[code] OTScanIt logfile created on: 5/7/2008 1:13:13 PM OTScanIt by OldTimer - Version 1.0.12.1 Folder = C:\Documents and Settings\ddcsystem\Desktop\OTScanIt Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 510.98 Mb Total Physical Memory | 181.70 Mb Available Physical Memory | 35.56% Memory free 2.91 Gb Paging File | 2.62 Gb Available in Paging File | 89.87% Paging File free Paging file location(s): C:\pagefile.sys 2500 2500; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 37.21 Gb Total Space | 15.32 Gb Free Space | 41.18% Space Free | Partition Type: NTFS D: Drive not present or media not loaded Drive E: | 7.99 Gb Total Space | 0.24 Gb Free Space | 3.05% Space Free | Partition Type: NTFS F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Drive K: | 12.69 Gb Total Space | 3.36 Gb Free Space | 26.45% Space Free | Partition Type: NTFS Drive L: | 12.69 Gb Total Space | 3.36 Gb Free Space | 26.45% Space Free | Partition Type: NTFS Drive V: | 12.69 Gb Total Space | 3.36 Gb Free Space | 26.45% Space Free | Partition Type: NTFS Drive X: | 33.83 Gb Total Space | 23.39 Gb Free Space | 69.12% Space Free | Partition Type: NTFS Drive Y: | 12.69 Gb Total Space | 3.36 Gb Free Space | 26.45% Space Free | Partition Type: NTFS Drive Z: | 33.83 Gb Total Space | 23.39 Gb Free Space | 69.12% Space Free | Partition Type: NTFS Computer Name: OPERKIRCHMAN Current User Name: ddcsystem Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user [Processes - Non-Microsoft Only] awhost32.exe -> %ProgramFiles%\Symantec\pcAnywhere\awhost32.exe -> Symantec Corporation [Ver = 10.5.1.505 | Size = 114749 bytes | Modified Date = 2/15/2002 10:51:00 AM | Attr = ] dklog.exe -> %SystemRoot%\SYSTEM32\dklog.exe -> Datakey, Inc. [Ver = 4.7.20.0035 | Size = 102400 bytes | Modified Date = 9/1/2004 5:14:32 PM | Attr = ] dkvcm.exe -> %SystemRoot%\SYSTEM32\dkvcm.exe -> Datakey, Inc. [Ver = 4.7.20.0035 | Size = 122880 bytes | Modified Date = 9/1/2004 5:29:56 PM | Attr = ] cvd.exe -> %ProgramFiles%\CommVault Systems\Galaxy\Base\cvd.exe -> CommVault Systems [Ver = 5.9.48 | Size = 65536 bytes | Modified Date = 10/29/2004 12:24:00 AM | Attr = ] frameworkservice.exe -> %ProgramFiles%\McAfee\Common Framework\FrameworkService.exe -> McAfee, Inc. [Ver = 3.6.0.480 | Size = 104000 bytes | Modified Date = 12/19/2006 11:24:50 AM | Attr = ] mcshield.exe -> %ProgramFiles%\McAfee\VirusScan Enterprise\Mcshield.exe -> McAfee, Inc. [Ver = VSCORE.13.3.2.101.x86 | Size = 144960 bytes | Modified Date = 2/22/2007 8:50:00 PM | Attr = ] vstskmgr.exe -> %ProgramFiles%\McAfee\VirusScan Enterprise\VsTskMgr.exe -> McAfee, Inc. [Ver = 8.5.0.830 | Size = 54872 bytes | Modified Date = 2/22/2007 8:50:00 PM | Attr = ] naprdmgr.exe -> %ProgramFiles%\McAfee\Common Framework\naPrdMgr.exe -> McAfee, Inc. [Ver = 3.6.0.480 | Size = 136768 bytes | Modified Date = 12/19/2006 11:27:54 AM | Attr = ] winvnc.exe -> %ProgramFiles%\UltraVNC\winvnc.exe -> UltraVNC [Ver = 1.1.0.2 | Size = 712704 bytes | Modified Date = 6/18/2006 3:56:10 PM | Attr = ] dkcktkn.exe -> %SystemRoot%\SYSTEM32\dkcktkn.exe -> Datakey, Inc. [Ver = 4.7.20.0035 | Size = 638976 bytes | Modified Date = 9/1/2004 5:21:22 PM | Attr = ] evmgrc.exe -> %ProgramFiles%\CommVault Systems\Galaxy\Base\EvMgrC.exe -> CommVault Systems [Ver = 5.9.48 | Size = 229376 bytes | Modified Date = 10/29/2004 1:30:14 AM | Attr = ] avgwdsvc.exe -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.100 | Size = 282904 bytes | Modified Date = 5/7/2008 11:47:43 AM | Attr = ] avgrsx.exe -> %ProgramFiles%\AVG\AVG8\avgrsx.exe -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.84 | Size = 311576 bytes | Modified Date = 5/7/2008 11:47:57 AM | Attr = ] dkautoreg.exe -> %ProgramFiles%\Datakey\Crypt32\dkAutoReg.exe -> Datakey, Inc. [Ver = 4.7.20.0035 | Size = 245760 bytes | Modified Date = 9/1/2004 5:22:52 PM | Attr = ] dkmonitor.exe -> %ProgramFiles%\Datakey\Crypt32\dkMonitor.exe -> Datakey, Inc. [Ver = 4.7.20.0035 | Size = 32768 bytes | Modified Date = 9/1/2004 5:22:18 PM | Attr = ] shstat.exe -> %ProgramFiles%\McAfee\VirusScan Enterprise\shstat.exe -> McAfee, Inc. [Ver = 8.5.0.830 | Size = 112216 bytes | Modified Date = 2/22/2007 8:50:00 PM | Attr = ] udaterui.exe -> %ProgramFiles%\McAfee\Common Framework\UdaterUI.exe -> McAfee, Inc. [Ver = 3.6.0.480 | Size = 136768 bytes | Modified Date = 12/19/2006 11:27:00 AM | Attr = ] avgtray.exe -> %ProgramFiles%\AVG\AVG8\avgtray.exe -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.94 | Size = 1177368 bytes | Modified Date = 5/7/2008 11:47:54 AM | Attr = ] mctray.exe -> %ProgramFiles%\McAfee\Common Framework\Mctray.exe -> McAfee, Inc. [Ver = 1.0.0.125 | Size = 86016 bytes | Modified Date = 12/19/2006 3:06:00 PM | Attr = ] otscanit.exe -> %UserProfile%\Desktop\OTScanIt\OTScanIt.exe -> OldTimer Tools [Ver = 1.0.12.1 | Size = 372224 bytes | Modified Date = 5/6/2008 2:53:20 PM | Attr = ] [Win32 Services - Non-Microsoft Only] (awhost32) pcAnywhere Host Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec\pcAnywhere\awhost32.exe -> Symantec Corporation [Ver = 10.5.1.505 | Size = 114749 bytes | Modified Date = 2/15/2002 10:51:00 AM | Attr = ] (DkLogger) Datakey's Log Service [Win32_Own | Auto | Running] -> %SystemRoot%\SYSTEM32\dklog.exe -> Datakey, Inc. [Ver = 4.7.20.0035 | Size = 102400 bytes | Modified Date = 9/1/2004 5:14:32 PM | Attr = ] (DkTknSrv) Datakey's Token Service [Win32_Own | Auto | Running] -> %SystemRoot%\SYSTEM32\dkcktkn.exe -> Datakey, Inc. [Ver = 4.7.20.0035 | Size = 638976 bytes | Modified Date = 9/1/2004 5:21:22 PM | Attr = ] (DkVcm) Datakey's Virtual Channel Monitor [Win32_Own | Auto | Running] -> %SystemRoot%\SYSTEM32\dkvcm.exe -> Datakey, Inc. [Ver = 4.7.20.0035 | Size = 122880 bytes | Modified Date = 9/1/2004 5:29:56 PM | Attr = ] (dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 3:56:48 AM | Attr = ] (DSBrokerService) DSBrokerService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\DellSupport\brkrsvc.exe -> [Ver = 1, 0, 0, 8 | Size = 76848 bytes | Modified Date = 3/7/2007 3:47:46 PM | Attr = ] (GxCVD(ControlSet001)) Galaxy Communications Service (ControlSet001) [Win32_Own | Auto | Running] -> %ProgramFiles%\CommVault Systems\Galaxy\Base\cvd.exe -> CommVault Systems [Ver = 5.9.48 | Size = 65536 bytes | Modified Date = 10/29/2004 12:24:00 AM | Attr = ] (GxEvMgrC(ControlSet001)) Galaxy Client Event Manager (ControlSet001) [Win32_Own | Auto | Running] -> %ProgramFiles%\CommVault Systems\Galaxy\Base\EvMgrC.exe -> CommVault Systems [Ver = 5.9.48 | Size = 229376 bytes | Modified Date = 10/29/2004 1:30:14 AM | Attr = ] (McAfeeFramework) McAfee Framework Service [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\Common Framework\FrameworkService.exe -> McAfee, Inc. [Ver = 3.6.0.480 | Size = 104000 bytes | Modified Date = 12/19/2006 11:24:50 AM | Attr = ] (McShield) McAfee McShield [Win32_Own | Auto | Paused] -> %ProgramFiles%\McAfee\VirusScan Enterprise\Mcshield.exe -> McAfee, Inc. [Ver = VSCORE.13.3.2.101.x86 | Size = 144960 bytes | Modified Date = 2/22/2007 8:50:00 PM | Attr = ] (McTaskManager) McAfee Task Manager [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\VirusScan Enterprise\VsTskMgr.exe -> McAfee, Inc. [Ver = 8.5.0.830 | Size = 54872 bytes | Modified Date = 2/22/2007 8:50:00 PM | Attr = ] (NetSvc) Intel NCS NetService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Intel\NCS\Sync\NetSvc.exe -> Intel(R) Corporation [Ver = 1.2.26.0 | Size = 143360 bytes | Modified Date = 3/3/2003 2:33:40 PM | Attr = ] (rpcapd) Remote Packet Capture Protocol v.0 (experimental) [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\WinPcap\rpcapd.exe -> CACE Technologies [Ver = 3, 1, 0, 27 | Size = 86016 bytes | Modified Date = 8/2/2005 5:18:49 PM | Attr = ] (winvnc) VNC Server [Win32_Own | Auto | Running] -> %ProgramFiles%\UltraVNC\winvnc.exe -> UltraVNC [Ver = 1.1.0.2 | Size = 712704 bytes | Modified Date = 6/18/2006 3:56:10 PM | Attr = ] (avg8wd) AVG8 WatchDog [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.100 | Size = 282904 bytes | Modified Date = 5/7/2008 11:47:43 AM | Attr = ] [Driver Services - Non-Microsoft Only] (aeaudio) aeaudio [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\aeaudio.sys -> Andrea Electronics Corporation [Ver = 1.0.0.2 (STUB) | Size = 4816 bytes | Modified Date = 4/1/2002 3:15:00 PM | Attr = ] (AliIde) AliIde [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ALIIDE.SYS -> Acer Laboratories Inc. [Ver = 1.20 | Size = 5248 bytes | Modified Date = 8/17/2001 2:51:56 PM | Attr = ] (amdagp) AMD AGP Bus Filter Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\amdagp.sys -> Advanced Micro Devices, Inc. [Ver = 5.00 (xpsp_sp2_rtm.040803-2158) | Size = 43008 bytes | Modified Date = 8/4/2004 2:07:42 AM | Attr = ] (asc) asc [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ASC.SYS -> Advanced System Products, Inc. [Ver = 2.9I-MS (XPClient.010817-1148) | Size = 26496 bytes | Modified Date = 8/17/2001 2:52:00 PM | Attr = ] (asc3550) asc3550 [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ASC3550.SYS -> Advanced System Products, Inc. [Ver = 3.1E-MS (XPClient.010817-1148) | Size = 14848 bytes | Modified Date = 8/17/2001 2:51:58 PM | Attr = ] (ati2mtaa) ati2mtaa [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\ati2mtaa.sys -> ATI Technologies Inc. [Ver = 6.13.10.5019 | Size = 327040 bytes | Modified Date = 8/4/2004 1:29:26 AM | Attr = ] (awlegacy) awlegacy [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\AWLEGACY.sys -> Symantec Corporation [Ver = 9.2.1 | Size = 10816 bytes | Modified Date = 9/11/2000 10:50:00 AM | Attr = ] (AW_HOST) AW_HOST [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\AW_HOST5.sys -> Symantec Corporation [Ver = 10.5.1.497 | Size = 33496 bytes | Modified Date = 2/11/2002 10:51:00 AM | Attr = ] (CmdIde) CmdIde [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\CMDIDE.SYS -> CMD Technology, Inc. [Ver = 2.0.7 (XPClient.010817-1148) | Size = 6656 bytes | Modified Date = 8/17/2001 2:51:54 PM | Attr = ] (COAX) COAX [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\COAX.SYS -> Wall Data Incorporated. [Ver = 1502,0,0 | Size = 26528 bytes | Modified Date = 2/15/1999 6:00:00 AM | Attr = ] (dac2w2k) dac2w2k [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\DAC2W2K.SYS -> Mylex Corporation [Ver = 6.00-21 (XPClient.010817-1148) | Size = 179584 bytes | Modified Date = 8/17/2001 2:52:16 PM | Attr = ] (dmboot) dmboot [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 799744 bytes | Modified Date = 8/4/2004 2:07:17 AM | Attr = ] (dmio) dmio [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 153344 bytes | Modified Date = 8/4/2004 2:07:16 AM | Attr = ] (dmload) dmload [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\DMLOAD.SYS -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 3/19/2004 6:35:20 PM | Attr = ] (DSproct) DSproct [Kernel | On_Demand | Stopped] -> %ProgramFiles%\DellSupport\GTAction\triggers\DSproct.sys -> Gteko Ltd. [Ver = 2, 0, 0, 30 | Size = 4736 bytes | Modified Date = 10/5/2006 4:07:28 PM | Attr = ] (dsunidrv) DellSupport UniDriver [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\dsunidrv.sys -> Gteko Ltd. [Ver = 1, 0, 0, 12 | Size = 5376 bytes | Modified Date = 2/25/2007 12:10:48 PM | Attr = S] (E100B) Intel(R) PRO Adapter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\e100b325.sys -> Intel Corporation [Ver = 7.0.26.0 built by: WinDDK | Size = 145408 bytes | Modified Date = 3/4/2003 1:56:26 PM | Attr = ] (Gernuwa) Gernuwa [Kernel | Boot | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\GERNUWA.sys -> Symantec Corporation [Ver = 10.5.0 | Size = 14944 bytes | Modified Date = 10/9/2001 10:50:00 AM | Attr = ] (HSFHWBS2) HSFHWBS2 [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\HSFHWBS2.sys -> Conexant Systems, Inc. [Ver = 7.06.00 | Size = 212224 bytes | Modified Date = 11/17/2003 4:59:20 PM | Attr = ] (HSF_DP) HSF_DP [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_DP.sys -> Conexant Systems, Inc. [Ver = 7.06.00 | Size = 1042432 bytes | Modified Date = 11/17/2003 4:56:26 PM | Attr = ] (ialm) ialm [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ialmnt5.sys -> Intel Corporation [Ver = 6.14.10.4020 | Size = 804317 bytes | Modified Date = 1/23/2005 11:05:06 AM | Attr = ] (iKeyEnum) Rainbow iKey Enumerator [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\IKEYENUM.SYS -> Rainbow Technologies Inc. [Ver = 1.18.16.66 | Size = 11256 bytes | Modified Date = 7/31/2003 12:42:42 PM | Attr = ] (iKeyIFD) Rainbow iKey Virtual Reader [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\IKEYIFD.SYS -> Rainbow Technologies Inc. [Ver = 1.18.16.66 | Size = 16696 bytes | Modified Date = 7/31/2003 12:41:46 PM | Attr = ] (mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\mdmxsdk.sys -> Conexant [Ver = 1.0.2.002 | Size = 11043 bytes | Modified Date = 4/9/2003 2:48:08 PM | Attr = ] (mfeapfk) McAfee Inc. [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\mfeapfk.sys -> McAfee, Inc. [Ver = SYSCORE.13.3.0.116.x86 | Size = 64360 bytes | Modified Date = 11/30/2006 8:50:00 AM | Attr = ] (mfeavfk) McAfee Inc. [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\mfeavfk.sys -> McAfee, Inc. [Ver = SYSCORE.13.3.0.116.x86 | Size = 72264 bytes | Modified Date = 11/30/2006 8:50:00 AM | Attr = ] (mfebopk) McAfee Inc. [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\mfebopk.sys -> McAfee, Inc. [Ver = SYSCORE.13.3.0.116.x86 | Size = 34152 bytes | Modified Date = 11/30/2006 8:50:00 AM | Attr = ] (mfehidk) McAfee Inc. [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\mfehidk.sys -> McAfee, Inc. [Ver = SYSCORE.13.3.0.120.x86 | Size = 170408 bytes | Modified Date = 2/22/2007 8:50:00 PM | Attr = ] (mfetdik) McAfee Inc. [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\mfetdik.sys -> McAfee, Inc. [Ver = SYSCORE.13.3.0.116.x86 | Size = 52136 bytes | Modified Date = 11/30/2006 8:50:00 AM | Attr = ] (mraid35x) mraid35x [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\MRAID35X.SYS -> American Megatrends Inc. [Ver = 6.19 (XPClient.010817-1148) | Size = 17280 bytes | Modified Date = 8/17/2001 2:52:12 PM | Attr = ] (NPF) NetGroup Packet Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\npf.sys -> CACE Technologies [Ver = 3, 1, 0, 27 | Size = 32512 bytes | Modified Date = 8/2/2005 5:10:13 PM | Attr = ] (omci) OMCI WDM Device Driver [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\omci.sys -> Dell Computer Corporation [Ver = 7, 0, 323, 0 | Size = 17217 bytes | Modified Date = 11/8/2002 2:45:06 PM | Attr = ] (Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\PTILINK.SYS -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 3/19/2004 6:41:54 PM | Attr = ] (ql1080) ql1080 [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\QL1080.SYS -> QLogic Corporation [Ver = 3.04 | Size = 40320 bytes | Modified Date = 8/17/2001 2:52:20 PM | Attr = ] (ql12160) ql12160 [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\QL12160.SYS -> QLogic Corporation [Ver = 7.13.02 (W64) | Size = 45312 bytes | Modified Date = 8/17/2001 2:52:20 PM | Attr = ] (ql1280) ql1280 [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\QL1280.SYS -> QLogic Corporation [Ver = 7.13.01 (W2K) | Size = 49024 bytes | Modified Date = 8/17/2001 2:52:18 PM | Attr = ] (RMBS) RMBS [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\RMBS.SYS -> Wall Data Incorporated. [Ver = 1502,0,0 | Size = 18208 bytes | Modified Date = 2/15/1999 6:00:00 AM | Attr = ] (RnbToken) Rainbow iKey Token Service [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\RNBTOKEN.SYS -> Rainbow Technologies Inc. [Ver = 1.18.16.66 | Size = 18168 bytes | Modified Date = 7/31/2003 12:41:04 PM | Attr = ] (Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\secdrv.sys -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. [Ver = 4.03.086 | Size = 20480 bytes | Modified Date = 11/13/2007 6:25:53 AM | Attr = ] (sisagp) SIS AGP Bus Filter [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\sisagp.sys -> Silicon Integrated Systems Corporation [Ver = 5.12.01.2010 (xpsp_sp2_rtm.040803-2158) | Size = 41088 bytes | Modified Date = 8/4/2004 2:07:42 AM | Attr = ] (smwdm) smwdm [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\smwdm.sys -> Analog Devices, Inc. [Ver = 5.12.01.3600 | Size = 580992 bytes | Modified Date = 5/6/2003 10:14:34 AM | Attr = ] (Sparrow) Sparrow [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\SPARROW.SYS -> Adaptec, Inc. [Ver = v2.0a (ReleaseBinaries.001205-1804) | Size = 19072 bytes | Modified Date = 8/17/2001 3:07:44 PM | Attr = ] (symc810) symc810 [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\SYMC810.SYS -> Symbios Logic Inc. [Ver = 5.1.2409.1 (ReleaseBinaries.001205-1804) | Size = 16256 bytes | Modified Date = 8/17/2001 3:07:34 PM | Attr = ] (symc8xx) symc8xx [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\SYMC8XX.SYS -> LSI Logic [Ver = 5.1.2409.1 (ReleaseBinaries.001205-1804) | Size = 32640 bytes | Modified Date = 8/17/2001 3:07:36 PM | Attr = ] (SymEvent) SymEvent [Kernel | On_Demand | Stopped] -> %ProgramFiles%\Symantec\SYMEVENT.SYS -> Symantec Corporation [Ver = 10.3.2.8 | Size = 57968 bytes | Modified Date = 9/18/2001 7:25:48 PM | Attr = ] (sym_hi) sym_hi [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\SYM_HI.SYS -> LSI Logic [Ver = 5.1.2462.0 (Lab01_N.010309-0027) | Size = 28384 bytes | Modified Date = 8/17/2001 3:07:40 PM | Attr = ] (sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\SYM_U3.SYS -> LSI Logic [Ver = 5.1.2462.0 (Lab01_N.010309-0027) | Size = 30688 bytes | Modified Date = 8/17/2001 3:07:42 PM | Attr = ] (ultra) ultra [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ULTRA.SYS -> Promise Technology, Inc. [Ver = 1.43 (Build 0603) | Size = 36736 bytes | Modified Date = 8/17/2001 2:52:22 PM | Attr = ] (vnccom) vnccom [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\vnccom.SYS -> RDV Soft [Ver = 1.0.0.17 | Size = 6016 bytes | Modified Date = 6/26/2004 2:22:00 PM | Attr = ] (vncdrv) vncdrv [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\vncdrv.sys -> RDV Soft [Ver = 1.00.17 | Size = 4736 bytes | Modified Date = 6/26/2004 2:22:00 PM | Attr = ] (winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_CNXT.sys -> Conexant Systems, Inc. [Ver = 7.06.00 built by: WinDDK | Size = 680704 bytes | Modified Date = 11/17/2003 4:58:02 PM | Attr = ] ({6080A529-897E-4629-A488-ABA0C29B635E}) Intel(R) Graphics Platform (SoftBIOS) Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ialmsbw.sys -> Intel Corporation [Ver = 6.13.10.3510 | Size = 113504 bytes | Modified Date = 4/15/2003 11:40:54 AM | Attr = ] ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91}) Intel(R) Graphics Chipset (KCH) Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ialmkchw.sys -> Intel Corporation [Ver = 6.13.10.3510 | Size = 78752 bytes | Modified Date = 4/15/2003 11:40:46 AM | Attr = ] (AvgMfx86) AVG On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\avgmfx86.sys -> GRISOFT, s.r.o. [Ver = 8.0.0.46 | Size = 26184 bytes | Modified Date = 5/7/2008 11:48:18 AM | Attr = ] (AvgLdx86) AVG AVI Loader Driver x86 [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\avgldx86.sys -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.58 | Size = 96520 bytes | Modified Date = 5/7/2008 11:48:21 AM | Attr = ] [Registry - Non-Microsoft Only] < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> acad5a50 -> %SystemRoot%\system32\ovpquvlx.DLL [rundll32.exe "C:\WINDOWS\system32\ovpquvlx.dll",b] -> File not found AVG8_TRAY -> %ProgramFiles%\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.94 | Size = 1177368 bytes | Modified Date = 5/7/2008 11:47:54 AM | Attr = ] BMaf9e69cc -> %SystemRoot%\system32\tfxmtqpo.DLL [Rundll32.exe "C:\WINDOWS\system32\tfxmtqpo.dll",s] -> File not found DkAutoReg.exe -> %ProgramFiles%\Datakey\Crypt32\dkAutoReg.exe [C:\Program Files\Datakey\Crypt32\DkAutoReg.exe] -> Datakey, Inc. [Ver = 4.7.20.0035 | Size = 245760 bytes | Modified Date = 9/1/2004 5:22:52 PM | Attr = ] DkMonitor.exe -> %ProgramFiles%\Datakey\Crypt32\dkMonitor.exe [C:\Program Files\Datakey\Crypt32\DkMonitor.exe] -> Datakey, Inc. [Ver = 4.7.20.0035 | Size = 32768 bytes | Modified Date = 9/1/2004 5:22:18 PM | Attr = ] DkStartup -> %ProgramFiles%\Datakey\Crypt32\DkStartup.exe [C:\Program Files\Datakey\Crypt32\DkStartup.exe] -> Datakey, Inc. [Ver = 4.7.20.0035 | Size = 217088 bytes | Modified Date = 9/1/2004 5:22:34 PM | Attr = ] McAfeeUpdaterUI -> %ProgramFiles%\McAfee\Common Framework\UdaterUI.exe ["C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey] -> McAfee, Inc. [Ver = 3.6.0.480 | Size = 136768 bytes | Modified Date = 12/19/2006 11:27:00 AM | Attr = ] ShStatEXE -> %ProgramFiles%\McAfee\VirusScan Enterprise\shstat.exe ["C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE] -> McAfee, Inc. [Ver = 8.5.0.830 | Size = 112216 bytes | Modified Date = 2/22/2007 8:50:00 PM | Attr = ] < OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> IMAIL-> Installed = 1 -> MAPI-> Installed = 1 -> MSFS-> Installed = 1 -> < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> SpybotSD TeaTimer -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe [C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe] -> Safer Networking Limited [Ver = 1, 5, 2, 16 | Size = 2097488 bytes | Modified Date = 1/28/2008 12:43:40 PM | Attr = RHS] < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> -> %AllUsersProfile%\Start Menu\Programs\Startup\e.bat -> [Ver = | Size = 36 bytes | Modified Date = 10/20/2006 8:38:31 AM | Attr = ] -> %AllUsersProfile%\Start Menu\Programs\Startup\fedline.bat -> [Ver = | Size = 108 bytes | Modified Date = 3/6/2008 6:54:31 PM | Attr = ] -> %AllUsersProfile%\Start Menu\Programs\Startup\k.bat -> [Ver = | Size = 216 bytes | Modified Date = 11/14/2007 6:04:03 PM | Attr = ] -> %AllUsersProfile%\Start Menu\Programs\Startup\nwdrive.bat -> [Ver = | Size = 52 bytes | Modified Date = 3/9/2007 12:45:13 PM | Attr = ] -> %AllUsersProfile%\Start Menu\Programs\Startup\tumbleweed.bat -> [Ver = | Size = 138 bytes | Modified Date = 9/25/2006 1:55:06 PM | Attr = ] -> %AllUsersProfile%\Start Menu\Programs\Startup\v.bat -> [Ver = | Size = 24 bytes | Modified Date = 1/14/2008 6:21:33 PM | Attr = ] -> %AllUsersProfile%\Start Menu\Programs\Startup\WinZip Quick Pick.lnk -> File not found < ddcsystem Startup Folder > -> C:\Documents and Settings\ddcsystem\Start Menu\Programs\Startup -> < AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> avgrsstx.dll -> %SystemRoot%\SYSTEM32\avgrsstx.dll -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.80 | Size = 10520 bytes | Modified Date = 5/7/2008 11:48:26 AM | Attr = ] *MultiFile Done* -> -> < SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> DkWLNP -> %SystemRoot%\SYSTEM32\DkWLNP.dll -> [Ver = | Size = 57344 bytes | Modified Date = 9/1/2004 5:29:48 PM | Attr = ] igfxcui -> %SystemRoot%\SYSTEM32\igfxsrvc.dll -> Intel Corporation [Ver = 3.0.0.4020 | Size = 348160 bytes | Modified Date = 1/23/2005 10:31:10 AM | Attr = ] PCANotify -> %SystemRoot%\SYSTEM32\PCANotify.dll -> Symantec Corporation [Ver = 10.5.1.505 | Size = 24638 bytes | Modified Date = 2/15/2002 10:51:00 AM | Attr = ] < CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> DDC users only. -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> WARNING! This computer system is the property of Delmarva Data Center and may be accessed only by authorized users. Unauthorized use of this system is strictly prohibited and may be subject to criminal prosecution. The Data Center may monitor any activity or communication on the system and retrieve any information stored within the system. By accessing and using this computer you are consenting to such monitoring and information retrieval for law enforcement and other purposes. Users should have no expectation of privacy as to any communication on or information stored within the system. -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> < CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoChangingWallPaper -> 1 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\\NoAddRemovePrograms -> 1 -> < CDROM Autorun Settings > [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\ -> -> *DependOnGroup* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DependOnGroup -> SCSI miniport -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Group -> SCSI CDROM Class -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Start -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Tag -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Type -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DisplayName -> CD-ROM Driver -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ImagePath -> C:\WINDOWS\SYSTEM32\DRIVERS\cdrom.sys [System32\DRIVERS\cdrom.sys] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 49536 bytes | Modified Date = 8/4/2004 1:59:52 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun -> 1 -> *AutoRunAlwaysDisable* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRunAlwaysDisable -> NEC MBR-7 -> -> File not found NEC MBR-7.4 -> -> File not found PIONEER CHANGR DRM-1804X -> -> File not found PIONEER CD-ROM DRM-6324X -> -> File not found PIONEER CD-ROM DRM-624X -> -> File not found TORiSAN CD-ROM CDR_C36 -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\0 -> IDE\CdRomLite-On_LTN486S_48x_Max_________________YDS6____\5&33fcab6&0&0.0.0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\NextInstance -> 1 -> < Drives - Autoruns > -> -> AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [Ver = | Size = 0 bytes | Modified Date = 3/20/2004 1:58:32 PM | Attr = ] < HOSTS File > (223107 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 10.5.0.207 xvision -> -> < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://172.16.32.88 -> HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.dell4me.com/mywaybiz -> HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\Default_Page_URL -> http://www.dell4me.com/mywaybiz -> HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: Main\\Start Page -> http://172.16.32.88 -> HKEY_CURRENT_USER\: ProxyEnable -> 1 -> HKEY_CURRENT_USER\: ProxyOverride -> 170.209.0.2;170.209.0.3;kirchman2;10.5.0.88;10.5.0.245;10.5.0.195;172.16.32.88;10.5.0.192; -> < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4163 domain(s) found. -> 33 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Adobe Systems Incorporated [Ver = 7.0.7.2006011200 | Size = 63128 bytes | Modified Date = 1/12/2006 9:38:22 PM | Attr = ] {26504DD1-4576-4CFC-B646-D8B227700496} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found {2833ADCA-43B6-4702-9D8B-C64CEEDDF361} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AVG\AVG8\avgssie.dll [AVG Safe Search] -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.90 | Size = 419096 bytes | Modified Date = 5/7/2008 11:47:58 AM | Attr = ] {42469102-6E6C-41F4-97C0-F83C3AB1E6B5} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\mllmk.dll [Reg Error: Value does not exist or could not be read.] -> File not found {44FC10FE-45D0-4221-800E-171533E3C19B} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found {53707962-6F74-2D53-2644-206D7942484F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> Safer Networking Limited [Ver = 1, 5, 0, 11 | Size = 1554256 bytes | Modified Date = 1/28/2008 12:43:28 PM | Attr = ] {5993FE19-FED1-412F-A5AB-3DBB1395EBE7} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\geede.dll [Reg Error: Value does not exist or could not be read.] -> File not found {601ED020-FB6C-11D3-87D8-0050DA59922B} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Ipswitch\WS_FTP Pro\wsbho2k0.dll [WsftpBrowserHelper Class] -> Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421 [Ver = 9,0,1,0 | Size = 118830 bytes | Modified Date = 8/18/2004 2:35:14 PM | Attr = ] {6A0AB1AC-75C0-4869-A98C-E8B46F122BB5} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found {7DB2D5A0-7241-4E79-B68D-6309F01C5231} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found {A057A204-BACC-4D26-9990-79A187E2698E} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AVG\AVG8\avgtoolbar.dll [AVG Security Toolbar] -> AVG, Technologies CZ, s.r.o [Ver = 5.0.2.387 | Size = 2050816 bytes | Modified Date = 5/7/2008 11:48:06 AM | Attr = ] < Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> {A057A204-BACC-4D26-9990-79A187E2698E} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AVG\AVG8\avgtoolbar.dll [AVG Security Toolbar] -> AVG, Technologies CZ, s.r.o [Ver = 5.0.2.387 | Size = 2050816 bytes | Modified Date = 5/7/2008 11:48:06 AM | Attr = ] < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AVG\AVG8\avgtoolbar.dll [AVG Security Toolbar] -> AVG, Technologies CZ, s.r.o [Ver = 5.0.2.387 | Size = 2050816 bytes | Modified Date = 5/7/2008 11:48:06 AM | Attr = ] < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Sun Java Console] -> File not found {d81ca86b-ef63-42af-bee3-4502d9a03c2d}: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [MUSICMATCH MX Web Player] -> File not found {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> Safer Networking Limited [Ver = 1, 5, 0, 11 | Size = 1554256 bytes | Modified Date = 1/28/2008 12:43:28 PM | Attr = ] < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> [Sun Java Console] -> File not found CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> Safer Networking Limited [Ver = 1, 5, 0, 11 | Size = 1554256 bytes | Modified Date = 1/28/2008 12:43:28 PM | Attr = ] < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < User Agent Post Platform [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform -> SV1 -> -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {34A6914D-D273-46F8-B29E-FC3807C10331} -> 10.5.0.191,10.5.0.131 (Intel(R) PRO/100 VE Network Connection) -> < Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> ipp: [HKEY_LOCAL_MACHINE] -> No CLSID value linkscanner:{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AVG\AVG8\avgpp.dll[XPLPPFilter Class] -> AVG Technologies CZ, s.r.o. [Ver = | Size = 79128 bytes | Modified Date = 5/7/2008 11:48:04 AM | Attr = ] msdaipp: [HKEY_LOCAL_MACHINE] -> No CLSID value < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab[Reg Error: Key does not exist or could not be opened.] -> {D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937}[HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}[HKEY_LOCAL_MACHINE] -> https://bankway.webex.com/client/T25L/support/ieatgpc.cab[GpcContainer Class] -> < Module Usage Keys [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/FP_AX_CAB_INSTALLER.exe\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/FP_AX_CAB_INSTALLER.exe\\.Owner -> {D27CDB6E-AE6D-11CF-96B8-444553540000} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/FP_AX_CAB_INSTALLER.exe\\{D27CDB6E-AE6D-11CF-96B8-444553540000} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/FP_AX_CAB_INSTALLER.exe\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/FP_AX_CAB_INSTALLER.exe\\.Owner -> {D27CDB6E-AE6D-11CF-96B8-444553540000} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/FP_AX_CAB_INSTALLER.exe\\{D27CDB6E-AE6D-11CF-96B8-444553540000} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ieatgpc.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ieatgpc.dll\\.Owner -> {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ieatgpc.dll\\{E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MOVEitUploadWizard3.4.0.ocx\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MOVEitUploadWizard3.4.0.ocx\\.Owner -> {A81DF11E-14EB-48F6-B7CF-8D06AB608DE3} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MOVEitUploadWizard3.4.0.ocx\\{A81DF11E-14EB-48F6-B7CF-8D06AB608DE3} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/iuctl.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/iuctl.dll\\.Owner -> Unknown Owner -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/iuengine.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/iuengine.dll\\.Owner -> Unknown Owner -> [Registry - Additional Scans - Non-Microsoft Only] < BotCheck > -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\DefaultLaunchPermission -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableDCOM -> Y -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\LegacyAuthenticationLevel -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableRemoteConnect -> Y -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineLaunchRestriction -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineAccessRestriction -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{A50398B8-9075-4FBF-A7A1-456BF21937AD} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{AD65A69D-3831-40D7-9629-9B0B50A93843} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{0040D221-54A1-11D1-9DE0-006097042D69} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\\System.EnterpriseServices.Thunk.dll -> -> Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ not found. -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\\NoAutoRebootWithLoggedOnUsers -> 0 -> Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ not found. -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ -> -> *Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> msv1_0 -> %SystemRoot%\SYSTEM32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 3:56:43 AM | Attr = ] C:\WINDOWS\system32\mllmk.dll -> %SystemRoot%\system32\mllmk.dll -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Bounds -> 0 [binary data] -> *Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> kerberos -> %SystemRoot%\SYSTEM32\kerberos.dll -> Microsoft Corporation [Ver = 5.1.2600.2698 (xpsp_sp2_gdr.050614-1522) | Size = 295936 bytes | Modified Date = 6/15/2005 1:49:30 PM | Attr = ] msv1_0 -> %SystemRoot%\SYSTEM32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 3:56:43 AM | Attr = ] schannel -> %SystemRoot%\SYSTEM32\schannel.dll -> Microsoft Corporation [Ver = 5.1.2600.3126 (xpsp_sp2_gdr.070425-0226) | Size = 144896 bytes | Modified Date = 4/25/2007 10:21:15 AM | Attr = ] wdigest -> %SystemRoot%\SYSTEM32\wdigest.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 49152 bytes | Modified Date = 8/4/2004 3:56:46 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\LsaPid -> 796 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\SecureBoot -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\auditbaseobjects -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\crashonauditfail -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\disabledomaincreds -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\everyoneincludesanonymous -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fipsalgorithmpolicy -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\forceguest -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fullprivilegeauditing -> [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\limitblankpassworduse -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\lmcompatibilitylevel -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nodefaultadminowner -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nolmhash -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymous -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymoussam -> 1 -> *Notification Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Notification Packages -> scecli -> %SystemRoot%\SYSTEM32\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 180224 bytes | Modified Date = 8/4/2004 3:56:44 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\ImpersonatePrivilegeUpgradeToolHasRun -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\ -> -> *ProviderOrder* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\\ProviderOrder -> Windows NT Access Provider -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\\ProviderPath -> C:\WINDOWS\SYSTEM32\ntmarta.dll [%SystemRoot%\system32\ntmarta.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 118784 bytes | Modified Date = 8/4/2004 3:56:44 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\\Pattern -> 14 FE F9 CB 3F 71 E7 07 AA EB 8B 1D EB DF F2 95 33 65 65 32 34 36 65 39 00 00 00 00 01 00 00 00 BC 01 00 00 C0 01 00 00 34 CA 06 00 45 9D BF 71 04 00 00 00 10 00 00 00 00 00 00 00 7E F8 80 87 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\\GrafBlumGroup -> 80 C9 25 8A 53 06 66 A5 0B [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\\Lookup -> 69 B4 FA 02 1B 75 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\Auth132 -> C:\WINDOWS\SYSTEM32\IISSUBA.DLL [IISSUBA] -> Microsoft Corporation [Ver = 6.0.2600.0 (xpclient.010817-1148) | Size = 9216 bytes | Modified Date = 3/19/2004 6:38:08 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\ntlmminclientsec -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\ntlmminserversec -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\\SkewMatrix -> 0D 0F BB BC F2 B5 CA B0 9C B5 C1 B4 D2 D2 E5 E4 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\\SSOURL -> http://www.passport.com -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\\Time -> CA 62 DE 3C 08 B2 C4 01 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Name -> Digest -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Comment -> Digest SSPI Authentication Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Capabilities -> 16464 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\RpcId -> 65535 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\TokenSize -> 65535 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Time -> 00 D9 4A 94 F8 79 C4 01 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Name -> DPA -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Comment -> DPA Security Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Capabilities -> 55 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\RpcId -> 17 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\TokenSize -> 768 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Time -> 00 D9 4A 94 F8 79 C4 01 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Name -> MSN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Comment -> MSN Security Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Capabilities -> 55 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\RpcId -> 18 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\TokenSize -> 768 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Time -> 80 6F E3 94 F8 79 C4 01 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> C:\WINDOWS\SYSTEM32\svchost.exe [%SystemRoot%\System32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 3:56:57 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 23383 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> C:\WINDOWS\SYSTEM32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Modified Date = 8/4/2004 3:56:42 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\\EnableFirewall -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\\DoNotAllowExceptions -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\\DisableNotifications -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> C:\WINDOWS\SYSTEM32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 3:56:56 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\\\Operator\c$\Program Files\FTPinterface1\GenericFTP.exe -> \\Operator\c$\Program Files\FTPinterface1\GenericFTP.exe:*:Enabled:GenericFTP.exe -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\FTPinterface1\GenericFTP.exe -> C:\Program Files\FTPinterface1\GenericFTP.exe [C:\Program Files\FTPinterface1\GenericFTP.exe:*:Enabled:Generic FTP] -> Delmarva Data Center [Ver = 2.0.0.6 | Size = 748544 bytes | Modified Date = 9/9/2004 2:02:33 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\MacFTP\MacFTP.exe -> C:\MacFTP\MacFTP.exe [C:\MacFTP\MacFTP.exe:*:Enabled:MacFTP] -> [Ver = | Size = 541696 bytes | Modified Date = 11/6/2002 11:00:14 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Generic FTP\GenericFTP.exe -> C:\Generic FTP\GenericFTP.exe [C:\Generic FTP\GenericFTP.exe:*:Enabled:Generic FTP] -> Delmarva Data Center [Ver = 2.0.0.6 | Size = 748544 bytes | Modified Date = 9/9/2004 2:02:33 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Symantec\pcAnywhere\winaw32.exe -> C:\Program Files\Symantec\pcAnywhere\winaw32.exe [C:\Program Files\Symantec\pcAnywhere\winaw32.exe:*:Enabled:pcAnywhere Main Program] -> Symantec Corporation [Ver = 10.5.1.505 | Size = 507964 bytes | Modified Date = 2/15/2002 10:51:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Symantec\pcAnywhere\awhost32.exe -> C:\Program Files\Symantec\pcAnywhere\awhost32.exe [C:\Program Files\Symantec\pcAnywhere\awhost32.exe:*:Enabled:pcAnywhere Host Service] -> Symantec Corporation [Ver = 10.5.1.505 | Size = 114749 bytes | Modified Date = 2/15/2002 10:51:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Kirchman\KCDriver.exe -> C:\Program Files\Kirchman\KCDriver.exe [C:\Program Files\Kirchman\KCDriver.exe:*:Enabled:KCDriver] -> Kirchman Corporation [Ver = 8.14.2031 | Size = 9134080 bytes | Modified Date = 8/4/2006 10:10:20 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\FedLineFTP_DDC\GenericFTP.exe -> C:\Program Files\FedLineFTP_DDC\GenericFTP.exe [C:\Program Files\FedLineFTP_DDC\GenericFTP.exe:*:Enabled:Generic FTP] -> Delmarva Data Center [Ver = 2.0.0.6 | Size = 748544 bytes | Modified Date = 9/9/2004 2:02:33 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Generic FTP\New GenericFTP\GenericFTP.exe -> C:\Generic FTP\New GenericFTP\GenericFTP.exe [C:\Generic FTP\New GenericFTP\GenericFTP.exe:*:Enabled:GenericFTP] -> DDC [Ver = 2.02.0007 | Size = 95232 bytes | Modified Date = 7/17/2007 12:05:13 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Tumbleweed\STClient\stclient.exe -> C:\Program Files\Tumbleweed\STClient\stclient.exe [C:\Program Files\Tumbleweed\STClient\stclient.exe:*:Enabled:SecureTransport] -> Tumbleweed Communications Corp. [Ver = 4, 2, 1, 33 | Size = 1957888 bytes | Modified Date = 1/31/2005 9:30:40 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\STARBIN\GenericFTP.exe -> C:\STARBIN\GenericFTP.exe [C:\STARBIN\GenericFTP.exe:*:Enabled:Generic FTP] -> Delmarva Data Center [Ver = 2.0.0.6 | Size = 748544 bytes | Modified Date = 9/9/2004 2:02:33 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\WINDOWS\SYSTEM32\ftp.exe -> C:\WINDOWS\SYSTEM32\ftp.exe [C:\WINDOWS\SYSTEM32\ftp.exe:*:Enabled:File Transfer Program] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 42496 bytes | Modified Date = 8/4/2004 3:56:49 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\di\DIFTP1.bat -> C:\di\DIFTP1.bat [C:\di\DIFTP1.bat:*:Enabled:DIFTP1.bat] -> [Ver = | Size = 3531 bytes | Modified Date = 1/14/2008 7:49:19 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Ipswitch\WS_FTP Pro\wsftpgui.exe -> C:\Program Files\Ipswitch\WS_FTP Pro\wsftpgui.exe [C:\Program Files\Ipswitch\WS_FTP Pro\wsftpgui.exe:*:Enabled:WS_FTP Pro Application] -> Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421 [Ver = 9,0,1,0 | Size = 397358 bytes | Modified Date = 8/18/2004 2:43:56 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Internet Explorer\iexplore.exe -> C:\Program Files\Internet Explorer\iexplore.exe [C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer] -> Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 93184 bytes | Modified Date = 8/4/2004 3:56:50 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Generic FTP\All Other FTP\GenericFTP.exe -> C:\Generic FTP\All Other FTP\GenericFTP.exe [C:\Generic FTP\All Other FTP\GenericFTP.exe:*:Enabled:GenericFTP] -> DDC [Ver = 2.02.0007 | Size = 95232 bytes | Modified Date = 7/17/2007 12:05:13 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\MacFTP\StarBilling.exe -> C:\MacFTP\StarBilling.exe [C:\MacFTP\StarBilling.exe:*:Enabled:StarBilling] -> [Ver = | Size = 541696 bytes | Modified Date = 4/18/2007 7:56:15 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\FTPbrowse\GenericFTP.exe -> C:\Program Files\FTPbrowse\GenericFTP.exe [C:\Program Files\FTPbrowse\GenericFTP.exe:*:Enabled:GenericFTP] -> DDC [Ver = 2.00.0002 | Size = 84992 bytes | Modified Date = 11/6/2006 12:46:11 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\UltraVNC\winvnc.exe -> C:\Program Files\UltraVNC\winvnc.exe [C:\Program Files\UltraVNC\winvnc.exe:*:Enabled:UltraVNC Server] -> UltraVNC [Ver = 1.1.0.2 | Size = 712704 bytes | Modified Date = 6/18/2006 3:56:10 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\McAfee\Common Framework\FrameworkService.exe -> C:\Program Files\McAfee\Common Framework\FrameworkService.exe [C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service] -> McAfee, Inc. [Ver = 3.6.0.480 | Size = 104000 bytes | Modified Date = 12/19/2006 11:24:50 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Digital Watchdog\NDMS\NDMS.exe -> C:\Program Files\Digital Watchdog\NDMS\NDMS.exe [C:\Program Files\Digital Watchdog\NDMS\NDMS.exe:*:Enabled:NDMS] -> [Ver = 2.8.0.1 | Size = 2604032 bytes | Modified Date = 8/10/2004 12:47:58 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\AVG\AVG8\avgupd.exe -> C:\Program Files\AVG\AVG8\avgupd.exe [C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe] -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.80 | Size = 796440 bytes | Modified Date = 5/7/2008 11:47:53 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\139:TCP -> 139:TCP:*:Enabled:@xpsp2res.dll,-22004 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\445:TCP -> 445:TCP:*:Enabled:@xpsp2res.dll,-22005 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\137:UDP -> 137:UDP:*:Enabled:@xpsp2res.dll,-22001 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\138:UDP -> 138:UDP:*:Enabled:@xpsp2res.dll,-22002 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\3389:TCP -> 3389:TCP:*:Enabled:@xpsp2res.dll,-22009 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\8400:TCP -> 8400:TCP:*:Enabled:Commvault -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\8400:UDP -> 8400:UDP:*:Enabled:Commvault -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\3413:TCP -> 3413:TCP:*:Enabled:Commvault -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\3412:TCP -> 3412:TCP:*:Enabled:Commvault -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\8401:TCP -> 8401:TCP:*:Enabled:Commvault -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\8402:TCP -> 8402:TCP:*:Enabled:Commvault -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\8403:TCP -> 8403:TCP:*:Enabled:Commvault -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> C:\WINDOWS\SYSTEM32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 3:56:56 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\FTPinterface1\GenericFTP.exe -> C:\Program Files\FTPinterface1\GenericFTP.exe [C:\Program Files\FTPinterface1\GenericFTP.exe:*:Disabled:Generic FTP] -> Delmarva Data Center [Ver = 2.0.0.6 | Size = 748544 bytes | Modified Date = 9/9/2004 2:02:33 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\FedLineFTP_DDC\GenericFTP.exe -> C:\Program Files\FedLineFTP_DDC\GenericFTP.exe [C:\Program Files\FedLineFTP_DDC\GenericFTP.exe:*:Enabled:Generic FTP] -> Delmarva Data Center [Ver = 2.0.0.6 | Size = 748544 bytes | Modified Date = 9/9/2004 2:02:33 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Kirchman\KCDriver.exe -> C:\Program Files\Kirchman\KCDriver.exe [C:\Program Files\Kirchman\KCDriver.exe:*:Enabled:KCDriver] -> Kirchman Corporation [Ver = 8.14.2031 | Size = 9134080 bytes | Modified Date = 8/4/2006 10:10:20 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Generic FTP\GenericFTP.exe -> C:\Generic FTP\GenericFTP.exe [C:\Generic FTP\GenericFTP.exe:*:Enabled:Generic FTP] -> Delmarva Data Center [Ver = 2.0.0.6 | Size = 748544 bytes | Modified Date = 9/9/2004 2:02:33 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\SYSTEM32\ftp.exe -> C:\WINDOWS\SYSTEM32\ftp.exe [C:\WINDOWS\SYSTEM32\ftp.exe:*:Enabled:File Transfer Program] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 42496 bytes | Modified Date = 8/4/2004 3:56:49 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\139:TCP -> 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\445:TCP -> 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\137:UDP -> 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\138:UDP -> 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{34A6914D-D273-46F8-B29E-FC3807C10331} -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{51FCC4A7-F17A-477C-A691-B45B5BF6DD15} -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{8AD85493-26B4-4BD0-B5E7-E3A141F7D2BB} -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> C:\WINDOWS\SYSTEM32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 3:56:57 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\SYSTEM32\wuauserv.dll [C:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Modified Date = 8/4/2004 3:56:46 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Description -> Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start. -> *DependOnService* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\DependOnService -> RPCSS -> %SystemRoot%\SYSTEM32\rpcss.dll -> Microsoft Corporation [Ver = 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) | Size = 397824 bytes | Modified Date = 7/26/2005 12:39:49 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\DisplayName -> Remote Registry -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\ImagePath -> C:\WINDOWS\SYSTEM32\svchost.exe [%SystemRoot%\system32\svchost.exe -k LocalService] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 3:56:57 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\ObjectName -> NT AUTHORITY\LocalService -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Group -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\FailureActions -> 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 E0 AD 08 00 01 00 00 00 E8 03 00 00 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters\\ServiceDll -> C:\WINDOWS\SYSTEM32\regsvc.dll [%SystemRoot%\system32\regsvc.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 59904 bytes | Modified Date = 8/4/2004 3:56:44 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security\\Security -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\\0 -> Root\LEGACY_REMOTEREGISTRY\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Type -> 16 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Start -> 4 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ImagePath -> C:\WINDOWS\SYSTEM32\tlntsvr.exe [C:\WINDOWS\System32\tlntsvr.exe] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 73216 bytes | Modified Date = 8/4/2004 3:56:57 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DisplayName -> Telnet -> *DependOnService* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DependOnService -> RPCSS -> %SystemRoot%\SYSTEM32\rpcss.dll -> Microsoft Corporation [Ver = 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) | Size = 397824 bytes | Modified Date = 7/26/2005 12:39:49 AM | Attr = ] TCPIP -> -> File not found NTLMSSP -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Description -> Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Security\\Security -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable -> 1 -> < Desktop Components > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\ -> 0 -> [Key] -> 0 -> FriendlyName = My Current Home Page -> 0 -> Source = About:Home -> 0 -> SubscribedURL = About:Home -> < Disabled MSConfig Folder Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\ -> < Disabled MSConfig Registry Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ -> acad5a50 hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemRoot%\system32\ovpquvlx.DLL -> File not found BMaf9e69cc hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemRoot%\system32\tfxmtqpo.DLL -> File not found DellSupport hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\DellSupport\DSAgnt.exe -> Gteko Ltd. [Ver = 3, 0, 0, 197 | Size = 460784 bytes | Modified Date = 3/15/2007 11:09:36 AM | Attr = ] < MountsPoints2 > -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##10.5.0.91#ACHPRODUCTION\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##10.5.0.91#ACHPRODUCTION\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##10.5.0.91#ACHPRODUCTION\\_CommentFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##10.5.0.91#ACHPRODUCTION\\_LabelFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##Intranet#bank76\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##Intranet#bank76\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##Intranet#bank76\\_CommentFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##Intranet#bank76\\_LabelFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##Intranet#bank76\\_AutorunStatus -> 01 DF DF 00 DF 01 00 01 01 EE FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 00 00 20 00 00 08 00 00 00 [binary data] -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##INTRANET#BANKS#BANK74\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##INTRANET#BANKS#BANK74\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##INTRANET#BANKS#BANK74\\_CommentFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##INTRANET#BANKS#BANK74\\_LabelFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##INTRANET#BANKS#BANK74\\_AutorunStatus -> 01 DF DF 00 DF 01 00 01 01 EE FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 00 00 20 00 00 08 00 00 00 [binary data] -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##Intranet#banks#BANK74#ACH IBS for Bank74_5\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##Intranet#banks#BANK74#ACH IBS for Bank74_5\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##Intranet#banks#BANK74#ACH IBS for Bank74_5\\_CommentFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##Intranet#banks#BANK74#ACH IBS for Bank74_5\\_LabelFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##Intranet#banks#BANK74#ACH IBS for Bank74_5\\_AutorunStatus -> 01 DF DF 00 DF 01 00 01 01 EE FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 00 00 20 00 00 08 00 00 00 [binary data] -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##intranet#banks#fundsxpress#bank73\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##intranet#banks#fundsxpress#bank73\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##intranet#banks#fundsxpress#bank73\\_CommentFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##intranet#banks#fundsxpress#bank73\\_LabelFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##intranet#DI\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##intranet#DI\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##intranet#DI\\_CommentFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##intranet#DI\\_LabelFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##xvision#c$#xvision#exportspool\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##xvision#c$#xvision#exportspool\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##xvision#c$#xvision#exportspool\\_CommentFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##xvision#c$#xvision#exportspool\\_LabelFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##xvision#c$#xvision#importspool\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##xvision#c$#xvision#importspool\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##xvision#c$#xvision#importspool\\_CommentFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##xvision#c$#xvision#importspool\\_LabelFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\A\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\A\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0bb30830-d19e-11d8-bc1d-806d6172696f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0bb30830-d19e-11d8-bc1d-806d6172696f}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0bb30831-d19e-11d8-bc1d-806d6172696f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0bb30831-d19e-11d8-bc1d-806d6172696f}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2410972b-584c-11db-ac50-00111104b19f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2410972b-584c-11db-ac50-00111104b19f}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d7a9e6c-f8e5-11db-ac5f-00111104b19f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d7a9e6c-f8e5-11db-ac5f-00111104b19f}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d7a9e6d-f8e5-11db-ac5f-00111104b19f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d7a9e6d-f8e5-11db-ac5f-00111104b19f}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d7a9e6d-f8e5-11db-ac5f-00111104b19f}\\_AutorunStatus -> 01 00 01 00 00 01 00 DF DF 5F DF 5F 5F 5F 5F DF DF 5F 5F 5F DF DF DF 5F 5F 5F DF DF DF 5F 5F DF 5F 5F 5F 5F 5F 01 00 01 01 EE FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 00 00 10 00 00 08 07 00 00 [binary data] -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d7a9e6d-f8e5-11db-ac5f-00111104b19f}\shell\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d7a9e6d-f8e5-11db-ac5f-00111104b19f}\shell\\ -> None -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d7a9e6d-f8e5-11db-ac5f-00111104b19f}\shell\Autoplay\ -> -> *MUIVerb* -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d7a9e6d-f8e5-11db-ac5f-00111104b19f}\shell\Autoplay\\MUIVerb -> @shell32.dll -> -> File not found -8504 -> -> File not found *MultiFile Done* -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d7a9e6d-f8e5-11db-ac5f-00111104b19f}\shell\Autoplay\DropTarget\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d7a9e6d-f8e5-11db-ac5f-00111104b19f}\shell\Autoplay\DropTarget\\CLSID -> {f26a669a-bcbb-4e37-abf9-7325da15f931} -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6A8F913D-B592-43FE-8E66-29874D16E67C}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6A8F913D-B592-43FE-8E66-29874D16E67C}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6A8F913D-B592-43FE-8E66-29874D16E67C}\\_CommentFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6A8F913D-B592-43FE-8E66-29874D16E67C}\\_LabelFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{80c70a35-63da-11d9-ac08-00111104b19f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{80c70a35-63da-11d9-ac08-00111104b19f}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9b480ff0-d1d7-11d8-a960-806d6172696f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9b480ff0-d1d7-11d8-a960-806d6172696f}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e2371fc-e0ce-11d8-abeb-806d6172696f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e2371fc-e0ce-11d8-abeb-806d6172696f}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e2371fd-e0ce-11d8-abeb-806d6172696f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e2371fd-e0ce-11d8-abeb-806d6172696f}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a96d5141-7a6c-11d8-afb1-806d6172696f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a96d5141-7a6c-11d8-afb1-806d6172696f}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a96d5142-7a6c-11d8-afb1-806d6172696f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a96d5142-7a6c-11d8-afb1-806d6172696f}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a96d5143-7a6c-11d8-afb1-806d6172696f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a96d5143-7a6c-11d8-afb1-806d6172696f}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{E9DEF107-2B3A-4B64-A8FC-4C6F15E3F3F1}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{E9DEF107-2B3A-4B64-A8FC-4C6F15E3F3F1}\\BaseClass -> Drive -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{E9DEF107-2B3A-4B64-A8FC-4C6F15E3F3F1}\\_CommentFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{E9DEF107-2B3A-4B64-A8FC-4C6F15E3F3F1}\\_LabelFromDesktopINI -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{80c70a35-63da-11d9-ac08-00111104b19f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{80c70a35-63da-11d9-ac08-00111104b19f}\\Data -> [Binary data over 100 bytes] -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{80c70a35-63da-11d9-ac08-00111104b19f}\\Generation -> 1 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{9e2371fc-e0ce-11d8-abeb-806d6172696f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{9e2371fc-e0ce-11d8-abeb-806d6172696f}\\Data -> [Binary data over 100 bytes] -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{9e2371fc-e0ce-11d8-abeb-806d6172696f}\\Generation -> 1 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{9e2371fd-e0ce-11d8-abeb-806d6172696f}\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{9e2371fd-e0ce-11d8-abeb-806d6172696f}\\Data -> [Binary data over 100 bytes] -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{9e2371fd-e0ce-11d8-abeb-806d6172696f}\\Generation -> 1 -> [Files/Folders - Created Within 90 days] $AVG8.VAULT$ -> %SystemDrive%\$AVG8.VAULT$ -> [Folder | Created Date = 5/7/2008 11:50:39 AM | Attr = H ] DIPa -> %SystemDrive%\DIPa -> [Folder | Created Date = 4/17/2008 9:39:04 AM | Attr = ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 535875584 bytes | Created Date = 5/7/2008 11:32:03 AM | Attr = HS] Remote Desktop Connection 118.lnk -> %SystemDrive%\Remote Desktop Connection 118.lnk -> [Ver = | Size = 1489 bytes | Created Date = 4/25/2008 2:21:21 PM | Attr = ] tumbleweed.pfx -> %SystemDrive%\tumbleweed.pfx -> [Ver = | Size = 2410 bytes | Created Date = 3/4/2008 5:45:55 PM | Attr = ] Avg -> %SystemRoot%\System32\drivers\Avg -> [Folder | Created Date = 5/7/2008 11:48:09 AM | Attr = ] avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [Ver = | Size = 5618689 bytes | Created Date = 5/7/2008 11:48:09 AM | Attr = ] incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [Ver = | Size = 23391261 bytes | Created Date = 5/7/2008 11:48:10 AM | Attr = ] microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [Ver = | Size = 142516 bytes | Created Date = 5/7/2008 11:48:10 AM | Attr = ] miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [Ver = | Size = 786367 bytes | Created Date = 5/7/2008 11:48:10 AM | Attr = ] avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.58 | Size = 96520 bytes | Created Date = 5/7/2008 11:48:20 AM | Attr = ] avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> GRISOFT, s.r.o. [Ver = 8.0.0.46 | Size = 26184 bytes | Created Date = 5/7/2008 11:48:18 AM | Attr = ] mfeapfk.sys -> %SystemRoot%\System32\drivers\mfeapfk.sys -> McAfee, Inc. [Ver = SYSCORE.13.3.0.116.x86 | Size = 64360 bytes | Created Date = 4/3/2008 5:46:26 PM | Attr = ] mfeavfk.sys -> %SystemRoot%\System32\drivers\mfeavfk.sys -> McAfee, Inc. [Ver = SYSCORE.13.3.0.116.x86 | Size = 72264 bytes | Created Date = 4/3/2008 5:46:26 PM | Attr = ] mfebopk.sys -> %SystemRoot%\System32\drivers\mfebopk.sys -> McAfee, Inc. [Ver = SYSCORE.13.3.0.116.x86 | Size = 34152 bytes | Created Date = 4/3/2008 5:46:27 PM | Attr = ] mfehidk.sys -> %SystemRoot%\System32\drivers\mfehidk.sys -> McAfee, Inc. [Ver = SYSCORE.13.3.0.120.x86 | Size = 170408 bytes | Created Date = 4/3/2008 5:46:25 PM | Attr = ] mfetdik.sys -> %SystemRoot%\System32\drivers\mfetdik.sys -> McAfee, Inc. [Ver = SYSCORE.13.3.0.116.x86 | Size = 52136 bytes | Created Date = 4/3/2008 5:46:25 PM | Attr = ] vnccom.SYS -> %SystemRoot%\System32\drivers\vnccom.SYS -> RDV Soft [Ver = 1.0.0.17 | Size = 6016 bytes | Created Date = 3/3/2008 1:09:54 PM | Attr = ] vncdrv.sys -> %SystemRoot%\System32\drivers\vncdrv.sys -> RDV Soft [Ver = 1.00.17 | Size = 4736 bytes | Created Date = 3/3/2008 1:09:15 PM | Attr = ] ' -> %SystemRoot%\System32\' -> [Ver = | Size = 198 bytes | Created Date = 3/3/2008 1:10:38 PM | Attr = ] avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.80 | Size = 10520 bytes | Created Date = 5/7/2008 11:48:26 AM | Attr = ] dwgmjjxr.dll -> %SystemRoot%\System32\dwgmjjxr.dll -> [Ver = | Size = 96320 bytes | Created Date = 4/24/2008 12:03:37 PM | Attr = ] dybxqehs.dll -> %SystemRoot%\System32\dybxqehs.dll -> [Ver = | Size = 67 bytes | Created Date = 4/29/2008 6:46:57 AM | Attr = ] epoPGPsdk.dll -> %SystemRoot%\System32\epoPGPsdk.dll -> PGP Corporation [Ver = 3.5.3 | Size = 1495552 bytes | Created Date = 4/3/2008 5:47:01 PM | Attr = ] epoPGPsdk.dll.sig -> %SystemRoot%\System32\epoPGPsdk.dll.sig -> [Ver = | Size = 280 bytes | Created Date = 4/3/2008 5:47:01 PM | Attr = ] fkqatwuv.dll -> %SystemRoot%\System32\fkqatwuv.dll -> [Ver = | Size = 97856 bytes | Created Date = 4/23/2008 12:11:32 PM | Attr = ] gngsocrq.dll -> %SystemRoot%\System32\gngsocrq.dll -> [Ver = | Size = 104512 bytes | Created Date = 4/29/2008 6:40:57 AM | Attr = ] hckwxtcm.dll -> %SystemRoot%\System32\hckwxtcm.dll -> [Ver = | Size = 67 bytes | Created Date = 4/28/2008 6:42:39 AM | Attr = ] hpvhflgq.dll -> %SystemRoot%\System32\hpvhflgq.dll -> [Ver = | Size = 88640 bytes | Created Date = 2/29/2008 9:37:06 AM | Attr = ] iuhiuvrn.ini -> %SystemRoot%\System32\iuhiuvrn.ini -> [Ver = | Size = 1314 bytes | Created Date = 2/27/2008 9:37:52 AM | Attr = HS] jgeruvwx.dll -> %SystemRoot%\System32\jgeruvwx.dll -> [Ver = | Size = 94272 bytes | Created Date = 4/24/2008 12:09:24 PM | Attr = ] kljqsjkv.dll -> %SystemRoot%\System32\kljqsjkv.dll -> [Ver = | Size = 89664 bytes | Created Date = 2/28/2008 9:34:36 AM | Attr = ] kmllm.ini -> %SystemRoot%\System32\kmllm.ini -> [Ver = | Size = 523758 bytes | Created Date = 2/14/2008 6:13:57 AM | Attr = HS] kmllm.ini2 -> %SystemRoot%\System32\kmllm.ini2 -> [Ver = | Size = 523758 bytes | Created Date = 2/14/2008 6:14:02 AM | Attr = HS] kwkvcuec.dll -> %SystemRoot%\System32\kwkvcuec.dll -> [Ver = | Size = 104000 bytes | Created Date = 4/28/2008 6:39:07 AM | Attr = ] ljyneknm.dll -> %SystemRoot%\System32\ljyneknm.dll -> [Ver = | Size = 84544 bytes | Created Date = 2/28/2008 9:37:29 AM | Attr = ] mbujhsnb.ini -> %SystemRoot%\System32\mbujhsnb.ini -> [Ver = | Size = 1542657 bytes | Created Date = 4/23/2008 12:08:43 PM | Attr = HS] mfdkdrbo.ini -> %SystemRoot%\System32\mfdkdrbo.ini -> [Ver = | Size = 1507031 bytes | Created Date = 4/28/2008 6:39:19 AM | Attr = HS] mnkenyjl.ini -> %SystemRoot%\System32\mnkenyjl.ini -> [Ver = | Size = 2154 bytes | Created Date = 2/28/2008 9:37:30 AM | Attr = HS] MRT.INI -> %SystemRoot%\System32\MRT.INI -> [Ver = | Size = 127 bytes | Created Date = 3/13/2008 3:06:03 AM | Attr = ] neauyyuv.dll -> %SystemRoot%\System32\neauyyuv.dll -> [Ver = | Size = 90176 bytes | Created Date = 2/27/2008 9:40:40 AM | Attr = ] nxyqrnej.dll -> %SystemRoot%\System32\nxyqrnej.dll -> [Ver = | Size = 67 bytes | Created Date = 4/29/2008 6:43:57 AM | Attr = ] obrdkdfm.dll -> %SystemRoot%\System32\obrdkdfm.dll -> [Ver = | Size = 87104 bytes | Created Date = 4/28/2008 6:39:17 AM | Attr = ] ocpnlpwq.dll -> %SystemRoot%\System32\ocpnlpwq.dll -> [Ver = | Size = 84544 bytes | Created Date = 2/29/2008 9:37:04 AM | Attr = ] peeungar.dll -> %SystemRoot%\System32\peeungar.dll -> [Ver = | Size = 88640 bytes | Created Date = 4/24/2008 12:06:24 PM | Attr = ] Primomonnt.dll -> %SystemRoot%\System32\Primomonnt.dll -> [Ver = | Size = 176235 bytes | Created Date = 3/3/2008 1:57:27 PM | Attr = ] qwplnpco.ini -> %SystemRoot%\System32\qwplnpco.ini -> [Ver = | Size = 1134 bytes | Created Date = 2/29/2008 9:37:16 AM | Attr = HS] ragnueep.ini -> %SystemRoot%\System32\ragnueep.ini -> [Ver = | Size = 1510299 bytes | Created Date = 4/24/2008 12:06:25 PM | Attr = HS] tfxmtqpo.dll1 -> %SystemRoot%\System32\tfxmtqpo.dll1 -> [Ver = | Size = 105536 bytes | Created Date = 4/25/2008 12:04:52 PM | Attr = ] vncdrv.dll -> %SystemRoot%\System32\vncdrv.dll -> RDV Soft [Ver = 1.00.19 | Size = 12800 bytes | Created Date = 3/3/2008 1:09:15 PM | Attr = ] vnchelp.dll -> %SystemRoot%\System32\vnchelp.dll -> RDV Soft [Ver = 4.0.1636.17 | Size = 5760 bytes | Created Date = 3/3/2008 1:09:15 PM | Attr = ] wbvfitsa.dll -> %SystemRoot%\System32\wbvfitsa.dll -> [Ver = | Size = 98880 bytes | Created Date = 4/25/2008 12:05:00 PM | Attr = ] xlvuqpvo.ini -> %SystemRoot%\System32\xlvuqpvo.ini -> [Ver = | Size = 1506971 bytes | Created Date = 4/25/2008 12:08:12 PM | Attr = HS] BMaf9e69cc.xml -> %SystemRoot%\BMaf9e69cc.xml -> [Ver = | Size = 109782 bytes | Created Date = 2/27/2008 9:34:42 AM | Attr = ] cookies.ini -> %SystemRoot%\cookies.ini -> [Ver = | Size = 597 bytes | Created Date = 4/25/2008 1:45:18 PM | Attr = ] PKZIP.EXE -> %SystemRoot%\PKZIP.EXE -> [Ver = | Size = 42166 bytes | Created Date = 4/17/2008 2:42:12 PM | Attr = ] pkzip25.exe -> %SystemRoot%\pkzip25.exe -> [Ver = | Size = 339456 bytes | Created Date = 4/17/2008 2:42:11 PM | Attr = ] PrimoPDF -> %SystemRoot%\PrimoPDF -> [Folder | Created Date = 3/3/2008 1:57:17 PM | Attr = ] 2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> pskt.ini -> %SystemRoot%\pskt.ini -> [Ver = | Size = 22 bytes | Created Date = 2/27/2008 9:34:41 AM | Attr = ] unins000.dat -> %SystemRoot%\unins000.dat -> [Ver = | Size = 2551 bytes | Created Date = 3/4/2008 3:54:21 PM | Attr = ] unins000.exe -> %SystemRoot%\unins000.exe -> [Ver = 51.49.0.0 | Size = 691545 bytes | Created Date = 3/4/2008 3:54:21 PM | Attr = ] wininit.ini -> %SystemRoot%\wininit.ini -> [Ver = | Size = 260 bytes | Created Date = 2/11/2008 1:08:28 PM | Attr = ] [Files/Folders - Modified Within 90 days] $AVG8.VAULT$ -> %SystemDrive%\$AVG8.VAULT$ -> [Folder | Modified Date = 5/7/2008 12:06:18 PM | Attr = H ] ACH -> %SystemDrive%\ACH -> [Folder | Modified Date = 5/7/2008 3:37:53 AM | Attr = ] ACHPRODUCTION -> %SystemDrive%\ACHPRODUCTION -> [Folder | Modified Date = 5/7/2008 1:00:42 PM | Attr = ] BOOT.INI -> %SystemDrive%\BOOT.INI -> [Ver = | Size = 211 bytes | Modified Date = 5/7/2008 11:48:38 AM | Attr = RHS] CardOrder -> %SystemDrive%\CardOrder -> [Folder | Modified Date = 5/7/2008 12:02:48 PM | Attr = ] di -> %SystemDrive%\di -> [Folder | Modified Date = 4/15/2008 4:29:59 PM | Attr = ] dic1 -> %SystemDrive%\dic1 -> [Folder | Modified Date = 4/17/2008 9:18:25 AM | Attr = ] Digital Insight -> %SystemDrive%\Digital Insight -> [Folder | Modified Date = 4/17/2008 11:01:22 AM | Attr = ] DIPa -> %SystemDrive%\DIPa -> [Folder | Modified Date = 4/24/2008 4:10:33 PM | Attr = ] Documents and Settings -> %SystemDrive%\Documents and Settings -> [Folder | Modified Date = 5/7/2008 11:46:20 AM | Attr = ] epsmac -> %SystemDrive%\epsmac -> [Folder | Modified Date = 5/2/2008 9:44:23 AM | Attr = ] FRIS -> %SystemDrive%\FRIS -> [Folder | Modified Date = 5/6/2008 5:07:07 PM | Attr = ] Generic FTP -> %SystemDrive%\Generic FTP -> [Folder | Modified Date = 5/7/2008 12:02:48 PM | Attr = ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 535875584 bytes | Modified Date = 5/7/2008 11:32:03 AM | Attr = HS] Kirchman -> %SystemDrive%\Kirchman -> [Folder | Modified Date = 5/7/2008 12:53:05 PM | Attr = ] MacFTP -> %SystemDrive%\MacFTP -> [Folder | Modified Date = 3/4/2008 9:22:32 PM | Attr = ] OneTouch -> %SystemDrive%\OneTouch -> [Folder | Modified Date = 5/6/2008 9:18:26 PM | Attr = ] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 5/7/2008 12:28:42 PM | Attr = R ] quarantine -> %SystemDrive%\quarantine -> [Folder | Modified Date = 5/6/2008 2:34:13 AM | Attr = ] RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Modified Date = 3/13/2008 10:20:03 AM | Attr = HS] Remote Desktop Connection 118.lnk -> %SystemDrive%\Remote Desktop Connection 118.lnk -> [Ver = | Size = 1489 bytes | Modified Date = 4/25/2008 2:22:33 PM | Attr = ] STARBIN -> %SystemDrive%\STARBIN -> [Folder | Modified Date = 5/1/2008 6:55:01 PM | Attr = ] tumbleweed.pfx -> %SystemDrive%\tumbleweed.pfx -> [Ver = | Size = 2410 bytes | Modified Date = 3/4/2008 5:45:56 PM | Attr = ] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 5/7/2008 11:48:51 AM | Attr = ] Avg -> %SystemRoot%\System32\drivers\Avg -> [Folder | Modified Date = 5/7/2008 11:51:25 AM | Attr = ] avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [Ver = | Size = 5618689 bytes | Modified Date = 5/7/2008 11:48:10 AM | Attr = ] incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [Ver = | Size = 23391261 bytes | Modified Date = 5/7/2008 11:51:14 AM | Attr = ] microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [Ver = | Size = 142516 bytes | Modified Date = 5/7/2008 11:50:51 AM | Attr = ] miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [Ver = | Size = 786367 bytes | Modified Date = 5/7/2008 11:48:10 AM | Attr = ] avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.58 | Size = 96520 bytes | Modified Date = 5/7/2008 11:48:21 AM | Attr = ] avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> GRISOFT, s.r.o. [Ver = 8.0.0.46 | Size = 26184 bytes | Modified Date = 5/7/2008 11:48:18 AM | Attr = ] ' -> %SystemRoot%\System32\' -> [Ver = | Size = 198 bytes | Modified Date = 3/3/2008 1:10:38 PM | Attr = ] apmctrc.BAK -> %SystemRoot%\System32\apmctrc.BAK -> [Ver = | Size = 0 bytes | Modified Date = 5/6/2008 11:38:55 AM | Attr = ] appmgmt -> %SystemRoot%\System32\appmgmt -> [Folder | Modified Date = 2/11/2008 12:34:43 PM | Attr = ] 2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.80 | Size = 10520 bytes | Modified Date = 5/7/2008 11:48:26 AM | Attr = ] CatRoot2 -> %SystemRoot%\System32\CatRoot2 -> [Folder | Modified Date = 4/22/2008 3:32:52 AM | Attr = ] DLLCACHE -> %SystemRoot%\System32\DLLCACHE -> [Folder | Modified Date = 4/9/2008 3:05:49 AM | Attr = RHS] DRIVERS -> %SystemRoot%\System32\DRIVERS -> [Folder | Modified Date = 5/7/2008 11:48:20 AM | Attr = ] dwgmjjxr.dll -> %SystemRoot%\System32\dwgmjjxr.dll -> [Ver = | Size = 96320 bytes | Modified Date = 4/24/2008 12:03:37 PM | Attr = ] dybxqehs.dll -> %SystemRoot%\System32\dybxqehs.dll -> [Ver = | Size = 67 bytes | Modified Date = 4/29/2008 6:46:57 AM | Attr = ] edeeg.ini -> %SystemRoot%\System32\edeeg.ini -> [Ver = | Size = 6674 bytes | Modified Date = 2/11/2008 3:24:41 PM | Attr = HS] edeeg.ini2 -> %SystemRoot%\System32\edeeg.ini2 -> [Ver = | Size = 6674 bytes | Modified Date = 2/11/2008 3:25:16 PM | Attr = HS] fkqatwuv.dll -> %SystemRoot%\System32\fkqatwuv.dll -> [Ver = | Size = 97856 bytes | Modified Date = 4/23/2008 12:11:32 PM | Attr = ] FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [Ver = | Size = 125320 bytes | Modified Date = 4/9/2008 3:36:56 AM | Attr = ] FxsTmp -> %SystemRoot%\System32\FxsTmp -> [Folder | Modified Date = 3/13/2008 4:53:01 AM | Attr = ] gngsocrq.dll -> %SystemRoot%\System32\gngsocrq.dll -> [Ver = | Size = 104512 bytes | Modified Date = 4/29/2008 6:40:57 AM | Attr = ] hckwxtcm.dll -> %SystemRoot%\System32\hckwxtcm.dll -> [Ver = | Size = 67 bytes | Modified Date = 4/28/2008 6:42:39 AM | Attr = ] hpvhflgq.dll -> %SystemRoot%\System32\hpvhflgq.dll -> [Ver = | Size = 88640 bytes | Modified Date = 2/29/2008 9:37:07 AM | Attr = ] iuhiuvrn.ini -> %SystemRoot%\System32\iuhiuvrn.ini -> [Ver = | Size = 1314 bytes | Modified Date = 2/28/2008 8:46:36 AM | Attr = HS] jgeruvwx.dll -> %SystemRoot%\System32\jgeruvwx.dll -> [Ver = | Size = 94272 bytes | Modified Date = 4/24/2008 12:09:25 PM | Attr = ] kljqsjkv.dll -> %SystemRoot%\System32\kljqsjkv.dll -> [Ver = | Size = 89664 bytes | Modified Date = 2/28/2008 9:34:37 AM | Attr = ] kmllm.ini -> %SystemRoot%\System32\kmllm.ini -> [Ver = | Size = 523758 bytes | Modified Date = 5/7/2008 11:50:41 AM | Attr = HS] kmllm.ini2 -> %SystemRoot%\System32\kmllm.ini2 -> [Ver = | Size = 523758 bytes | Modified Date = 5/7/2008 11:48:59 AM | Attr = HS] kwkvcuec.dll -> %SystemRoot%\System32\kwkvcuec.dll -> [Ver = | Size = 104000 bytes | Modified Date = 4/28/2008 6:39:07 AM | Attr = ] ljyneknm.dll -> %SystemRoot%\System32\ljyneknm.dll -> [Ver = | Size = 84544 bytes | Modified Date = 2/28/2008 9:37:30 AM | Attr = ] Macromed -> %SystemRoot%\System32\Macromed -> [Folder | Modified Date = 2/12/2008 1:20:14 AM | Attr = ] mbujhsnb.ini -> %SystemRoot%\System32\mbujhsnb.ini -> [Ver = | Size = 1542657 bytes | Modified Date = 4/24/2008 11:57:39 AM | Attr = HS] mfdkdrbo.ini -> %SystemRoot%\System32\mfdkdrbo.ini -> [Ver = | Size = 1507031 bytes | Modified Date = 4/28/2008 6:39:36 AM | Attr = HS] mnkenyjl.ini -> %SystemRoot%\System32\mnkenyjl.ini -> [Ver = | Size = 2154 bytes | Modified Date = 2/29/2008 12:07:30 AM | Attr = HS] MRT.INI -> %SystemRoot%\System32\MRT.INI -> [Ver = | Size = 127 bytes | Modified Date = 3/13/2008 3:06:03 AM | Attr = ] neauyyuv.dll -> %SystemRoot%\System32\neauyyuv.dll -> [Ver = | Size = 90176 bytes | Modified Date = 2/27/2008 9:40:41 AM | Attr = ] NtmsData -> %SystemRoot%\System32\NtmsData -> [Folder | Modified Date = 5/6/2008 9:19:03 PM | Attr = ] nxyqrnej.dll -> %SystemRoot%\System32\nxyqrnej.dll -> [Ver = | Size = 67 bytes | Modified Date = 4/29/2008 6:43:57 AM | Attr = ] obrdkdfm.dll -> %SystemRoot%\System32\obrdkdfm.dll -> [Ver = | Size = 87104 bytes | Modified Date = 4/28/2008 6:39:18 AM | Attr = ] ocpnlpwq.dll -> %SystemRoot%\System32\ocpnlpwq.dll -> [Ver = | Size = 84544 bytes | Modified Date = 2/29/2008 9:37:05 AM | Attr = ] peeungar.dll -> %SystemRoot%\System32\peeungar.dll -> [Ver = | Size = 88640 bytes | Modified Date = 4/24/2008 12:06:25 PM | Attr = ] PERFC009.DAT -> %SystemRoot%\System32\PERFC009.DAT -> [Ver = | Size = 64200 bytes | Modified Date = 4/13/2008 3:05:20 AM | Attr = ] PERFH009.DAT -> %SystemRoot%\System32\PERFH009.DAT -> [Ver = | Size = 407670 bytes | Modified Date = 4/13/2008 3:05:20 AM | Attr = ] PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [Ver = | Size = 458826 bytes | Modified Date = 4/13/2008 3:05:20 AM | Attr = ] qwplnpco.ini -> %SystemRoot%\System32\qwplnpco.ini -> [Ver = | Size = 1134 bytes | Modified Date = 3/1/2008 12:15:55 AM | Attr = HS] ragnueep.ini -> %SystemRoot%\System32\ragnueep.ini -> [Ver = | Size = 1510299 bytes | Modified Date = 4/24/2008 7:19:22 PM | Attr = HS] tfxmtqpo.dll1 -> %SystemRoot%\System32\tfxmtqpo.dll1 -> [Ver = | Size = 105536 bytes | Modified Date = 4/25/2008 12:04:53 PM | Attr = ] wbvfitsa.dll -> %SystemRoot%\System32\wbvfitsa.dll -> [Ver = | Size = 98880 bytes | Modified Date = 4/25/2008 12:05:06 PM | Attr = ] WPA.DBL -> %SystemRoot%\System32\WPA.DBL -> [Ver = | Size = 2278 bytes | Modified Date = 4/23/2008 7:08:25 AM | Attr = ] xlvuqpvo.ini -> %SystemRoot%\System32\xlvuqpvo.ini -> [Ver = | Size = 1506971 bytes | Modified Date = 4/28/2008 6:38:43 AM | Attr = HS] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 4/9/2008 3:06:02 AM | Attr = H ] 2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 88140675.dk1 -> %SystemRoot%\88140675.dk1 -> [Ver = | Size = 2346 bytes | Modified Date = 4/23/2008 5:22:15 AM | Attr = ] 88140675.dk2 -> %SystemRoot%\88140675.dk2 -> [Ver = | Size = 1762 bytes | Modified Date = 4/23/2008 5:22:51 AM | Attr = ] 88140679.dk1 -> %SystemRoot%\88140679.dk1 -> [Ver = | Size = 2338 bytes | Modified Date = 5/2/2008 3:55:41 AM | Attr = ] 88140679.dk2 -> %SystemRoot%\88140679.dk2 -> [Ver = | Size = 1762 bytes | Modified Date = 5/2/2008 3:59:35 AM | Attr = ] 88140682.dk1 -> %SystemRoot%\88140682.dk1 -> [Ver = | Size = 2338 bytes | Modified Date = 3/19/2008 3:52:33 PM | Attr = ] 88140682.dk2 -> %SystemRoot%\88140682.dk2 -> [Ver = | Size = 1762 bytes | Modified Date = 3/19/2008 3:53:00 PM | Attr = ] 88236441.dk1 -> %SystemRoot%\88236441.dk1 -> [Ver = | Size = 2354 bytes | Modified Date = 5/7/2008 3:34:35 AM | Attr = ] 88236441.dk2 -> %SystemRoot%\88236441.dk2 -> [Ver = | Size = 1762 bytes | Modified Date = 5/7/2008 3:35:00 AM | Attr = ] assembly -> %SystemRoot%\assembly -> [Folder | Modified Date = 4/13/2008 3:11:04 AM | Attr = R S] BMaf9e69cc.xml -> %SystemRoot%\BMaf9e69cc.xml -> [Ver = | Size = 109782 bytes | Modified Date = 5/7/2008 8:38:23 AM | Attr = ] BOOTSTAT.DAT -> %SystemRoot%\BOOTSTAT.DAT -> [Ver = | Size = 2048 bytes | Modified Date = 5/7/2008 11:32:03 AM | Attr = S] cookies.ini -> %SystemRoot%\cookies.ini -> [Ver = | Size = 597 bytes | Modified Date = 4/26/2008 11:45:31 AM | Attr = ] CSC -> %SystemRoot%\CSC -> [Folder | Modified Date = 5/7/2008 11:32:12 AM | Attr = HS] Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 3/2/2008 4:08:46 AM | Attr = ] Downloaded Installations -> %SystemRoot%\Downloaded Installations -> [Folder | Modified Date = 2/11/2008 12:34:40 PM | Attr = ] Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 5/6/2008 5:20:47 PM | Attr = S] Help -> %SystemRoot%\Help -> [Folder | Modified Date = 3/1/2008 1:37:49 PM | Attr = ] imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1355 bytes | Modified Date = 4/9/2008 3:05:59 AM | Attr = ] INF -> %SystemRoot%\INF -> [Folder | Modified Date = 4/9/2008 3:06:08 AM | Attr = H ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 5/7/2008 12:13:45 PM | Attr = HS] Microsoft.NET -> %SystemRoot%\Microsoft.NET -> [Folder | Modified Date = 4/13/2008 3:11:08 AM | Attr = ] MSAGENT -> %SystemRoot%\MSAGENT -> [Folder | Modified Date = 3/2/2008 4:17:35 AM | Attr = ] ODBC.INI -> %SystemRoot%\ODBC.INI -> [Ver = | Size = 737 bytes | Modified Date = 3/7/2008 11:23:14 AM | Attr = ] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 5/7/2008 1:11:38 PM | Attr = ] PrimoPDF -> %SystemRoot%\PrimoPDF -> [Folder | Modified Date = 3/3/2008 1:57:17 PM | Attr = ] primopdf.ini -> %SystemRoot%\primopdf.ini -> [Ver = | Size = 310 bytes | Modified Date = 3/3/2008 1:57:22 PM | Attr = ] pskt.ini -> %SystemRoot%\pskt.ini -> [Ver = | Size = 22 bytes | Modified Date = 5/7/2008 8:59:51 AM | Attr = ] pss -> %SystemRoot%\pss -> [Folder | Modified Date = 2/29/2008 12:17:54 AM | Attr = ] randseed.rnd -> %SystemRoot%\randseed.rnd -> [Ver = | Size = 512 bytes | Modified Date = 3/23/2008 5:33:04 PM | Attr = ] Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 2/27/2008 11:15:09 AM | Attr = ] SECURITY -> %SystemRoot%\SECURITY -> [Folder | Modified Date = 5/7/2008 11:31:22 AM | Attr = ] SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Modified Date = 3/1/2008 1:37:57 PM | Attr = ] SYSTEM.INI -> %SystemRoot%\SYSTEM.INI -> [Ver = | Size = 227 bytes | Modified Date = 5/7/2008 11:48:37 AM | Attr = ] SYSTEM32 -> %SystemRoot%\SYSTEM32 -> [Folder | Modified Date = 5/7/2008 12:29:33 PM | Attr = ] Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 5/7/2008 1:14:08 PM | Attr = ] unins000.dat -> %SystemRoot%\unins000.dat -> [Ver = | Size = 2551 bytes | Modified Date = 3/4/2008 3:54:21 PM | Attr = ] unins000.exe -> %SystemRoot%\unins000.exe -> [Ver = 51.49.0.0 | Size = 691545 bytes | Modified Date = 3/4/2008 3:53:34 PM | Attr = ] WDTCPCON.INI -> %SystemRoot%\WDTCPCON.INI -> [Ver = | Size = 27 bytes | Modified Date = 5/7/2008 7:18:49 AM | Attr = ] WIN.INI -> %SystemRoot%\WIN.INI -> [Ver = | Size = 857 bytes | Modified Date = 5/7/2008 11:48:37 AM | Attr = ] wininit.ini -> %SystemRoot%\wininit.ini -> [Ver = | Size = 260 bytes | Modified Date = 3/7/2008 12:04:49 AM | Attr = ] WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 5/7/2008 11:47:13 AM | Attr = ] BackupACH_C1.job -> %SystemRoot%\tasks\BackupACH_C1.job -> [Ver = | Size = 364 bytes | Modified Date = 5/6/2008 7:01:06 PM | Attr = ] BackupACH_C1001.job -> %SystemRoot%\tasks\BackupACH_C1001.job -> [Ver = | Size = 370 bytes | Modified Date = 5/6/2008 7:01:06 PM | Attr = ] BackupACH_C1002.job -> %SystemRoot%\tasks\BackupACH_C1002.job -> [Ver = | Size = 370 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] BackupACH_DDC.job -> %SystemRoot%\tasks\BackupACH_DDC.job -> [Ver = | Size = 370 bytes | Modified Date = 5/7/2008 7:01:02 AM | Attr = ] BackupACH_NWSB.job -> %SystemRoot%\tasks\BackupACH_NWSB.job -> [Ver = | Size = 370 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] BackupACH_NWSB001.job -> %SystemRoot%\tasks\BackupACH_NWSB001.job -> [Ver = | Size = 376 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] @Alternate Data Stream - 88 bytes -> %SystemRoot%\tasks\BackupACH_NWSB001.job:SummaryInformation @Alternate Data Stream - 0 bytes -> %SystemRoot%\tasks\BackupACH_NWSB001.job:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} BackupACH_NWSB002.job -> %SystemRoot%\tasks\BackupACH_NWSB002.job -> [Ver = | Size = 376 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] Backup_COL0.job -> %SystemRoot%\tasks\Backup_COL0.job -> [Ver = | Size = 378 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] Backup_COL1.job -> %SystemRoot%\tasks\Backup_COL1.job -> [Ver = | Size = 384 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] Backup_COL2.job -> %SystemRoot%\tasks\Backup_COL2.job -> [Ver = | Size = 386 bytes | Modified Date = 5/7/2008 7:01:03 AM | Attr = ] Backup_ExtNacha.job -> %SystemRoot%\tasks\Backup_ExtNacha.job -> [Ver = | Size = 362 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] rpc.job -> %SystemRoot%\tasks\rpc.job -> [Ver = | Size = 386 bytes | Modified Date = 5/1/2008 9:00:00 AM | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 5/7/2008 11:32:15 AM | Attr = H ] C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [Folder | Modified Date = 7/28/2004 3:59:19 PM | Attr = ] qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [Ver = | Size = 5902 bytes | Modified Date = 5/7/2008 11:34:10 AM | Attr = ] qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [Ver = | Size = 5902 bytes | Modified Date = 5/7/2008 11:34:10 AM | Attr = ] C:\Documents and Settings\ddcsystem\Local Settings\Temp\ -> C:\Documents and Settings\ddcsystem\Local Settings\Temp -> [Folder | Modified Date = 5/7/2008 1:09:11 PM | Attr = ] wbxtrc1.dat -> C:\Documents and Settings\ddcsystem\Local Settings\Temp\wbxtrc1.dat -> [Ver = | Size = 297106 bytes | Modified Date = 5/6/2008 5:28:54 PM | Attr = ] 245 C:\Documents and Settings\ddcsystem\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\ddcsystem\Local Settings\Temp\*.tmp -> C:\WINDOWS\Temp\ -> C:\WINDOWS\Temp -> [Folder | Modified Date = 5/7/2008 1:14:13 PM | Attr = ] GLF18.EXE -> C:\WINDOWS\Temp\GLF18.EXE -> [Ver = | Size = 167171 bytes | Modified Date = 3/16/2007 8:55:06 AM | Attr = ] GLF1E7.EXE -> C:\WINDOWS\Temp\GLF1E7.EXE -> [Ver = | Size = 167171 bytes | Modified Date = 3/16/2007 8:55:06 AM | Attr = ] GLF270.EXE -> C:\WINDOWS\Temp\GLF270.EXE -> [Ver = | Size = 167171 bytes | Modified Date = 3/16/2007 8:55:06 AM | Attr = ] GLF2D4.EXE -> C:\WINDOWS\Temp\GLF2D4.EXE -> [Ver = | Size = 167171 bytes | Modified Date = 3/16/2007 8:55:06 AM | Attr = ] GLFF.EXE -> C:\WINDOWS\Temp\GLFF.EXE -> [Ver = | Size = 167171 bytes | Modified Date = 3/16/2007 8:55:06 AM | Attr = ] 10 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> C:\WINDOWS\Temp\ONE138.tmp\ -> C:\WINDOWS\Temp\ONE138.tmp\ -> [Folder | Modified Date = 2/9/2008 11:20:01 AM | Attr = ] upgrade.exe -> C:\WINDOWS\Temp\ONE138.tmp\upgrade.exe -> [Ver = | Size = 271780 bytes | Modified Date = 2/6/2008 9:03:28 PM | Attr = ] C:\WINDOWS\Temp\ONE144.tmp\ -> C:\WINDOWS\Temp\ONE144.tmp\ -> [Folder | Modified Date = 2/10/2008 5:16:22 PM | Attr = ] upgrade.exe -> C:\WINDOWS\Temp\ONE144.tmp\upgrade.exe -> [Ver = | Size = 271645 bytes | Modified Date = 2/8/2008 3:06:52 PM | Attr = ] C:\WINDOWS\Temp\ONE2B92.tmp\ -> C:\WINDOWS\Temp\ONE2B92.tmp\ -> [Folder | Modified Date = 12/13/2007 11:45:31 AM | Attr = ] upgrade.exe -> C:\WINDOWS\Temp\ONE2B92.tmp\upgrade.exe -> [Ver = | Size = 271682 bytes | Modified Date = 10/17/2007 7:23:56 PM | Attr = ] C:\WINDOWS\Temp\ONE2D2.tmp\ -> C:\WINDOWS\Temp\ONE2D2.tmp\ -> [Folder | Modified Date = 1/21/2008 8:48:16 PM | Attr = ] upgrade.exe -> C:\WINDOWS\Temp\ONE2D2.tmp\upgrade.exe -> [Ver = | Size = 272124 bytes | Modified Date = 1/21/2008 6:32:28 PM | Attr = ] C:\WINDOWS\Temp\ONE738.tmp\ -> C:\WINDOWS\Temp\ONE738.tmp\ -> [Folder | Modified Date = 1/17/2008 10:15:08 PM | Attr = ] upgrade.exe -> C:\WINDOWS\Temp\ONE738.tmp\upgrade.exe -> [Ver = | Size = 271936 bytes | Modified Date = 1/17/2008 7:23:30 PM | Attr = ] C:\WINDOWS\Temp\ONE8C.tmp\ -> C:\WINDOWS\Temp\ONE8C.tmp\ -> [Folder | Modified Date = 1/28/2008 10:58:28 PM | Attr = ] upgrade.exe -> C:\WINDOWS\Temp\ONE8C.tmp\upgrade.exe -> [Ver = | Size = 275834 bytes | Modified Date = 1/28/2008 6:58:54 PM | Attr = ] C:\WINDOWS\Temp\ONEE1.tmp\ -> C:\WINDOWS\Temp\ONEE1.tmp\ -> [Folder | Modified Date = 1/15/2008 4:53:44 PM | Attr = ] upgrade.exe -> C:\WINDOWS\Temp\ONEE1.tmp\upgrade.exe -> [Ver = | Size = 277286 bytes | Modified Date = 12/5/2007 9:24:26 PM | Attr = ] C:\WINDOWS\Temp\ONEF.tmp\ -> C:\WINDOWS\Temp\ONEF.tmp\ -> [Folder | Modified Date = 1/25/2008 6:44:33 AM | Attr = ] upgrade.exe -> C:\WINDOWS\Temp\ONEF.tmp\upgrade.exe -> [Ver = | Size = 272280 bytes | Modified Date = 1/24/2008 7:09:48 PM | Attr = ] C:\WINDOWS\Temp\Cookies\ -> C:\WINDOWS\Temp\Cookies -> [Folder | Modified Date = 7/28/2004 3:48:14 PM | Attr = S] index.dat -> C:\WINDOWS\Temp\Cookies\index.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/11/2008 6:05:01 PM | Attr = ] C:\WINDOWS\Temp\History\History.IE5\ -> C:\WINDOWS\Temp\History\History.IE5\ -> [Folder | Modified Date = 7/28/2004 3:48:14 PM | Attr = S] index.dat -> C:\WINDOWS\Temp\History\History.IE5\index.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/11/2008 6:05:01 PM | Attr = ] C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ -> [Folder | Modified Date = 7/28/2004 3:48:14 PM | Attr = S] index.dat -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat -> [Ver = | Size = 32768 bytes | Modified Date = 2/11/2008 6:05:01 PM | Attr = ] C:\WINDOWS\Temp\History\History.IE5\ -> C:\WINDOWS\Temp\History\History.IE5\ -> [Folder | Modified Date = 7/28/2004 3:48:14 PM | Attr = S] desktop.ini -> C:\WINDOWS\Temp\History\History.IE5\desktop.ini -> [Ver = | Size = 113 bytes | Modified Date = 7/28/2004 3:48:14 PM | Attr = HS] C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ -> [Folder | Modified Date = 7/28/2004 3:48:14 PM | Attr = S] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/28/2004 3:48:14 PM | Attr = HS] C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\0D23K92B\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\0D23K92B -> [Folder | Modified Date = 7/28/2004 3:48:14 PM | Attr = S] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\0D23K92B\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/28/2004 3:48:14 PM | Attr = HS] C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\G5YVOP2B\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\G5YVOP2B -> [Folder | Modified Date = 7/28/2004 3:48:14 PM | Attr = S] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\G5YVOP2B\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/28/2004 3:48:14 PM | Attr = HS] C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\OXQNO1I7\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\OXQNO1I7 -> [Folder | Modified Date = 7/28/2004 3:48:14 PM | Attr = S] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\OXQNO1I7\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/28/2004 3:48:14 PM | Attr = HS] C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\SP6VOTIZ\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\SP6VOTIZ -> [Folder | Modified Date = 7/28/2004 3:48:14 PM | Attr = S] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\SP6VOTIZ\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 7/28/2004 3:48:14 PM | Attr = HS] [File - Lop Check: Additional Folder Scans - Non-Microsoft Only] Application Data -> C:\Documents and Settings\All Users\Application Data -> [Folder | Modified Date = 5/7/2008 11:47:36 AM | Attr = RH ] Adobe -> C:\Documents and Settings\All Users\Application Data\Adobe -> [Folder | Modified Date = 6/22/2006 11:10:29 PM | Attr = ] Acrobat -> C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat -> [Folder | Modified Date = 6/22/2006 11:10:29 PM | Attr = ] 7.0 -> C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0 -> [Folder | Modified Date = 6/22/2006 11:10:29 PM | Attr = ] Replicate -> C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0\Replicate -> [Folder | Modified Date = 6/22/2006 11:10:29 PM | Attr = ] Security -> C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0\Replicate\Security -> [Folder | Modified Date = 6/22/2006 11:10:29 PM | Attr = ] Photoshop Album -> C:\Documents and Settings\All Users\Application Data\Adobe\Photoshop Album -> [Folder | Modified Date = 3/23/2006 5:57:19 AM | Attr = ] 3.0 -> C:\Documents and Settings\All Users\Application Data\Adobe\Photoshop Album\3.0 -> [Folder | Modified Date = 3/23/2006 5:57:08 AM | Attr = ] Catalog Folders -> C:\Documents and Settings\All Users\Application Data\Adobe\Photoshop Album\Catalog Folders -> [Folder | Modified Date = 3/23/2006 5:57:04 AM | Attr = ] My Catalog -> C:\Documents and Settings\All Users\Application Data\Adobe\Photoshop Album\Catalog Folders\My Catalog -> [Folder | Modified Date = 3/23/2006 5:57:05 AM | Attr = ] Catalogs -> C:\Documents and Settings\All Users\Application Data\Adobe\Photoshop Album\Catalogs -> [Folder | Modified Date = 1/24/2008 5:56:40 PM | Attr = ] avg8 -> C:\Documents and Settings\All Users\Application Data\avg8 -> [Folder | Modified Date = 5/7/2008 11:47:37 AM | Attr = ] admincli -> C:\Documents and Settings\All Users\Application Data\avg8\admincli -> [Folder | Modified Date = 5/7/2008 11:47:36 AM | Attr = ] AvgAm -> C:\Documents and Settings\All Users\Application Data\avg8\AvgAm -> [Folder | Modified Date = 5/7/2008 11:47:36 AM | Attr = ] Cfg -> C:\Documents and Settings\All Users\Application Data\avg8\Cfg -> [Folder | Modified Date = 5/7/2008 11:52:28 AM | Attr = ] emc -> C:\Documents and Settings\All Users\Application Data\avg8\emc -> [Folder | Modified Date = 5/7/2008 11:47:36 AM | Attr = ] Log -> C:\Documents and Settings\All Users\Application Data\avg8\Log -> [Folder | Modified Date = 5/7/2008 11:53:51 AM | Attr = ] Lsdb -> C:\Documents and Settings\All Users\Application Data\avg8\Lsdb -> [Folder | Modified Date = 5/7/2008 11:51:25 AM | Attr = ] Prev -> C:\Documents and Settings\All Users\Application Data\avg8\Lsdb\Prev -> [Folder | Modified Date = 5/7/2008 11:47:37 AM | Attr = ] scanlogs -> C:\Documents and Settings\All Users\Application Data\avg8\scanlogs -> [Folder | Modified Date = 5/7/2008 12:30:58 PM | Attr = ] update -> C:\Documents and Settings\All Users\Application Data\avg8\update -> [Folder | Modified Date = 5/7/2008 11:50:38 AM | Attr = ] backup -> C:\Documents and Settings\All Users\Application Data\avg8\update\backup -> [Folder | Modified Date = 5/7/2008 11:51:25 AM | Attr = ] download -> C:\Documents and Settings\All Users\Application Data\avg8\update\download -> [Folder | Modified Date = 5/7/2008 11:50:51 AM | Attr = ] prepare -> C:\Documents and Settings\All Users\Application Data\avg8\update\prepare -> [Folder | Modified Date = 5/7/2008 11:51:23 AM | Attr = ] CyberLink -> C:\Documents and Settings\All Users\Application Data\CyberLink -> [Folder | Modified Date = 7/9/2004 8:00:10 AM | Attr = ] Media Experience -> C:\Documents and Settings\All Users\Application Data\CyberLink\Media Experience -> [Folder | Modified Date = 7/9/2004 8:00:10 AM | Attr = ] DMX More Applications -> C:\Documents and Settings\All Users\Application Data\CyberLink\Media Experience\DMX More Applications -> [Folder | Modified Date = 7/9/2004 8:00:10 AM | Attr = ] Movie -> C:\Documents and Settings\All Users\Application Data\CyberLink\Media Experience\DMX More Applications\Movie -> [Folder | Modified Date = 7/9/2004 8:00:10 AM | Attr = ] Music -> C:\Documents and Settings\All Users\Application Data\CyberLink\Media Experience\DMX More Applications\Music -> [Folder | Modified Date = 7/9/2004 8:00:10 AM | Attr = ] Dell -> C:\Documents and Settings\All Users\Application Data\Dell -> [Folder | Modified Date = 1/27/2008 1:17:18 AM | Attr = ] TransferAgent -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent -> [Folder | Modified Date = 1/27/2008 1:17:21 AM | Attr = ] da -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\da -> [Folder | Modified Date = 1/27/2008 1:17:19 AM | Attr = ] da-DK -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\da-DK -> [Folder | Modified Date = 1/27/2008 1:17:19 AM | Attr = ] de -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\de -> [Folder | Modified Date = 1/27/2008 1:17:19 AM | Attr = ] de-DE -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\de-DE -> [Folder | Modified Date = 1/27/2008 1:17:19 AM | Attr = ] en -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\en -> [Folder | Modified Date = 1/27/2008 1:17:19 AM | Attr = ] en-US -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\en-US -> [Folder | Modified Date = 1/27/2008 1:17:19 AM | Attr = ] es -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\es -> [Folder | Modified Date = 1/27/2008 1:17:19 AM | Attr = ] es-ES -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\es-ES -> [Folder | Modified Date = 1/27/2008 1:17:19 AM | Attr = ] fi -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\fi -> [Folder | Modified Date = 1/27/2008 1:17:19 AM | Attr = ] fi-FI -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\fi-FI -> [Folder | Modified Date = 1/27/2008 1:17:19 AM | Attr = ] fr -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\fr -> [Folder | Modified Date = 1/27/2008 1:17:19 AM | Attr = ] fr-FR -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\fr-FR -> [Folder | Modified Date = 1/27/2008 1:17:19 AM | Attr = ] it -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\it -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] it-IT -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\it-IT -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] ja -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\ja -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] ja-JP -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\ja-JP -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] ko -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\ko -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] ko-KR -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\ko-KR -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] nb-NO -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\nb-NO -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] nl -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\nl -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] nl-BE -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\nl-BE -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] nl-NL -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\nl-NL -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] nn-NO -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\nn-NO -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] no -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\no -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] pt -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\pt -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] pt-BR -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\pt-BR -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] sv -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\sv -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] sv-FI -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\sv-FI -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] sv-SE -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\sv-SE -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] zh-CHS -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\zh-CHS -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] zh-CHT -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\zh-CHT -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] zh-CN -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\zh-CN -> [Folder | Modified Date = 1/27/2008 1:17:20 AM | Attr = ] zh-HK -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\zh-HK -> [Folder | Modified Date = 1/27/2008 1:17:21 AM | Attr = ] zh-TW -> C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\zh-TW -> [Folder | Modified Date = 1/27/2008 1:17:21 AM | Attr = ] GTek -> C:\Documents and Settings\All Users\Application Data\GTek -> [Folder | Modified Date = 6/9/2005 11:12:14 PM | Attr = H ] gtny -> C:\Documents and Settings\All Users\Application Data\GTek\gtny -> [Folder | Modified Date = 3/6/2008 3:34:10 PM | Attr = ] GTUpdate -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate -> [Folder | Modified Date = 6/9/2005 11:11:52 PM | Attr = ] AUpdate -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate -> [Folder | Modified Date = 4/16/2007 6:31:09 AM | Attr = H ] Channels -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels -> [Folder | Modified Date = 4/23/2007 6:25:06 AM | Attr = H ] ch5 -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5 -> [Folder | Modified Date = 5/4/2006 11:49:41 PM | Attr = H ] chdata -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\chdata -> [Folder | Modified Date = 5/4/2006 11:49:39 PM | Attr = H ] Config -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\Config -> [Folder | Modified Date = 5/4/2006 11:49:41 PM | Attr = H ] HTML -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\HTML -> [Folder | Modified Date = 5/4/2006 11:49:41 PM | Attr = H ] diag -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\HTML\diag -> [Folder | Modified Date = 5/4/2006 11:49:41 PM | Attr = ] group_icon -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\HTML\group_icon -> [Folder | Modified Date = 5/4/2006 11:49:41 PM | Attr = ] Internet -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\HTML\group_icon\Internet -> [Folder | Modified Date = 5/4/2006 11:49:41 PM | Attr = ] Performance -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\HTML\group_icon\Performance -> [Folder | Modified Date = 5/4/2006 11:49:41 PM | Attr = ] Security -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\HTML\group_icon\Security -> [Folder | Modified Date = 5/4/2006 11:49:41 PM | Attr = ] Policies -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\Policies -> [Folder | Modified Date = 5/4/2006 11:49:41 PM | Attr = H ] Triggers -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\Triggers -> [Folder | Modified Date = 5/4/2006 11:49:41 PM | Attr = H ] DellSupport -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\DellSupport -> [Folder | Modified Date = 4/16/2007 6:31:09 AM | Attr = ] GDQL_Cache -> C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\DellSupport\GDQL_Cache -> [Folder | Modified Date = 7/14/2007 9:15:14 AM | Attr = ] Ipswitch -> C:\Documents and Settings\All Users\Application Data\Ipswitch -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] WS_FTP -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP -> [Folder | Modified Date = 3/13/2008 4:09:42 AM | Attr = ] DirCache -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\DirCache -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] FireScripts -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\FireScripts -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] HTML -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] Res_409_9.01 -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01 -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] CONNECTIONWIZARD -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\CONNECTIONWIZARD -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] CSS -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\CSS -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] ERRORS -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\ERRORS -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] FTPVIEW -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\FTPVIEW -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] LOGIN -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\LOGIN -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] NEWSITEFOLDER -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\NEWSITEFOLDER -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] NEWSITENAME -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\NEWSITENAME -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] PGPGENKEYWIZ -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\PGPGENKEYWIZ -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] PGPIMPKEYWIZ -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\PGPIMPKEYWIZ -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] SSHCLIENTKEYCREATE -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\SSHCLIENTKEYCREATE -> [Folder | Modified Date = 1/4/2008 3:32:16 PM | Attr = ] SSHCLIENTKEYIMPORT -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\SSHCLIENTKEYIMPORT -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] SSHTRUSTEDKEYS -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\SSHTRUSTEDKEYS -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] SSLCERTIMPWIZ -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\SSLCERTIMPWIZ -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] SSLCREATECERTWIZ -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\SSLCREATECERTWIZ -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] TMP -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\TMP -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] Logs -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\Logs -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] pgp -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\pgp -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] Sites -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\Sites -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] SSH -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\SSH -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] ClientKeyStore -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\SSH\ClientKeyStore -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] TrustedKeyStore -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\SSH\TrustedKeyStore -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] SSL -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\SSL -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] Certs -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\SSL\Certs -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] Storage -> C:\Documents and Settings\All Users\Application Data\Ipswitch\WS_FTP\Storage -> [Folder | Modified Date = 1/4/2008 3:32:15 PM | Attr = ] McAfee -> C:\Documents and Settings\All Users\Application Data\McAfee -> [Folder | Modified Date = 4/3/2008 5:47:44 PM | Attr = ] Common Framework -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework -> [Folder | Modified Date = 5/6/2008 5:29:58 PM | Attr = ] AgentEvents -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\AgentEvents -> [Folder | Modified Date = 4/3/2008 5:47:01 PM | Attr = ] Current -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current -> [Folder | Modified Date = 4/25/2008 5:11:12 PM | Attr = ] ENCPTCNT6000 -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current\ENCPTCNT6000 -> [Folder | Modified Date = 4/3/2008 6:00:17 PM | Attr = ] MPEMSBCK1000 -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current\MPEMSBCK1000 -> [Folder | Modified Date = 4/3/2008 5:55:51 PM | Attr = ] MPEPRDCK1000 -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current\MPEPRDCK1000 -> [Folder | Modified Date = 4/3/2008 5:56:44 PM | Attr = ] MPESVRUP1000 -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current\MPESVRUP1000 -> [Folder | Modified Date = 4/3/2008 5:57:38 PM | Attr = ] MPEVIRCK1000 -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current\MPEVIRCK1000 -> [Folder | Modified Date = 4/3/2008 5:58:31 PM | Attr = ] PATCHTMP1000 -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current\PATCHTMP1000 -> [Folder | Modified Date = 4/3/2008 5:59:24 PM | Attr = ] PATCHTMP2000 -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current\PATCHTMP2000 -> [Folder | Modified Date = 4/25/2008 5:11:12 PM | Attr = ] PUPDAT__1000 -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current\PUPDAT__1000 -> [Folder | Modified Date = 4/3/2008 6:09:58 PM | Attr = ] SPAMSAFE1000 -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current\SPAMSAFE1000 -> [Folder | Modified Date = 4/28/2008 5:31:11 PM | Attr = ] VIRUSCAN8600 -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current\VIRUSCAN8600 -> [Folder | Modified Date = 4/3/2008 5:54:57 PM | Attr = ] VSCANDAT1000 -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current\VSCANDAT1000 -> [Folder | Modified Date = 5/6/2008 5:28:32 PM | Attr = ] VSCANENG1000 -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Current\VSCANENG1000 -> [Folder | Modified Date = 5/6/2008 5:23:11 PM | Attr = ] Db -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Db -> [Folder | Modified Date = 4/24/2008 5:28:00 PM | Attr = ] Software -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Db\Software -> [Folder | Modified Date = 4/3/2008 5:47:01 PM | Attr = ] Task -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Task -> [Folder | Modified Date = 4/3/2008 5:47:40 PM | Attr = ] TaskInternalData -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Task\TaskInternalData -> [Folder | Modified Date = 4/3/2008 5:47:40 PM | Attr = ] TaskTempData -> C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Task\TaskTempData -> [Folder | Modified Date = 5/6/2008 5:21:01 PM | Attr = ] DesktopProtection -> C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection -> [Folder | Modified Date = 4/12/2008 9:14:47 AM | Attr = ] Microsoft -> C:\Documents and Settings\All Users\Application Data\Microsoft -> [Folder | Modified Date = 6/9/2005 4:10:02 AM | Attr = S] Crypto -> C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto -> [Folder | Modified Date = 7/9/2004 7:31:42 AM | Attr = S] DSS -> C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS -> [Folder | Modified Date = 7/9/2004 7:31:42 AM | Attr = S] MachineKeys -> C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys -> [Folder | Modified Date = 4/11/2006 11:44:03 PM | Attr = S] RSA -> C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA -> [Folder | Modified Date = 7/28/2004 4:15:24 PM | Attr = S] MachineKeys -> C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys -> [Folder | Modified Date = 4/9/2007 7:13:06 AM | Attr = S] S-1-5-18 -> C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18 -> [Folder | Modified Date = 7/28/2004 4:15:24 PM | Attr = S] Dr Watson -> C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson -> [Folder | Modified Date = 10/26/2004 8:56:57 AM | Attr = ] HTML Help -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help -> [Folder | Modified Date = 7/9/2004 7:31:42 AM | Attr = ] Media Index -> C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index -> [Folder | Modified Date = 10/14/2004 11:15:05 AM | Attr = ] Media Player -> C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player -> [Folder | Modified Date = 10/14/2004 12:01:40 PM | Attr = ] Network -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network -> [Folder | Modified Date = 7/9/2004 7:31:42 AM | Attr = ] Connections -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections -> [Folder | Modified Date = 10/14/2004 12:01:54 PM | Attr = ] Cm -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Cm -> [Folder | Modified Date = 10/14/2004 12:01:54 PM | Attr = ] Pbk -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk -> [Folder | Modified Date = 7/29/2004 10:52:38 AM | Attr = ] Downloader -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [Folder | Modified Date = 7/28/2004 3:59:19 PM | Attr = ] User Account Pictures -> C:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures -> [Folder | Modified Date = 7/28/2004 3:51:46 PM | Attr = ] Default Pictures -> C:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures -> [Folder | Modified Date = 7/9/2004 7:32:34 AM | Attr = ] USMT -> C:\Documents and Settings\All Users\Application Data\Microsoft\USMT -> [Folder | Modified Date = 6/9/2005 4:10:02 AM | Attr = ] Windows NT -> C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT -> [Folder | Modified Date = 7/9/2004 7:31:42 AM | Attr = ] MSFax -> C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax -> [Folder | Modified Date = 7/9/2004 7:32:34 AM | Attr = ] ActivityLog -> C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog -> [Folder | Modified Date = 7/9/2004 7:32:34 AM | Attr = ] Common Coverpages -> C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\Common Coverpages -> [Folder | Modified Date = 7/9/2004 7:32:34 AM | Attr = ] Inbox -> C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\Inbox -> [Folder | Modified Date = 7/9/2004 7:32:34 AM | Attr = ] Queue -> C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\Queue -> [Folder | Modified Date = 4/16/2007 2:13:22 PM | Attr = HS] SentItems -> C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\SentItems -> [Folder | Modified Date = 7/9/2004 7:32:34 AM | Attr = ] MSN6 -> C:\Documents and Settings\All Users\Application Data\MSN6 -> [Folder | Modified Date = 12/6/2004 8:51:47 PM | Attr = ] SBSI -> C:\Documents and Settings\All Users\Application Data\SBSI -> [Folder | Modified Date = 7/9/2004 7:31:42 AM | Attr = ] ORUN -> C:\Documents and Settings\All Users\Application Data\SBSI\ORUN -> [Folder | Modified Date = 7/9/2004 7:31:42 AM | Attr = ] Spybot - Search & Destroy -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy -> [Folder | Modified Date = 3/4/2008 3:58:06 PM | Attr = ] Backups -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups -> [Folder | Modified Date = 2/12/2008 4:23:47 PM | Attr = ] Excludes -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Excludes -> [Folder | Modified Date = 2/29/2008 12:08:14 AM | Attr = ] Logs -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Logs -> [Folder | Modified Date = 12/17/2007 8:53:27 PM | Attr = ] Recovery -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery -> [Folder | Modified Date = 3/9/2008 7:42:37 PM | Attr = ] Snapshots -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots -> [Folder | Modified Date = 3/4/2008 3:58:06 PM | Attr = ] Snapshots2 -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2 -> [Folder | Modified Date = 5/7/2008 12:02:33 PM | Attr = ] Symantec -> C:\Documents and Settings\All Users\Application Data\Symantec -> [Folder | Modified Date = 7/28/2004 4:00:55 PM | Attr = ] LiveUpdate -> C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate -> [Folder | Modified Date = 7/28/2004 3:57:15 PM | Attr = ] Downloads -> C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads -> [Folder | Modified Date = 7/28/2004 4:00:10 PM | Attr = ] pcAnywhere -> C:\Documents and Settings\All Users\Application Data\Symantec\pcAnywhere -> [Folder | Modified Date = 6/18/2007 7:07:22 PM | Attr = ] Windows Genuine Advantage -> C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage -> [Folder | Modified Date = 1/18/2006 4:49:17 PM | Attr = ] data -> C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage\data -> [Folder | Modified Date = 1/18/2006 4:49:17 PM | Attr = ] Winferno -> C:\Documents and Settings\All Users\Application Data\Winferno -> [Folder | Modified Date = 12/13/2007 2:58:56 PM | Attr = ] RegPowerClean -> C:\Documents and Settings\All Users\Application Data\Winferno\RegPowerClean -> [Folder | Modified Date = 12/13/2007 2:58:56 PM | Attr = ] WinZip -> C:\Documents and Settings\All Users\Application Data\WinZip -> [Folder | Modified Date = 4/13/2007 4:27:40 PM | Attr = ] Application Data -> C:\Documents and Settings\ddcsystem\Application Data -> [Folder | Modified Date = 5/7/2008 12:28:11 PM | Attr = RH ] Adobe -> C:\Documents and Settings\ddcsystem\Application Data\Adobe -> [Folder | Modified Date = 3/5/2008 3:55:49 AM | Attr = ] Acrobat -> C:\Documents and Settings\ddcsystem\Application Data\Adobe\Acrobat -> [Folder | Modified Date = 3/5/2008 3:55:49 AM | Attr = ] 7.0 -> C:\Documents and Settings\ddcsystem\Application Data\Adobe\Acrobat\7.0 -> [Folder | Modified Date = 3/10/2008 3:11:57 PM | Attr = ] Collab -> C:\Documents and Settings\ddcsystem\Application Data\Adobe\Acrobat\7.0\Collab -> [Folder | Modified Date = 3/10/2008 3:12:00 PM | Attr = ] JavaScripts -> C:\Documents and Settings\ddcsystem\Application Data\Adobe\Acrobat\7.0\JavaScripts -> [Folder | Modified Date = 3/10/2008 3:11:57 PM | Attr = ] Preferences -> C:\Documents and Settings\ddcsystem\Application Data\Adobe\Acrobat\7.0\Preferences -> [Folder | Modified Date = 3/26/2008 11:36:30 PM | Attr = ] Updater -> C:\Documents and Settings\ddcsystem\Application Data\Adobe\Acrobat\7.0\Updater -> [Folder | Modified Date = 3/10/2008 3:11:57 PM | Attr = ] Flash Player -> C:\Documents and Settings\ddcsystem\Application Data\Adobe\Flash Player -> [Folder | Modified Date = 3/5/2008 12:16:04 AM | Attr = ] AssetCache -> C:\Documents and Settings\ddcsystem\Application Data\Adobe\Flash Player\AssetCache -> [Folder | Modified Date = 3/5/2008 12:16:04 AM | Attr = ] LHCQSQ4T -> C:\Documents and Settings\ddcsystem\Application Data\Adobe\Flash Player\AssetCache\LHCQSQ4T -> [Folder | Modified Date = 5/3/2008 10:18:22 AM | Attr = ] AdobeUM -> C:\Documents and Settings\ddcsystem\Application Data\AdobeUM -> [Folder | Modified Date = 3/8/2008 5:23:57 AM | Attr = ] AVGTOOLBAR -> C:\Documents and Settings\ddcsystem\Application Data\AVGTOOLBAR -> [Folder | Modified Date = 5/7/2008 12:58:11 PM | Attr = ] NewCfg -> C:\Documents and Settings\ddcsystem\Application Data\AVGTOOLBAR\NewCfg -> [Folder | Modified Date = 5/7/2008 12:54:58 PM | Attr = ] FileZilla -> C:\Documents and Settings\ddcsystem\Application Data\FileZilla -> [Folder | Modified Date = 5/6/2008 7:38:10 PM | Attr = ] GTek -> C:\Documents and Settings\ddcsystem\Application Data\GTek -> [Folder | Modified Date = 3/4/2008 3:48:39 PM | Attr = ] GTUpdate -> C:\Documents and Settings\ddcsystem\Application Data\GTek\GTUpdate -> [Folder | Modified Date = 3/4/2008 3:48:39 PM | Attr = ] AUpdate -> C:\Documents and Settings\ddcsystem\Application Data\GTek\GTUpdate\AUpdate -> [Folder | Modified Date = 3/4/2008 3:48:39 PM | Attr = ] DellSupport -> C:\Documents and Settings\ddcsystem\Application Data\GTek\GTUpdate\AUpdate\DellSupport -> [Folder | Modified Date = 3/4/2008 3:48:40 PM | Attr = ] Identities -> C:\Documents and Settings\ddcsystem\Application Data\Identities -> [Folder | Modified Date = 7/9/2004 7:31:44 AM | Attr = ] {68C8549C-B54C-49C8-AE06-8BBD06069FA8} -> C:\Documents and Settings\ddcsystem\Application Data\Identities\{68C8549C-B54C-49C8-AE06-8BBD06069FA8} -> [Folder | Modified Date = 7/9/2004 7:31:44 AM | Attr = ] Ipswitch -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch -> [Folder | Modified Date = 3/31/2008 11:11:54 AM | Attr = ] WS_FTP -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP -> [Folder | Modified Date = 4/15/2008 8:11:22 AM | Attr = ] DirCache -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\DirCache -> [Folder | Modified Date = 5/7/2008 12:31:30 PM | Attr = ] FireScripts -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\FireScripts -> [Folder | Modified Date = 3/4/2008 4:13:44 PM | Attr = ] HTML -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML -> [Folder | Modified Date = 3/4/2008 4:13:44 PM | Attr = ] Res_409_9.01 -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01 -> [Folder | Modified Date = 3/6/2008 11:43:03 AM | Attr = ] CONNECTIONWIZARD -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\CONNECTIONWIZARD -> [Folder | Modified Date = 3/4/2008 4:13:44 PM | Attr = ] CSS -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\CSS -> [Folder | Modified Date = 3/4/2008 4:13:44 PM | Attr = ] ERRORS -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\ERRORS -> [Folder | Modified Date = 3/4/2008 4:13:44 PM | Attr = ] FTPVIEW -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\FTPVIEW -> [Folder | Modified Date = 3/4/2008 4:13:44 PM | Attr = ] LOGIN -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\LOGIN -> [Folder | Modified Date = 3/4/2008 4:13:44 PM | Attr = ] NEWSITEFOLDER -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\NEWSITEFOLDER -> [Folder | Modified Date = 3/4/2008 4:13:44 PM | Attr = ] NEWSITENAME -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\NEWSITENAME -> [Folder | Modified Date = 3/4/2008 4:13:45 PM | Attr = ] PGPGENKEYWIZ -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\PGPGENKEYWIZ -> [Folder | Modified Date = 3/4/2008 4:13:45 PM | Attr = ] PGPIMPKEYWIZ -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\PGPIMPKEYWIZ -> [Folder | Modified Date = 3/4/2008 4:13:45 PM | Attr = ] SSHCLIENTKEYCREATE -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\SSHCLIENTKEYCREATE -> [Folder | Modified Date = 3/4/2008 4:13:45 PM | Attr = ] SSHCLIENTKEYIMPORT -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\SSHCLIENTKEYIMPORT -> [Folder | Modified Date = 3/4/2008 4:13:45 PM | Attr = ] SSHTRUSTEDKEYS -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\SSHTRUSTEDKEYS -> [Folder | Modified Date = 3/4/2008 4:13:45 PM | Attr = ] SSLCERTIMPWIZ -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\SSLCERTIMPWIZ -> [Folder | Modified Date = 3/4/2008 4:13:45 PM | Attr = ] SSLCREATECERTWIZ -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\SSLCREATECERTWIZ -> [Folder | Modified Date = 3/4/2008 4:13:45 PM | Attr = ] TMP -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\HTML\Res_409_9.01\TMP -> [Folder | Modified Date = 5/5/2008 11:17:33 AM | Attr = ] Logs -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\Logs -> [Folder | Modified Date = 5/7/2008 12:31:28 PM | Attr = ] pgp -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\pgp -> [Folder | Modified Date = 3/7/2008 3:50:16 PM | Attr = ] Sites -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\Sites -> [Folder | Modified Date = 3/6/2008 11:04:10 AM | Attr = ] SSH -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\SSH -> [Folder | Modified Date = 3/7/2008 3:36:51 PM | Attr = ] ClientKeyStore -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\SSH\ClientKeyStore -> [Folder | Modified Date = 3/7/2008 3:36:51 PM | Attr = ] SSL -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\SSL -> [Folder | Modified Date = 3/12/2008 10:26:35 AM | Attr = ] Certs -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\SSL\Certs -> [Folder | Modified Date = 3/4/2008 4:13:44 PM | Attr = ] Storage -> C:\Documents and Settings\ddcsystem\Application Data\Ipswitch\WS_FTP\Storage -> [Folder | Modified Date = 3/6/2008 11:58:38 AM | Attr = ] Jasc Software Inc -> C:\Documents and Settings\ddcsystem\Application Data\Jasc Software Inc -> [Folder | Modified Date = 7/9/2004 8:02:03 AM | Attr = ] Paint Shop Pro 8 -> C:\Documents and Settings\ddcsystem\Application Data\Jasc Software Inc\Paint Shop Pro 8 -> [Folder | Modified Date = 7/9/2004 8:02:03 AM | Attr = ] Cache -> C:\Documents and Settings\ddcsystem\Application Data\Jasc Software Inc\Paint Shop Pro 8\Cache -> [Folder | Modified Date = 7/9/2004 8:02:03 AM | Attr = ] Macromedia -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia -> [Folder | Modified Date = 3/5/2008 12:54:45 AM | Attr = ] Flash Player -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player -> [Folder | Modified Date = 3/5/2008 12:54:45 AM | Attr = ] #SharedObjects -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects -> [Folder | Modified Date = 3/5/2008 12:54:45 AM | Attr = ] 7QR8S6U6 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6 -> [Folder | Modified Date = 5/1/2008 12:32:35 AM | Attr = ] acmemarkets.shoplocal.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\acmemarkets.shoplocal.com -> [Folder | Modified Date = 4/15/2008 1:53:48 PM | Attr = ] ads1.msn.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\ads1.msn.com -> [Folder | Modified Date = 5/7/2008 6:04:36 AM | Attr = ] assets.espn.go.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\assets.espn.go.com -> [Folder | Modified Date = 4/26/2008 7:17:05 AM | Attr = ] ivp -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\assets.espn.go.com\ivp -> [Folder | Modified Date = 4/26/2008 7:17:05 AM | Attr = ] player -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\assets.espn.go.com\ivp\player -> [Folder | Modified Date = 4/26/2008 7:17:05 AM | Attr = ] player185.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\assets.espn.go.com\ivp\player\player185.swf -> [Folder | Modified Date = 4/26/2008 7:17:05 AM | Attr = ] motion -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\assets.espn.go.com\motion -> [Folder | Modified Date = 4/26/2008 7:05:03 AM | Attr = ] fsp -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\assets.espn.go.com\motion\fsp -> [Folder | Modified Date = 4/26/2008 7:05:03 AM | Attr = ] FSPRoot -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\assets.espn.go.com\motion\fsp\FSPRoot -> [Folder | Modified Date = 4/26/2008 7:05:03 AM | Attr = ] espnmotion13_cv.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\assets.espn.go.com\motion\fsp\FSPRoot\espnmotion13_cv.swf -> [Folder | Modified Date = 4/26/2008 7:05:04 AM | Attr = ] babystrology.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\babystrology.com -> [Folder | Modified Date = 3/22/2008 6:38:20 AM | Attr = ] tickers -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\babystrology.com\tickers -> [Folder | Modified Date = 3/22/2008 6:38:20 AM | Attr = ] baby-ticker-glass.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\babystrology.com\tickers\baby-ticker-glass.swf -> [Folder | Modified Date = 3/22/2008 6:38:20 AM | Attr = ] bankofamerica.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\bankofamerica.com -> [Folder | Modified Date = 3/5/2008 8:02:04 PM | Attr = ] sas -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\bankofamerica.com\sas -> [Folder | Modified Date = 3/5/2008 8:02:04 PM | Attr = ] sas-docs -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\bankofamerica.com\sas\sas-docs -> [Folder | Modified Date = 3/5/2008 8:02:04 PM | Attr = ] html -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\bankofamerica.com\sas\sas-docs\html -> [Folder | Modified Date = 3/5/2008 8:02:04 PM | Attr = ] pmfso.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\bankofamerica.com\sas\sas-docs\html\pmfso.swf -> [Folder | Modified Date = 3/5/2008 8:02:05 PM | Attr = ] bc.newsweek.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\bc.newsweek.com -> [Folder | Modified Date = 5/7/2008 5:57:13 AM | Attr = ] bin.clearspring.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\bin.clearspring.com -> [Folder | Modified Date = 5/7/2008 8:36:58 AM | Attr = ] blst.msn.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\blst.msn.com -> [Folder | Modified Date = 4/9/2008 2:35:50 AM | Attr = ] br -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\blst.msn.com\br -> [Folder | Modified Date = 4/9/2008 2:35:50 AM | Attr = ] chan -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\blst.msn.com\br\chan -> [Folder | Modified Date = 4/9/2008 2:35:50 AM | Attr = ] cs -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\blst.msn.com\br\chan\cs -> [Folder | Modified Date = 4/9/2008 2:35:50 AM | Attr = ] InTheMotherhoodV2 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\blst.msn.com\br\chan\cs\InTheMotherhoodV2 -> [Folder | Modified Date = 4/9/2008 2:35:50 AM | Attr = ] static -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\blst.msn.com\br\chan\cs\InTheMotherhoodV2\static -> [Folder | Modified Date = 4/9/2008 2:35:51 AM | Attr = ] swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\blst.msn.com\br\chan\cs\InTheMotherhoodV2\static\swf -> [Folder | Modified Date = 4/9/2008 2:35:51 AM | Attr = ] 6 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\blst.msn.com\br\chan\cs\InTheMotherhoodV2\static\swf\6 -> [Folder | Modified Date = 4/9/2008 2:35:51 AM | Attr = ] VideoPlayer.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\blst.msn.com\br\chan\cs\InTheMotherhoodV2\static\swf\6\VideoPlayer.swf -> [Folder | Modified Date = 4/9/2008 2:35:51 AM | Attr = ] cache.reverbnation.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\cache.reverbnation.com -> [Folder | Modified Date = 3/26/2008 8:34:24 AM | Attr = ] widgets -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\cache.reverbnation.com\widgets -> [Folder | Modified Date = 3/26/2008 8:34:24 AM | Attr = ] serve_unprotected -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\cache.reverbnation.com\widgets\serve_unprotected -> [Folder | Modified Date = 3/26/2008 8:34:24 AM | Attr = ] 13 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\cache.reverbnation.com\widgets\serve_unprotected\13 -> [Folder | Modified Date = 3/26/2008 8:34:24 AM | Attr = ] widget.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\cache.reverbnation.com\widgets\serve_unprotected\13\widget.swf -> [Folder | Modified Date = 3/26/2008 8:34:24 AM | Attr = ] cbslocal.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\cbslocal.com -> [Folder | Modified Date = 3/12/2008 6:38:55 AM | Attr = ] CBS -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\cbslocal.com\CBS -> [Folder | Modified Date = 3/12/2008 6:38:55 AM | Attr = ] national -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\cbslocal.com\CBS\national -> [Folder | Modified Date = 3/12/2008 6:38:55 AM | Attr = ] swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\cbslocal.com\CBS\national\swf -> [Folder | Modified Date = 3/12/2008 6:38:55 AM | Attr = ] cbs_poll.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\cbslocal.com\CBS\national\swf\cbs_poll.swf -> [Folder | Modified Date = 5/3/2008 11:15:00 AM | Attr = ] chatango.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\chatango.com -> [Folder | Modified Date = 3/22/2008 4:50:33 AM | Attr = ] community.bonnaroo.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\community.bonnaroo.com -> [Folder | Modified Date = 3/19/2008 12:50:33 PM | Attr = ] kickapps -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\community.bonnaroo.com\kickapps -> [Folder | Modified Date = 3/19/2008 12:50:33 PM | Attr = ] flash -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\community.bonnaroo.com\kickapps\flash -> [Folder | Modified Date = 3/19/2008 12:50:33 PM | Attr = ] premium_drop_v3.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\community.bonnaroo.com\kickapps\flash\premium_drop_v3.swf -> [Folder | Modified Date = 3/19/2008 12:50:33 PM | Attr = ] cosmos.bcst.yahoo.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\cosmos.bcst.yahoo.com -> [Folder | Modified Date = 3/6/2008 2:16:56 AM | Attr = ] d.yimg.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\d.yimg.com -> [Folder | Modified Date = 5/2/2008 12:34:53 AM | Attr = ] flash.quantserve.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\flash.quantserve.com -> [Folder | Modified Date = 3/7/2008 1:39:14 AM | Attr = ] gamblerstelevision.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\gamblerstelevision.com -> [Folder | Modified Date = 4/25/2008 2:44:49 AM | Attr = ] swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\gamblerstelevision.com\swf -> [Folder | Modified Date = 4/25/2008 2:44:49 AM | Attr = ] player_spotxchange.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\gamblerstelevision.com\swf\player_spotxchange.swf -> [Folder | Modified Date = 4/25/2008 2:44:49 AM | Attr = ] giantfood.shoplocal.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\giantfood.shoplocal.com -> [Folder | Modified Date = 4/15/2008 1:51:31 PM | Attr = ] images.soapbox.msn.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\images.soapbox.msn.com -> [Folder | Modified Date = 5/7/2008 5:53:54 AM | Attr = ] flash -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\images.soapbox.msn.com\flash -> [Folder | Modified Date = 3/13/2008 1:06:28 AM | Attr = ] soapbox1_1.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\images.soapbox.msn.com\flash\soapbox1_1.swf -> [Folder | Modified Date = 5/7/2008 5:57:03 AM | Attr = ] interclick.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\interclick.com -> [Folder | Modified Date = 3/28/2008 7:35:32 AM | Attr = ] l.yimg.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com -> [Folder | Modified Date = 4/29/2008 2:36:37 AM | Attr = ] cosmos.bcst.yahoo.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com -> [Folder | Modified Date = 3/5/2008 1:58:16 AM | Attr = ] ver -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver -> [Folder | Modified Date = 4/2/2008 1:04:40 AM | Attr = ] 256.0 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\256.0 -> [Folder | Modified Date = 3/7/2008 1:17:42 AM | Attr = ] embed-2008-01-23-1334 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\256.0\embed-2008-01-23-1334 -> [Folder | Modified Date = 3/5/2008 1:58:17 AM | Attr = ] swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\256.0\embed-2008-01-23-1334\swf -> [Folder | Modified Date = 3/5/2008 1:58:17 AM | Attr = ] yup_embed_module.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\256.0\embed-2008-01-23-1334\swf\yup_embed_module.swf -> [Folder | Modified Date = 3/5/2008 1:58:17 AM | Attr = ] popup-2008-01-23-1334 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\256.0\popup-2008-01-23-1334 -> [Folder | Modified Date = 3/7/2008 1:17:42 AM | Attr = ] swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\256.0\popup-2008-01-23-1334\swf -> [Folder | Modified Date = 3/7/2008 1:17:42 AM | Attr = ] POP_meta.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\256.0\popup-2008-01-23-1334\swf\POP_meta.swf -> [Folder | Modified Date = 3/7/2008 1:17:42 AM | Attr = ] 260.0 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\260.0 -> [Folder | Modified Date = 4/5/2008 6:25:58 AM | Attr = ] embed-2008-03-20-0932 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\260.0\embed-2008-03-20-0932 -> [Folder | Modified Date = 4/2/2008 1:04:40 AM | Attr = ] swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\260.0\embed-2008-03-20-0932\swf -> [Folder | Modified Date = 4/2/2008 1:04:40 AM | Attr = ] yup_embed_module.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\260.0\embed-2008-03-20-0932\swf\yup_embed_module.swf -> [Folder | Modified Date = 4/2/2008 1:04:40 AM | Attr = ] popup-2008-03-20-0932 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\260.0\popup-2008-03-20-0932 -> [Folder | Modified Date = 4/5/2008 6:25:58 AM | Attr = ] swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\260.0\popup-2008-03-20-0932\swf -> [Folder | Modified Date = 4/5/2008 6:25:58 AM | Attr = ] POP_meta.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\cosmos.bcst.yahoo.com\ver\260.0\popup-2008-03-20-0932\swf\POP_meta.swf -> [Folder | Modified Date = 4/5/2008 6:25:58 AM | Attr = ] us.yimg.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\us.yimg.com -> [Folder | Modified Date = 3/14/2008 3:35:12 AM | Attr = ] i -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\us.yimg.com\i -> [Folder | Modified Date = 3/14/2008 3:35:12 AM | Attr = ] ligans -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\us.yimg.com\i\ligans -> [Folder | Modified Date = 3/14/2008 3:35:12 AM | Attr = ] kids -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\us.yimg.com\i\ligans\kids -> [Folder | Modified Date = 3/14/2008 3:35:12 AM | Attr = ] common -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\us.yimg.com\i\ligans\kids\common -> [Folder | Modified Date = 3/14/2008 3:35:12 AM | Attr = ] flash -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\us.yimg.com\i\ligans\kids\common\flash -> [Folder | Modified Date = 3/14/2008 3:35:12 AM | Attr = ] nav-1.2.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\l.yimg.com\us.yimg.com\i\ligans\kids\common\flash\nav-1.2.swf -> [Folder | Modified Date = 3/14/2008 3:35:12 AM | Attr = ] ll.static.abc.go.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\ll.static.abc.go.com -> [Folder | Modified Date = 3/14/2008 7:37:50 AM | Attr = ] wrapper -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\ll.static.abc.go.com\wrapper -> [Folder | Modified Date = 3/14/2008 7:37:50 AM | Attr = ] 1001 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\ll.static.abc.go.com\wrapper\1001 -> [Folder | Modified Date = 3/14/2008 7:37:50 AM | Attr = ] wrapper_v1.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\ll.static.abc.go.com\wrapper\1001\wrapper_v1.swf -> [Folder | Modified Date = 3/20/2008 12:58:17 AM | Attr = ] login.yahoo.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\login.yahoo.com -> [Folder | Modified Date = 3/7/2008 9:06:44 PM | Attr = ] media01.kyte.tv -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\media01.kyte.tv -> [Folder | Modified Date = 3/27/2008 5:56:41 AM | Attr = ] flash -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\media01.kyte.tv\flash -> [Folder | Modified Date = 3/27/2008 5:56:41 AM | Attr = ] MarbachLoader.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\media01.kyte.tv\flash\MarbachLoader.swf -> [Folder | Modified Date = 3/27/2008 5:56:41 AM | Attr = ] #kt -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\media01.kyte.tv\flash\MarbachLoader.swf\#kt -> [Folder | Modified Date = 3/28/2008 4:01:42 AM | Attr = ] mochibot.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\mochibot.com -> [Folder | Modified Date = 3/13/2008 9:46:56 AM | Attr = ] msn.foxsports.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\msn.foxsports.com -> [Folder | Modified Date = 3/11/2008 11:33:38 PM | Attr = ] msnbcmedia.msn.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\msnbcmedia.msn.com -> [Folder | Modified Date = 4/9/2008 2:34:05 AM | Attr = ] nuptialstv.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\nuptialstv.com -> [Folder | Modified Date = 4/25/2008 2:34:56 AM | Attr = ] swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\nuptialstv.com\swf -> [Folder | Modified Date = 4/25/2008 2:34:56 AM | Attr = ] player_spotxchange.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\nuptialstv.com\swf\player_spotxchange.swf -> [Folder | Modified Date = 4/25/2008 2:34:56 AM | Attr = ] pagead2.googlesyndication.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\pagead2.googlesyndication.com -> [Folder | Modified Date = 3/19/2008 2:10:05 PM | Attr = ] pagead -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\pagead2.googlesyndication.com\pagead -> [Folder | Modified Date = 3/19/2008 2:10:05 PM | Attr = ] googleadplayer.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\pagead2.googlesyndication.com\pagead\googleadplayer.swf -> [Folder | Modified Date = 3/19/2008 2:10:05 PM | Attr = ] pandora.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\pandora.com -> [Folder | Modified Date = 3/26/2008 4:57:26 AM | Attr = ] player.hulu.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\player.hulu.com -> [Folder | Modified Date = 3/13/2008 12:22:35 AM | Attr = ] 2.00 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\player.hulu.com\2.00 -> [Folder | Modified Date = 3/13/2008 12:22:35 AM | Attr = ] msn_player.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\player.hulu.com\2.00\msn_player.swf -> [Folder | Modified Date = 3/15/2008 2:22:11 AM | Attr = ] prod.untd.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\prod.untd.com -> [Folder | Modified Date = 3/22/2008 6:51:44 AM | Attr = ] resources.imeem.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\resources.imeem.com -> [Folder | Modified Date = 4/25/2008 3:13:21 AM | Attr = ] reverbnation.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\reverbnation.com -> [Folder | Modified Date = 3/7/2008 1:39:15 AM | Attr = ] rpmfreaks.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\rpmfreaks.com -> [Folder | Modified Date = 4/25/2008 2:35:22 AM | Attr = ] swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\rpmfreaks.com\swf -> [Folder | Modified Date = 4/25/2008 2:35:22 AM | Attr = ] player_spotxchange.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\rpmfreaks.com\swf\player_spotxchange.swf -> [Folder | Modified Date = 4/25/2008 2:35:22 AM | Attr = ] s.mcstatic.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\s.mcstatic.com -> [Folder | Modified Date = 4/5/2008 9:00:38 AM | Attr = ] secureinclude.ebaystatic.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\secureinclude.ebaystatic.com -> [Folder | Modified Date = 5/7/2008 12:42:36 AM | Attr = ] st.msn.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\st.msn.com -> [Folder | Modified Date = 3/6/2008 1:49:53 AM | Attr = ] br -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\st.msn.com\br -> [Folder | Modified Date = 3/6/2008 1:49:53 AM | Attr = ] chan -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\st.msn.com\br\chan -> [Folder | Modified Date = 3/6/2008 1:49:53 AM | Attr = ] cs -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\st.msn.com\br\chan\cs -> [Folder | Modified Date = 3/6/2008 1:49:53 AM | Attr = ] InTheMotherhoodV2 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\st.msn.com\br\chan\cs\InTheMotherhoodV2 -> [Folder | Modified Date = 3/6/2008 1:49:53 AM | Attr = ] static -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\st.msn.com\br\chan\cs\InTheMotherhoodV2\static -> [Folder | Modified Date = 3/6/2008 1:49:53 AM | Attr = ] swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\st.msn.com\br\chan\cs\InTheMotherhoodV2\static\swf -> [Folder | Modified Date = 3/15/2008 2:18:04 AM | Attr = ] 4 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\st.msn.com\br\chan\cs\InTheMotherhoodV2\static\swf\4 -> [Folder | Modified Date = 3/6/2008 1:49:53 AM | Attr = ] VideoPlayer.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\st.msn.com\br\chan\cs\InTheMotherhoodV2\static\swf\4\VideoPlayer.swf -> [Folder | Modified Date = 3/6/2008 1:49:53 AM | Attr = ] 6 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\st.msn.com\br\chan\cs\InTheMotherhoodV2\static\swf\6 -> [Folder | Modified Date = 3/15/2008 2:18:04 AM | Attr = ] VideoPlayer.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\st.msn.com\br\chan\cs\InTheMotherhoodV2\static\swf\6\VideoPlayer.swf -> [Folder | Modified Date = 3/15/2008 2:18:04 AM | Attr = ] stb.msn.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\stb.msn.com -> [Folder | Modified Date = 5/1/2008 12:32:35 AM | Attr = ] strawberrygames.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\strawberrygames.com -> [Folder | Modified Date = 3/13/2008 9:47:09 AM | Attr = ] swfs -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\strawberrygames.com\swfs -> [Folder | Modified Date = 3/13/2008 9:47:09 AM | Attr = ] bloons.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\strawberrygames.com\swfs\bloons.swf -> [Folder | Modified Date = 3/13/2008 9:59:43 AM | Attr = ] stuff.pyzam.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\stuff.pyzam.com -> [Folder | Modified Date = 3/22/2008 4:29:39 AM | Attr = ] suitesmart.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\suitesmart.com -> [Folder | Modified Date = 3/14/2008 3:21:55 AM | Attr = ] _f5e.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\suitesmart.com\_f5e.swf -> [Folder | Modified Date = 4/4/2008 7:16:16 AM | Attr = ] us.i1.yimg.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\us.i1.yimg.com -> [Folder | Modified Date = 3/14/2008 3:36:47 AM | Attr = ] cosmos.bcst.yahoo.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\us.i1.yimg.com\cosmos.bcst.yahoo.com -> [Folder | Modified Date = 3/14/2008 3:36:46 AM | Attr = ] player -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\us.i1.yimg.com\cosmos.bcst.yahoo.com\player -> [Folder | Modified Date = 3/14/2008 3:36:46 AM | Attr = ] embed-2-0-2007-01-30-1601 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\us.i1.yimg.com\cosmos.bcst.yahoo.com\player\embed-2-0-2007-01-30-1601 -> [Folder | Modified Date = 3/14/2008 3:36:46 AM | Attr = ] swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\us.i1.yimg.com\cosmos.bcst.yahoo.com\player\embed-2-0-2007-01-30-1601\swf -> [Folder | Modified Date = 3/14/2008 3:36:46 AM | Attr = ] yup_embed_module.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\us.i1.yimg.com\cosmos.bcst.yahoo.com\player\embed-2-0-2007-01-30-1601\swf\yup_embed_module.swf -> [Folder | Modified Date = 3/14/2008 3:36:46 AM | Attr = ] video.google.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\video.google.com -> [Folder | Modified Date = 3/22/2008 4:50:21 AM | Attr = ] googleplayer.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\video.google.com\googleplayer.swf -> [Folder | Modified Date = 3/22/2008 4:50:21 AM | Attr = ] video.nbcuni.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\video.nbcuni.com -> [Folder | Modified Date = 5/3/2008 10:13:12 AM | Attr = ] vlaze.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\vlaze.com -> [Folder | Modified Date = 4/26/2008 11:31:40 AM | Attr = ] swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\vlaze.com\swf -> [Folder | Modified Date = 4/26/2008 11:31:40 AM | Attr = ] player_spotxchange.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\vlaze.com\swf\player_spotxchange.swf -> [Folder | Modified Date = 5/1/2008 12:27:34 AM | Attr = ] void.snocap.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\void.snocap.com -> [Folder | Modified Date = 3/22/2008 4:50:25 AM | Attr = ] s -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\void.snocap.com\s -> [Folder | Modified Date = 3/22/2008 4:50:26 AM | Attr = ] store.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\void.snocap.com\s\store.swf -> [Folder | Modified Date = 3/22/2008 4:50:26 AM | Attr = ] storefront.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\void.snocap.com\s\storefront.swf -> [Folder | Modified Date = 3/22/2008 4:50:26 AM | Attr = ] widget-a1.slide.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\widget-a1.slide.com -> [Folder | Modified Date = 3/28/2008 4:08:44 AM | Attr = ] www.cmt.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.cmt.com -> [Folder | Modified Date = 4/5/2008 8:53:55 AM | Attr = ] global -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.cmt.com\global -> [Folder | Modified Date = 3/13/2008 3:35:19 AM | Attr = ] flash -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.cmt.com\global\flash -> [Folder | Modified Date = 3/13/2008 3:35:19 AM | Attr = ] module -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.cmt.com\global\flash\module -> [Folder | Modified Date = 3/13/2008 3:35:19 AM | Attr = ] mtv -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.cmt.com\global\flash\module\mtv -> [Folder | Modified Date = 3/13/2008 3:35:19 AM | Attr = ] playerlib -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.cmt.com\global\flash\module\mtv\playerlib -> [Folder | Modified Date = 3/13/2008 3:35:19 AM | Attr = ] 0.2.3.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.cmt.com\global\flash\module\mtv\playerlib\0.2.3.swf -> [Folder | Modified Date = 4/4/2008 2:45:20 AM | Attr = ] www.dailymotion.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.dailymotion.com -> [Folder | Modified Date = 3/22/2008 5:05:52 AM | Attr = ] flash -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.dailymotion.com\flash -> [Folder | Modified Date = 3/22/2008 5:05:52 AM | Attr = ] dmplayer -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.dailymotion.com\flash\dmplayer -> [Folder | Modified Date = 3/22/2008 5:05:52 AM | Attr = ] dmplayer.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.dailymotion.com\flash\dmplayer\dmplayer.swf -> [Folder | Modified Date = 3/22/2008 5:05:52 AM | Attr = ] www.heavy.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.heavy.com -> [Folder | Modified Date = 4/18/2008 3:17:18 PM | Attr = ] flash -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.heavy.com\flash -> [Folder | Modified Date = 4/18/2008 3:17:18 PM | Attr = ] 7417.4 -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.heavy.com\flash\7417.4 -> [Folder | Modified Date = 4/18/2008 3:17:18 PM | Attr = ] HeavyVideoPlayer.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.heavy.com\flash\7417.4\HeavyVideoPlayer.swf -> [Folder | Modified Date = 4/18/2008 3:17:18 PM | Attr = ] www.npr.org -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.npr.org -> [Folder | Modified Date = 3/13/2008 1:53:21 AM | Attr = ] player -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.npr.org\player -> [Folder | Modified Date = 3/13/2008 1:53:21 AM | Attr = ] main -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.npr.org\player\main -> [Folder | Modified Date = 3/13/2008 1:53:21 AM | Attr = ] audioPlayer.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.npr.org\player\main\audioPlayer.swf -> [Folder | Modified Date = 4/12/2008 2:12:35 AM | Attr = ] www.strawberrygames.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.strawberrygames.com -> [Folder | Modified Date = 3/14/2008 8:49:46 AM | Attr = ] swfs -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.strawberrygames.com\swfs -> [Folder | Modified Date = 3/14/2008 8:49:46 AM | Attr = ] bloons.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.strawberrygames.com\swfs\bloons.swf -> [Folder | Modified Date = 3/14/2008 9:23:22 AM | Attr = ] www.thestringdusters.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.thestringdusters.com -> [Folder | Modified Date = 4/5/2008 11:37:32 AM | Attr = ] play -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.thestringdusters.com\play -> [Folder | Modified Date = 4/5/2008 11:37:32 AM | Attr = ] xspf_jukebox.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.thestringdusters.com\play\xspf_jukebox.swf -> [Folder | Modified Date = 4/5/2008 11:37:32 AM | Attr = ] www.vh1.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.vh1.com -> [Folder | Modified Date = 4/12/2008 1:21:55 AM | Attr = ] global -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.vh1.com\global -> [Folder | Modified Date = 3/14/2008 3:22:02 AM | Attr = ] flash -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.vh1.com\global\flash -> [Folder | Modified Date = 3/14/2008 3:22:02 AM | Attr = ] module -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.vh1.com\global\flash\module -> [Folder | Modified Date = 3/14/2008 3:22:02 AM | Attr = ] mtv -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.vh1.com\global\flash\module\mtv -> [Folder | Modified Date = 3/14/2008 3:22:02 AM | Attr = ] playerlib -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.vh1.com\global\flash\module\mtv\playerlib -> [Folder | Modified Date = 3/14/2008 3:22:02 AM | Attr = ] 0.2.3.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.vh1.com\global\flash\module\mtv\playerlib\0.2.3.swf -> [Folder | Modified Date = 4/12/2008 1:29:11 AM | Attr = ] www.wbaltv.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.wbaltv.com -> [Folder | Modified Date = 3/14/2008 6:15:00 AM | Attr = ] download -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.wbaltv.com\download -> [Folder | Modified Date = 3/14/2008 6:15:00 AM | Attr = ] sh -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.wbaltv.com\download\sh -> [Folder | Modified Date = 3/14/2008 6:15:00 AM | Attr = ] images -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.wbaltv.com\download\sh\images -> [Folder | Modified Date = 3/14/2008 6:15:00 AM | Attr = ] flash -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.wbaltv.com\download\sh\images\flash -> [Folder | Modified Date = 3/14/2008 6:15:00 AM | Attr = ] mediawindow_320x340_v1.swf -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.wbaltv.com\download\sh\images\flash\mediawindow_320x340_v1.swf -> [Folder | Modified Date = 3/14/2008 6:15:00 AM | Attr = ] www.youtube.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\www.youtube.com -> [Folder | Modified Date = 4/17/2008 5:53:41 AM | Attr = ] x.mochiads.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\x.mochiads.com -> [Folder | Modified Date = 3/14/2008 8:49:35 AM | Attr = ] youtube.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\#SharedObjects\7QR8S6U6\youtube.com -> [Folder | Modified Date = 3/26/2008 9:36:47 AM | Attr = ] macromedia.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com -> [Folder | Modified Date = 3/5/2008 12:54:45 AM | Attr = ] support -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support -> [Folder | Modified Date = 3/5/2008 12:54:45 AM | Attr = ] flashplayer -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer -> [Folder | Modified Date = 3/5/2008 12:54:45 AM | Attr = ] sys -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys -> [Folder | Modified Date = 5/5/2008 8:27:18 AM | Attr = ] #acmemarkets.shoplocal.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#acmemarkets.shoplocal.com -> [Folder | Modified Date = 4/15/2008 1:53:16 PM | Attr = ] #ads1.msn.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#ads1.msn.com -> [Folder | Modified Date = 3/5/2008 1:46:50 AM | Attr = ] #assets.espn.go.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#assets.espn.go.com -> [Folder | Modified Date = 4/26/2008 7:05:03 AM | Attr = ] #babystrology.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#babystrology.com -> [Folder | Modified Date = 3/22/2008 6:38:20 AM | Attr = ] #bankofamerica.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bankofamerica.com -> [Folder | Modified Date = 3/5/2008 8:02:04 PM | Attr = ] #bc.newsweek.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bc.newsweek.com -> [Folder | Modified Date = 4/11/2008 1:39:20 AM | Attr = ] #bin.clearspring.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com -> [Folder | Modified Date = 3/10/2008 9:15:27 AM | Attr = ] #blst.msn.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#blst.msn.com -> [Folder | Modified Date = 4/9/2008 2:35:50 AM | Attr = ] #cache.reverbnation.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#cache.reverbnation.com -> [Folder | Modified Date = 3/7/2008 1:39:17 AM | Attr = ] #cbslocal.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#cbslocal.com -> [Folder | Modified Date = 3/12/2008 6:38:55 AM | Attr = ] #chatango.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#chatango.com -> [Folder | Modified Date = 3/22/2008 4:50:33 AM | Attr = ] #community.bonnaroo.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#community.bonnaroo.com -> [Folder | Modified Date = 3/19/2008 12:50:33 PM | Attr = ] #cosmos.bcst.yahoo.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#cosmos.bcst.yahoo.com -> [Folder | Modified Date = 3/6/2008 2:16:56 AM | Attr = ] #d.yimg.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#d.yimg.com -> [Folder | Modified Date = 3/6/2008 1:22:43 AM | Attr = ] #flash.quantserve.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#flash.quantserve.com -> [Folder | Modified Date = 3/7/2008 1:39:14 AM | Attr = ] #gamblerstelevision.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#gamblerstelevision.com -> [Folder | Modified Date = 4/25/2008 2:44:49 AM | Attr = ] #giantfood.shoplocal.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#giantfood.shoplocal.com -> [Folder | Modified Date = 4/5/2008 6:13:44 AM | Attr = ] #images.soapbox.msn.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#images.soapbox.msn.com -> [Folder | Modified Date = 3/13/2008 1:06:28 AM | Attr = ] #interclick.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com -> [Folder | Modified Date = 3/6/2008 1:34:32 PM | Attr = ] #l.yimg.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#l.yimg.com -> [Folder | Modified Date = 3/5/2008 1:58:16 AM | Attr = ] #ll.static.abc.go.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#ll.static.abc.go.com -> [Folder | Modified Date = 3/14/2008 7:37:50 AM | Attr = ] #login.yahoo.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#login.yahoo.com -> [Folder | Modified Date = 3/7/2008 9:06:44 PM | Attr = ] #media01.kyte.tv -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#media01.kyte.tv -> [Folder | Modified Date = 3/27/2008 5:56:41 AM | Attr = ] #mochibot.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#mochibot.com -> [Folder | Modified Date = 3/13/2008 9:46:56 AM | Attr = ] #msn.foxsports.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#msn.foxsports.com -> [Folder | Modified Date = 3/11/2008 11:33:38 PM | Attr = ] #msnbcmedia.msn.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#msnbcmedia.msn.com -> [Folder | Modified Date = 3/7/2008 3:35:06 AM | Attr = ] #nuptialstv.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#nuptialstv.com -> [Folder | Modified Date = 4/25/2008 2:34:56 AM | Attr = ] #pagead2.googlesyndication.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#pagead2.googlesyndication.com -> [Folder | Modified Date = 3/19/2008 2:10:05 PM | Attr = ] #pandora.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#pandora.com -> [Folder | Modified Date = 3/19/2008 2:46:11 AM | Attr = ] #player.hulu.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#player.hulu.com -> [Folder | Modified Date = 3/13/2008 12:22:35 AM | Attr = ] #prod.untd.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#prod.untd.com -> [Folder | Modified Date = 3/22/2008 6:50:51 AM | Attr = ] #resources.imeem.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#resources.imeem.com -> [Folder | Modified Date = 3/22/2008 5:25:47 AM | Attr = ] #reverbnation.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#reverbnation.com -> [Folder | Modified Date = 3/7/2008 1:39:15 AM | Attr = ] #rpmfreaks.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#rpmfreaks.com -> [Folder | Modified Date = 4/25/2008 2:35:22 AM | Attr = ] #s.mcstatic.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#s.mcstatic.com -> [Folder | Modified Date = 4/5/2008 9:00:38 AM | Attr = ] #secureinclude.ebaystatic.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#secureinclude.ebaystatic.com -> [Folder | Modified Date = 4/29/2008 12:18:45 AM | Attr = ] #st.msn.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#st.msn.com -> [Folder | Modified Date = 3/6/2008 1:49:53 AM | Attr = ] #stb.msn.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#stb.msn.com -> [Folder | Modified Date = 5/1/2008 12:32:35 AM | Attr = ] #strawberrygames.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#strawberrygames.com -> [Folder | Modified Date = 3/13/2008 9:47:09 AM | Attr = ] #stuff.pyzam.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#stuff.pyzam.com -> [Folder | Modified Date = 3/22/2008 4:29:39 AM | Attr = ] #suitesmart.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#suitesmart.com -> [Folder | Modified Date = 3/14/2008 3:21:55 AM | Attr = ] #us.i1.yimg.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#us.i1.yimg.com -> [Folder | Modified Date = 3/14/2008 3:36:46 AM | Attr = ] #video.google.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#video.google.com -> [Folder | Modified Date = 3/22/2008 4:50:21 AM | Attr = ] #video.nbcuni.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#video.nbcuni.com -> [Folder | Modified Date = 4/4/2008 1:32:13 AM | Attr = ] #vlaze.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#vlaze.com -> [Folder | Modified Date = 4/26/2008 11:31:40 AM | Attr = ] #void.snocap.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#void.snocap.com -> [Folder | Modified Date = 3/22/2008 4:50:25 AM | Attr = ] #widget-a1.slide.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#widget-a1.slide.com -> [Folder | Modified Date = 3/28/2008 4:08:43 AM | Attr = ] #www.cmt.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.cmt.com -> [Folder | Modified Date = 3/13/2008 3:35:19 AM | Attr = ] #www.dailymotion.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.dailymotion.com -> [Folder | Modified Date = 3/22/2008 5:05:52 AM | Attr = ] #www.heavy.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.heavy.com -> [Folder | Modified Date = 4/18/2008 3:17:16 PM | Attr = ] #www.npr.org -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.npr.org -> [Folder | Modified Date = 3/13/2008 1:53:21 AM | Attr = ] #www.strawberrygames.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.strawberrygames.com -> [Folder | Modified Date = 3/14/2008 8:49:46 AM | Attr = ] #www.thestringdusters.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.thestringdusters.com -> [Folder | Modified Date = 4/5/2008 11:37:32 AM | Attr = ] #www.vh1.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.vh1.com -> [Folder | Modified Date = 3/14/2008 3:22:02 AM | Attr = ] #www.wbaltv.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.wbaltv.com -> [Folder | Modified Date = 3/14/2008 6:15:00 AM | Attr = ] #www.youtube.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.youtube.com -> [Folder | Modified Date = 3/7/2008 1:39:14 AM | Attr = ] #x.mochiads.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#x.mochiads.com -> [Folder | Modified Date = 3/13/2008 9:46:55 AM | Attr = ] #youtube.com -> C:\Documents and Settings\ddcsystem\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#youtube.com -> [Folder | Modified Date = 3/26/2008 9:35:39 AM | Attr = ] Microsoft -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft -> [Folder | Modified Date = 4/23/2008 11:42:29 AM | Attr = S] AddIns -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\AddIns -> [Folder | Modified Date = 3/5/2008 4:26:47 AM | Attr = ] CLR Security Config -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\CLR Security Config -> [Folder | Modified Date = 3/4/2008 6:40:06 PM | Attr = ] v2.0.50727.42 -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\CLR Security Config\v2.0.50727.42 -> [Folder | Modified Date = 3/5/2008 6:31:15 AM | Attr = ] Credentials -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Credentials -> [Folder | Modified Date = 3/4/2008 3:48:02 PM | Attr = S] S-1-5-21-631826640-757734709-1114090867-4289 -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Credentials\S-1-5-21-631826640-757734709-1114090867-4289 -> [Folder | Modified Date = 3/4/2008 3:48:02 PM | Attr = S] CryptnetUrlCache -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\CryptnetUrlCache -> [Folder | Modified Date = 4/23/2008 11:42:29 AM | Attr = S] Content -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\CryptnetUrlCache\Content -> [Folder | Modified Date = 4/23/2008 11:42:30 AM | Attr = S] MetaData -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\CryptnetUrlCache\MetaData -> [Folder | Modified Date = 4/23/2008 11:42:30 AM | Attr = S] Crypto -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Crypto -> [Folder | Modified Date = 7/9/2004 8:00:56 AM | Attr = S] RSA -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Crypto\RSA -> [Folder | Modified Date = 3/4/2008 5:48:16 PM | Attr = S] S-1-5-21-631826640-757734709-1114090867-4289 -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Crypto\RSA\S-1-5-21-631826640-757734709-1114090867-4289 -> [Folder | Modified Date = 3/4/2008 5:48:16 PM | Attr = S] Excel -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Excel -> [Folder | Modified Date = 4/5/2008 6:22:04 AM | Attr = ] XLSTART -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Excel\XLSTART -> [Folder | Modified Date = 4/5/2008 6:22:04 AM | Attr = ] HTML Help -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\HTML Help -> [Folder | Modified Date = 3/6/2008 11:14:00 AM | Attr = ] Internet Explorer -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Internet Explorer -> [Folder | Modified Date = 4/29/2008 11:18:23 AM | Attr = ] Custom Settings -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Internet Explorer\Custom Settings -> [Folder | Modified Date = 4/29/2008 11:18:20 AM | Attr = ] Custom0 -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Internet Explorer\Custom Settings\Custom0 -> [Folder | Modified Date = 4/29/2008 11:18:20 AM | Attr = ] Custom1 -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Internet Explorer\Custom Settings\Custom1 -> [Folder | Modified Date = 4/29/2008 11:18:21 AM | Attr = ] Quick Launch -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Internet Explorer\Quick Launch -> [Folder | Modified Date = 4/7/2008 1:21:16 PM | Attr = R ] MMC -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\MMC -> [Folder | Modified Date = 4/23/2008 7:16:52 AM | Attr = ] Office -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Office -> [Folder | Modified Date = 3/5/2008 1:23:18 PM | Attr = ] Recent -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Office\Recent -> [Folder | Modified Date = 5/7/2008 8:45:48 AM | Attr = ] Outlook -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Outlook -> [Folder | Modified Date = 5/7/2008 11:46:22 AM | Attr = ] Proof -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Proof -> [Folder | Modified Date = 5/7/2008 7:36:03 AM | Attr = ] Protect -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Protect -> [Folder | Modified Date = 3/4/2008 5:48:16 PM | Attr = S] S-1-5-21-1847130808-3342227337-2615664831-500 -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Protect\S-1-5-21-1847130808-3342227337-2615664831-500 -> [Folder | Modified Date = 7/9/2004 8:00:56 AM | Attr = S] S-1-5-21-631826640-757734709-1114090867-4289 -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Protect\S-1-5-21-631826640-757734709-1114090867-4289 -> [Folder | Modified Date = 3/4/2008 5:48:16 PM | Attr = S] SystemCertificates -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\SystemCertificates -> [Folder | Modified Date = 7/9/2004 7:31:44 AM | Attr = S] My -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\SystemCertificates\My -> [Folder | Modified Date = 3/4/2008 4:22:05 PM | Attr = S] Certificates -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\SystemCertificates\My\Certificates -> [Folder | Modified Date = 5/7/2008 11:38:57 AM | Attr = S] CRLs -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\SystemCertificates\My\CRLs -> [Folder | Modified Date = 7/9/2004 7:32:34 AM | Attr = S] CTLs -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\SystemCertificates\My\CTLs -> [Folder | Modified Date = 7/9/2004 7:32:34 AM | Attr = S] Keys -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\SystemCertificates\My\Keys -> [Folder | Modified Date = 3/6/2008 1:14:08 PM | Attr = S] Templates -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Templates -> [Folder | Modified Date = 5/7/2008 8:57:33 AM | Attr = ] Windows -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Windows -> [Folder | Modified Date = 3/10/2008 1:00:50 PM | Attr = ] Themes -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Windows\Themes -> [Folder | Modified Date = 4/22/2008 3:29:35 AM | Attr = ] Word -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Word -> [Folder | Modified Date = 5/7/2008 8:57:32 AM | Attr = ] STARTUP -> C:\Documents and Settings\ddcsystem\Application Data\Microsoft\Word\STARTUP -> [Folder | Modified Date = 3/5/2008 1:22:58 PM | Attr = ] Sun -> C:\Documents and Settings\ddcsystem\Application Data\Sun -> [Folder | Modified Date = 7/9/2004 7:54:10 AM | Attr = ] Java -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java -> [Folder | Modified Date = 7/9/2004 7:54:10 AM | Attr = ] Deployment -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment -> [Folder | Modified Date = 3/20/2008 1:26:42 AM | Attr = ] cache -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\cache -> [Folder | Modified Date = 3/20/2008 1:26:42 AM | Attr = ] javapi -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\cache\javapi -> [Folder | Modified Date = 3/20/2008 1:26:42 AM | Attr = ] v1.0 -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\cache\javapi\v1.0 -> [Folder | Modified Date = 3/20/2008 1:26:42 AM | Attr = ] ext -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\ext -> [Folder | Modified Date = 3/20/2008 1:26:42 AM | Attr = ] file -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file -> [Folder | Modified Date = 3/20/2008 1:26:42 AM | Attr = ] jar -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar -> [Folder | Modified Date = 3/20/2008 1:26:42 AM | Attr = ] tmp -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\tmp -> [Folder | Modified Date = 3/20/2008 1:26:42 AM | Attr = ] tmp -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\cache\tmp -> [Folder | Modified Date = 3/20/2008 1:26:42 AM | Attr = ] ext -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\ext -> [Folder | Modified Date = 3/20/2008 1:26:42 AM | Attr = ] javaws -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\javaws -> [Folder | Modified Date = 7/9/2004 7:54:11 AM | Attr = ] cache -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\javaws\cache -> [Folder | Modified Date = 7/9/2004 7:54:11 AM | Attr = ] log -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\log -> [Folder | Modified Date = 3/29/2008 6:04:49 AM | Attr = ] security -> C:\Documents and Settings\ddcsystem\Application Data\Sun\Java\Deployment\security -> [Folder | Modified Date = 3/20/2008 1:26:42 AM | Attr = ] C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [Folder | Modified Date = 12/13/2007 11:44:01 AM | Attr = S] BackupACH_C1.job -> C:\WINDOWS\Tasks\BackupACH_C1.job -> [Ver = | Size = 364 bytes | Modified Date = 5/6/2008 7:01:06 PM | Attr = ] BackupACH_C1001.job -> C:\WINDOWS\Tasks\BackupACH_C1001.job -> [Ver = | Size = 370 bytes | Modified Date = 5/6/2008 7:01:06 PM | Attr = ] BackupACH_C1002.job -> C:\WINDOWS\Tasks\BackupACH_C1002.job -> [Ver = | Size = 370 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] BackupACH_DDC.job -> C:\WINDOWS\Tasks\BackupACH_DDC.job -> [Ver = | Size = 370 bytes | Modified Date = 5/7/2008 7:01:02 AM | Attr = ] BackupACH_NWSB.job -> C:\WINDOWS\Tasks\BackupACH_NWSB.job -> [Ver = | Size = 370 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] BackupACH_NWSB001.job -> C:\WINDOWS\Tasks\BackupACH_NWSB001.job -> [Ver = | Size = 376 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] @Alternate Data Stream - 88 bytes -> %SystemRoot%\Tasks\BackupACH_NWSB001.job:SummaryInformation @Alternate Data Stream - 0 bytes -> %SystemRoot%\Tasks\BackupACH_NWSB001.job:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} BackupACH_NWSB002.job -> C:\WINDOWS\Tasks\BackupACH_NWSB002.job -> [Ver = | Size = 376 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] Backup_COL0.job -> C:\WINDOWS\Tasks\Backup_COL0.job -> [Ver = | Size = 378 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] Backup_COL1.job -> C:\WINDOWS\Tasks\Backup_COL1.job -> [Ver = | Size = 384 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] Backup_COL2.job -> C:\WINDOWS\Tasks\Backup_COL2.job -> [Ver = | Size = 386 bytes | Modified Date = 5/7/2008 7:01:03 AM | Attr = ] Backup_ExtNacha.job -> C:\WINDOWS\Tasks\Backup_ExtNacha.job -> [Ver = | Size = 362 bytes | Modified Date = 5/6/2008 7:01:07 PM | Attr = ] DESKTOP.INI -> C:\WINDOWS\Tasks\DESKTOP.INI -> [Ver = | Size = 65 bytes | Modified Date = 3/19/2004 6:40:06 PM | Attr = RH ] rpc.job -> C:\WINDOWS\Tasks\rpc.job -> [Ver = | Size = 386 bytes | Modified Date = 5/1/2008 9:00:00 AM | Attr = ] SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 5/7/2008 11:32:15 AM | Attr = H ] [File - Purity Scan: Additional Folder Scans - Non-Microsoft Only] < End of report > [/code]