = 8692 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00074.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00074.DAT -> [Ver = | Size = 1432 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00075.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00075.DAT -> [Ver = | Size = 8956 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00076.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00076.DAT -> [Ver = | Size = 20044 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00077.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00077.DAT -> [Ver = | Size = 21364 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00078.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00078.DAT -> [Ver = | Size = 25456 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00079.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00079.DAT -> [Ver = | Size = 15952 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00080.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00080.DAT -> [Ver = | Size = 12520 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00081.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00081.DAT -> [Ver = | Size = 8692 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00082.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00082.DAT -> [Ver = | Size = 244 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00083.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00083.DAT -> [Ver = | Size = 6184 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00084.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00084.DAT -> [Ver = | Size = 17140 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00085.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00085.DAT -> [Ver = | Size = 22156 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00086.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00086.DAT -> [Ver = | Size = 15028 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00087.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00087.DAT -> [Ver = | Size = 25852 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00088.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00088.DAT -> [Ver = | Size = 22552 bytes | Modified Date = 8/13/2007 7:42:08 PM | Attr = ] Filelist00089.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00089.DAT -> [Ver = | Size = 8692 bytes | Modified Date = 8/13/2007 7:42:09 PM | Attr = ] Filelist00090.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00090.DAT -> [Ver = | Size = 508 bytes | Modified Date = 8/13/2007 7:42:09 PM | Attr = ] Filelist00091.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00091.DAT -> [Ver = | Size = 4600 bytes | Modified Date = 8/13/2007 7:42:09 PM | Attr = ] Filelist00092.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00092.DAT -> [Ver = | Size = 12784 bytes | Modified Date = 8/13/2007 7:42:09 PM | Attr = ] Filelist00093.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00093.DAT -> [Ver = | Size = 9220 bytes | Modified Date = 8/13/2007 7:42:10 PM | Attr = ] Filelist00094.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00094.DAT -> [Ver = | Size = 11596 bytes | Modified Date = 8/13/2007 7:42:10 PM | Attr = ] Filelist00095.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00095.DAT -> [Ver = | Size = 15424 bytes | Modified Date = 8/13/2007 7:42:11 PM | Attr = ] Filelist00096.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00096.DAT -> [Ver = | Size = 15160 bytes | Modified Date = 8/13/2007 7:42:11 PM | Attr = ] Filelist00097.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00097.DAT -> [Ver = | Size = 9880 bytes | Modified Date = 8/13/2007 7:42:12 PM | Attr = ] Filelist00098.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00098.DAT -> [Ver = | Size = 5392 bytes | Modified Date = 8/13/2007 7:42:12 PM | Attr = ] Filelist00099.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00099.DAT -> [Ver = | Size = 372 bytes | Modified Date = 8/13/2007 7:42:12 PM | Attr = ] Filelist00100.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00100.DAT -> [Ver = | Size = 2856 bytes | Modified Date = 8/13/2007 7:42:12 PM | Attr = ] Filelist00101.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00101.DAT -> [Ver = | Size = 904 bytes | Modified Date = 8/13/2007 7:42:12 PM | Attr = ] Filelist00102.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00102.DAT -> [Ver = | Size = 644 bytes | Modified Date = 8/13/2007 7:42:12 PM | Attr = ] Filelist00103.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00103.DAT -> [Ver = | Size = 4844 bytes | Modified Date = 8/13/2007 7:42:13 PM | Attr = ] Filelist00104.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00104.DAT -> [Ver = | Size = 2880 bytes | Modified Date = 8/13/2007 7:42:13 PM | Attr = ] Filelist00105.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00105.DAT -> [Ver = | Size = 1952 bytes | Modified Date = 8/13/2007 7:42:13 PM | Attr = ] Filelist00106.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00106.DAT -> [Ver = | Size = 1956 bytes | Modified Date = 8/13/2007 7:42:13 PM | Attr = ] Filelist00107.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00107.DAT -> [Ver = | Size = 508 bytes | Modified Date = 8/13/2007 7:42:14 PM | Attr = ] Filelist00108.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00108.DAT -> [Ver = | Size = 376 bytes | Modified Date = 8/13/2007 7:42:14 PM | Attr = ] Filelist00109.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00109.DAT -> [Ver = | Size = 252 bytes | Modified Date = 8/13/2007 7:42:14 PM | Attr = ] Filelist00110.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00110.DAT -> [Ver = | Size = 408 bytes | Modified Date = 8/13/2007 7:42:14 PM | Attr = ] Filelist00111.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00111.DAT -> [Ver = | Size = 252 bytes | Modified Date = 8/13/2007 7:42:14 PM | Attr = ] Filelist00112.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00112.DAT -> [Ver = | Size = 256 bytes | Modified Date = 8/13/2007 7:42:14 PM | Attr = ] Filelist00113.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00113.DAT -> [Ver = | Size = 2860 bytes | Modified Date = 8/13/2007 7:42:14 PM | Attr = ] Filelist00114.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\Filelist00114.DAT -> [Ver = | Size = 252 bytes | Modified Date = 8/13/2007 7:42:14 PM | Attr = ] FilelistIndex.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\FSX\SceneryIndexes\FilelistIndex.DAT -> [Ver = | Size = 56268 bytes | Modified Date = 12/8/2007 1:18:32 AM | Attr = ] hhcolreg.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\hhcolreg.dat -> [Ver = | Size = 15285 bytes | Modified Date = 4/6/2008 11:02:05 PM | Attr = ] qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [Ver = | Size = 10384 bytes | Modified Date = 4/15/2008 3:47:17 PM | Attr = ] qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [Ver = | Size = 10384 bytes | Modified Date = 4/15/2008 3:47:17 PM | Attr = ] opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [Ver = | Size = 8206 bytes | Modified Date = 8/31/2006 12:01:08 AM | Attr = ] 1e5087d3-4b65-3a13-e56e-f8c0b01c389d.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\1e5087d3-4b65-3a13-e56e-f8c0b01c389d.dat -> [Ver = | Size = 3338 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] 2aa181cf-5771-3146-73c7-afbf7e9ced2e.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\2aa181cf-5771-3146-73c7-afbf7e9ced2e.dat -> [Ver = | Size = 16644 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] 325ecd9f-b45c-7657-310d-a3ec69566036.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\325ecd9f-b45c-7657-310d-a3ec69566036.dat -> [Ver = | Size = 4324 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] 3a2d0e4e-183a-3be6-de12-f79b20b6726b.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\3a2d0e4e-183a-3be6-de12-f79b20b6726b.dat -> [Ver = | Size = 4339 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] 43b3fb56-0aa1-cf24-fcd5-ace4f579aa78.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\43b3fb56-0aa1-cf24-fcd5-ace4f579aa78.dat -> [Ver = | Size = 6043 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] 489a8769-9e79-acc1-cbc8-9335a4d64e0c.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\489a8769-9e79-acc1-cbc8-9335a4d64e0c.dat -> [Ver = | Size = 6182 bytes | Modified Date = 8/13/2007 7:40:21 PM | Attr = ] 4a9b95b9-1079-3d9a-1dd0-511ab9735c52.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\4a9b95b9-1079-3d9a-1dd0-511ab9735c52.dat -> [Ver = | Size = 4190 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] 4d65484d-3a91-d8c6-9e13-3afe018aa34f.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\4d65484d-3a91-d8c6-9e13-3afe018aa34f.dat -> [Ver = | Size = 11352 bytes | Modified Date = 8/13/2007 7:40:27 PM | Attr = ] 61003c70-2333-4da9-f637-1240e25f9b46.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\61003c70-2333-4da9-f637-1240e25f9b46.dat -> [Ver = | Size = 5105 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] 6d1fc144-430d-92ee-a585-fccf492243f1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\6d1fc144-430d-92ee-a585-fccf492243f1.dat -> [Ver = | Size = 16652 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] 6f61c46d-9dc1-f0f3-a292-7e1624eb720a.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\6f61c46d-9dc1-f0f3-a292-7e1624eb720a.dat -> [Ver = | Size = 4256 bytes | Modified Date = 8/13/2007 7:40:23 PM | Attr = ] 7fc76939-1749-9389-638e-b057f3111dfe.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\7fc76939-1749-9389-638e-b057f3111dfe.dat -> [Ver = | Size = 8266 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] 9728020c-33b1-869d-8ca7-2da2673eeba6.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\9728020c-33b1-869d-8ca7-2da2673eeba6.dat -> [Ver = | Size = 13319 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] a6231563-605a-e942-e160-ed5a632b59dc.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\a6231563-605a-e942-e160-ed5a632b59dc.dat -> [Ver = | Size = 3037 bytes | Modified Date = 8/13/2007 7:40:21 PM | Attr = ] ab660f4d-94aa-d09c-6310-81d9292e9934.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\ab660f4d-94aa-d09c-6310-81d9292e9934.dat -> [Ver = | Size = 5612 bytes | Modified Date = 8/13/2007 7:40:23 PM | Attr = ] af154ab4-7867-7da2-509f-55369e19b78a.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\af154ab4-7867-7da2-509f-55369e19b78a.dat -> [Ver = | Size = 5259 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] b3724b38-a0be-7e2e-680a-76a2b74d87ae.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\b3724b38-a0be-7e2e-680a-76a2b74d87ae.dat -> [Ver = | Size = 11422 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] b63271ae-c613-2d09-eede-d8f740f9fbdc.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\b63271ae-c613-2d09-eede-d8f740f9fbdc.dat -> [Ver = | Size = 3447 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] bb94bdbd-e879-9f77-c792-8f2b062f83fa.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\bb94bdbd-e879-9f77-c792-8f2b062f83fa.dat -> [Ver = | Size = 3033 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] c7f13e4f-3a54-f72a-4415-9de346aa9a51.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\c7f13e4f-3a54-f72a-4415-9de346aa9a51.dat -> [Ver = | Size = 3448 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] e840ba51-07a0-5a6f-202f-a1d2634d5cb6.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\e840ba51-07a0-5a6f-202f-a1d2634d5cb6.dat -> [Ver = | Size = 11430 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] f0f642df-b163-4f5b-70aa-9dbfadeaa323.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\f0f642df-b163-4f5b-70aa-9dbfadeaa323.dat -> [Ver = | Size = 3978 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] f68611eb-e389-1a51-bd94-636faf15e309.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\f68611eb-e389-1a51-bd94-636faf15e309.dat -> [Ver = | Size = 7371 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] fda68769-b92c-0baa-a72e-cdf551afdbb7.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\SLDL\SoftwareLicensing\fda68769-b92c-0baa-a72e-cdf551afdbb7.dat -> [Ver = | Size = 13323 bytes | Modified Date = 8/13/2007 7:35:19 PM | Attr = ] VCExpress000223.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\VCExpress\8.0\VCExpress000223.dat -> [Ver = | Size = 677178 bytes | Modified Date = 10/28/2007 9:44:08 AM | Attr = H ] Perflib_Perfdata_4a0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_4a0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/15/2008 3:46:42 PM | Attr = ] Perflib_Perfdata_8a0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_8a0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/15/2008 3:47:22 PM | Attr = ] [Files Modified - Additional Folder Scans - Non-Microsoft Only] Adobe -> %AllUsersProfile%\Application Data\Adobe -> [Folder | Modified Date = 3/21/2008 2:44:01 PM | Attr = ] Ahead -> %AllUsersProfile%\Application Data\Ahead -> [Folder | Modified Date = 3/15/2008 8:40:34 PM | Attr = ] Avg7 -> %AllUsersProfile%\Application Data\Avg7 -> [Folder | Modified Date = 3/16/2008 3:04:34 AM | Attr = ] desktop.ini -> %AllUsersProfile%\Application Data\desktop.ini -> [Ver = | Size = 62 bytes | Modified Date = 3/16/2008 2:19:01 AM | Attr = HS] Intuit Canada -> %AllUsersProfile%\Application Data\Intuit Canada -> [Folder | Modified Date = 3/9/2008 8:28:45 PM | Attr = ] Microsoft -> %AllUsersProfile%\Application Data\Microsoft -> [Folder | Modified Date = 4/8/2008 5:51:34 PM | Attr = S] Nero -> %AllUsersProfile%\Application Data\Nero -> [Folder | Modified Date = 3/15/2008 8:37:42 PM | Attr = ] noteborq -> %AllUsersProfile%\Application Data\noteborq -> [Folder | Modified Date = 4/12/2008 12:31:37 AM | Attr = ] Subliminal Flash -> %AllUsersProfile%\Application Data\Subliminal Flash -> [Folder | Modified Date = 3/16/2008 1:42:05 AM | Attr = ] Symantec -> %AllUsersProfile%\Application Data\Symantec -> [Folder | Modified Date = 3/16/2008 3:15:43 AM | Attr = ] TEMP -> %AllUsersProfile%\Application Data\TEMP -> [Folder | Modified Date = 4/11/2008 8:29:34 AM | Attr = ] @Alternate Data Stream - 498 bytes -> %AllUsersProfile%\Application Data\TEMP:05EE1EEF @Alternate Data Stream - 151 bytes -> %AllUsersProfile%\Application Data\TEMP:0B9D8E22 @Alternate Data Stream - 132 bytes -> %AllUsersProfile%\Application Data\TEMP:1A6AFE3D @Alternate Data Stream - 124 bytes -> %AllUsersProfile%\Application Data\TEMP:242231A9 @Alternate Data Stream - 133 bytes -> %AllUsersProfile%\Application Data\TEMP:268F887D @Alternate Data Stream - 110 bytes -> %AllUsersProfile%\Application Data\TEMP:3D5184D8 @Alternate Data Stream - 109 bytes -> %AllUsersProfile%\Application Data\TEMP:42294FD9 @Alternate Data Stream - 115 bytes -> %AllUsersProfile%\Application Data\TEMP:4DE8EA4B @Alternate Data Stream - 105 bytes -> %AllUsersProfile%\Application Data\TEMP:6509ADED @Alternate Data Stream - 104 bytes -> %AllUsersProfile%\Application Data\TEMP:756C8543 @Alternate Data Stream - 201 bytes -> %AllUsersProfile%\Application Data\TEMP:7AB4D952 @Alternate Data Stream - 122 bytes -> %AllUsersProfile%\Application Data\TEMP:8CE646EE @Alternate Data Stream - 109 bytes -> %AllUsersProfile%\Application Data\TEMP:B203B914 @Alternate Data Stream - 135 bytes -> %AllUsersProfile%\Application Data\TEMP:BE76DBCF @Alternate Data Stream - 106 bytes -> %AllUsersProfile%\Application Data\TEMP:BF218358 WLInstaller -> %AllUsersProfile%\Application Data\WLInstaller -> [Folder | Modified Date = 4/8/2008 5:50:55 PM | Attr = ] Adobe -> %AppData%\Adobe -> [Folder | Modified Date = 3/21/2008 2:49:01 PM | Attr = ] Ahead -> %AppData%\Ahead -> [Folder | Modified Date = 4/12/2008 8:05:33 AM | Attr = ] com.kennettnet.MusicRescue.plist -> %AppData%\com.kennettnet.MusicRescue.plist -> [Ver = | Size = 3232 bytes | Modified Date = 4/4/2008 6:49:22 PM | Attr = ] com.kennettnet.MusicRescueProfiles.plist -> %AppData%\com.kennettnet.MusicRescueProfiles.plist -> [Ver = | Size = 194066 bytes | Modified Date = 4/4/2008 6:49:23 PM | Attr = ] CopyTrans -> %AppData%\CopyTrans -> [Folder | Modified Date = 2/28/2008 5:50:29 PM | Attr = ] Eltima Software -> %AppData%\Eltima Software -> [Folder | Modified Date = 4/11/2008 4:32:40 PM | Attr = ] FrostWire -> %AppData%\FrostWire -> [Folder | Modified Date = 4/4/2008 7:01:11 PM | Attr = ] Moyea -> %AppData%\Moyea -> [Folder | Modified Date = 4/11/2008 4:37:48 PM | Attr = ] TmpRecentIcons -> %AppData%\TmpRecentIcons -> [Folder | Modified Date = 4/12/2008 10:09:00 AM | Attr = ] Winamp -> %AppData%\Winamp -> [Folder | Modified Date = 3/25/2008 4:47:21 PM | Attr = ] ApplicationHistory -> %UserProfile%\Local Settings\Application Data\ApplicationHistory -> [Folder | Modified Date = 4/12/2008 7:51:47 AM | Attr = ] DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [Ver = | Size = 124928 bytes | Modified Date = 4/12/2008 8:07:27 AM | Attr = ] GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [Ver = | Size = 110544 bytes | Modified Date = 3/28/2008 5:23:55 PM | Attr = ] IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [Ver = | Size = 2112228 bytes | Modified Date = 3/13/2008 5:53:56 PM | Attr = H ] IsolatedStorage -> %UserProfile%\Local Settings\Application Data\IsolatedStorage -> [Folder | Modified Date = 4/11/2008 4:56:14 PM | Attr = ] Last.fm -> %UserProfile%\Local Settings\Application Data\Last.fm -> [Folder | Modified Date = 4/15/2008 9:01:08 AM | Attr = ] Microsoft -> %UserProfile%\Local Settings\Application Data\Microsoft -> [Folder | Modified Date = 4/13/2008 9:38:11 PM | Attr = ] Sony Ericsson -> %UserProfile%\Local Settings\Application Data\Sony Ericsson -> [Folder | Modified Date = 2/10/2008 5:50:24 PM | Attr = ] Steam -> %UserProfile%\Local Settings\Application Data\Steam -> [Folder | Modified Date = 1/31/2008 9:40:07 PM | Attr = ] Symantec -> %UserProfile%\Local Settings\Application Data\Symantec -> [Folder | Modified Date = 3/16/2008 11:50:21 PM | Attr = ] desktop.ini -> %AllUsersProfile%\Documents\desktop.ini -> [Ver = | Size = 132 bytes | Modified Date = 3/16/2008 2:19:01 AM | Attr = HS] aaa1.mp3 -> %UserProfile%\My Documents\aaa1.mp3 -> [Ver = | Size = 415868 bytes | Modified Date = 2/20/2008 8:29:22 PM | Attr = ] Adobe -> %UserProfile%\My Documents\Adobe -> [Folder | Modified Date = 3/21/2008 2:50:46 PM | Attr = ] AdobeStockPhotos -> %UserProfile%\My Documents\AdobeStockPhotos -> [Folder | Modified Date = 1/26/2008 8:18:04 PM | Attr = ] antro -> %UserProfile%\My Documents\antro -> [Folder | Modified Date = 3/6/2008 11:57:16 PM | Attr = ] Cambrian 543 mya.doc -> %UserProfile%\My Documents\Cambrian 543 mya.doc -> [Ver = | Size = 26112 bytes | Modified Date = 3/5/2008 8:28:26 PM | Attr = ] clip0001.avi -> %UserProfile%\My Documents\clip0001.avi -> [Ver = | Size = 24636936 bytes | Modified Date = 2/16/2008 5:00:40 PM | Attr = ] clip0002.avi -> %UserProfile%\My Documents\clip0002.avi -> [Ver = | Size = 9002 bytes | Modified Date = 3/6/2008 5:37:21 PM | Attr = ] clip0003.avi -> %UserProfile%\My Documents\clip0003.avi -> [Ver = | Size = 33256742 bytes | Modified Date = 3/6/2008 5:40:52 PM | Attr = ] clip0004.avi -> %UserProfile%\My Documents\clip0004.avi -> [Ver = | Size = 16145080 bytes | Modified Date = 3/6/2008 5:43:39 PM | Attr = ] clip0005.avi -> %UserProfile%\My Documents\clip0005.avi -> [Ver = | Size = 6341048 bytes | Modified Date = 3/6/2008 5:45:35 PM | Attr = ] clip0006.avi -> %UserProfile%\My Documents\clip0006.avi -> [Ver = | Size = 38453032 bytes | Modified Date = 3/6/2008 5:51:53 PM | Attr = ] clip0007.avi -> %UserProfile%\My Documents\clip0007.avi -> [Ver = | Size = 4923812 bytes | Modified Date = 3/6/2008 5:54:13 PM | Attr = ] GTA Vice City User Files -> %UserProfile%\My Documents\GTA Vice City User Files -> [Folder | Modified Date = 1/31/2008 5:20:27 PM | Attr = ] My Received Files -> %UserProfile%\My Documents\My Received Files -> [Folder | Modified Date = 4/10/2008 3:36:35 PM | Attr = ] My Sharing Folders.lnk -> %UserProfile%\My Documents\My Sharing Folders.lnk -> [Ver = | Size = 581 bytes | Modified Date = 4/15/2008 7:10:56 AM | Attr = ] NeroVision -> %UserProfile%\My Documents\NeroVision -> [Folder | Modified Date = 4/12/2008 8:05:33 AM | Attr = ] Visual Studio 2005 -> %UserProfile%\My Documents\Visual Studio 2005 -> [Folder | Modified Date = 4/14/2008 5:20:46 PM | Attr = ] QuickTime Player.lnk -> %AllUsersProfile%\Desktop\QuickTime Player.lnk -> [Ver = | Size = 1604 bytes | Modified Date = 4/9/2008 3:52:46 PM | Attr = ] Windows Live Messenger .lnk -> %AllUsersProfile%\Desktop\Windows Live Messenger .lnk -> [Ver = | Size = 1827 bytes | Modified Date = 4/8/2008 5:51:59 PM | Attr = ] Antro rough work.zip -> %UserProfile%\Desktop\Antro rough work.zip -> [Ver = | Size = 700514 bytes | Modified Date = 4/4/2008 8:57:34 AM | Attr = ] appleipod.bat -> %UserProfile%\Desktop\appleipod.bat -> [Ver = | Size = 246 bytes | Modified Date = 4/9/2008 4:23:43 PM | Attr = ] backups -> %UserProfile%\Desktop\backups -> [Folder | Modified Date = 4/13/2008 6:53:34 PM | Attr = ] ComboFix.exe -> %UserProfile%\Desktop\ComboFix.exe -> [Ver = | Size = 1698889 bytes | Modified Date = 4/13/2008 7:05:56 PM | Attr = ] Counter Strike 1.6 Non Steam.lnk -> %UserProfile%\Desktop\Counter Strike 1.6 Non Steam.lnk -> [Ver = | Size = 749 bytes | Modified Date = 4/12/2008 9:27:53 AM | Attr = ] ddd -> %UserProfile%\Desktop\ddd -> [Folder | Modified Date = 4/11/2008 5:10:55 PM | Attr = ] dss.exe -> %UserProfile%\Desktop\dss.exe -> [Ver = 3, 2, 8, 1 | Size = 686630 bytes | Modified Date = 4/13/2008 1:15:39 PM | Attr = ] erunt-setup.exe -> %UserProfile%\Desktop\erunt-setup.exe -> Lars Hederer [Ver = | Size = 791393 bytes | Modified Date = 4/13/2008 6:56:54 PM | Attr = ] ERUNT.lnk -> %UserProfile%\Desktop\ERUNT.lnk -> [Ver = | Size = 592 bytes | Modified Date = 4/13/2008 6:57:21 PM | Attr = ] fix.reg -> %UserProfile%\Desktop\fix.reg -> [Ver = | Size = 127 bytes | Modified Date = 4/13/2008 6:59:22 PM | Attr = ] Florin.exe -> %UserProfile%\Desktop\Florin.exe -> Trend Micro Inc. [Ver = 2.00.0002 | Size = 401720 bytes | Modified Date = 4/12/2008 11:58:14 PM | Attr = ] gfpro.exe -> %UserProfile%\Desktop\gfpro.exe -> GetFLV, Inc. [Ver = | Size = 5476592 bytes | Modified Date = 4/12/2008 7:56:22 AM | Attr = ] HiJackThis.exe -> %UserProfile%\Desktop\HiJackThis.exe -> Trend Micro Inc. [Ver = 2.00.0002 | Size = 401720 bytes | Modified Date = 4/12/2008 11:58:14 PM | Attr = ] install_asm_en.exe -> %UserProfile%\Desktop\install_asm_en.exe -> Locussoftcorp LTD [Ver = 1.0.8.0 | Size = 462616 bytes | Modified Date = 4/11/2008 6:39:03 PM | Attr = ] Lab chem.docx -> %UserProfile%\Desktop\Lab chem.docx -> [Ver = | Size = 12576 bytes | Modified Date = 4/10/2008 3:36:31 PM | Attr = ] New Microsoft Word Document.doc -> %UserProfile%\Desktop\New Microsoft Word Document.doc -> [Ver = | Size = 27648 bytes | Modified Date = 4/4/2008 9:00:04 AM | Attr = ] New Microsoft Word Document1.doc -> %UserProfile%\Desktop\New Microsoft Word Document1.doc -> [Ver = | Size = 37376 bytes | Modified Date = 4/13/2008 6:37:31 PM | Attr = ] NoLop.exe -> %UserProfile%\Desktop\NoLop.exe -> PunkTools [Ver = 3.00.0052 | Size = 40448 bytes | Modified Date = 4/13/2008 6:36:22 PM | Attr = ] Other -> %UserProfile%\Desktop\Other -> [Folder | Modified Date = 4/11/2008 5:11:05 PM | Attr = ] OTMoveIt2.exe -> %UserProfile%\Desktop\OTMoveIt2.exe -> OldTimer Tools [Ver = 1.0.4.1 | Size = 291840 bytes | Modified Date = 4/13/2008 1:13:53 PM | Attr = ] OTscan it -> %UserProfile%\Desktop\OTscan it -> [Folder | Modified Date = 4/15/2008 3:57:42 PM | Attr = ] OTScanIt.exe -> %UserProfile%\Desktop\OTScanIt.exe -> [Ver = | Size = 540250 bytes | Modified Date = 4/15/2008 3:57:15 PM | Attr = ] swf_video_converter.exe -> %UserProfile%\Desktop\swf_video_converter.exe -> Eltima Software [Ver = 3.0.20.77 | Size = 4583830 bytes | Modified Date = 4/12/2008 7:52:51 AM | Attr = ] Thumbs.db -> %UserProfile%\Desktop\Thumbs.db -> [Ver = | Size = 213504 bytes | Modified Date = 4/10/2008 10:18:12 PM | Attr = HS] @Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable untitled.bmp -> %UserProfile%\Desktop\untitled.bmp -> [Ver = | Size = 5292054 bytes | Modified Date = 4/7/2008 4:30:52 PM | Attr = ] Wallpapes -> %UserProfile%\Desktop\Wallpapes -> [Folder | Modified Date = 4/13/2008 10:31:28 PM | Attr = ] desktop.ini -> %AllUsersProfile%\Start Menu\Programs\Startup\desktop.ini -> [Ver = | Size = 84 bytes | Modified Date = 3/16/2008 2:34:11 AM | Attr = HS] ERUNT AutoBackup.lnk -> %UserProfile%\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk -> [Ver = | Size = 767 bytes | Modified Date = 4/13/2008 6:57:30 PM | Attr = ] Last.fm Helper.lnk -> %UserProfile%\Start Menu\Programs\Startup\Last.fm Helper.lnk -> [Ver = | Size = 655 bytes | Modified Date = 4/15/2008 7:26:15 AM | Attr = ] Adobe -> %CommonProgramFiles%\Adobe -> [Folder | Modified Date = 3/21/2008 2:44:24 PM | Attr = ] Ahead -> %CommonProgramFiles%\Ahead -> [Folder | Modified Date = 3/15/2008 8:43:37 PM | Attr = ] AnswerWorks 4.0 -> %CommonProgramFiles%\AnswerWorks 4.0 -> [Folder | Modified Date = 3/9/2008 8:29:27 PM | Attr = ] Microsoft Shared -> %CommonProgramFiles%\Microsoft Shared -> [Folder | Modified Date = 4/8/2008 5:51:34 PM | Attr = ] Scanner -> %CommonProgramFiles%\Scanner -> [Folder | Modified Date = 3/31/2008 5:47:52 PM | Attr = ] Symantec Shared -> %CommonProgramFiles%\Symantec Shared -> [Folder | Modified Date = 3/16/2008 3:17:40 AM | Attr = ] System -> %CommonProgramFiles%\System -> [Folder | Modified Date = 3/17/2008 12:54:18 AM | Attr = ] Thraex Software -> %CommonProgramFiles%\Thraex Software -> [Folder | Modified Date = 1/31/2008 9:42:02 PM | Attr = ] WindowsLiveInstaller -> %CommonProgramFiles%\WindowsLiveInstaller -> [Folder | Modified Date = 4/8/2008 5:51:26 PM | Attr = HS] [File - Purity Scan: Additional Folder Scans - Non-Microsoft Only] < End of report > [/code]