[code] OTScanIt logfile created on: 4/22/2008 3:25:41 AM OTScanIt by OldTimer - Version 1.0.11.0 Folder = C:\Documents and Settings\Boo\Desktop\OTScanIt Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1.50 Gb Total Physical Memory | 1.08 Gb Available Physical Memory | 72.06% Memory free 3.35 Gb Paging File | 3.04 Gb Available in Paging File | 90.59% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 149.05 Gb Total Space | 35.42 Gb Free Space | 23.76% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded Drive F: | 37.26 Gb Total Space | 2.47 Gb Free Space | 6.63% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: BOO Current User Name: Boo Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users [Processes - Non-Microsoft Only] lexbces.exe -> %SystemRoot%\system32\LEXBCES.EXE -> Lexmark International, Inc. [Ver = 9.41 | Size = 311296 bytes | Modified Date = 1/13/2004 7:00:02 PM | Attr = ] lexpps.exe -> %SystemRoot%\system32\LEXPPS.EXE -> Lexmark International, Inc. [Ver = 9.41 | Size = 174592 bytes | Modified Date = 1/13/2004 6:55:51 PM | Attr = ] guard.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 5/30/2007 8:31:10 AM | Attr = ] avgamsvr.exe -> %ProgramFiles%\Grisoft\AVG7\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.496 | Size = 418816 bytes | Modified Date = 10/24/2007 2:10:51 AM | Attr = ] avgupsvc.exe -> %ProgramFiles%\Grisoft\AVG7\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 6/16/2007 8:52:00 AM | Attr = ] avgemc.exe -> %ProgramFiles%\Grisoft\AVG7\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.510 | Size = 406528 bytes | Modified Date = 12/21/2007 3:10:48 AM | Attr = ] mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> Apple Computer, Inc. [Ver = 1,0,3,1 | Size = 229376 bytes | Modified Date = 2/28/2006 12:42:38 PM | Attr = ] nvsvc32.exe -> %SystemRoot%\system32\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.10.8421 | Size = 143436 bytes | Modified Date = 3/9/2006 3:29:00 PM | Attr = ] psiservice.exe -> %SystemRoot%\system32\PSIService.exe -> [Ver = 2.0.0.1 | Size = 174656 bytes | Modified Date = 11/2/2006 9:40:12 PM | Attr = ] slserv.exe -> %SystemRoot%\system32\slserv.exe -> [Ver = 2.80.00(24Apr2000) | Size = 45056 bytes | Modified Date = 1/17/2003 5:02:00 AM | Attr = ] sstray.exe -> %SystemRoot%\system32\sstray.exe -> NVIDIA Corporation [Ver = 1.00.00.0366 | Size = 73728 bytes | Modified Date = 9/2/2003 9:25:04 PM | Attr = ] shwicon2k.exe -> %ProgramFiles%\Multimedia Card Reader\shwicon2k.exe -> Alcor Micro, Corp. [Ver = 1, 4, 0, 8 | Size = 139264 bytes | Modified Date = 11/19/2003 11:32:04 PM | Attr = ] jusched.exe -> %ProgramFiles%\Java\jre1.6.0_05\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 144784 bytes | Modified Date = 2/22/2008 5:25:21 AM | Attr = ] soundman.exe -> %SystemRoot%\SOUNDMAN.EXE -> Realtek Semiconductor Corp. [Ver = 5.1.0.24 | Size = 65024 bytes | Modified Date = 2/26/2004 4:53:30 AM | Attr = ] mixer.exe -> %SystemRoot%\mixer.exe -> C-Media Electronic Inc. (www.cmedia.com.tw) [Ver = 1.58 | Size = 1818624 bytes | Modified Date = 10/15/2002 7:00:20 PM | Attr = ] avgas.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 6/11/2007 5:25:42 AM | Attr = ] otscanit.exe -> %UserProfile%\Desktop\OTScanIt\OTScanIt.exe -> OldTimer Tools [Ver = 1.0.11.0 | Size = 371200 bytes | Modified Date = 4/21/2008 9:38:22 PM | Attr = ] [Win32 Services - Non-Microsoft Only] (Adobe LM Service) Adobe LM Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Adobe Systems Shared\Service\Adobelmsvc.exe -> [Ver = 2.41.000 | Size = 68096 bytes | Modified Date = 1/24/2007 11:43:52 AM | Attr = ] (avg anti-spyware guard) avg anti-spyware guard [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 5/30/2007 8:31:10 AM | Attr = ] (Avg7Alrt) AVG7 Alert Manager Server [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG7\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.496 | Size = 418816 bytes | Modified Date = 10/24/2007 2:10:51 AM | Attr = ] (Avg7UpdSvc) AVG7 Update Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG7\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 6/16/2007 8:52:00 AM | Attr = ] (AVGEMS) AVG E-mail Scanner [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG7\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.510 | Size = 406528 bytes | Modified Date = 12/21/2007 3:10:48 AM | Attr = ] (Bonjour Service) ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> Apple Computer, Inc. [Ver = 1,0,3,1 | Size = 229376 bytes | Modified Date = 2/28/2006 12:42:38 PM | Attr = ] (dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 3:56:48 AM | Attr = ] (FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Modified Date = 6/16/2007 11:33:32 AM | Attr = ] (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\1150\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.50.42618 | Size = 69632 bytes | Modified Date = 11/14/2005 2:06:04 AM | Attr = ] (LexBceS) LexBce Server [Win32_Own | Auto | Running] -> %SystemRoot%\system32\LEXBCES.EXE -> Lexmark International, Inc. [Ver = 9.41 | Size = 311296 bytes | Modified Date = 1/13/2004 7:00:02 PM | Attr = ] (NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.10.8421 | Size = 143436 bytes | Modified Date = 3/9/2006 3:29:00 PM | Attr = ] (Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\system32\HPZipm12.exe -> HP [Ver = 6, 0, 0, 0 | Size = 65795 bytes | Modified Date = 3/9/2003 12:31:02 AM | Attr = R ] (ProtexisLicensing) ProtexisLicensing [Win32_Own | Auto | Running] -> %SystemRoot%\system32\PSIService.exe -> [Ver = 2.0.0.1 | Size = 174656 bytes | Modified Date = 11/2/2006 9:40:12 PM | Attr = ] (SLService) SmartLinkService [Win32_Own | Auto | Running] -> %SystemRoot%\system32\slserv.exe -> [Ver = 2.80.00(24Apr2000) | Size = 45056 bytes | Modified Date = 1/17/2003 5:02:00 AM | Attr = ] [Registry - Non-Microsoft Only] < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> -> [] -> File not found !AVG Anti-Spyware -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe ["C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized] -> GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 6/11/2007 5:25:42 AM | Attr = ] AVG7_CC -> %ProgramFiles%\Grisoft\AVG7\avgcc.exe [C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP] -> GRISOFT, s.r.o. [Ver = 7.5.0.522 | Size = 579584 bytes | Modified Date = 4/17/2008 2:10:45 AM | Attr = ] CHotkey -> %SystemRoot%\zHotkey.exe [zHotkey.exe] -> Chicony [Ver = 3, 0, 0, 1 | Size = 496640 bytes | Modified Date = 6/3/2003 3:01:32 PM | Attr = ] C-Media Mixer -> %SystemRoot%\mixer.exe [Mixer.exe /startup] -> C-Media Electronic Inc. (www.cmedia.com.tw) [Ver = 1.58 | Size = 1818624 bytes | Modified Date = 10/15/2002 7:00:20 PM | Attr = ] Easy SpyRemover -> %ProgramFiles%\Easy SpyRemover\EasySpyRemover.exe [C:\Program Files\Easy SpyRemover\EasySpyRemover.exe /smart] -> File not found Lexmark 4200 Series -> %ProgramFiles%\Lexmark 4200 Series\lxbmbmgr.exe ["C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"] -> Lexmark International, Inc. [Ver = 0.1.25.0 | Size = 57344 bytes | Modified Date = 1/16/2004 6:04:08 AM | Attr = ] nForce Tray Options -> %SystemRoot%\system32\sstray.exe [sstray.exe /r] -> NVIDIA Corporation [Ver = 1.00.00.0366 | Size = 73728 bytes | Modified Date = 9/2/2003 9:25:04 PM | Attr = ] NvCplDaemon -> %SystemRoot%\system32\nvcpl.dll [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> NVIDIA Corporation [Ver = 6.14.10.8421 | Size = 7561216 bytes | Modified Date = 3/9/2006 3:29:00 PM | Attr = ] NvMediaCenter -> %SystemRoot%\system32\nvmctray.dll [RunDLL32.exe NvMCTray.dll,NvTaskbarInit] -> NVIDIA Corporation [Ver = 6.14.10.8421 | Size = 86016 bytes | Modified Date = 3/9/2006 3:29:00 PM | Attr = ] nwiz -> %SystemRoot%\system32\nwiz.exe [nwiz.exe /install] -> [Ver = | Size = 1519616 bytes | Modified Date = 3/9/2006 3:29:00 PM | Attr = ] SoundMan -> %SystemRoot%\SOUNDMAN.EXE [SOUNDMAN.EXE] -> Realtek Semiconductor Corp. [Ver = 5.1.0.24 | Size = 65024 bytes | Modified Date = 2/26/2004 4:53:30 AM | Attr = ] SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_05\bin\jusched.exe ["C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"] -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 144784 bytes | Modified Date = 2/22/2008 5:25:21 AM | Attr = ] Sunkist2k -> %ProgramFiles%\Multimedia Card Reader\shwicon2k.exe [C:\Program Files\Multimedia Card Reader\shwicon2k.exe] -> Alcor Micro, Corp. [Ver = 1, 4, 0, 8 | Size = 139264 bytes | Modified Date = 11/19/2003 11:32:04 PM | Attr = ] < OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> IMAIL-> Installed = 1 -> MAPI-> Installed = 1 -> MSFS-> Installed = 1 -> < Run [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> AVG7_Run -> %ProgramFiles%\Grisoft\AVG7\avgw.exe [C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE] -> GRISOFT, s.r.o. [Ver = 7.5.0.502 | Size = 219136 bytes | Modified Date = 10/24/2007 2:10:54 AM | Attr = ] < Run [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> AVG7_Run -> %ProgramFiles%\Grisoft\AVG7\avgw.exe [C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE] -> GRISOFT, s.r.o. [Ver = 7.5.0.502 | Size = 219136 bytes | Modified Date = 10/24/2007 2:10:54 AM | Attr = ] < Run [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> AVG7_Run -> %ProgramFiles%\Grisoft\AVG7\avgw.exe [C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE] -> GRISOFT, s.r.o. [Ver = 7.5.0.502 | Size = 219136 bytes | Modified Date = 10/24/2007 2:10:54 AM | Attr = ] < Run [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> AVG7_Run -> %ProgramFiles%\Grisoft\AVG7\avgw.exe [C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE] -> GRISOFT, s.r.o. [Ver = 7.5.0.502 | Size = 219136 bytes | Modified Date = 10/24/2007 2:10:54 AM | Attr = ] < Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup -> < Administrator.BOO Startup Folder > -> C:\Documents and Settings\Administrator.BOO\Start Menu\Programs\Startup -> < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> < Boo Startup Folder > -> C:\Documents and Settings\Boo\Start Menu\Programs\Startup -> < Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> < ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> {57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> GRISOFT s.r.o. [Ver = 7, 5, 1, 36 | Size = 79408 bytes | Modified Date = 5/30/2007 8:29:58 AM | Attr = ] < SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005] > -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> audfjouq -> %SystemRoot%\system32\omlfoml.dll -> [Ver = | Size = 75264 bytes | Modified Date = 7/10/2007 6:38:28 AM | Attr = ] < CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\\{17492023-C23A-453E-A040-C7C580BBF700} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> < CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\comdlg32\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\comdlg32\\NoFileMru -> 1 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ClearRecentDocsOnExit -> 01 00 00 00 [binary data] -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoRecentDocsHistory -> 01 00 00 00 [binary data] -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoRecentDocsNetHood -> 01 00 00 00 [binary data] -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableRegistryTools -> 0 -> < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> 0 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> 0 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005] > -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\comdlg32\ -> -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\comdlg32\\NoFileMru -> 1 -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ClearRecentDocsOnExit -> 01 00 00 00 [binary data] -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoRecentDocsHistory -> 01 00 00 00 [binary data] -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoRecentDocsNetHood -> 01 00 00 00 [binary data] -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableRegistryTools -> 0 -> < HOSTS File > (734 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://www.emachines.com -> HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\Search Bar -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\Search Bar -> http://www.google.com/ie -> HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: Main\\Start Page -> http://www.google.com/ -> HKEY_CURRENT_USER\: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found HKEY_CURRENT_USER\: ProxyEnable -> 0 -> HKEY_CURRENT_USER\: ProxyOverride -> *.local -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: Main\\Search Bar -> http://www.google.com/ie -> HKEY_USERS\.DEFAULT\: Main\\Start Page -> http://www.emachines.com -> HKEY_USERS\.DEFAULT\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: Main\\Search Bar -> http://www.google.com/ie -> HKEY_USERS\S-1-5-18\: Main\\Start Page -> http://www.emachines.com -> HKEY_USERS\S-1-5-18\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> HKEY_USERS\S-1-5-19\: Main\\Search Bar -> http://www.google.com/ie -> HKEY_USERS\S-1-5-19\: Main\\Start Page -> http://www.emachines.com -> HKEY_USERS\S-1-5-19\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> HKEY_USERS\S-1-5-20\: Main\\Search Bar -> http://www.google.com/ie -> HKEY_USERS\S-1-5-20\: Main\\Start Page -> http://www.emachines.com -> HKEY_USERS\S-1-5-20\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\] > -> -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\: Main\\Search Bar -> http://www.google.com/ie -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\: Main\\Start Page -> http://www.google.com/ -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\: ProxyEnable -> 0 -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\: ProxyOverride -> *.local -> < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 1 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4395 domain(s) found. -> 33 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 80 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4395 domain(s) found. -> 33 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 80 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4395 domain(s) found. -> 33 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 80 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4395 domain(s) found. -> 33 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 80 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4395 domain(s) found. -> 33 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 80 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\] > -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4395 domain(s) found. -> 33 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\] > -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 80 range(s) found. -> < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {B625BB74-18E6-4B32-ABC6-ABBC83F83404} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\omlfoml.dll [Reg Error: Value does not exist or could not be read.] -> [Ver = | Size = 75264 bytes | Modified Date = 7/10/2007 6:38:28 AM | Attr = ] < Internet Explorer Bars [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found {4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Bars [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Bars [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Bars [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Bars [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Bars [HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\] > -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found {4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\] > -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_05\bin\npjpi160_05.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 132496 bytes | Modified Date = 2/22/2008 5:25:19 AM | Attr = ] {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} [HKEY_CURRENT_USER] -> %ProgramFiles%\Java\jre1.6.0_05\bin\ssv.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 509328 bytes | Modified Date = 2/22/2008 5:25:19 AM | Attr = ] < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_05\bin\npjpi160_05.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 132496 bytes | Modified Date = 2/22/2008 5:25:19 AM | Attr = ] < Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_05\bin\npjpi160_05.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 132496 bytes | Modified Date = 2/22/2008 5:25:19 AM | Attr = ] CmdMapping\\{6224f700-cba3-4071-b251-47cb894244cd} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_05\bin\npjpi160_05.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 132496 bytes | Modified Date = 2/22/2008 5:25:19 AM | Attr = ] CmdMapping\\{6224f700-cba3-4071-b251-47cb894244cd} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\] > -> HKEY_USERS\S-1-5-21-3997198034-387375040-3945152865-1005\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_05\bin\npjpi160_05.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 132496 bytes | Modified Date = 2/22/2008 5:25:19 AM | Attr = ] < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> Extension\.spop -> %ProgramFiles%\Internet Explorer\PLUGINS\NPDocBox.dll [] -> InterTrust Technologies Corporation, Inc. [Ver = 1.0.30.95 | Size = 225280 bytes | Modified Date = 1/30/2001 2:56:24 PM | Attr = ] < User Agent Post Platform [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform -> SV1 -> -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {0F26B7EA-DA71-457D-9570-92322F4C1CB1} -> 85.255.115.28,85.255.112.172 (D-Link Air DWL-122 Wireless USB Adapter) -> {35FB3660-A452-4832-A4BF-A4B05CA79AEA} -> 85.255.115.28,85.255.112.172 (SiS 900-Based PCI Fast Ethernet Adapter) -> {57533417-CCA1-4D0A-B8E8-595C205CF89C} -> 85.255.115.28,85.255.112.172 () -> {E20A380E-8ADB-4F88-B715-3D0712C273EB} -> 85.255.115.28,85.255.112.172 (NVIDIA nForce MCP Networking Controller) -> < Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] -> %ProgramFiles%\Bonjour\mdnsNSP.dll -> Apple Computer, Inc. [Ver = 1,0,3,1 | Size = 94208 bytes | Modified Date = 2/28/2006 12:42:30 PM | Attr = ] < Default Protocols [HKEY_USERS\.DEFAULT\] - Select to Repair > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\S-1-5-18\] - Select to Repair > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\S-1-5-19\] - Select to Repair > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\S-1-5-20\] - Select to Repair > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> ipp: [HKEY_LOCAL_MACHINE] -> No CLSID value msdaipp: [HKEY_LOCAL_MACHINE] -> No CLSID value < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {17492023-C23A-453E-A040-C7C580BBF700}[HKEY_LOCAL_MACHINE] -> http://go.microsoft.com/fwlink/?linkid=39204[Windows Genuine Advantage Validation Tool] -> {233C1507-6A77-46A4-9443-F871F945D258}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab[Shockwave ActiveX Control] -> {2d8ed06d-3c30-438b-96ae-4d110fdc1fb8}[HKEY_LOCAL_MACHINE] -> http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab[ActiveScan 2.0 Installer Class] -> {644E432F-49D3-41A1-8DD5-E099162EEEC5}[HKEY_LOCAL_MACHINE] -> http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab[Symantec RuFSI Utility Class] -> {8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab[Java Plug-in 1.6.0_05] -> {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab[Java Plug-in 1.5.0_06] -> {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab[Java Plug-in 1.5.0_09] -> {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab[Java Plug-in 1.5.0_11] -> {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab[Java Plug-in 1.6.0_01] -> {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab[Java Plug-in 1.6.0_02] -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab[Java Plug-in 1.6.0_05] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab[Java Plug-in 1.6.0_05] -> {D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> {F55C25D3-D16A-11D3-81DF-00A0C91F5E7D}[HKEY_LOCAL_MACHINE] -> http://www.kiddonet.com/kiddonet/GtekPrt.ocx[Gtek Print Control] -> < Module Usage Keys [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/as2stubie.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/as2stubie.dll\\.Owner -> {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/as2stubie.dll\\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/GtekPrt.ocx\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/GtekPrt.ocx\\.Owner -> {F55C25D3-D16A-11D3-81DF-00A0C91F5E7D} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/GtekPrt.ocx\\{F55C25D3-D16A-11D3-81DF-00A0C91F5E7D} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/iLinci75.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/iLinci75.dll\\.Owner -> {03A89EFD-E023-5707-A22D-45F77558EB4C} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/iLinci75.dll\\{03A89EFD-E023-5707-A22D-45F77558EB4C} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/libcomm.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/libcomm.dll\\.Owner -> {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/libcomm.dll\\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/rufsi.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/rufsi.dll\\.Owner -> {644E432F-49D3-41A1-8DD5-E099162EEEC5} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/rufsi.dll\\{644E432F-49D3-41A1-8DD5-E099162EEEC5} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SproutWebLauncher.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SproutWebLauncher.dll\\.Owner -> {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SproutWebLauncher.dll\\{D54160C3-DB7B-4534-9B65-190EE4A9C7F7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/zylomgamesplayer.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/zylomgamesplayer.dll\\.Owner -> {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/zylomgamesplayer.dll\\{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/LegitCheckControl.DLL\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/LegitCheckControl.DLL\\.Owner -> Unknown Owner -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/LegitCheckControl.DLL\\{17492023-C23A-453E-A040-C7C580BBF700} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\\.Owner -> Unknown Owner -> [Registry - Additional Scans - Non-Microsoft Only] < BotCheck > -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\DefaultLaunchPermission -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableDCOM -> Y -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineLaunchRestriction -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineAccessRestriction -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{A50398B8-9075-4FBF-A7A1-456BF21937AD} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{AD65A69D-3831-40D7-9629-9B0B50A93843} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{0040D221-54A1-11D1-9DE0-006097042D69} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\\DisableMonitoring -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\\DisableMonitoring -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> -> Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ not found. -> -> Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ not found. -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ -> -> *Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 3:56:43 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Bounds -> 0 [binary data] -> *Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> kerberos -> %SystemRoot%\system32\kerberos.dll -> Microsoft Corporation [Ver = 5.1.2600.2698 (xpsp_sp2_gdr.050614-1522) | Size = 295936 bytes | Modified Date = 6/15/2005 1:49:30 PM | Attr = ] msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 3:56:43 AM | Attr = ] schannel -> %SystemRoot%\system32\schannel.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 144896 bytes | Modified Date = 8/4/2004 3:56:44 AM | Attr = ] wdigest -> %SystemRoot%\system32\wdigest.dll -> Microsoft Corporation [Ver = 5.1.2600.2874 (xpsp_sp2_gdr.060323-1516) | Size = 49152 bytes | Modified Date = 3/24/2006 12:37:50 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\LsaPid -> 756 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\SecureBoot -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\auditbaseobjects -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\crashonauditfail -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\disabledomaincreds -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\everyoneincludesanonymous -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fipsalgorithmpolicy -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\forceguest -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fullprivilegeauditing -> [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\limitblankpassworduse -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\lmcompatibilitylevel -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nodefaultadminowner -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nolmhash -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymous -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymoussam -> 1 -> *Notification Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Notification Packages -> scecli -> %SystemRoot%\system32\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 180224 bytes | Modified Date = 8/4/2004 3:56:44 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\ImpersonatePrivilegeUpgradeToolHasRun -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\ -> -> *ProviderOrder* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\\ProviderOrder -> Windows NT Access Provider -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\\ProviderPath -> C:\WINDOWS\system32\ntmarta.dll [%SystemRoot%\system32\ntmarta.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 118784 bytes | Modified Date = 8/4/2004 3:56:44 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\\Pattern -> B9 6E 93 E7 EF B0 98 7F 6A 78 FD 04 A3 25 6E 48 35 65 39 61 34 31 37 39 00 00 00 00 01 00 00 00 C0 01 00 00 C4 01 00 00 34 CA 06 00 45 9D BF 71 04 00 00 00 10 00 00 00 00 00 00 00 99 A0 5D C1 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\\GrafBlumGroup -> 8A AB 96 9B EB 33 43 59 BB [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\\Lookup -> 57 4D 5D 4F AA 14 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminclientsec -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminserversec -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\\SkewMatrix -> 98 91 19 5C EC B0 85 AA 87 6E E5 D8 3C 53 F8 37 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\\SSOURL -> http://www.passport.com -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\\Time -> A0 47 1A 3F C9 A3 C8 01 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Name -> Digest -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Comment -> Digest SSPI Authentication Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Capabilities -> 16464 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\RpcId -> 65535 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\TokenSize -> 65535 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Time -> 00 D9 4A 94 F8 79 C4 01 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Name -> DPA -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Comment -> DPA Security Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Capabilities -> 55 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\RpcId -> 17 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\TokenSize -> 768 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Time -> 00 D9 4A 94 F8 79 C4 01 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Name -> MSN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Comment -> MSN Security Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Capabilities -> 55 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\RpcId -> 18 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\TokenSize -> 768 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Time -> 80 6F E3 94 F8 79 C4 01 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> C:\WINDOWS\system32\svchost.exe [%SystemRoot%\System32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 3:56:57 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 33660 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> C:\WINDOWS\system32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Modified Date = 8/4/2004 3:56:42 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\S\ -> -> -> Reg Error: Key does not exist or could not be opened. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{A5F22D8F-FBD1-401F-AF8B-3C5AF6AC5679} -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> C:\WINDOWS\system32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 3:56:57 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\system32\wuauserv.dll [C:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Modified Date = 8/4/2004 3:56:46 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\ not found. -> -> Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\ not found. -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\EnableAutodial -> 0 -> < Desktop Components > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\ -> 0 -> [Key] -> 0 -> FriendlyName = My Current Home Page -> 0 -> Source = About:Home -> 0 -> SubscribedURL = About:Home -> [Files/Folders - Created Within 90 days] Logs -> %SystemDrive%\Logs -> [Folder | Created Date = 3/25/2008 10:21:44 AM | Attr = ] _OTMoveIt -> %SystemDrive%\_OTMoveIt -> [Folder | Created Date = 4/22/2008 3:08:40 AM | Attr = ] AFS2K.SYS -> %SystemRoot%\System32\drivers\AFS2K.SYS -> Oak Technology Inc. [Ver = 3.1.14.886 | Size = 82380 bytes | Created Date = 4/21/2008 11:43:22 AM | Attr = ] AvgAsCln.sys -> %SystemRoot%\System32\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 10872 bytes | Created Date = 4/21/2008 10:57:06 AM | Attr = ] cjshkfad.exe -> %SystemRoot%\System32\cjshkfad.exe -> [Ver = | Size = 102400 bytes | Created Date = 4/21/2008 5:19:58 AM | Attr = ] DDASrc.ax -> %SystemRoot%\System32\DDASrc.ax -> [Ver = | Size = 995328 bytes | Created Date = 2/15/2008 8:19:26 PM | Attr = ] DDSource.tlb -> %SystemRoot%\System32\DDSource.tlb -> [Ver = | Size = 2572 bytes | Created Date = 2/15/2008 8:19:27 PM | Attr = ] etwvglsf.exe -> %SystemRoot%\System32\etwvglsf.exe -> [Ver = | Size = 102400 bytes | Created Date = 4/21/2008 6:50:02 AM | Attr = ] exyritet.exe -> %SystemRoot%\System32\exyritet.exe -> [Ver = | Size = 102400 bytes | Created Date = 4/21/2008 5:49:59 AM | Attr = ] fmfcbodm.exe -> %SystemRoot%\System32\fmfcbodm.exe -> [Ver = | Size = 110592 bytes | Created Date = 4/21/2008 3:38:19 AM | Attr = ] GSEffect.dll -> %SystemRoot%\System32\GSEffect.dll -> Imagetech Corporation [Ver = 1, 0, 0, 1 | Size = 581632 bytes | Created Date = 2/15/2008 8:19:26 PM | Attr = ] gtmlobmd.exe -> %SystemRoot%\System32\gtmlobmd.exe -> [Ver = | Size = 94208 bytes | Created Date = 4/21/2008 11:37:12 AM | Attr = ] gtyvgbiz.exe -> %SystemRoot%\System32\gtyvgbiz.exe -> [Ver = | Size = 102400 bytes | Created Date = 4/20/2008 7:46:07 PM | Attr = ] gvozulop.exe -> %SystemRoot%\System32\gvozulop.exe -> [Ver = | Size = 102400 bytes | Created Date = 4/21/2008 9:07:06 AM | Attr = ] ibqlmvwd.exe -> %SystemRoot%\System32\ibqlmvwd.exe -> [Ver = | Size = 110592 bytes | Created Date = 4/20/2008 8:46:08 PM | Attr = ] java.exe -> %SystemRoot%\System32\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 135168 bytes | Created Date = 3/16/2008 1:05:40 PM | Attr = ] javaw.exe -> %SystemRoot%\System32\javaw.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 135168 bytes | Created Date = 3/16/2008 1:05:40 PM | Attr = ] javaws.exe -> %SystemRoot%\System32\javaws.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 139264 bytes | Created Date = 3/16/2008 1:05:40 PM | Attr = ] jspijotm.exe -> %SystemRoot%\System32\jspijotm.exe -> [Ver = | Size = 110592 bytes | Created Date = 4/20/2008 11:08:14 PM | Attr = ] khkvevkb.exe -> %SystemRoot%\System32\khkvevkb.exe -> [Ver = | Size = 94208 bytes | Created Date = 4/21/2008 11:07:08 AM | Attr = ] lmbkrqju.exe -> %SystemRoot%\System32\lmbkrqju.exe -> [Ver = | Size = 110592 bytes | Created Date = 4/21/2008 1:08:17 AM | Attr = ] lsjihcho.exe -> %SystemRoot%\System32\lsjihcho.exe -> [Ver = | Size = 110592 bytes | Created Date = 4/21/2008 1:38:17 AM | Attr = ] ludkpsvu.exe -> %SystemRoot%\System32\ludkpsvu.exe -> [Ver = | Size = 110592 bytes | Created Date = 4/21/2008 2:08:18 AM | Attr = ] lurifspq.exe -> %SystemRoot%\System32\lurifspq.exe -> [Ver = | Size = 110592 bytes | Created Date = 4/21/2008 3:08:19 AM | Attr = ] mngbgzot.exe -> %SystemRoot%\System32\mngbgzot.exe -> [Ver = | Size = 110592 bytes | Created Date = 4/20/2008 8:16:08 PM | Attr = ] nudunifw.exe -> %SystemRoot%\System32\nudunifw.exe -> [Ver = | Size = 110592 bytes | Created Date = 4/21/2008 12:08:15 AM | Attr = ] ojcdcvkz.exe -> %SystemRoot%\System32\ojcdcvkz.exe -> [Ver = | Size = 102400 bytes | Created Date = 4/20/2008 6:16:05 PM | Attr = ] pezqlotm.exe -> %SystemRoot%\System32\pezqlotm.exe -> [Ver = | Size = 110592 bytes | Created Date = 4/21/2008 4:38:21 AM | Attr = ] RegOCX.exe -> %SystemRoot%\System32\RegOCX.exe -> [Ver = | Size = 57344 bytes | Created Date = 2/15/2008 8:19:27 PM | Attr = ] svcp.csv -> %SystemRoot%\System32\svcp.csv -> [Ver = | Size = 0 bytes | Created Date = 4/21/2008 4:56:15 AM | Attr = ] vefgrofm.exe -> %SystemRoot%\System32\vefgrofm.exe -> [Ver = | Size = 110592 bytes | Created Date = 4/20/2008 11:38:14 PM | Attr = ] wlgzwnir.exe -> %SystemRoot%\System32\wlgzwnir.exe -> [Ver = | Size = 102400 bytes | Created Date = 4/20/2008 7:16:06 PM | Attr = ] xvid.ax -> %SystemRoot%\System32\xvid.ax -> [Ver = | Size = 61440 bytes | Created Date = 2/15/2008 8:19:27 PM | Attr = ] xvid.inf -> %SystemRoot%\System32\xvid.inf -> [Ver = | Size = 2864 bytes | Created Date = 2/15/2008 8:19:27 PM | Attr = ] xvidcore.dll -> %SystemRoot%\System32\xvidcore.dll -> [Ver = | Size = 593920 bytes | Created Date = 2/15/2008 8:19:27 PM | Attr = ] xvidvfw.dll -> %SystemRoot%\System32\xvidvfw.dll -> [Ver = | Size = 151552 bytes | Created Date = 2/15/2008 8:19:27 PM | Attr = ] yjmxkzsv.exe -> %SystemRoot%\System32\yjmxkzsv.exe -> [Ver = | Size = 102400 bytes | Created Date = 4/21/2008 6:20:00 AM | Attr = ] ypknidcj.exe -> %SystemRoot%\System32\ypknidcj.exe -> [Ver = | Size = 102400 bytes | Created Date = 4/20/2008 6:46:06 PM | Attr = ] ypybwvmb.exe -> %SystemRoot%\System32\ypybwvmb.exe -> [Ver = | Size = 102400 bytes | Created Date = 4/21/2008 8:20:08 AM | Attr = ] bctwvwhm.dll -> %SystemRoot%\bctwvwhm.dll -> [Ver = | Size = 65024 bytes | Created Date = 4/20/2008 12:33:38 PM | Attr = ] CMMIXER.INI -> %SystemRoot%\CMMIXER.INI -> [Ver = | Size = 101 bytes | Created Date = 2/26/2008 4:49:46 PM | Attr = ] ghcfuzef.dll -> %SystemRoot%\ghcfuzef.dll -> [Ver = | Size = 192512 bytes | Created Date = 4/20/2008 12:33:39 PM | Attr = ] mainms.vpi -> %SystemRoot%\mainms.vpi -> [Ver = | Size = 138 bytes | Created Date = 4/20/2008 12:33:18 PM | Attr = RHS] megavid.cdt -> %SystemRoot%\megavid.cdt -> [Ver = | Size = 4 bytes | Created Date = 4/20/2008 12:33:13 PM | Attr = ] mgwwgmke -> %SystemRoot%\mgwwgmke -> [Folder | Created Date = 4/20/2008 12:33:40 PM | Attr = ] 1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> mixerdef.ini -> %SystemRoot%\mixerdef.ini -> [Ver = | Size = 25 bytes | Created Date = 2/26/2008 4:48:31 PM | Attr = ] muotr.so -> %SystemRoot%\muotr.so -> [Ver = | Size = 33 bytes | Created Date = 4/20/2008 12:33:13 PM | Attr = RHS] OVT -> %SystemRoot%\OVT -> [Folder | Created Date = 2/15/2008 8:20:02 PM | Attr = ] ovtcam -> %SystemRoot%\ovtcam -> [Folder | Created Date = 2/15/2008 8:20:02 PM | Attr = ] [Files Created - Additional Folder Scans - Non-Microsoft Only] Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [Folder | Created Date = 4/21/2008 11:41:44 AM | Attr = ] obcxubst.dll -> %AllUsersProfile%\Application Data\obcxubst.dll -> [Ver = | Size = 65024 bytes | Created Date = 4/20/2008 12:33:39 PM | Attr = ] odwxozop -> %AllUsersProfile%\Application Data\odwxozop -> [Folder | Created Date = 4/20/2008 12:33:47 PM | Attr = ] GameHouse -> %AppData%\GameHouse -> [Folder | Created Date = 2/3/2008 4:44:28 PM | Attr = ] Grisoft -> %AppData%\Grisoft -> [Folder | Created Date = 4/21/2008 10:57:17 AM | Attr = ] Malwarebytes -> %AppData%\Malwarebytes -> [Folder | Created Date = 4/21/2008 11:42:51 AM | Attr = ] angel_1.psd -> %UserProfile%\My Documents\angel_1.psd -> [Ver = | Size = 6512764 bytes | Created Date = 3/7/2008 9:32:33 PM | Attr = ] angel_2.psd -> %UserProfile%\My Documents\angel_2.psd -> [Ver = | Size = 6024892 bytes | Created Date = 3/8/2008 10:06:21 AM | Attr = ] angel_3.psd -> %UserProfile%\My Documents\angel_3.psd -> [Ver = | Size = 8142160 bytes | Created Date = 3/11/2008 8:04:30 PM | Attr = ] angel_4.psd -> %UserProfile%\My Documents\angel_4.psd -> [Ver = | Size = 8221929 bytes | Created Date = 3/12/2008 8:18:23 AM | Attr = ] CS Project -> %UserProfile%\My Documents\CS Project -> [Folder | Created Date = 2/15/2008 8:31:07 PM | Attr = ] Gem%20hunt(1).xls -> %UserProfile%\My Documents\Gem%20hunt(1).xls -> [Ver = | Size = 35840 bytes | Created Date = 3/12/2008 10:56:13 AM | Attr = ] Image8.jpg -> %UserProfile%\My Documents\Image8.jpg -> [Ver = | Size = 168876 bytes | Created Date = 3/15/2008 1:19:57 PM | Attr = ] Image8.pspimage -> %UserProfile%\My Documents\Image8.pspimage -> [Ver = | Size = 3146398 bytes | Created Date = 3/15/2008 1:20:05 PM | Attr = ] Kayla Gibson_howto.doc -> %UserProfile%\My Documents\Kayla Gibson_howto.doc -> [Ver = | Size = 24576 bytes | Created Date = 2/25/2008 12:22:15 PM | Attr = ] Krysta Gibson_DescriptiveParagraph.doc -> %UserProfile%\My Documents\Krysta Gibson_DescriptiveParagraph.doc -> [Ver = | Size = 24064 bytes | Created Date = 2/25/2008 2:13:55 PM | Attr = ] Michael.doc -> %UserProfile%\My Documents\Michael.doc -> [Ver = | Size = 26112 bytes | Created Date = 4/11/2008 7:55:13 AM | Attr = ] michael_resume.doc -> %UserProfile%\My Documents\michael_resume.doc -> [Ver = | Size = 21504 bytes | Created Date = 4/14/2008 3:15:32 PM | Attr = ] When Tomorrow Starts Without Me.doc -> %UserProfile%\My Documents\When Tomorrow Starts Without Me.doc -> [Ver = | Size = 24576 bytes | Created Date = 3/11/2008 6:54:16 PM | Attr = ] AVG Anti-Spyware.lnk -> %AllUsersProfile%\Desktop\AVG Anti-Spyware.lnk -> [Ver = | Size = 849 bytes | Created Date = 4/21/2008 10:57:10 AM | Attr = ] Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [Ver = | Size = 696 bytes | Created Date = 4/21/2008 11:41:44 AM | Attr = ] Board Games with Scott » BGWS 042 - World of Warcraft, the Boardgame.url -> %UserProfile%\Desktop\Board Games with Scott » BGWS 042 - World of Warcraft, the Boardgame.url -> [Ver = | Size = 226 bytes | Created Date = 2/15/2008 12:47:18 PM | Attr = ] DAZ -> %UserProfile%\Desktop\DAZ -> [Folder | Created Date = 4/16/2008 7:13:12 AM | Attr = ] GND2 -> %UserProfile%\Desktop\GND2 -> [Folder | Created Date = 4/19/2008 3:14:54 PM | Attr = ] JumbleStory.doc -> %UserProfile%\Desktop\JumbleStory.doc -> [Ver = | Size = 62976 bytes | Created Date = 2/25/2008 2:23:00 PM | Attr = ] NewsReport.mpg -> %UserProfile%\Desktop\NewsReport.mpg -> [Ver = | Size = 7316992 bytes | Created Date = 2/16/2008 2:56:09 PM | Attr = ] OTScanIt -> %UserProfile%\Desktop\OTScanIt -> [Folder | Created Date = 4/22/2008 3:24:02 AM | Attr = ] OTScanIt.exe -> %UserProfile%\Desktop\OTScanIt.exe -> [Ver = | Size = 542061 bytes | Created Date = 4/22/2008 3:23:19 AM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\OTScanIt.exe:Zone.Identifier ps_ac2218_PlacesSummerPs.exe -> %UserProfile%\Desktop\ps_ac2218_PlacesSummerPs.exe -> BitRock SL [Ver = 1,0,0,0 | Size = 43135505 bytes | Created Date = 3/26/2008 2:14:20 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\ps_ac2218_PlacesSummerPs.exe:Zone.Identifier Shortcut to Crusty.exe.lnk -> %UserProfile%\Desktop\Shortcut to Crusty.exe.lnk -> [Ver = | Size = 814 bytes | Created Date = 4/21/2008 10:53:48 AM | Attr = ] Untitled2.png -> %UserProfile%\Desktop\Untitled2.png -> [Ver = | Size = 201934 bytes | Created Date = 3/7/2008 8:25:10 PM | Attr = ] [Files/Folders - Modified Within 90 days] $VAULT$.AVG -> %SystemDrive%\$VAULT$.AVG -> [Folder | Modified Date = 4/21/2008 2:38:01 PM | Attr = RH ] boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 211 bytes | Modified Date = 4/10/2008 5:41:08 PM | Attr = RHS] Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 4/21/2008 12:18:29 PM | Attr = H ] Documents and Settings -> %SystemDrive%\Documents and Settings -> [Folder | Modified Date = 4/20/2008 2:42:59 PM | Attr = ] Logs -> %SystemDrive%\Logs -> [Folder | Modified Date = 3/25/2008 10:21:44 AM | Attr = ] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 4/21/2008 12:07:58 PM | Attr = ] System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 4/21/2008 2:53:57 PM | Attr = HS] TEMP -> %SystemDrive%\TEMP -> [Folder | Modified Date = 3/10/2008 6:25:59 PM | Attr = ] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 4/21/2008 12:04:16 PM | Attr = ] _OTMoveIt -> %SystemDrive%\_OTMoveIt -> [Folder | Modified Date = 4/22/2008 3:08:40 AM | Attr = ] AFS2K.SYS -> %SystemRoot%\System32\drivers\AFS2K.SYS -> Oak Technology Inc. [Ver = 3.1.14.886 | Size = 82380 bytes | Modified Date = 4/21/2008 12:18:24 PM | Attr = ] etc -> %SystemRoot%\System32\drivers\etc -> [Folder | Modified Date = 4/20/2008 10:24:17 PM | Attr = ] CatRoot2 -> %SystemRoot%\System32\CatRoot2 -> [Folder | Modified Date = 4/21/2008 2:57:51 PM | Attr = ] 10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> cjshkfad.exe -> %SystemRoot%\System32\cjshkfad.exe -> [Ver = | Size = 102400 bytes | Modified Date = 4/21/2008 5:19:58 AM | Attr = ] dllcache -> %SystemRoot%\System32\dllcache -> [Folder | Modified Date = 2/26/2008 4:40:51 PM | Attr = RHS] drivers -> %SystemRoot%\System32\drivers -> [Folder | Modified Date = 4/21/2008 12:18:25 PM | Attr = ] etwvglsf.exe -> %SystemRoot%\System32\etwvglsf.exe -> [Ver = | Size = 102400 bytes | Modified Date = 4/21/2008 6:50:02 AM | Attr = ] exyritet.exe -> %SystemRoot%\System32\exyritet.exe -> [Ver = | Size = 102400 bytes | Modified Date = 4/21/2008 5:49:59 AM | Attr = ] fmfcbodm.exe -> %SystemRoot%\System32\fmfcbodm.exe -> [Ver = | Size = 110592 bytes | Modified Date = 4/21/2008 3:38:19 AM | Attr = ] gtmlobmd.exe -> %SystemRoot%\System32\gtmlobmd.exe -> [Ver = | Size = 94208 bytes | Modified Date = 4/21/2008 11:37:12 AM | Attr = ] gtyvgbiz.exe -> %SystemRoot%\System32\gtyvgbiz.exe -> [Ver = | Size = 102400 bytes | Modified Date = 4/20/2008 7:46:07 PM | Attr = ] gvozulop.exe -> %SystemRoot%\System32\gvozulop.exe -> [Ver = | Size = 102400 bytes | Modified Date = 4/21/2008 9:07:06 AM | Attr = ] ibqlmvwd.exe -> %SystemRoot%\System32\ibqlmvwd.exe -> [Ver = | Size = 110592 bytes | Modified Date = 4/20/2008 8:46:08 PM | Attr = ] java.exe -> %SystemRoot%\System32\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 135168 bytes | Modified Date = 2/22/2008 2:23:35 AM | Attr = ] javacpl.cpl -> %SystemRoot%\System32\javacpl.cpl -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 69632 bytes | Modified Date = 2/22/2008 3:33:31 AM | Attr = ] javaw.exe -> %SystemRoot%\System32\javaw.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 135168 bytes | Modified Date = 2/22/2008 2:23:39 AM | Attr = ] javaws.exe -> %SystemRoot%\System32\javaws.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 139264 bytes | Modified Date = 2/22/2008 3:33:32 AM | Attr = ] jspijotm.exe -> %SystemRoot%\System32\jspijotm.exe -> [Ver = | Size = 110592 bytes | Modified Date = 4/20/2008 11:08:14 PM | Attr = ] khkvevkb.exe -> %SystemRoot%\System32\khkvevkb.exe -> [Ver = | Size = 94208 bytes | Modified Date = 4/21/2008 11:07:08 AM | Attr = ] lmbkrqju.exe -> %SystemRoot%\System32\lmbkrqju.exe -> [Ver = | Size = 110592 bytes | Modified Date = 4/21/2008 1:08:17 AM | Attr = ] LogFiles -> %SystemRoot%\System32\LogFiles -> [Folder | Modified Date = 4/21/2008 11:06:21 AM | Attr = ] lsjihcho.exe -> %SystemRoot%\System32\lsjihcho.exe -> [Ver = | Size = 110592 bytes | Modified Date = 4/21/2008 1:38:17 AM | Attr = ] ludkpsvu.exe -> %SystemRoot%\System32\ludkpsvu.exe -> [Ver = | Size = 110592 bytes | Modified Date = 4/21/2008 2:08:18 AM | Attr = ] lurifspq.exe -> %SystemRoot%\System32\lurifspq.exe -> [Ver = | Size = 110592 bytes | Modified Date = 4/21/2008 3:08:19 AM | Attr = ] mngbgzot.exe -> %SystemRoot%\System32\mngbgzot.exe -> [Ver = | Size = 110592 bytes | Modified Date = 4/20/2008 8:16:08 PM | Attr = ] nudunifw.exe -> %SystemRoot%\System32\nudunifw.exe -> [Ver = | Size = 110592 bytes | Modified Date = 4/21/2008 12:08:15 AM | Attr = ] nvapps.xml -> %SystemRoot%\System32\nvapps.xml -> [Ver = | Size = 50228 bytes | Modified Date = 4/22/2008 3:21:50 AM | Attr = ] ojcdcvkz.exe -> %SystemRoot%\System32\ojcdcvkz.exe -> [Ver = | Size = 102400 bytes | Modified Date = 4/20/2008 6:16:05 PM | Attr = ] perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [Ver = | Size = 59440 bytes | Modified Date = 4/9/2008 7:29:02 PM | Attr = ] perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [Ver = | Size = 395200 bytes | Modified Date = 4/9/2008 7:29:02 PM | Attr = ] PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [Ver = | Size = 462168 bytes | Modified Date = 4/9/2008 7:29:02 PM | Attr = ] pezqlotm.exe -> %SystemRoot%\System32\pezqlotm.exe -> [Ver = | Size = 110592 bytes | Modified Date = 4/21/2008 4:38:21 AM | Attr = ] Restore -> %SystemRoot%\System32\Restore -> [Folder | Modified Date = 4/21/2008 2:53:57 PM | Attr = ] svcp.csv -> %SystemRoot%\System32\svcp.csv -> [Ver = | Size = 0 bytes | Modified Date = 4/21/2008 4:56:17 AM | Attr = ] vefgrofm.exe -> %SystemRoot%\System32\vefgrofm.exe -> [Ver = | Size = 110592 bytes | Modified Date = 4/20/2008 11:38:14 PM | Attr = ] wlgzwnir.exe -> %SystemRoot%\System32\wlgzwnir.exe -> [Ver = | Size = 102400 bytes | Modified Date = 4/20/2008 7:16:06 PM | Attr = ] wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [Ver = | Size = 1374 bytes | Modified Date = 4/22/2008 3:16:38 AM | Attr = ] yjmxkzsv.exe -> %SystemRoot%\System32\yjmxkzsv.exe -> [Ver = | Size = 102400 bytes | Modified Date = 4/21/2008 6:20:00 AM | Attr = ] ypknidcj.exe -> %SystemRoot%\System32\ypknidcj.exe -> [Ver = | Size = 102400 bytes | Modified Date = 4/20/2008 6:46:06 PM | Attr = ] ypybwvmb.exe -> %SystemRoot%\System32\ypybwvmb.exe -> [Ver = | Size = 102400 bytes | Modified Date = 4/21/2008 8:20:08 AM | Attr = ] bctwvwhm.dll -> %SystemRoot%\bctwvwhm.dll -> [Ver = | Size = 65024 bytes | Modified Date = 4/20/2008 12:33:38 PM | Attr = ] bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 4/22/2008 3:15:54 AM | Attr = S] CMMIXER.INI -> %SystemRoot%\CMMIXER.INI -> [Ver = | Size = 101 bytes | Modified Date = 3/12/2008 1:50:58 PM | Attr = ] Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 4/21/2008 11:06:09 AM | Attr = ] 1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 4/20/2008 5:31:08 PM | Attr = S] ghcfuzef.dll -> %SystemRoot%\ghcfuzef.dll -> [Ver = | Size = 192512 bytes | Modified Date = 4/20/2008 12:33:39 PM | Attr = ] inf -> %SystemRoot%\inf -> [Folder | Modified Date = 4/20/2008 5:31:17 PM | Attr = H ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 4/21/2008 12:18:32 PM | Attr = HS] lexstat.ini -> %SystemRoot%\lexstat.ini -> [Ver = | Size = 894 bytes | Modified Date = 4/14/2008 3:21:35 PM | Attr = ] mainms.vpi -> %SystemRoot%\mainms.vpi -> [Ver = | Size = 138 bytes | Modified Date = 4/20/2008 12:33:18 PM | Attr = RHS] megavid.cdt -> %SystemRoot%\megavid.cdt -> [Ver = | Size = 4 bytes | Modified Date = 4/21/2008 8:34:43 AM | Attr = ] mgwwgmke -> %SystemRoot%\mgwwgmke -> [Folder | Modified Date = 4/20/2008 12:33:41 PM | Attr = ] mixerdef.ini -> %SystemRoot%\mixerdef.ini -> [Ver = | Size = 25 bytes | Modified Date = 2/26/2008 4:48:31 PM | Attr = ] muotr.so -> %SystemRoot%\muotr.so -> [Ver = | Size = 33 bytes | Modified Date = 4/21/2008 8:36:45 AM | Attr = RHS] NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [Ver = | Size = 116 bytes | Modified Date = 4/16/2008 4:17:08 PM | Attr = ] network diagnostic -> %SystemRoot%\network diagnostic -> [Folder | Modified Date = 3/26/2008 7:51:53 AM | Attr = ] OVT -> %SystemRoot%\OVT -> [Folder | Modified Date = 2/15/2008 8:20:02 PM | Attr = ] ovtcam -> %SystemRoot%\ovtcam -> [Folder | Modified Date = 2/15/2008 8:20:02 PM | Attr = ] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 4/20/2008 12:34:01 PM | Attr = ] security -> %SystemRoot%\security -> [Folder | Modified Date = 4/20/2008 2:43:21 PM | Attr = ] system -> %SystemRoot%\system -> [Folder | Modified Date = 2/26/2008 4:40:31 PM | Attr = ] system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 227 bytes | Modified Date = 4/10/2008 5:41:08 PM | Attr = ] system32 -> %SystemRoot%\system32 -> [Folder | Modified Date = 4/21/2008 12:18:23 PM | Attr = ] Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 4/22/2008 3:21:53 AM | Attr = ] win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 928 bytes | Modified Date = 4/10/2008 5:41:08 PM | Attr = ] Wininit.ini -> %SystemRoot%\Wininit.ini -> [Ver = | Size = 390 bytes | Modified Date = 4/20/2008 2:10:03 PM | Attr = ] Defrag Job #02.job -> %SystemRoot%\tasks\Defrag Job #02.job -> [Ver = | Size = 256 bytes | Modified Date = 4/19/2008 6:19:26 AM | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 4/20/2008 1:54:28 PM | Attr = H ] qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [Ver = | Size = 4232 bytes | Modified Date = 4/22/2008 12:19:47 AM | Attr = ] qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [Ver = | Size = 5486 bytes | Modified Date = 4/22/2008 12:19:47 AM | Attr = ] opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [Ver = | Size = 8206 bytes | Modified Date = 1/28/2006 11:43:32 PM | Attr = ] wkcalcat.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wkcalcat.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/30/2006 9:18:49 PM | Attr = ] CAGFS9GT.com%2Fsearch%3Fhl%3Den%26q%3Danimal%2Bcrossing%2Bwild%2Bworld%2Bturnips&cc=100&flash=9&u_h=1024&u_w=1280&u_ah=1024&u_aw=1280&u_cd=32&u_tz=-240&u_his=2&u_java=true -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\CAGFS9GT.com -> File not found imp[1].com%2Ffiles%2Fdetails%2F1233678%2F25344816%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\imp[1].com -> [Ver = | Size = 579 bytes | Modified Date = 7/4/2007 11:35:54 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1232690%2F3168102%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\imp[1].com -> [Ver = | Size = 589 bytes | Modified Date = 7/4/2007 11:36:10 AM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D0%26subcategory%3DAll%26quality%3DAll%26seeded%3D0%26external%3D2%26query%3Dposer%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\imp[1].com -> [Ver = | Size = 674 bytes | Modified Date = 7/4/2007 11:36:30 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1233439%2F28512918%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\imp[1].com -> [Ver = | Size = 1120 bytes | Modified Date = 7/4/2007 7:46:33 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1232301%2F3168102%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\imp[1].com -> [Ver = | Size = 589 bytes | Modified Date = 7/4/2007 7:55:13 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1230186%2F19008612%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\imp[1].com -> [Ver = | Size = 1122 bytes | Modified Date = 7/4/2007 8:02:10 AM | Attr = ] imp[1].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\imp[1].com -> [Ver = | Size = 1031 bytes | Modified Date = 7/4/2007 11:35:02 AM | Attr = ] imp[2].com%2Ffiles%2Fdetails%2F1233678%2F25344816%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\imp[2].com -> [Ver = | Size = 590 bytes | Modified Date = 7/4/2007 11:35:55 AM | Attr = ] pagetype=channel&subdomain=faqs.ign[1].com&random=1183467872290&PageId=1183467872290&property=ign®insider=a&tile=1183467896734 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\pagetype=channel&subdomain=faqs.ign -> [Ver = | Size = 863 bytes | Modified Date = 7/3/2007 9:04:56 AM | Attr = ] platform_id=653161&hosted_id=8300&network=fim®insider=a&subdomain=search.ign[1].com&PageId=1183467918352&random=1183467918352&property=ign&tile=1183467942953 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\platform_id=653161&hosted_id=8300&network=fim®insider=a&subdomain=search.ign -> [Ver = | Size = 930 bytes | Modified Date = 7/3/2007 9:05:43 AM | Attr = ] platform_id=653161&hosted_id=8300&network=fim®insider=a&subdomain=search.ign[1].com&PageId=1183468054146&random=1183468054146&property=ign&tile=1183468078625 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\platform_id=653161&hosted_id=8300&network=fim®insider=a&subdomain=search.ign -> [Ver = | Size = 1234 bytes | Modified Date = 7/3/2007 9:07:58 AM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D0%26subcategory%3D0%26quality%3D0%26seeded%3D0%26external%3D2%26query%3Dposer%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\imp[1].com -> [Ver = | Size = 670 bytes | Modified Date = 7/6/2007 12:51:49 PM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1236361%2F3168102%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\imp[1].com -> [Ver = | Size = 589 bytes | Modified Date = 7/5/2007 7:24:36 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fuid%3D0%26category%3D1%26subcategory%3D0%26language%3D1%26seeded%3D0%26quality%3D0%26external%3D2%26query%3D%26sort%3D%26page%3D3&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\imp[1].com -> [Ver = | Size = 691 bytes | Modified Date = 7/5/2007 7:28:57 PM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1201112%2F6336204%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\imp[1].com -> [Ver = | Size = 588 bytes | Modified Date = 7/6/2007 6:15:47 PM | Attr = ] imp[1].com%2Ffiles%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\imp[1].com -> [Ver = | Size = 559 bytes | Modified Date = 7/6/2007 6:03:57 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D3%26subcategory%3D0%26language%3D1%26quality%3D0%26seeded%3D0%26external%3D2%26query%3Dwinx%2Bclub%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\imp[1].com -> [Ver = | Size = 690 bytes | Modified Date = 7/6/2007 6:10:22 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D1%26subcategory%3D0%26language%3D1%26quality%3D0%26seeded%3D0%26external%3D2%26query%3D%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\imp[1].com -> [Ver = | Size = 669 bytes | Modified Date = 7/4/2007 7:01:54 PM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1234767%2F22176714%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\imp[1].com -> [Ver = | Size = 578 bytes | Modified Date = 7/4/2007 7:02:37 PM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1236285%2F15840510%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\imp[1].com -> [Ver = | Size = 1125 bytes | Modified Date = 7/5/2007 4:39:01 PM | Attr = ] imp[1].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\imp[1].com -> [Ver = | Size = 1027 bytes | Modified Date = 7/5/2007 7:23:55 PM | Attr = ] imp[2].com%2Ffiles%2F%3Fcategory%3D1%26subcategory%3D0%26language%3D1%26quality%3D0%26seeded%3D0%26external%3D2%26query%3D%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\imp[2].com -> [Ver = | Size = 670 bytes | Modified Date = 7/4/2007 7:03:39 PM | Attr = ] imp[2].com%2Ffiles%2F%3Fcategory%3D0%26subcategory%3D0%26quality%3D0%26seeded%3D0%26external%3D2%26query%3Dposer%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\imp[2].com -> [Ver = | Size = 1335 bytes | Modified Date = 7/6/2007 12:52:40 PM | Attr = ] log[1].com&guid=0ED2E34B-9F27-4C50-ADB0-0E8CFE10DC14&sf= -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\log[1].com -> [Ver = | Size = 1 bytes | Modified Date = 7/5/2007 7:34:40 PM | Attr = ] imp[1].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\imp[1].com -> [Ver = | Size = 551 bytes | Modified Date = 7/7/2007 11:28:06 AM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D1%26subcategory%3D0%26language%3D1%26quality%3D0%26seeded%3D0%26external%3D2%26query%3D%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\imp[1].com -> [Ver = | Size = 680 bytes | Modified Date = 7/7/2007 11:31:12 AM | Attr = ] imp[2].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\imp[2].com -> [Ver = | Size = 550 bytes | Modified Date = 7/7/2007 1:42:28 PM | Attr = ] imp[3].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\imp[3].com -> [Ver = | Size = 1027 bytes | Modified Date = 7/7/2007 1:42:30 PM | Attr = ] 52 C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\*.tmp files -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\*.tmp -> CAYL8JCN.com%2Fsearch%3Fhl%3Den%26q%3Danimal%2Bcrossing%2Bwild%2Bworld%2Bglitches&cc=100&flash=9&u_h=1024&u_w=1280&u_ah=1024&u_aw=1280&u_cd=32&u_tz=-240&u_his=6&u_java=true -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT6NS5MZ\CAYL8JCN.com -> File not found imp[1].com%2Ffiles%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT6NS5MZ\imp[1].com -> [Ver = | Size = 559 bytes | Modified Date = 7/4/2007 7:37:48 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1233351%2F3168102%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT6NS5MZ\imp[1].com -> [Ver = | Size = 588 bytes | Modified Date = 7/4/2007 7:47:52 AM | Attr = ] imp[1].com%2Ffiles%2F%3Fuid%3D0%26category%3D1%26subcategory%3D0%26language%3D1%26seeded%3D0%26quality%3D0%26external%3D2%26query%3D%26sort%3D%26page%3D3&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT6NS5MZ\imp[1].com -> [Ver = | Size = 1395 bytes | Modified Date = 7/4/2007 7:49:13 AM | Attr = ] imp[2].com%2Ffiles%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT6NS5MZ\imp[2].com -> [Ver = | Size = 549 bytes | Modified Date = 7/4/2007 11:35:13 AM | Attr = ] pagetype=channel&subdomain=ds.ign[1].com&random=1183467881493&PageId=1183467881493&property=ign®insider=a&tile=1183467905937 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT6NS5MZ\pagetype=channel&subdomain=ds.ign -> [Ver = | Size = 873 bytes | Modified Date = 7/3/2007 9:05:06 AM | Attr = ] platform_id=653161&hosted_id=8300&network=fim&src=wrapper®insider=a&subdomain=search.ign[1].com&name=ATAtracker&PageId=1183467915071&random=1183467915071&ct=js&property=ign& -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT6NS5MZ\platform_id=653161&hosted_id=8300&network=fim&src=wrapper®insider=a&subdomain=search.ign -> File not found r=http%253A%252F%252Ffaqs.ign[1].com&network_id=12&name=ATAtracker&PageId=1183467879828&random=1183467879828&ct=js&r=http$3A$2F$2Ffaqs$2Eign$2Ecom$2F&property=ign& -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT6NS5MZ\r=http%253A%252F%252Ffaqs.ign -> [Ver = | Size = 2 bytes | Modified Date = 7/3/2007 9:05:05 AM | Attr = ] imp[1].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\HKH10Q01\imp[1].com -> [Ver = | Size = 1027 bytes | Modified Date = 7/7/2007 11:28:05 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1237031%2F3168102%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\HKH10Q01\imp[1].com -> [Ver = | Size = 589 bytes | Modified Date = 7/7/2007 11:30:35 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1231357%2F22176714%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\HKH10Q01\imp[1].com -> [Ver = | Size = 590 bytes | Modified Date = 7/7/2007 1:44:21 PM | Attr = ] log[1].com&guid=D15B3518-BF2A-4808-86F8-C02D03ED2826&sf= -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\HKH10Q01\log[1].com -> [Ver = | Size = 1 bytes | Modified Date = 7/8/2007 4:17:15 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D0%26subcategory%3D0%26quality%3D0%26seeded%3D0%26external%3D2%26query%3Dbratz%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\imp[1].com -> [Ver = | Size = 670 bytes | Modified Date = 7/6/2007 6:14:10 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fuid%3D0%26category%3D1%26subcategory%3D0%26language%3D1%26seeded%3D0%26quality%3D0%26external%3D2%26query%3D%26sort%3D%26page%3D3&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\imp[1].com -> [Ver = | Size = 1391 bytes | Modified Date = 7/4/2007 7:06:44 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D1%26subcategory%3D0%26language%3D1%26quality%3D0%26seeded%3D0%26external%3D2%26query%3D%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\imp[1].com -> [Ver = | Size = 680 bytes | Modified Date = 7/5/2007 7:24:48 PM | Attr = ] imp[1].com%2Ffiles%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\imp[1].com -> [Ver = | Size = 1052 bytes | Modified Date = 7/6/2007 6:03:59 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D3%26subcategory%3D0%26language%3D1%26quality%3D0%26seeded%3D0%26external%3D2%26query%3Dwinx%2Bclub%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\imp[1].com -> [Ver = | Size = 691 bytes | Modified Date = 7/6/2007 6:13:11 PM | Attr = ] imp[2].com%2Ffiles%2F%3Fcategory%3D1%26subcategory%3D0%26language%3D1%26quality%3D0%26seeded%3D0%26external%3D2%26query%3D%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\imp[2].com -> [Ver = | Size = 680 bytes | Modified Date = 7/5/2007 7:24:48 PM | Attr = ] imp[3].com%2Ffiles%2F%3Fcategory%3D1%26subcategory%3D0%26language%3D1%26quality%3D0%26seeded%3D0%26external%3D2%26query%3D%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\imp[3].com -> [Ver = | Size = 1360 bytes | Modified Date = 7/6/2007 12:49:35 PM | Attr = ] log[1].com&guid=DF102D50-61EA-40E0-A660-425C000E5EDC&sf= -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\log[1].com -> [Ver = | Size = 1 bytes | Modified Date = 7/5/2007 7:41:28 PM | Attr = ] log[1].com&guid=3F4C4D21-E6BB-4828-ABE6-458CB7CA2F7B&sf= -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\log[1].com -> [Ver = | Size = 1 bytes | Modified Date = 7/5/2007 7:41:36 PM | Attr = ] CA63G9AF.com%2Fsearch%3Fhl%3Den%26q%3Danimal%2Bcrossing%2Bwild%2Bworld%2Bglitches&cc=100&flash=9&u_h=1024&u_w=1280&u_ah=1024&u_aw=1280&u_cd=32&u_tz=-240&u_his=6&u_java=true -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\CA63G9AF.com -> File not found CAV7IWVX.com%2Fsearch%3Fhl%3Den%26q%3Danimal%2Bcrossing%2Bwild%2Bworld%2Bturnips&cc=100&flash=9&u_h=1024&u_w=1280&u_ah=1024&u_aw=1280&u_cd=32&u_tz=-240&u_his=2&u_java=true -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\CAV7IWVX.com -> File not found hosted_id=7598&network=fim&src=wrapper&channel_id=237®insider=a&subdomain=faqs.ign[1].com&name=ATAtracker&PageId=1183552734937&random=1183552734937&ct=js&property=ign& -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\hosted_id=7598&network=fim&src=wrapper&channel_id=237®insider=a&subdomain=faqs.ign -> File not found imp[1].com%2Ffiles%2Fdetails%2F1230723%2F9504306%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\imp[1].com -> [Ver = | Size = 1120 bytes | Modified Date = 7/4/2007 8:00:29 AM | Attr = ] imp[1].com%2Ffiles%2F%3Fuid%3D0%26category%3D1%26subcategory%3D0%26language%3D1%26seeded%3D0%26quality%3D0%26external%3D2%26query%3D%26sort%3D%26page%3D2&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\imp[1].com -> [Ver = | Size = 1390 bytes | Modified Date = 7/4/2007 7:48:15 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1232796%2F19008612%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\imp[1].com -> [Ver = | Size = 1121 bytes | Modified Date = 7/4/2007 7:50:21 AM | Attr = ] imp[1].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\imp[1].com -> [Ver = | Size = 1028 bytes | Modified Date = 7/4/2007 7:36:22 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1231283%2F9504306%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\imp[1].com -> [Ver = | Size = 1123 bytes | Modified Date = 7/4/2007 7:41:59 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1231283%2F%3Fshow_files%3D%26page%3D1&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\imp[1].com -> [Ver = | Size = 1173 bytes | Modified Date = 7/4/2007 7:42:20 AM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D1%26subcategory%3DAll%26language%3D1%26quality%3DAll%26seeded%3D0%26external%3D2%26query%3D%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\imp[1].com -> [Ver = | Size = 1370 bytes | Modified Date = 7/4/2007 7:45:50 AM | Attr = ] imp[2].com%2Ffiles%2F%3Fcategory%3D1%26subcategory%3DAll%26language%3D1%26quality%3DAll%26seeded%3D0%26external%3D2%26query%3D4400%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\imp[2].com -> [Ver = | Size = 676 bytes | Modified Date = 7/4/2007 7:38:34 AM | Attr = ] imp[2].com%2Ffiles%2Fdetails%2F1232796%2F19008612%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\imp[2].com -> [Ver = | Size = 1122 bytes | Modified Date = 7/4/2007 7:50:21 AM | Attr = ] imp[2].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\imp[2].com -> [Ver = | Size = 1026 bytes | Modified Date = 7/4/2007 7:53:59 AM | Attr = ] imp[3].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\imp[3].com -> [Ver = | Size = 1031 bytes | Modified Date = 7/4/2007 7:53:59 AM | Attr = ] log[1].com&guid=A877491C-3505-496A-A5F0-18EDAC97C3BF&sf= -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\log[1].com -> [Ver = | Size = 1 bytes | Modified Date = 7/3/2007 2:56:55 PM | Attr = ] pagetype=channel&subdomain=faqs.ign[1].com&random=1183552747320&PageId=1183552747320&property=ign®insider=a&tile=1183552774437 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\pagetype=channel&subdomain=faqs.ign -> [Ver = | Size = 845 bytes | Modified Date = 7/4/2007 8:39:34 AM | Attr = ] platform_id=653161&hosted_id=8300&network=fim®insider=a&subdomain=search.ign[1].com&PageId=1183467917367&random=1183467917367&property=ign&tile=1183467941812 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\platform_id=653161&hosted_id=8300&network=fim®insider=a&subdomain=search.ign -> [Ver = | Size = 5188 bytes | Modified Date = 7/3/2007 9:05:41 AM | Attr = ] platform_id=653161&hosted_id=8300&network=fim®insider=a&subdomain=search.ign[1].com&PageId=1183467917852&random=1183467917852&property=ign&tile=1183467942265 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\platform_id=653161&hosted_id=8300&network=fim®insider=a&subdomain=search.ign -> [Ver = | Size = 955 bytes | Modified Date = 7/3/2007 9:05:42 AM | Attr = ] platform_id=653161&hosted_id=8300&network=fim®insider=a&subdomain=search.ign[1].com&PageId=1183468055287&random=1183468055287&property=ign&tile=1183468079968 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\platform_id=653161&hosted_id=8300&network=fim®insider=a&subdomain=search.ign -> [Ver = | Size = 930 bytes | Modified Date = 7/3/2007 9:08:00 AM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D0%26subcategory%3DAll%26quality%3DAll%26seeded%3D0%26external%3D2%26query%3Dposer%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\OFAHGX0M\imp[1].com -> [Ver = | Size = 1341 bytes | Modified Date = 7/7/2007 11:30:28 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1237031%2F3168102%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\OFAHGX0M\imp[1].com -> [Ver = | Size = 589 bytes | Modified Date = 7/7/2007 11:30:36 AM | Attr = ] 52 C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\OFAHGX0M\*.tmp files -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\OFAHGX0M\*.tmp -> imp[1].com%2Ffiles%2Fdetails%2F1217921%2F3168102%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\R41PFKWW\imp[1].com -> [Ver = | Size = 589 bytes | Modified Date = 7/6/2007 12:52:10 PM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1236993%2F9504306%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\R41PFKWW\imp[1].com -> [Ver = | Size = 589 bytes | Modified Date = 7/6/2007 6:17:34 PM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1201112%2F6336204%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\R41PFKWW\imp[1].com -> [Ver = | Size = 1123 bytes | Modified Date = 7/6/2007 6:15:52 PM | Attr = ] imp[1].com%2Ffiles%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\R41PFKWW\imp[1].com -> [Ver = | Size = 559 bytes | Modified Date = 7/6/2007 6:09:44 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D0%26subcategory%3DAll%26quality%3DAll%26seeded%3D0%26external%3D2%26query%3Dwinx%2Bclub%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\R41PFKWW\imp[1].com -> [Ver = | Size = 680 bytes | Modified Date = 7/6/2007 6:09:55 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D1%26subcategory%3D0%26language%3D1%26quality%3D0%26seeded%3D0%26external%3D2%26query%3D%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\R41PFKWW\imp[1].com -> [Ver = | Size = 1361 bytes | Modified Date = 7/4/2007 7:02:01 PM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1235770%2F3168102%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\R41PFKWW\imp[1].com -> [Ver = | Size = 1123 bytes | Modified Date = 7/5/2007 7:26:45 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fuid%3D0%26category%3D1%26subcategory%3D0%26language%3D1%26seeded%3D0%26quality%3D0%26external%3D2%26query%3D%26sort%3D%26page%3D2&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\R41PFKWW\imp[1].com -> [Ver = | Size = 691 bytes | Modified Date = 7/6/2007 12:50:14 PM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1218090%2F3168102%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\R41PFKWW\imp[1].com -> [Ver = | Size = 589 bytes | Modified Date = 7/6/2007 12:50:57 PM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1217921%2F3168102%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[1].com -> [Ver = | Size = 1119 bytes | Modified Date = 7/6/2007 12:52:09 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D0%26subcategory%3D0%26quality%3D0%26seeded%3D0%26external%3D2%26query%3Dposer%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[1].com -> [Ver = | Size = 670 bytes | Modified Date = 7/6/2007 12:51:49 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fuid%3D0%26category%3D1%26subcategory%3D0%26language%3D1%26seeded%3D0%26quality%3D0%26external%3D2%26query%3D%26sort%3D%26page%3D4&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[1].com -> [Ver = | Size = 1394 bytes | Modified Date = 7/5/2007 7:29:18 PM | Attr = ] imp[1].com%2Ffiles%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[1].com -> [Ver = | Size = 558 bytes | Modified Date = 7/6/2007 12:49:25 PM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1059999%2F28512918%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[1].com -> [Ver = | Size = 1121 bytes | Modified Date = 7/6/2007 6:10:42 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D3%26subcategory%3D0%26language%3D1%26quality%3D0%26seeded%3D0%26external%3D2%26query%3Dwinx%2Bclub%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[1].com -> [Ver = | Size = 691 bytes | Modified Date = 7/6/2007 6:13:12 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fuid%3D0%26category%3D1%26subcategory%3D0%26language%3D1%26seeded%3D0%26quality%3D0%26external%3D2%26query%3D%26sort%3D%26page%3D3&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[1].com -> [Ver = | Size = 1391 bytes | Modified Date = 7/4/2007 7:06:48 PM | Attr = ] imp[1].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[1].com -> [Ver = | Size = 1028 bytes | Modified Date = 7/5/2007 4:37:51 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D0%26subcategory%3DAll%26quality%3DAll%26seeded%3D0%26external%3D2%26query%3Dposer%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[1].com -> [Ver = | Size = 674 bytes | Modified Date = 7/5/2007 4:39:33 PM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D1%26subcategory%3D0%26language%3D1%26quality%3D0%26seeded%3D0%26external%3D2%26query%3D%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[1].com -> [Ver = | Size = 680 bytes | Modified Date = 7/5/2007 7:24:07 PM | Attr = ] imp[2].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[2].com -> [Ver = | Size = 551 bytes | Modified Date = 7/5/2007 4:37:51 PM | Attr = ] imp[2].com%2Ffiles%2F%3Fcategory%3D0%26subcategory%3D0%26quality%3D0%26seeded%3D0%26external%3D2%26query%3Dposer%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[2].com -> [Ver = | Size = 1332 bytes | Modified Date = 7/6/2007 12:52:40 PM | Attr = ] imp[3].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\imp[3].com -> [Ver = | Size = 551 bytes | Modified Date = 7/6/2007 12:49:20 PM | Attr = ] log[1].com&guid=9AEBB500-88AA-408C-A6C1-3E744D71508D&sf= -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\log[1].com -> [Ver = | Size = 1 bytes | Modified Date = 7/5/2007 9:13:23 PM | Attr = ] CAPAN5XQ.com%2Fthe-4400-season-4%2F&cc=100&flash=9&u_h=1024&u_w=1280&u_ah=1024&u_aw=1280&u_cd=32&u_tz=-240&u_his=9&u_java=true -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\CAPAN5XQ.com -> [Ver = | Size = 2858 bytes | Modified Date = 7/3/2007 3:14:50 PM | Attr = ] CAUP6L4H.com%2Ftag%2Fthe%2B4400%2Bseason%2B4&cc=100&flash=9&u_h=1024&u_w=1280&u_ah=1024&u_aw=1280&u_cd=32&u_tz=-240&u_his=10&u_java=true -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\CAUP6L4H.com -> [Ver = | Size = 2937 bytes | Modified Date = 7/3/2007 3:15:03 PM | Attr = ] hosted_id=7598&network=fim&src=wrapper&channel_id=237®insider=a&subdomain=faqs.ign[1].com&name=ATAtracker&PageId=1183467869188&random=1183467869188&ct=js&property=ign& -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\hosted_id=7598&network=fim&src=wrapper&channel_id=237®insider=a&subdomain=faqs.ign -> File not found imp[1].com%2Ffiles%2F%3Fuid%3D0%26category%3D3%26subcategory%3D0%26language%3D1%26seeded%3D0%26quality%3D0%26external%3D2%26query%3D%26sort%3D%26page%3D3&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\imp[1].com -> [Ver = | Size = 1395 bytes | Modified Date = 7/4/2007 11:38:39 AM | Attr = ] imp[1].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\imp[1].com -> [Ver = | Size = 551 bytes | Modified Date = 7/4/2007 7:36:22 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1230723%2F9504306%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\imp[1].com -> [Ver = | Size = 588 bytes | Modified Date = 7/4/2007 8:00:27 AM | Attr = ] imp[1].com%2Ffiles%2F%3Fuid%3D0%26category%3D4%26subcategory%3D166%26language%3D1%26seeded%3D0%26quality%3D0%26external%3D2%26query%3D%26sort%3D%26page%3D2&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\imp[1].com -> [Ver = | Size = 692 bytes | Modified Date = 7/4/2007 8:02:37 AM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D0%26subcategory%3DAll%26quality%3DAll%26seeded%3D0%26external%3D2%26query%3Dposer%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\imp[1].com -> [Ver = | Size = 663 bytes | Modified Date = 7/4/2007 11:35:29 AM | Attr = ] imp[2].com%2Ffiles%2F%3Fuid%3D0%26category%3D4%26subcategory%3D166%26language%3D1%26seeded%3D0%26quality%3D0%26external%3D2%26query%3D%26sort%3D%26page%3D2&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\imp[2].com -> [Ver = | Size = 1396 bytes | Modified Date = 7/4/2007 8:02:40 AM | Attr = ] imp[2].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\imp[2].com -> [Ver = | Size = 551 bytes | Modified Date = 7/4/2007 11:35:02 AM | Attr = ] imp[2].com%2Ffiles%2F%3Fcategory%3D0%26subcategory%3DAll%26quality%3DAll%26seeded%3D0%26external%3D2%26query%3Dposer%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\imp[2].com -> [Ver = | Size = 675 bytes | Modified Date = 7/4/2007 11:36:00 AM | Attr = ] imp[3].com%2Ffiles%2F%3Fcategory%3D0%26subcategory%3DAll%26quality%3DAll%26seeded%3D0%26external%3D2%26query%3Dposer%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\imp[3].com -> [Ver = | Size = 662 bytes | Modified Date = 7/4/2007 11:36:00 AM | Attr = ] log[1].com&guid=AF87059C-A8E6-480C-AF41-952B287134A6&sf= -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\log[1].com -> [Ver = | Size = 1 bytes | Modified Date = 7/3/2007 5:51:45 PM | Attr = ] platform_id=653161&hosted_id=8300&network=fim&src=wrapper®insider=a&subdomain=search.ign[1].com&name=ATAtracker&PageId=1183468053662&random=1183468053662&ct=js&property=ign& -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\platform_id=653161&hosted_id=8300&network=fim&src=wrapper®insider=a&subdomain=search.ign -> File not found platform_id=653161&hosted_id=8300&network=fim®insider=a&subdomain=search.ign[1].com&PageId=1183468054833&random=1183468054833&property=ign&tile=1183468079390 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\platform_id=653161&hosted_id=8300&network=fim®insider=a&subdomain=search.ign -> [Ver = | Size = 955 bytes | Modified Date = 7/3/2007 9:07:59 AM | Attr = ] imp[1].com%2Ffiles%2Fdetails%2F1231357%2F22176714%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\YCS1M4XF\imp[1].com -> [Ver = | Size = 590 bytes | Modified Date = 7/7/2007 1:44:21 PM | Attr = ] imp[1].com%2F&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\YCS1M4XF\imp[1].com -> [Ver = | Size = 1028 bytes | Modified Date = 7/9/2007 7:06:52 AM | Attr = ] imp[1].com%2Ffiles%2F%3Fcategory%3D4%26subcategory%3D166%26language%3D1%26quality%3D0%26seeded%3D0%26external%3D2%26query%3D%26uid%3D0%26sort%3D&r=0 -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\YCS1M4XF\imp[1].com -> [Ver = | Size = 683 bytes | Modified Date = 7/9/2007 7:07:27 AM | Attr = ] 52 C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\YCS1M4XF\*.tmp files -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\YCS1M4XF\*.tmp -> AutoDL%3FBundleId=10750_b1977f85.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\AutoDL%3FBundleId=10750_b1977f85.exe -> Sun Microsystems, Inc. [Ver = 5.0.90.3 | Size = 251656 bytes | Modified Date = 10/16/2006 4:10:33 PM | Attr = ] AutoRun.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\AutoRun.exe -> Electronic Arts Inc. [Ver = 1.08.00.432 | Size = 724992 bytes | Modified Date = 2/4/2006 5:33:04 AM | Attr = ] bbnew.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\bbnew.exe -> Microsoft [Ver = 1.00.0003 | Size = 35848 bytes | Modified Date = 4/20/2008 12:33:09 PM | Attr = ] dlc.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\dlc.exe -> [Ver = | Size = 86016 bytes | Modified Date = 9/13/2005 2:38:25 PM | Attr = ] eauninstall.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\eauninstall.exe -> Electronic Arts Inc. [Ver = 1.08.00.432 | Size = 344064 bytes | Modified Date = 2/4/2006 5:33:04 AM | Attr = ] eon_uninst_101.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\eon_uninst_101.exe -> [Ver = 1, 0, 0, 1 | Size = 225280 bytes | Modified Date = 1/31/2006 10:37:25 AM | Attr = ] FFTB-REAL_signed.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\FFTB-REAL_signed.exe -> [Ver = | Size = 6871480 bytes | Modified Date = 9/17/2007 3:10:36 PM | Attr = ] GDSSetup.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\GDSSetup.exe -> [Ver = | Size = 743016 bytes | Modified Date = 2/3/2008 4:44:17 PM | Attr = ] GoogleInstApp.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\GoogleInstApp.exe -> RealNetworks [Ver = 1.0.0.926 | Size = 2364704 bytes | Modified Date = 10/17/2007 7:15:48 PM | Attr = ] hpzmsi01.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\hpzmsi01.exe -> Hewlett-Packard [Ver = 5,3,0,75 | Size = 1130496 bytes | Modified Date = 4/27/2005 3:01:55 PM | Attr = ] hpzscr01.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\hpzscr01.exe -> Hewlett-Packard [Ver = 5,3,0,75 | Size = 790528 bytes | Modified Date = 4/27/2005 3:05:09 PM | Attr = ] mlsA90.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\mlsA90.exe -> [Ver = 1.0.0.0.0 | Size = 252819 bytes | Modified Date = 7/18/2007 12:52:49 PM | Attr = ] mplayerc.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\mplayerc.exe -> Gabest [Ver = 6, 4, 9, 0 | Size = 5689344 bytes | Modified Date = 3/20/2006 3:37:52 PM | Attr = ] RCT3WILD_ANY-UPDATE2_USA.EXE -> C:\Documents and Settings\Boo\Local Settings\Temp\RCT3WILD_ANY-UPDATE2_USA.EXE -> ATARI, Inc. [Ver = 1, 0, 0, 1 | Size = 17872151 bytes | Modified Date = 11/25/2007 8:59:25 PM | Attr = ] setup_wm.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\setup_wm.exe -> Microsoft Corporation [Ver = 10.00.00.3646 | Size = 819200 bytes | Modified Date = 9/22/2004 6:46:04 PM | Attr = ] The Battle for Middle-earth II_uninst.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\The Battle for Middle-earth II_uninst.exe -> Electronic Arts Inc. [Ver = 1.05.04.00 | Size = 73728 bytes | Modified Date = 1/3/2006 11:54:47 PM | Attr = ] unhelper.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\unhelper.exe -> GameHouse [Ver = 1, 0, 0, 1 | Size = 102400 bytes | Modified Date = 6/5/2007 6:39:52 PM | Attr = ] war3_Install.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\war3_Install.exe -> Blizzard Entertainment [Ver = 1, 0, 0, 0 | Size = 294912 bytes | Modified Date = 6/7/2002 3:08:56 PM | Attr = ] 100 C:\Documents and Settings\Boo\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Boo\Local Settings\Temp\*.tmp -> DivXInstaller.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\Div1.tmp\DivXInstaller.exe -> DivX, Inc. [Ver = 6.8.0.4 | Size = 17625224 bytes | Modified Date = 12/26/2007 5:37:16 PM | Attr = ] DivXInstaller.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\DivBD.tmp\DivXInstaller.exe -> DivX, Inc. [Ver = 1.0.0.299 | Size = 21736784 bytes | Modified Date = 6/8/2007 6:13:55 PM | Attr = ] HP_CounterReport_Update.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\HPSU63K_.I07\HP_CounterReport_Update.exe -> [Ver = | Size = 288416 bytes | Modified Date = 11/13/2006 2:44:48 PM | Attr = ] hprbupdatepatch.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\HPSUGJYN.DJ1\hprbupdatepatch.exe -> Hewlett-Packard Company [Ver = 82.0.0.0 | Size = 113776 bytes | Modified Date = 11/13/2006 2:48:28 PM | Attr = ] hprbUpdate.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\HPSUGJYN.DJ1\signed\hprbUpdate.exe -> Hewlett-Packard Co. [Ver = 82.0.00.000 | Size = 50744 bytes | Modified Date = 6/12/2006 4:30:13 PM | Attr = ] hprbupdatep.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\HPSUGJYN.DJ1\signed\hprbupdatep.exe -> [Ver = | Size = 112184 bytes | Modified Date = 6/16/2006 5:29:03 PM | Attr = ] HPPSE1.9.1.3-2ENU.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\HPSUOGU_.3KX\HPPSE1.9.1.3-2ENU.exe -> Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 5649544 bytes | Modified Date = 11/13/2006 2:46:20 PM | Attr = ] shfolder.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\is-VDLTS.tmp\shfolder.exe -> Microsoft Corporation [Ver = 5.50.4027.300 | Size = 117288 bytes | Modified Date = 3/10/2004 7:34:20 PM | Attr = ] umdf.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\IXP000.TMP\umdf.exe -> Microsoft Corporation [Ver = 6.1.0022.4 (SRV03_QFE.031113-0918) | Size = 753960 bytes | Modified Date = 10/1/2006 6:00:50 PM | Attr = ] WindowsXP-MSCompPackV1-x86.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\IXP000.TMP\WindowsXP-MSCompPackV1-x86.exe -> Microsoft Corporation [Ver = 6.1.0022.4 (SRV03_QFE.031113-0918) | Size = 596288 bytes | Modified Date = 10/2/2006 6:04:46 PM | Attr = ] wmfdist11.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\IXP000.TMP\wmfdist11.exe -> Microsoft Corporation [Ver = 6.1.0022.4 (SRV03_QFE.031113-0918) | Size = 9824584 bytes | Modified Date = 11/2/2006 12:59:24 PM | Attr = ] wmp11.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\IXP000.TMP\wmp11.exe -> Microsoft Corporation [Ver = 6.1.0022.4 (SRV03_QFE.031113-0918) | Size = 12780344 bytes | Modified Date = 11/2/2006 1:18:24 PM | Attr = ] wmpappcompat.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\IXP000.TMP\wmpappcompat.exe -> Microsoft Corporation [Ver = 2 | Size = 897848 bytes | Modified Date = 10/4/2006 9:00:44 PM | Attr = ] uninstall.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\nstmp\uninstall.exe -> mozilla.org [Ver = 1, 0, 0, 2 | Size = 86678 bytes | Modified Date = 9/18/2006 10:12:59 PM | Attr = ] uninstall.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\nstmp1\uninstall.exe -> mozilla.org [Ver = 1, 0, 0, 2 | Size = 86678 bytes | Modified Date = 6/2/2006 9:31:49 PM | Attr = ] SETUP.EXE -> C:\Documents and Settings\Boo\Local Settings\Temp\pft52C~tmp\SETUP.EXE -> InstallShield Software Corporation [Ver = 5.10.146.0 | Size = 60416 bytes | Modified Date = 1/22/1998 11:08:28 PM | Attr = R ] _ISDEL.EXE -> C:\Documents and Settings\Boo\Local Settings\Temp\pft52C~tmp\_ISDEL.EXE -> InstallShield Software Corporation [Ver = 5.10.146.0 | Size = 8704 bytes | Modified Date = 1/27/1998 3:07:44 PM | Attr = R ] InstallRiseOfAtlantis[1].exe -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KTQ30LUB\InstallRiseOfAtlantis[1].exe -> [Ver = | Size = 22083856 bytes | Modified Date = 6/29/2007 7:09:42 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Local Settings\Temp\Temporary Internet Files\Content.IE5\KTQ30LUB\InstallRiseOfAtlantis[1].exe:Zone.Identifier WMPAU.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\WMC0000.tmp\WMPAU.exe -> Microsoft Corporation [Ver = 11.0.5721.5146 (WMP_11.061018-2006) | Size = 1669120 bytes | Modified Date = 11/1/2006 7:31:38 PM | Attr = ] dxsetup.exe -> C:\Documents and Settings\Boo\Local Settings\Temp\ZT2_PDLC\DirectX\dxsetup.exe -> Microsoft Corporation [Ver = 4.9.0.0904 | Size = 484560 bytes | Modified Date = 10/15/2006 8:11:04 AM | Attr = ] AutoRunGUI.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\AutoRunGUI.dll -> Electronic Arts Inc. [Ver = 1.08.00.00 | Size = 942080 bytes | Modified Date = 1/30/2006 10:56:47 PM | Attr = ] BarControl.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\BarControl.dll -> Google, Inc [Ver = 1.0.0.8 | Size = 94208 bytes | Modified Date = 2/3/2008 4:44:17 PM | Attr = ] fftbapi.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\fftbapi.dll -> [Ver = | Size = 50688 bytes | Modified Date = 9/17/2007 3:10:36 PM | Attr = ] GoogleToolbar.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\GoogleToolbar.dll -> Google Inc. [Ver = 2, 0, 110, 0 | Size = 745472 bytes | Modified Date = 2/3/2008 4:44:17 PM | Attr = ] INST01.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\INST01.dll -> [Ver = | Size = 131072 bytes | Modified Date = 7/22/2005 11:44:10 AM | Attr = ] INST011.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\INST011.dll -> [Ver = | Size = 53248 bytes | Modified Date = 6/27/2002 6:32:28 PM | Attr = ] mpegc.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\mpegc.dll -> [Ver = | Size = 56832 bytes | Modified Date = 12/20/1999 8:04:50 AM | Attr = R ] msvcp60.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\msvcp60.dll -> Microsoft Corporation [Ver = 6.00.8168.0 | Size = 401462 bytes | Modified Date = 12/17/2006 9:07:57 AM | Attr = ] SIntf16.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\SIntf16.dll -> [Ver = | Size = 12305 bytes | Modified Date = 11/25/2007 9:10:43 PM | Attr = ] SIntf32.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\SIntf32.dll -> [Ver = | Size = 20016 bytes | Modified Date = 11/25/2007 9:10:43 PM | Attr = ] SIntfNT.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\SIntfNT.dll -> [Ver = | Size = 24744 bytes | Modified Date = 11/25/2007 9:10:43 PM | Attr = ] SWFXXLRT.DLL -> C:\Documents and Settings\Boo\Local Settings\Temp\SWFXXLRT.DLL -> [Ver = | Size = 45056 bytes | Modified Date = 12/16/2007 6:44:25 PM | Attr = ] twapi-2.0a2.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\twapi-2.0a2.dll -> Ashok P. Nadkarni [Ver = 2.0.2 | Size = 409692 bytes | Modified Date = 6/1/2007 2:08:10 PM | Attr = ] twapi-2.0a7.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\twapi-2.0a7.dll -> Ashok P. Nadkarni [Ver = 2.0.7 | Size = 417884 bytes | Modified Date = 12/5/2007 5:19:59 AM | Attr = ] 100 C:\Documents and Settings\Boo\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Boo\Local Settings\Temp\*.tmp -> e2bbf.DLL -> C:\Documents and Settings\Boo\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\e2bbf.DLL -> [Ver = | Size = 36864 bytes | Modified Date = 5/2/2002 4:36:42 PM | Attr = R ] Eula.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\Eula.dll -> [Ver = 1, 0, 0, 1 | Size = 135168 bytes | Modified Date = 4/7/2003 5:00:22 PM | Attr = R ] MCSetup.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\MCSetup.dll -> [Ver = | Size = 45056 bytes | Modified Date = 8/16/2001 9:00:10 AM | Attr = R ] 7Z.DLL -> C:\Documents and Settings\Boo\Local Settings\Temp\_PASFX939\7Z.DLL -> [Ver = | Size = 76288 bytes | Modified Date = 6/16/2007 9:04:02 AM | Attr = ] _Setup.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\{31C1B5C0-6361-4F92-A5ED-DF43C2EEBD21}\_Setup.dll -> Macrovision Corporation [Ver = 12.0.49974 | Size = 152496 bytes | Modified Date = 2/15/2008 8:19:02 PM | Attr = ] _Setup.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\isp710.tmp\_Setup.dll -> Macrovision Corporation [Ver = 11.00.28844 | Size = 368640 bytes | Modified Date = 7/20/2007 7:04:37 PM | Attr = ] System.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\nsn29.tmp\System.dll -> [Ver = | Size = 10240 bytes | Modified Date = 7/7/2007 8:36:18 PM | Attr = ] _SETUP.DLL -> C:\Documents and Settings\Boo\Local Settings\Temp\pft52C~tmp\_SETUP.DLL -> InstallShield Software Corporation [Ver = 5.10.146.0 | Size = 11264 bytes | Modified Date = 1/23/1998 3:40:20 PM | Attr = R ] PidGen.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\ZT2_PDLC\PidGen.dll -> Microsoft [Ver = 1, 5, 0, 8 | Size = 23344 bytes | Modified Date = 10/15/2006 8:11:16 AM | Attr = ] update.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\ZT2_PDLC\update.dll -> [Ver = | Size = 68400 bytes | Modified Date = 10/15/2006 8:11:02 AM | Attr = ] ZT2PID.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\ZT2_PDLC\ZT2PID.dll -> [Ver = | Size = 97072 bytes | Modified Date = 10/15/2006 8:11:00 AM | Attr = ] Eula.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\ZT2_PDLC\Data\Eula.dll -> Microsoft Corporation [Ver = 1.1.3096.31 | Size = 80688 bytes | Modified Date = 10/15/2006 8:11:14 AM | Attr = ] DSETUP.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\ZT2_PDLC\DirectX\DSETUP.dll -> Microsoft Corporation [Ver = 4.9.0.0904 | Size = 74448 bytes | Modified Date = 10/15/2006 8:11:00 AM | Attr = ] dsetup32.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\ZT2_PDLC\DirectX\dsetup32.dll -> Microsoft Corporation [Ver = 4.9.0.0904 | Size = 2248400 bytes | Modified Date = 10/15/2006 8:11:02 AM | Attr = ] strings.dll -> C:\Documents and Settings\Boo\Local Settings\Temp\ZT2_PDLC\Strings\strings.dll -> Microsoft Corporation [Ver = 21, 7, 0, 12 | Size = 52016 bytes | Modified Date = 10/15/2006 8:11:02 AM | Attr = ] 000.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\000.dat -> [Ver = | Size = 10240 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 001.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\001.dat -> [Ver = | Size = 10240 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 002.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\002.dat -> [Ver = | Size = 349696 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 003.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\003.dat -> [Ver = | Size = 36864 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 004.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\004.dat -> [Ver = | Size = 69632 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 005.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\005.dat -> [Ver = | Size = 55296 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 006.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\006.dat -> [Ver = | Size = 10240 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 007.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\007.dat -> [Ver = | Size = 13824 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 008.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\008.dat -> [Ver = | Size = 15360 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 009.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\009.dat -> [Ver = | Size = 100864 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 010.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\010.dat -> [Ver = | Size = 278528 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 011.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\011.dat -> [Ver = | Size = 16896 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 012.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\012.dat -> [Ver = | Size = 11776 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 013.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\013.dat -> [Ver = | Size = 11776 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 014.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\014.dat -> [Ver = | Size = 13824 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 015.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\015.dat -> [Ver = | Size = 6770775 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 016.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\016.dat -> [Ver = | Size = 44544 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 017.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\017.dat -> [Ver = | Size = 813 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 018.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\018.dat -> [Ver = | Size = 78336 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 019.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\019.dat -> [Ver = | Size = 27648 bytes | Modified Date = 6/24/2006 9:48:18 AM | Attr = ] 020.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\020.dat -> [Ver = | Size = 4638208 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 021.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\021.dat -> [Ver = | Size = 53248 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 022.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\022.dat -> [Ver = | Size = 131072 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 023.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\023.dat -> [Ver = | Size = 61440 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 024.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\024.dat -> [Ver = | Size = 4040320 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 025.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\025.dat -> [Ver = | Size = 101376 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 026.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\026.dat -> [Ver = | Size = 252416 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 027.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\027.dat -> [Ver = | Size = 39936 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 028.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\028.dat -> [Ver = | Size = 36864 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 029.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\029.dat -> [Ver = | Size = 10240 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 030.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\030.dat -> [Ver = | Size = 48128 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 031.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\031.dat -> [Ver = | Size = 3467 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 032.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\032.dat -> [Ver = | Size = 2064 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 033.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\033.dat -> [Ver = | Size = 105924 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 034.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\034.dat -> [Ver = | Size = 66048 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 035.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\035.dat -> [Ver = | Size = 90112 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 036.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\036.dat -> [Ver = | Size = 78522 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 037.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\037.dat -> [Ver = | Size = 79360 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 038.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\038.dat -> [Ver = | Size = 35328 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 039.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\039.dat -> [Ver = | Size = 10752 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 040.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\040.dat -> [Ver = | Size = 12013 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 041.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\041.dat -> [Ver = | Size = 6386 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 042.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\042.dat -> [Ver = | Size = 114176 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 043.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\043.dat -> [Ver = | Size = 10752 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 044.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\044.dat -> [Ver = | Size = 53248 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 045.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\045.dat -> [Ver = | Size = 37888 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 046.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\046.dat -> [Ver = | Size = 12288 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 047.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\047.dat -> [Ver = | Size = 12288 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 048.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\048.dat -> [Ver = | Size = 208896 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 049.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\049.dat -> [Ver = | Size = 11907 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 050.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\050.dat -> [Ver = | Size = 55808 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 051.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\051.dat -> [Ver = | Size = 74752 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 052.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\052.dat -> [Ver = | Size = 12288 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 053.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\053.dat -> [Ver = | Size = 10752 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 054.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\054.dat -> [Ver = | Size = 9728 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 055.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\055.dat -> [Ver = | Size = 11776 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 056.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\056.dat -> [Ver = | Size = 34816 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 057.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\057.dat -> [Ver = | Size = 43520 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 058.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\058.dat -> [Ver = | Size = 34304 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 059.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\059.dat -> [Ver = | Size = 13312 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 060.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\060.dat -> [Ver = | Size = 577 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 061.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\061.dat -> [Ver = | Size = 54784 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 062.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\062.dat -> [Ver = | Size = 41936 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 063.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\063.dat -> [Ver = | Size = 11264 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 064.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\064.dat -> [Ver = | Size = 52736 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 065.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\065.dat -> [Ver = | Size = 13312 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 066.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\066.dat -> [Ver = | Size = 9728 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 067.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\067.dat -> [Ver = | Size = 638 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 068.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\068.dat -> [Ver = | Size = 18944 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 069.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\069.dat -> [Ver = | Size = 17408 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 070.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\070.dat -> [Ver = | Size = 45568 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 071.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\071.dat -> [Ver = | Size = 64000 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 072.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\072.dat -> [Ver = | Size = 10752 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 073.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\073.dat -> [Ver = | Size = 231424 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 074.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\074.dat -> [Ver = | Size = 10240 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 075.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\075.dat -> [Ver = | Size = 10240 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 076.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\076.dat -> [Ver = | Size = 37376 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 077.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\077.dat -> [Ver = | Size = 115200 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 078.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\078.dat -> [Ver = | Size = 9216 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] 079.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\079.dat -> [Ver = | Size = 9216 bytes | Modified Date = 6/24/2006 9:48:20 AM | Attr = ] hpfscr05.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\hpfscr05.dat -> [Ver = | Size = 8251 bytes | Modified Date = 5/23/2005 1:51:04 PM | Attr = ] hpqbud01.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\hpqbud01.dat -> [Ver = | Size = 18930 bytes | Modified Date = 5/12/2005 1:11:12 AM | Attr = ] hpqbud05.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\hpqbud05.dat -> [Ver = | Size = 17698 bytes | Modified Date = 5/12/2005 1:15:05 AM | Attr = ] hpqhsc01.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\hpqhsc01.dat -> [Ver = | Size = 17340 bytes | Modified Date = 5/12/2005 1:08:00 AM | Attr = ] hpzscr01.exe.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\hpzscr01.exe.dat -> [Ver = | Size = 10621 bytes | Modified Date = 2/10/2005 2:40:01 PM | Attr = ] oickxmkl.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\oickxmkl.dat -> [Ver = | Size = 4 bytes | Modified Date = 7/4/2007 7:56:01 AM | Attr = ] 100 C:\Documents and Settings\Boo\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Boo\Local Settings\Temp\*.tmp -> global.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Adobe\Bridge CS3\Opera\global.dat -> [Ver = | Size = 130 bytes | Modified Date = 6/20/2007 12:31:27 PM | Attr = ] index.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Cookies\index.dat -> [Ver = | Size = 81920 bytes | Modified Date = 7/9/2007 7:36:02 AM | Attr = ] index.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\History\History.IE5\index.dat -> [Ver = | Size = 131072 bytes | Modified Date = 7/9/2007 7:36:02 AM | Attr = ] lang.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\pft52C~tmp\lang.dat -> [Ver = | Size = 4525 bytes | Modified Date = 10/20/1997 11:20:28 AM | Attr = R ] os.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\pft52C~tmp\os.dat -> [Ver = | Size = 417 bytes | Modified Date = 5/6/1997 3:15:20 PM | Attr = R ] index.dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat -> [Ver = | Size = 6373376 bytes | Modified Date = 7/9/2007 7:38:00 AM | Attr = ] dmads_Allstate_AHAU1929_30-done[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\dmads_Allstate_AHAU1929_30-done[1].dat -> [Ver = | Size = 2576611 bytes | Modified Date = 7/6/2007 7:33:24 PM | Attr = ] ncis081c[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\ncis081c[1].dat -> [Ver = | Size = 50170300 bytes | Modified Date = 7/5/2007 8:20:07 PM | Attr = ] ncis081d[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\ncis081d[1].dat -> [Ver = | Size = 39223716 bytes | Modified Date = 7/5/2007 8:36:58 PM | Attr = ] enc_atnt[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\enc_atnt[1].dat -> [Ver = | Size = 175078 bytes | Modified Date = 7/8/2007 5:02:38 PM | Attr = ] free_latina_0019-225[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\free_latina_0019-225[1].dat -> [Ver = | Size = 1714176 bytes | Modified Date = 7/8/2007 6:17:03 PM | Attr = ] gl15208c[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\gl15208c[1].dat -> [Ver = | Size = 47347610 bytes | Modified Date = 7/8/2007 5:35:36 PM | Attr = ] 52 C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\*.tmp files -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\*.tmp -> csi711a[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CTY78TIJ\csi711a[1].dat -> [Ver = | Size = 61912889 bytes | Modified Date = 6/29/2007 3:11:26 PM | Attr = ] gl15208b[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\HKH10Q01\gl15208b[1].dat -> [Ver = | Size = 59139192 bytes | Modified Date = 7/8/2007 5:23:31 PM | Attr = ] csi713c[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\csi713c[1].dat -> [Ver = | Size = 47941760 bytes | Modified Date = 7/6/2007 7:39:18 PM | Attr = ] dmads_GM_Cadillac_VOD-done[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\dmads_GM_Cadillac_VOD-done[1].dat -> [Ver = | Size = 1008255 bytes | Modified Date = 7/6/2007 1:53:10 PM | Attr = ] dmads_McDonalds_VOD_15-done[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\dmads_McDonalds_VOD_15-done[1].dat -> [Ver = | Size = 1277761 bytes | Modified Date = 7/6/2007 1:43:04 PM | Attr = ] enc_mcdonalds[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\enc_mcdonalds[1].dat -> [Ver = | Size = 191918 bytes | Modified Date = 7/6/2007 1:28:59 PM | Attr = ] ncis081a_new[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\ncis081a_new[1].dat -> [Ver = | Size = 58015655 bytes | Modified Date = 7/5/2007 7:54:12 PM | Attr = ] csi711d[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KTQ30LUB\csi711d[1].dat -> [Ver = | Size = 33405841 bytes | Modified Date = 6/29/2007 3:51:29 PM | Attr = ] ncis086a[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\ncis086a[1].dat -> [Ver = | Size = 51884748 bytes | Modified Date = 7/3/2007 5:58:05 PM | Attr = ] csi711b[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXY3O5MJ\csi711b[1].dat -> [Ver = | Size = 35364823 bytes | Modified Date = 6/29/2007 3:23:58 PM | Attr = ] csi711c[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXY3O5MJ\csi711c[1].dat -> [Ver = | Size = 70511825 bytes | Modified Date = 6/29/2007 3:34:46 PM | Attr = ] dmads_GM_Buick_VOD-done[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\R41PFKWW\dmads_GM_Buick_VOD-done[1].dat -> [Ver = | Size = 903293 bytes | Modified Date = 7/6/2007 7:45:47 PM | Attr = ] ncis081b[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\R41PFKWW\ncis081b[1].dat -> [Ver = | Size = 49318644 bytes | Modified Date = 7/5/2007 8:05:23 PM | Attr = ] csi713a[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\csi713a[1].dat -> [Ver = | Size = 66778416 bytes | Modified Date = 7/6/2007 1:34:51 PM | Attr = ] csi713b[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\csi713b[1].dat -> [Ver = | Size = 43782053 bytes | Modified Date = 7/6/2007 1:48:01 PM | Attr = ] csi713d[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\csi713d[1].dat -> [Ver = | Size = 44970622 bytes | Modified Date = 7/6/2007 7:51:22 PM | Attr = ] enc_mcdonalds[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\enc_mcdonalds[1].dat -> [Ver = | Size = 191912 bytes | Modified Date = 7/6/2007 1:28:11 PM | Attr = ] enc_all_state[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\enc_all_state[1].dat -> [Ver = | Size = 145306 bytes | Modified Date = 7/3/2007 5:51:15 PM | Attr = ] gl15208a[1].dat -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\YCS1M4XF\gl15208a[1].dat -> [Ver = | Size = 61928423 bytes | Modified Date = 7/8/2007 5:09:33 PM | Attr = ] 52 C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\YCS1M4XF\*.tmp files -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\YCS1M4XF\*.tmp -> Dll_.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Dll_.ini -> [Ver = | Size = 1156 bytes | Modified Date = 4/21/2008 12:18:32 PM | Attr = ] 100 C:\Documents and Settings\Boo\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Boo\Local Settings\Temp\*.tmp -> 0x0401.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0401.ini -> [Ver = | Size = 3935 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x0404.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0404.ini -> [Ver = | Size = 3209 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x0405.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0405.ini -> [Ver = | Size = 4382 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x0406.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0406.ini -> [Ver = | Size = 4408 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x0407.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0407.ini -> [Ver = | Size = 4667 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x0408.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0408.ini -> [Ver = | Size = 5058 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x0409.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0409.ini -> [Ver = | Size = 4187 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x040a.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x040a.ini -> [Ver = | Size = 4824 bytes | Modified Date = 6/26/2007 4:42:00 PM | Attr = ] 0x040b.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x040b.ini -> [Ver = | Size = 4291 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x040c.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x040c.ini -> [Ver = | Size = 4938 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x040d.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x040d.ini -> [Ver = | Size = 3614 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x040e.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x040e.ini -> [Ver = | Size = 4174 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x0410.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0410.ini -> [Ver = | Size = 4710 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x0411.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0411.ini -> [Ver = | Size = 4325 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x0413.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0413.ini -> [Ver = | Size = 4653 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x0414.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0414.ini -> [Ver = | Size = 4371 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x0415.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0415.ini -> [Ver = | Size = 4455 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] 0x0416.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0416.ini -> [Ver = | Size = 4509 bytes | Modified Date = 6/26/2007 4:42:00 PM | Attr = ] 0x0419.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0419.ini -> [Ver = | Size = 4455 bytes | Modified Date = 6/26/2007 4:42:00 PM | Attr = ] 0x041d.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x041d.ini -> [Ver = | Size = 4179 bytes | Modified Date = 6/26/2007 4:42:00 PM | Attr = ] 0x0804.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\0x0804.ini -> [Ver = | Size = 3266 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] Setup.INI -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\Setup.INI -> [Ver = | Size = 1461 bytes | Modified Date = 6/26/2007 4:41:59 PM | Attr = ] _ISMSIDEL.INI -> C:\Documents and Settings\Boo\Local Settings\Temp\_isEA\_ISMSIDEL.INI -> [Ver = | Size = 1305 bytes | Modified Date = 6/26/2007 4:42:00 PM | Attr = ] setup.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\{31C1B5C0-6361-4F92-A5ED-DF43C2EEBD21}\setup.ini -> [Ver = | Size = 488 bytes | Modified Date = 2/15/2008 8:19:02 PM | Attr = ] _isdel.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\{31C1B5C0-6361-4F92-A5ED-DF43C2EEBD21}\_isdel.ini -> [Ver = | Size = 182 bytes | Modified Date = 2/15/2008 8:23:44 PM | Attr = ] _ispackdel.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\{31C1B5C0-6361-4F92-A5ED-DF43C2EEBD21}\_ispackdel.ini -> [Ver = | Size = 1106 bytes | Modified Date = 2/15/2008 8:19:02 PM | Attr = ] opera6.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Adobe\Bridge CS3\Opera\opera6.ini -> [Ver = | Size = 232 bytes | Modified Date = 6/14/2007 8:21:02 PM | Attr = ] opera6.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Adobe\Bridge CS3\Opera\profile\opera6.ini -> [Ver = | Size = 455 bytes | Modified Date = 6/14/2007 8:21:02 PM | Attr = ] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\History\History.IE5\desktop.ini -> [Ver = | Size = 113 bytes | Modified Date = 9/10/2006 1:32:44 PM | Attr = HS] uninstall.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\nstmp\uninstall.ini -> [Ver = | Size = 6126 bytes | Modified Date = 9/18/2006 10:12:59 PM | Attr = ] uninstall.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\nstmp1\uninstall.ini -> [Ver = | Size = 6452 bytes | Modified Date = 4/22/2006 12:16:23 PM | Attr = ] SETUP.INI -> C:\Documents and Settings\Boo\Local Settings\Temp\pft52C~tmp\SETUP.INI -> [Ver = | Size = 62 bytes | Modified Date = 11/24/1998 5:20:16 PM | Attr = R ] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 9/10/2006 1:32:44 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\41URS1EN\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 6/7/2007 7:10:31 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\50WN1L8L\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/1/2007 9:45:45 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\5O3U7FPV\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/4/2007 1:29:56 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/7/2007 9:49:00 AM | Attr = HS] 52 C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\*.tmp files -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLUFOLEV\*.tmp -> desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\CTY78TIJ\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 6/7/2007 7:10:31 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT6NS5MZ\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/1/2007 9:45:45 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\HKH10Q01\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/7/2007 9:49:00 AM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\J1GGKZBJ\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/4/2007 1:29:56 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KTQ30LUB\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 6/7/2007 7:10:31 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KX63GT6F\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/1/2007 9:45:45 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXY3O5MJ\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 6/7/2007 7:10:31 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\OFAHGX0M\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/7/2007 9:49:00 AM | Attr = HS] 52 C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\OFAHGX0M\*.tmp files -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\OFAHGX0M\*.tmp -> desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\R41PFKWW\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/4/2007 1:29:56 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\U0TLJ3BN\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/4/2007 1:29:56 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYFG16J\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/1/2007 9:45:45 PM | Attr = HS] desktop.ini -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\YCS1M4XF\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/7/2007 9:49:00 AM | Attr = HS] 52 C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\YCS1M4XF\*.tmp files -> C:\Documents and Settings\Boo\Local Settings\Temp\Temporary Internet Files\Content.IE5\YCS1M4XF\*.tmp -> alcupd.exe -> C:\WINDOWS\Temp\alcupd.exe -> Realtek Semiconductor Corp. [Ver = 1, 7, 0, 0 | Size = 208896 bytes | Modified Date = 2/27/2004 6:14:22 AM | Attr = ] Remove.exe -> C:\WINDOWS\Temp\Remove.exe -> [Ver = 1, 1, 0, 0 | Size = 36864 bytes | Modified Date = 11/30/2002 12:40:54 AM | Attr = ] RTLCPL.exe -> C:\WINDOWS\Temp\RTLCPL.exe -> Realtek Semiconductor Corp. [Ver = 1.0.1.20 | Size = 6964736 bytes | Modified Date = 3/19/2004 7:28:52 AM | Attr = ] soundman.exe -> C:\WINDOWS\Temp\soundman.exe -> Realtek Semiconductor Corp. [Ver = 5.1.0.24 | Size = 65024 bytes | Modified Date = 2/26/2004 4:53:30 AM | Attr = ] ~GL_120D.EXE -> C:\WINDOWS\Temp\~GL_120D.EXE -> [Ver = | Size = 2560 bytes | Modified Date = 12/25/2006 9:34:27 AM | Attr = ] ~GL_174A.EXE -> C:\WINDOWS\Temp\~GL_174A.EXE -> [Ver = | Size = 2560 bytes | Modified Date = 12/26/2006 10:09:31 AM | Attr = ] ~GL_2F2E.EXE -> C:\WINDOWS\Temp\~GL_2F2E.EXE -> [Ver = | Size = 2560 bytes | Modified Date = 12/25/2006 10:31:39 AM | Attr = ] 3 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> Setup.exe -> C:\WINDOWS\Temp\pft7~tmp\Setup.exe -> InstallShield Software Corporation [Ver = 5, 52, 164, 0 | Size = 73728 bytes | Modified Date = 1/12/1999 12:42:20 PM | Attr = R ] _ISDel.exe -> C:\WINDOWS\Temp\pft7~tmp\_ISDel.exe -> InstallShield Software Corporation [Ver = 5, 51, 138, 0 | Size = 27648 bytes | Modified Date = 10/27/1998 1:06:48 PM | Attr = R ] AcroRd32.exe -> C:\WINDOWS\Temp\pft7~tmp\Reader\AcroRd32.exe -> Adobe Systems Incorporated [Ver = 5.0.1.2001032700 | Size = 3870784 bytes | Modified Date = 3/27/2001 10:44:58 PM | Attr = R ] audio3d.dll -> C:\WINDOWS\Temp\audio3d.dll -> Sensaura Ltd [Ver = 4.12.01.2009 | Size = 65536 bytes | Modified Date = 8/19/2003 7:36:16 AM | Attr = ] crlds3d.dll -> C:\WINDOWS\Temp\crlds3d.dll -> Sensaura Ltd [Ver = 4.12.01.2002 | Size = 765952 bytes | Modified Date = 11/21/2002 3:07:10 AM | Attr = ] newdev.dll -> C:\WINDOWS\Temp\newdev.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 248832 bytes | Modified Date = 8/4/2004 3:56:44 AM | Attr = ] RtlCPAPI.dll -> C:\WINDOWS\Temp\RtlCPAPI.dll -> [Ver = 1, 0, 0, 2 | Size = 155648 bytes | Modified Date = 2/9/2004 3:18:18 AM | Attr = ] 3 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> _Setup.dll -> C:\WINDOWS\Temp\pft7~tmp\_Setup.dll -> InstallShield Software Corporation [Ver = 5, 50, 134, 0 | Size = 34816 bytes | Modified Date = 9/29/1998 5:34:56 PM | Attr = R ] AceLite.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\AceLite.dll -> Adobe Systems, Incorporated [Ver = 1.02.00 | Size = 397312 bytes | Modified Date = 2/28/2001 10:29:36 AM | Attr = R ] ACROFX32.DLL -> C:\WINDOWS\Temp\pft7~tmp\Reader\ACROFX32.DLL -> [Ver = | Size = 53248 bytes | Modified Date = 5/12/2000 7:30:02 PM | Attr = R ] Agm.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\Agm.dll -> Adobe Systems, Incorporated [Ver = 4.04.26 | Size = 1138688 bytes | Modified Date = 3/14/2001 11:06:02 AM | Attr = R ] Bib.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\Bib.dll -> Adobe Systems, Incorporated [Ver = 1.0.20 | Size = 147456 bytes | Modified Date = 1/20/2001 11:13:36 PM | Attr = R ] CoolType.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\CoolType.dll -> Adobe Systems, Incorporated [Ver = 4.04.26 | Size = 1441792 bytes | Modified Date = 3/14/2001 11:06:02 AM | Attr = R ] msvcp60.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\msvcp60.dll -> Microsoft Corporation [Ver = 6.00.8168.0 | Size = 401462 bytes | Modified Date = 12/1/1999 1:40:28 AM | Attr = R ] msvcrt.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\msvcrt.dll -> Microsoft Corporation [Ver = 6.00.8397.0 | Size = 266293 bytes | Modified Date = 2/11/1999 4:33:58 AM | Attr = R ] oleaut32.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\oleaut32.dll -> Microsoft Corporation [Ver = 2.30.4261 | Size = 598288 bytes | Modified Date = 6/18/1998 12:33:08 PM | Attr = R ] vdk150.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\vdk150.dll -> [Ver = | Size = 878592 bytes | Modified Date = 7/24/2000 6:47:08 PM | Attr = R ] WHA Library.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\WHA Library.dll -> Adobe Systems Incorporated [Ver = 0.2.0.0 | Size = 167936 bytes | Modified Date = 3/15/2001 7:14:38 AM | Attr = R ] nppdf32.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\Browser\nppdf32.dll -> Adobe Systems Inc. [Ver = 5.0.0.2001031500 | Size = 103312 bytes | Modified Date = 2/26/2001 10:48:44 PM | Attr = R ] NPDocBox.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\plug_ins\InterTrust\NPDocBox.dll -> InterTrust Technologies Corporation, Inc. [Ver = 1.0.30.95 | Size = 225280 bytes | Modified Date = 3/14/2001 5:52:06 AM | Attr = R ] QT2.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\plug_ins\Movie\QT2.dll -> Adobe Systems, Inc. [Ver = 5.0.0.0 | Size = 24576 bytes | Modified Date = 3/15/2001 7:00:24 AM | Attr = R ] QT3.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\plug_ins\Movie\QT3.dll -> Adobe Systems, Inc. [Ver = 5.0.0.0 | Size = 32768 bytes | Modified Date = 3/15/2001 7:00:42 AM | Attr = R ] QT4.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\plug_ins\Movie\QT4.dll -> Adobe Systems, Inc. [Ver = 5.0.0.0 | Size = 36864 bytes | Modified Date = 3/15/2001 7:01:02 AM | Attr = R ] Uninst.dll -> C:\WINDOWS\Temp\pft7~tmp\Reader\Uninstall\Uninst.dll -> Adobe Systems, Inc. [Ver = 4.0.11 | Size = 81920 bytes | Modified Date = 2/26/2001 10:48:44 PM | Attr = R ] NPSVGVw.dll -> C:\WINDOWS\Temp\pft7~tmp\SVG Files\NPSVGVw.dll -> Adobe Systems Inc. [Ver = 2, 0, 0, 55 | Size = 299059 bytes | Modified Date = 3/14/2001 3:10:56 PM | Attr = R ] SVGControl.dll -> C:\WINDOWS\Temp\pft7~tmp\SVG Files\SVGControl.dll -> Adobe Systems Incorporated [Ver = 2, 0, 0, 55 | Size = 491574 bytes | Modified Date = 3/14/2001 3:14:00 PM | Attr = R ] SVGRSRC.DLL -> C:\WINDOWS\Temp\pft7~tmp\SVG Files\SVGRSRC.DLL -> [Ver = | Size = 12288 bytes | Modified Date = 3/14/2001 3:06:24 PM | Attr = R ] SVGView.dll -> C:\WINDOWS\Temp\pft7~tmp\SVG Files\SVGView.dll -> Adobe Systems Incorporated [Ver = 2, 0, 0, 55 | Size = 1597491 bytes | Modified Date = 3/14/2001 3:07:52 PM | Attr = R ] oickxmkl.dat -> C:\WINDOWS\Temp\oickxmkl.dat -> [Ver = | Size = 4 bytes | Modified Date = 6/29/2007 8:19:57 AM | Attr = ] Perflib_Perfdata_2454.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_2454.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/6/2007 9:00:49 PM | Attr = ] Perflib_Perfdata_6970.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6970.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/14/2007 10:54:22 AM | Attr = ] Perflib_Perfdata_708c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_708c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/10/2007 7:26:52 AM | Attr = ] Perflib_Perfdata_75bc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_75bc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/12/2007 10:01:22 PM | Attr = ] Perflib_Perfdata_76e4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_76e4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/22/2007 8:49:33 AM | Attr = ] Perflib_Perfdata_7bf0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_7bf0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/18/2007 6:14:18 PM | Attr = ] Perflib_Perfdata_fc4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fc4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/12/2006 6:31:58 PM | Attr = ] 3 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> index.dat -> C:\WINDOWS\Temp\Cookies\index.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/28/2007 7:42:24 PM | Attr = ] index.dat -> C:\WINDOWS\Temp\History\History.IE5\index.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/28/2007 7:42:24 PM | Attr = ] lang.dat -> C:\WINDOWS\Temp\pft7~tmp\lang.dat -> [Ver = | Size = 23541 bytes | Modified Date = 1/12/1999 11:34:42 AM | Attr = R ] os.dat -> C:\WINDOWS\Temp\pft7~tmp\os.dat -> [Ver = | Size = 450 bytes | Modified Date = 7/27/1998 6:41:06 PM | Attr = R ] index.dat -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/28/2007 7:42:24 PM | Attr = ] desktop.ini -> C:\WINDOWS\Temp\History\History.IE5\desktop.ini -> [Ver = | Size = 113 bytes | Modified Date = 5/28/2007 9:05:28 PM | Attr = HS] Abcpy.ini -> C:\WINDOWS\Temp\pft7~tmp\Abcpy.ini -> [Ver = | Size = 3026 bytes | Modified Date = 4/4/2001 3:57:10 PM | Attr = R ] SETUP.INI -> C:\WINDOWS\Temp\pft7~tmp\SETUP.INI -> [Ver = | Size = 103 bytes | Modified Date = 3/28/2001 4:35:10 PM | Attr = R ] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 5/28/2007 9:05:28 PM | Attr = HS] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\BGGGT7FN\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 5/28/2007 9:05:28 PM | Attr = HS] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\G3U9QHWT\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 5/28/2007 9:05:28 PM | Attr = HS] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KLKBMPUT\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 5/28/2007 9:05:28 PM | Attr = HS] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\PWOT7IM4\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 5/28/2007 9:05:28 PM | Attr = HS] [Files Modified - Additional Folder Scans - Non-Microsoft Only] Adobe -> %AllUsersProfile%\Application Data\Adobe -> [Folder | Modified Date = 4/8/2008 6:17:04 PM | Attr = ] avg7 -> %AllUsersProfile%\Application Data\avg7 -> [Folder | Modified Date = 4/21/2008 5:08:59 AM | Attr = ] Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [Folder | Modified Date = 4/21/2008 11:41:44 AM | Attr = ] obcxubst.dll -> %AllUsersProfile%\Application Data\obcxubst.dll -> [Ver = | Size = 65024 bytes | Modified Date = 4/20/2008 12:33:39 PM | Attr = ] odwxozop -> %AllUsersProfile%\Application Data\odwxozop -> [Folder | Modified Date = 4/21/2008 12:00:50 PM | Attr = ] Spybot - Search & Destroy -> %AllUsersProfile%\Application Data\Spybot - Search & Destroy -> [Folder | Modified Date = 4/21/2008 11:07:25 AM | Attr = ] Adobe -> %AppData%\Adobe -> [Folder | Modified Date = 4/8/2008 6:17:04 PM | Attr = ] AVG7 -> %AppData%\AVG7 -> [Folder | Modified Date = 4/21/2008 2:54:16 PM | Attr = ] Cosmos Prefs -> %AppData%\Cosmos Prefs -> [Ver = | Size = 134405 bytes | Modified Date = 3/26/2008 8:33:28 AM | Attr = ] GameHouse -> %AppData%\GameHouse -> [Folder | Modified Date = 2/3/2008 4:44:28 PM | Attr = ] Grisoft -> %AppData%\Grisoft -> [Folder | Modified Date = 4/21/2008 10:57:17 AM | Attr = ] Malwarebytes -> %AppData%\Malwarebytes -> [Folder | Modified Date = 4/21/2008 11:42:51 AM | Attr = ] Poser 7 -> %AppData%\Poser 7 -> [Folder | Modified Date = 4/20/2008 11:08:12 AM | Attr = ] uTorrent -> %AppData%\uTorrent -> [Folder | Modified Date = 4/21/2008 4:08:27 PM | Attr = ] DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [Ver = | Size = 76288 bytes | Modified Date = 4/16/2008 4:16:59 PM | Attr = ] IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [Ver = | Size = 7987382 bytes | Modified Date = 4/18/2008 1:00:39 PM | Attr = H ] Microsoft -> %UserProfile%\Local Settings\Application Data\Microsoft -> [Folder | Modified Date = 4/6/2008 3:53:00 PM | Attr = ] My Music -> %AllUsersProfile%\Documents\My Music -> [Folder | Modified Date = 3/10/2008 9:16:28 AM | Attr = R ] 1_Texture Resources -> %UserProfile%\My Documents\1_Texture Resources -> [Folder | Modified Date = 4/1/2008 9:52:06 AM | Attr = ] angel_1.psd -> %UserProfile%\My Documents\angel_1.psd -> [Ver = | Size = 6512764 bytes | Modified Date = 3/7/2008 10:17:41 PM | Attr = ] angel_2.psd -> %UserProfile%\My Documents\angel_2.psd -> [Ver = | Size = 6024892 bytes | Modified Date = 3/8/2008 10:06:22 AM | Attr = ] angel_3.psd -> %UserProfile%\My Documents\angel_3.psd -> [Ver = | Size = 8142160 bytes | Modified Date = 3/11/2008 8:04:33 PM | Attr = ] angel_4.psd -> %UserProfile%\My Documents\angel_4.psd -> [Ver = | Size = 8221929 bytes | Modified Date = 3/12/2008 8:18:25 AM | Attr = ] CS Project -> %UserProfile%\My Documents\CS Project -> [Folder | Modified Date = 2/21/2008 4:06:24 PM | Attr = ] Gem%20hunt(1).xls -> %UserProfile%\My Documents\Gem%20hunt(1).xls -> [Ver = | Size = 35840 bytes | Modified Date = 3/12/2008 10:56:13 AM | Attr = ] Image8.jpg -> %UserProfile%\My Documents\Image8.jpg -> [Ver = | Size = 168876 bytes | Modified Date = 3/15/2008 1:19:58 PM | Attr = ] Image8.pspimage -> %UserProfile%\My Documents\Image8.pspimage -> [Ver = | Size = 3146398 bytes | Modified Date = 3/15/2008 1:20:07 PM | Attr = ] Kayla Gibson_howto.doc -> %UserProfile%\My Documents\Kayla Gibson_howto.doc -> [Ver = | Size = 24576 bytes | Modified Date = 2/25/2008 12:22:15 PM | Attr = ] Krysta Gibson_DescriptiveParagraph.doc -> %UserProfile%\My Documents\Krysta Gibson_DescriptiveParagraph.doc -> [Ver = | Size = 24064 bytes | Modified Date = 2/25/2008 2:13:56 PM | Attr = ] Michael.doc -> %UserProfile%\My Documents\Michael.doc -> [Ver = | Size = 26112 bytes | Modified Date = 4/11/2008 7:55:13 AM | Attr = ] michael_resume.doc -> %UserProfile%\My Documents\michael_resume.doc -> [Ver = | Size = 21504 bytes | Modified Date = 4/14/2008 3:21:49 PM | Attr = ] My Library -> %UserProfile%\My Documents\My Library -> [Folder | Modified Date = 3/7/2008 8:13:53 PM | Attr = ] My Pictures -> %UserProfile%\My Documents\My Pictures -> [Folder | Modified Date = 4/6/2008 3:48:33 PM | Attr = R ] My PSP Files -> %UserProfile%\My Documents\My PSP Files -> [Folder | Modified Date = 4/6/2008 4:46:17 PM | Attr = ] Thumbs.db -> %UserProfile%\My Documents\Thumbs.db -> [Ver = | Size = 86528 bytes | Modified Date = 3/16/2008 8:09:36 AM | Attr = HS] @Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable When Tomorrow Starts Without Me.doc -> %UserProfile%\My Documents\When Tomorrow Starts Without Me.doc -> [Ver = | Size = 24576 bytes | Modified Date = 3/11/2008 6:54:16 PM | Attr = ] AVG Anti-Spyware.lnk -> %AllUsersProfile%\Desktop\AVG Anti-Spyware.lnk -> [Ver = | Size = 849 bytes | Modified Date = 4/21/2008 10:57:10 AM | Attr = ] Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [Ver = | Size = 696 bytes | Modified Date = 4/21/2008 11:41:44 AM | Attr = ] Board Games with Scott » BGWS 042 - World of Warcraft, the Boardgame.url -> %UserProfile%\Desktop\Board Games with Scott » BGWS 042 - World of Warcraft, the Boardgame.url -> [Ver = | Size = 226 bytes | Modified Date = 2/15/2008 12:47:18 PM | Attr = ] DAZ -> %UserProfile%\Desktop\DAZ -> [Folder | Modified Date = 4/16/2008 11:53:01 AM | Attr = ] GND2 -> %UserProfile%\Desktop\GND2 -> [Folder | Modified Date = 4/19/2008 3:17:10 PM | Attr = ] JumbleStory.doc -> %UserProfile%\Desktop\JumbleStory.doc -> [Ver = | Size = 62976 bytes | Modified Date = 2/25/2008 2:23:01 PM | Attr = ] NewsReport.mpg -> %UserProfile%\Desktop\NewsReport.mpg -> [Ver = | Size = 7316992 bytes | Modified Date = 2/16/2008 2:58:42 PM | Attr = ] OTScanIt -> %UserProfile%\Desktop\OTScanIt -> [Folder | Modified Date = 4/22/2008 3:24:02 AM | Attr = ] OTScanIt.exe -> %UserProfile%\Desktop\OTScanIt.exe -> [Ver = | Size = 542061 bytes | Modified Date = 4/22/2008 3:23:19 AM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\OTScanIt.exe:Zone.Identifier ps_ac2218_PlacesSummerPs.exe -> %UserProfile%\Desktop\ps_ac2218_PlacesSummerPs.exe -> BitRock SL [Ver = 1,0,0,0 | Size = 43135505 bytes | Modified Date = 3/26/2008 2:14:23 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\ps_ac2218_PlacesSummerPs.exe:Zone.Identifier Shortcut to Crusty.exe.lnk -> %UserProfile%\Desktop\Shortcut to Crusty.exe.lnk -> [Ver = | Size = 814 bytes | Modified Date = 4/21/2008 10:53:48 AM | Attr = ] Thumbs.db -> %UserProfile%\Desktop\Thumbs.db -> [Ver = | Size = 21504 bytes | Modified Date = 4/21/2008 9:25:50 AM | Attr = HS] @Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable Untitled2.png -> %UserProfile%\Desktop\Untitled2.png -> [Ver = | Size = 201934 bytes | Modified Date = 3/7/2008 8:25:11 PM | Attr = ] DAZ -> %CommonProgramFiles%\DAZ -> [Folder | Modified Date = 4/20/2008 9:49:10 AM | Attr = ] [File - Purity Scan: Additional Folder Scans - Non-Microsoft Only] < End of report > [/code]