Monitoring HKEY 80000002\Software Monitoring HKEY 80000001\Software [REGISTRY] \Count [MODIFIED] C:\WINDOWS\system32\drivers\etc\hosts [MODIFIED] C:\WINDOWS\system32\userinit.exe [MODIFIED] C:\WINDOWS\system32\userinit.exe [MODIFIED] C:\WINDOWS\system32\userinit.exe [MODIFIED] C:\WINDOWS\system32\userinit.exe [MODIFIED] C:\WINDOWS\system32\userinit.exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Cookies [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Perflib_Perfdata_96c.dat [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Perflib_Perfdata_96c.dat [MODIFIED] C:\Documents and Settings\Administrator\Desktop\banner.exe [MODIFIED] C:\Documents and Settings\Administrator\Desktop\banner.exe [MODIFIED] C:\Documents and Settings\Administrator\Desktop\banner.exe [MODIFIED] C:\Documents and Settings\Administrator\Desktop\banner.exe [MODIFIED] C:\Documents and Settings\Administrator\Desktop\banner.exe [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF2D87.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF2D87.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF2D87.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF2D87.tmp [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Cookies [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\wbem\Logs\wbemcore.log [REGISTRY] \Count [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\MUICache [ADDED] C:\WINDOWS\system32\lmsxsltsso.dll [MODIFIED] C:\WINDOWS\system32\lmsxsltsso.dll [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Cookies [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [ADDED] C:\WINDOWS\Prefetch\BANNER.EXE-1BDFBEF3.pf [MODIFIED] C:\WINDOWS\Prefetch\BANNER.EXE-1BDFBEF3.pf [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [REMOVED] C:\DOCUME~1\ADMINI~1\Desktop\banner.exe [MODIFIED] C:\WINDOWS\system32\wbem\Logs\wbemcore.log [MODIFIED] C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf [MODIFIED] C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf [MODIFIED] C:\Documents and Settings\Administrator\Desktop\wuaucldt.exe [MODIFIED] C:\Documents and Settings\Administrator\Desktop\wuaucldt.exe [MODIFIED] C:\Documents and Settings\Administrator\Desktop\wuaucldt.exe [MODIFIED] C:\Documents and Settings\Administrator\Desktop\wuaucldt.exe [MODIFIED] C:\Documents and Settings\Administrator\Desktop\wuaucldt.exe [MODIFIED] C:\Documents and Settings\Administrator\NTUSER.DAT [REGISTRY] \Count [ADDED] C:\WINDOWS\system32\wuaucldt.exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\MUICache [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tasksz[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tasksz[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tasksz[1].htm [MODIFIED] C:\WINDOWS\system32\wuaucldt.exe [ADDED] C:\Documents and Settings\Administrator\wuaucldt.exe [MODIFIED] C:\Documents and Settings\Administrator\wuaucldt.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[1].exe [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp9B3E.tmp [MODIFIED] C:\WINDOWS\Prefetch\REGFSNOTIFY.EXE-2AD4318E.pf [MODIFIED] C:\WINDOWS\Prefetch\REGFSNOTIFY.EXE-2AD4318E.pf [MODIFIED] C:\WINDOWS\system32\net.exe [MODIFIED] C:\WINDOWS\system32\net.exe [MODIFIED] C:\WINDOWS\system32\net.exe [MODIFIED] C:\WINDOWS\system32\net.exe [MODIFIED] C:\WINDOWS\system32\net.exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[1].exe [MODIFIED] C:\WINDOWS\system32\sc.exe [MODIFIED] C:\WINDOWS\system32\sc.exe [MODIFIED] C:\WINDOWS\system32\sc.exe [MODIFIED] C:\WINDOWS\system32\sc.exe [MODIFIED] C:\WINDOWS\system32\sc.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp9B3E.tmp [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[1].exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp9B3E.tmp [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [ADDED] C:\WINDOWS\Prefetch\WUAUCLDT.EXE-038A4EBD.pf [MODIFIED] C:\WINDOWS\Prefetch\WUAUCLDT.EXE-038A4EBD.pf [ADDED] C:\WINDOWS\system32\msxslt.dat [MODIFIED] C:\WINDOWS\system32\msxslt.dat [REMOVED] C:\DOCUME~1\ADMINI~1\Desktop\wuaucldt.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\s0q6.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\s0q6.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\s0q6.exe [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\807bbc7dfd214b55f1c805691df00ea7[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\807bbc7dfd214b55f1c805691df00ea7[1].htm [ADDED] C:\WINDOWS\Prefetch\SC.EXE-012262AF.pf [MODIFIED] C:\WINDOWS\Prefetch\SC.EXE-012262AF.pf [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFB3CD.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFB3CD.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFB3CD.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFB3CD.tmp [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Cookies [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Ivzed [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\1[1].exe [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpA540.tmp [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\268077.bat [ADDED] C:\Documents and Settings\Administrator\Application Data\Oztie [ADDED] C:\Documents and Settings\Administrator\Application Data\Oztie\uhyx.exe [ADDED] C:\Documents and Settings\Administrator\Application Data\Yhox [ADDED] C:\Documents and Settings\Administrator\Application Data\Yhox\ycago.ohu [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\268077.bat [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\1[1].exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpA540.tmp [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\wbem\Logs\wbemcore.log [MODIFIED] C:\WINDOWS\system32\wbem\Logs\wbemess.log [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF2D87.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF2D87.tmp [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF2D87.tmp [ADDED] C:\WINDOWS\Prefetch\S0Q6.EXE-045F9938.pf [MODIFIED] C:\WINDOWS\Prefetch\S0Q6.EXE-045F9938.pf [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\1[1].exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpA540.tmp [MODIFIED] C:\WINDOWS\system32\msxslt.dat [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\5d3d339efa321680b94db68556fe2647[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\5d3d339efa321680b94db68556fe2647[1].htm [MODIFIED] C:\WINDOWS\system32\wbem\Logs\wbemess.log [REMOVED] C:\Documents and Settings\Administrator\Desktop\s0q6.exe [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\268077.bat [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[2].exe [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpAA22.tmp [MODIFIED] C:\WINDOWS\system32\wbem\Logs\wbemess.log [ADDED] C:\WINDOWS\system32\wininet.exe [MODIFIED] C:\WINDOWS\system32\wininet.exe [MODIFIED] C:\WINDOWS\system32\wininet.exe [ADDED] C:\WINDOWS\system32\svshost.dll [MODIFIED] C:\WINDOWS\system32\svshost.dll [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Oztie\uhyx.exe [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Oztie\uhyx.exe [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Oztie\uhyx.exe [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Oztie\uhyx.exe [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Oztie [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Yhox\ycago.ohu [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Yhox [MODIFIED] C:\WINDOWS\system32\wininet.exe [MODIFIED] C:\WINDOWS\system32\wininet.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\wininet.exe [MODIFIED] C:\WINDOWS\system32\wininet.exe [MODIFIED] C:\WINDOWS\system32\wininet.exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[2].exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpAA22.tmp [ADDED] C:\WINDOWS\system32\winint.exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[2].exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpAA22.tmp [MODIFIED] C:\WINDOWS\system32\msxslt.dat [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19 [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Internet Explorer [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Internet Explorer\Privacy [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [MODIFIED] C:\WINDOWS\system32\net1.exe [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\db177f4d2855988161e83115a995305c[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\db177f4d2855988161e83115a995305c[1].htm [ADDED] C:\WINDOWS\Prefetch\NET1.EXE-029B9DB4.pf [MODIFIED] C:\WINDOWS\Prefetch\NET1.EXE-029B9DB4.pf [ADDED] C:\WINDOWS\Prefetch\NET.EXE-01A53C2F.pf [MODIFIED] C:\WINDOWS\Prefetch\NET.EXE-01A53C2F.pf [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\1[1].exe [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpAED6.tmp [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\1[1].exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpAED6.tmp [MODIFIED] C:\WINDOWS\system32\msxslt.dat [RENAMED (OLD)] C:\Documents and Settings\Administrator\Application Data\Yhox\ycago.ohu[RENAMED (NEW)] C:\Documents and Settings\Administrator\Application Data\Yhox\ycago.tmp[MODIFIED] C:\Documents and Settings\Administrator\Application Data\Yhox\ycago.tmp [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\6678fb3a25c72025a073f9e9c21f9cb9[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\6678fb3a25c72025a073f9e9c21f9cb9[1].htm [ADDED] C:\Documents and Settings\Administrator\Application Data\Yhox\ycago.ohu [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Yhox\ycago.ohu [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@addthis[2].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@addthis[2].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@dl.javafx[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@dl.javafx[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@gmer[2].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@gmer[2].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@google[2].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@google[2].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@m.webtrends[2].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@m.webtrends[2].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@media6degrees[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@media6degrees[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@parosproxy[1].txt [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Ivzed [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@parosproxy[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@quantserve[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@quantserve[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@sourceforge[2].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@sourceforge[2].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@techsmith[2].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@techsmith[2].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@verify[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@verify[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@voicefive[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@voicefive[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@www.microsoft[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@www.microsoft[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@www.techsmith[1].txt [REMOVED] C:\Documents and Settings\Administrator\Cookies\administrator@www.techsmith[1].txt [ADDED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [ADDED] C:\WINDOWS\system32\sdra64.exe [MODIFIED] C:\WINDOWS\system32\sdra64.exe [MODIFIED] C:\WINDOWS\system32\sdra64.exe [MODIFIED] C:\WINDOWS\system32\sdra64.exe [MODIFIED] C:\WINDOWS\system32\sdra64.exe [MODIFIED] C:\WINDOWS\system32\sdra64.exe [MODIFIED] C:\WINDOWS\system32\sdra64.exe [MODIFIED] C:\WINDOWS\system32\sdra64.exe [MODIFIED] C:\WINDOWS\system32\sdra64.exe [MODIFIED] C:\WINDOWS\system32\sdra64.exe [MODIFIED] C:\WINDOWS\system32\sdra64.exe [MODIFIED] C:\WINDOWS\system32\winint.exe [MODIFIED] C:\WINDOWS\system32\sdra64.exe [MODIFIED] C:\WINDOWS\system32\sdra64.exe [ADDED] C:\WINDOWS\system32\lowsec [MODIFIED] C:\WINDOWS\system32\lowsec [ADDED] C:\WINDOWS\system32\lowsec\local.ds [ADDED] C:\WINDOWS\system32\lowsec\user.ds [MODIFIED] C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\LocalService\Local Settings\History [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\LocalService\Cookies [MODIFIED] C:\Documents and Settings\LocalService\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\LocalService\Local Settings\History\History.IE5 [MODIFIED] C:\WINDOWS\system32\lowsec\user.ds [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths [MODIFIED] C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf [MODIFIED] C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1 [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2 [ADDED] C:\WINDOWS\Prefetch\TMPA540.TMP-294679A8.pf [MODIFIED] C:\WINDOWS\Prefetch\TMPA540.TMP-294679A8.pf [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3 [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4 [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network [ADDED] C:\WINDOWS\Prefetch\WUAUCLDT.EXE-0EE87C35.pf [MODIFIED] C:\WINDOWS\Prefetch\WUAUCLDT.EXE-0EE87C35.pf [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [ADDED] C:\WINDOWS\Prefetch\S0Q6.EXE-07E4FEDA.pf [MODIFIED] C:\WINDOWS\Prefetch\S0Q6.EXE-07E4FEDA.pf [MODIFIED] C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\LocalService\Local Settings\History [MODIFIED] C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5 [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5 [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5 [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\desktop.ini [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\I7EL6DC5 [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\I7EL6DC5 [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\I7EL6DC5 [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\I7EL6DC5\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\I7EL6DC5\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\I7EL6DC5\desktop.ini [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\CLYS7EA4 [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\CLYS7EA4 [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\CLYS7EA4 [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\CLYS7EA4\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\CLYS7EA4\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\CLYS7EA4\desktop.ini [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5ERKLMF [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5ERKLMF [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5ERKLMF [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5ERKLMF\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5ERKLMF\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5ERKLMF\desktop.ini [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YHWPUBS5 [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YHWPUBS5 [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YHWPUBS5 [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YHWPUBS5\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YHWPUBS5\desktop.ini [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YHWPUBS5\desktop.ini [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Cookies [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Cookies [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Cookies\index.dat [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Cookies\index.dat [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Cookies\index.dat [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\History [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpaa56a325.bat [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpaa56a325.bat [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpaa56a325.bat [MODIFIED] C:\WINDOWS\system32\cmd.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\History [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\History\History.IE5 [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\History\History.IE5\index.dat [ADDED] C:\WINDOWS\system32\msxslt3.exe [MODIFIED] C:\WINDOWS\system32\msxslt3.exe [MODIFIED] C:\WINDOWS\system32\msxslt3.exe [MODIFIED] C:\WINDOWS\system32\msxslt3.exe [MODIFIED] C:\WINDOWS\system32\msxslt3.exe [MODIFIED] C:\WINDOWS\system32\msxslt3.exe [MODIFIED] C:\WINDOWS\system32\msxslt3.exe [MODIFIED] C:\WINDOWS\system32\msxslt3.exe [MODIFIED] C:\WINDOWS\system32\msxslt3.exe [MODIFIED] C:\WINDOWS\system32\msxslt3.exe [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\History\History.IE5\index.dat [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\History\History.IE5\index.dat [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5 [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\History\History.IE5 [ADDED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\History\History.IE5\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\History\History.IE5\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\History\History.IE5\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\History\History.IE5\desktop.ini [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat [MODIFIED] C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat [ADDED] C:\WINDOWS\Prefetch\TMPAED6.TMP-0701F3B2.pf [MODIFIED] C:\WINDOWS\Prefetch\TMPAED6.TMP-0701F3B2.pf [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp9B3E.tmp [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpaa56a325.bat [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [RENAMED (OLD)] C:\WINDOWS\system32\lowsec\user.ds[RENAMED (NEW)] C:\WINDOWS\system32\lowsec\user.ds.lll[MODIFIED] C:\WINDOWS\system32\lowsec\user.ds.lll [ADDED] C:\WINDOWS\system32\lowsec\user.ds [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7437821.tmp [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\boty[1].dat [ADDED] C:\WINDOWS\Temp\tmpF1BB.tmp [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Ivzed [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\boty[1].dat [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\boty[1].dat [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\boty[1].dat [MODIFIED] C:\Documents and Settings\Administrator\NTUSER.DAT [MODIFIED] C:\WINDOWS\Temp\tmpF1BB.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7437821.tmp [MODIFIED] C:\WINDOWS\system32\msxslt.dat [ADDED] C:\WINDOWS\system32\wzrd_1.dll [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\wzrd_1.dll [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7437821.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7437821.tmp [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7437821.tmp [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2435126.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzrd_1 [ADDED] C:\WINDOWS\Temp\tmpF5C2.tmp [MODIFIED] C:\WINDOWS\system32\lowsec [MODIFIED] C:\WINDOWS\system32\lowsec\local.ds [REMOVED] C:\WINDOWS\system32\lowsec\local.ds [ADDED] C:\WINDOWS\system32\lowsec\local.ds [MODIFIED] C:\WINDOWS\system32\lowsec\local.ds [MODIFIED] C:\WINDOWS\Temp\tmpF5C2.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2435126.exe [MODIFIED] C:\WINDOWS\system32\msxslt.dat [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2435126.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [ADDED] C:\WINDOWS\Temp\tmpFAE2.tmp [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\3582833.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\3582833.tmp [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\3582833.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2435126.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2435126.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2435126.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2435126.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2435126.exe [ADDED] C:\WINDOWS\system32\txpxr_985409472 [REMOVED] C:\WINDOWS\system32\txpxr_985409472 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Cookies [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\WINDOWS\Temp\tmpFAE2.tmp [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\play-video[1].png [ADDED] C:\WINDOWS\Prefetch\TMPF5C2.TMP-0F733558.pf [MODIFIED] C:\WINDOWS\Prefetch\TMPF5C2.TMP-0F733558.pf [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\toc[2].css [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\msxslt.dat [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\content[1].js [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\WBEM [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\news_info[2].gif [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[1].htm [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1 [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[6] [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3 [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4 [ADDED] C:\WINDOWS\Temp\tmp70.tmp [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\help[1].properties [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\cust_suc_nav_line[1].gif [RENAMED (OLD)] C:\Documents and Settings\Administrator\wuaucldt.exe[RENAMED (NEW)] C:\documents and settings\administrator\wuaucldt .exe[REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\redirect[1].js [MODIFIED] C:\Documents and Settings\Administrator\wuaucldt .exe [ADDED] C:\Documents and Settings\Administrator\wuaucldt.exe [MODIFIED] C:\Documents and Settings\Administrator\wuaucldt.exe [MODIFIED] C:\Documents and Settings\Administrator\wuaucldt.exe [RENAMED (OLD)] C:\Documents and Settings\Administrator\Application Data\Oztie\uhyx.exe[RENAMED (NEW)] C:\Documents and Settings\Administrator\Application Data\Oztie\uhyx .exe[MODIFIED] C:\Documents and Settings\Administrator\Application Data\Oztie\uhyx .exe [ADDED] C:\Documents and Settings\Administrator\Application Data\Oztie\uhyx.exe [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Oztie\uhyx.exe [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Oztie\uhyx.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\resultslist[1].js [MODIFIED] C:\Program Files\pdfforge Toolbar\SearchSettings.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\tgar[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\au_button_right[2].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\content[1].js [MODIFIED] C:\WINDOWS\Temp\tmp70.tmp [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\table-sortedDown[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[4] [MODIFIED] C:\WINDOWS\system32\msxslt.dat [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\muweb_site[1].cab [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\au_bg_rightmiddle[2].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\news_bg_topmiddle[2].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\mirrors[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[1].htm [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\bgNav-gray[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\cntnt_grade[1].gif [ADDED] C:\Documents and Settings\Administrator\Application Data\Ovboi [ADDED] C:\Documents and Settings\Administrator\Application Data\Ovboi\geby.exe [ADDED] C:\Documents and Settings\Administrator\Application Data\Cogyez [ADDED] C:\Documents and Settings\Administrator\Application Data\Cogyez\pyyc.beu [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\tgar[5].js [ADDED] C:\WINDOWS\system32\0041.DLL [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\loading-9x9[1].gif [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\powerOn-16x16[1].png [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Nyah [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\nav-news-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\blank[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\camtasia[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\welcome-left[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\au_bg_leftbottom[1].gif [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\wsu_180x68[1].png [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [MODIFIED] C:\WINDOWS\system32\0041.DLL [ADDED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\MUICache [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [MODIFIED] C:\WINDOWS\system32\WORK.DAT [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\nav-sprite[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\CAK4PJN0.gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fTurkey[1].png [MODIFIED] C:\Program Files\pdfforge Toolbar\SearchSettings.exe [MODIFIED] C:\Program Files\pdfforge Toolbar\SearchSettings.exe [MODIFIED] C:\Program Files\pdfforge Toolbar\SearchSettings.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\toolbar_sm[1].png [MODIFIED] C:\Program Files\pdfforge Toolbar\SearchSettings.exe [RENAMED (OLD)] C:\Program Files\pdfforge Toolbar\SearchSettings.exe[RENAMED (NEW)] C:\Program Files\pdfforge Toolbar\SearchSettings .exe[MODIFIED] C:\Program Files\pdfforge Toolbar\SearchSettings .exe [ADDED] C:\Program Files\pdfforge Toolbar\SearchSettings.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\tgar[2].js [MODIFIED] C:\Program Files\pdfforge Toolbar\SearchSettings.exe [MODIFIED] C:\Program Files\pdfforge Toolbar\SearchSettings.exe [RENAMED (OLD)] C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe[RENAMED (NEW)] C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp .exe[MODIFIED] C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp .exe [ADDED] C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe [MODIFIED] C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe [MODIFIED] C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe [RENAMED (OLD)] C:\Program Files\Parallels\Parallels Tools\prl_cc.exe[RENAMED (NEW)] C:\Program Files\Parallels\Parallels Tools\prl_cc .exe[MODIFIED] C:\Program Files\Parallels\Parallels Tools\prl_cc .exe [ADDED] C:\Program Files\Parallels\Parallels Tools\prl_cc.exe [MODIFIED] C:\Program Files\Parallels\Parallels Tools\prl_cc.exe [MODIFIED] C:\Program Files\Parallels\Parallels Tools\prl_cc.exe [RENAMED (OLD)] C:\Program Files\Java\jre6\bin\jusched.exe[RENAMED (NEW)] C:\Program Files\Java\jre6\bin\jusched .exe[MODIFIED] C:\Program Files\Java\jre6\bin\jusched .exe [ADDED] C:\Program Files\Java\jre6\bin\jusched.exe [MODIFIED] C:\Program Files\Java\jre6\bin\jusched.exe [MODIFIED] C:\Program Files\Java\jre6\bin\jusched.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\banner-bg[1].jpg [RENAMED (OLD)] C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe[RENAMED (NEW)] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl .exe[REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\success-lg[1].gif [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Ovboi\geby.exe [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Ovboi\geby.exe [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Ovboi\geby.exe [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Ovboi\geby.exe [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Ovboi [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Cogyez\pyyc.beu [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Cogyez [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ws-2[1].css [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl .exe [ADDED] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\cff2_s[1].jpg [MODIFIED] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [MODIFIED] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\cff1_s[1].jpg [RENAMED (OLD)] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[RENAMED (NEW)] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM .exe[MODIFIED] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM .exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Nyah [ADDED] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [ADDED] C:\WINDOWS\Prefetch\TMPFAE2.TMP-1C7FEBE6.pf [MODIFIED] C:\WINDOWS\Prefetch\TMPFAE2.TMP-1C7FEBE6.pf [MODIFIED] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [MODIFIED] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\newsletter-v-seperate[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\module[1].properties [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\vmwareLogo-320x122[1].png [MODIFIED] C:\Documents and Settings\Administrator\wuaucldt.exe [MODIFIED] C:\Documents and Settings\Administrator\wuaucldt.exe [MODIFIED] C:\Documents and Settings\Administrator\wuaucldt.exe [MODIFIED] C:\Documents and Settings\Administrator\wuaucldt.exe [MODIFIED] C:\Documents and Settings\Administrator\wuaucldt.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[10] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\espaceur[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fDenmark[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\dot[2].gif [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\cs6-ie6[1].css [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Cookies [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\icon-new_window-white[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\ui.dialog[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\banner.160x600[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[7] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\question-16x16[1].png [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\bg-site[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[5] [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\highslide-full.packed[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\arrow[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\google_custom_search_watermark[1].gif [RENAMED (OLD)] C:\Documents and Settings\Administrator\Application Data\Cogyez\pyyc.beu[RENAMED (NEW)] C:\Documents and Settings\Administrator\Application Data\Cogyez\pyyc.tmp[MODIFIED] C:\Documents and Settings\Administrator\Application Data\Cogyez\pyyc.tmp [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fp-lcu-bg[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\vm-poweredOn-16x16[1].png [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tips-vi-box[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[4] [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [ADDED] C:\Documents and Settings\Administrator\Application Data\Cogyez\pyyc.beu [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[5] [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Cogyez\pyyc.beu [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\jquery.tsc.min[1].js [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\homepage_slider_recorder[1].png [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\redirect[1].js [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Nyah [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Cookies [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\wbc-config[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\rounded-white[1].png [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\WINDOWS\system32\lowsec\user.ds [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\banner-right[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\nav_logo7[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\CA97QCDW.HTM [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\tgar[6].js [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\au_shieldred[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\host-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[3] [MODIFIED] C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol [REMOVED] C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[4] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\type[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\info_16x[1].gif [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\wsiconinst72[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\jslib-config[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\host-maintenance-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\news_bg_righttop[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\au_bg_lefttop[1].gif [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tgar[4].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ui.core[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\module[1].properties [MODIFIED] C:\WINDOWS\Prefetch\TMPF5C2.TMP-0F733558.pf [MODIFIED] C:\WINDOWS\Prefetch\TMPF5C2.TMP-0F733558.pf [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\suspendTransient-16x16[1].png [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\host-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\homepage_slider_ppt[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\wuident[1].cab [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\resultslist[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\0078ae_1x400_textures_02_glass_45[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\file[1].png [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7681593.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fGermany[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fBulgaria[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[3] [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7681593.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\news_bg_bottommiddle[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\toc[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\content[4].js [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\module[1].properties [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\split-horiz[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\linkbin[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search-gray[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\check_google_links[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\au_shieldgreen[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\nav.bg[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\vm-normal-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\powerOffDisabled-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[3] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\info_16x[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\css[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\nav-partners-00[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\nav99[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\nav-services-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\button_left[1].gif [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\close_sm[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\nav_logo6[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\bg-grade-gray[1].gif [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7681593.exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\InstallStatus[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\InstallStatus[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\InstallStatus[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\InstallStatus[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\content[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\jquery-1.2.6.min[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\vmwareLogo-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\toparw-gray[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\f6f6f6_1x100_textures_06_inset_hard_100[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\inventory[1].properties [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ADSAdClient31[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ADSAdClient31[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ADSAdClient31[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ADSAdClient31[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\wiki[2].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\windows[1].png [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\3067118.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\3067118.tmp [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\3067118.tmp [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\tpc=quality_assurance;tpc=swdev_oo;tpc=testing;tpc=python;tpc=softdevlibraries;tpc=education;tpc=debuggers;aud=developers;aud=enduser_qa;ord=5194048907293889 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\default[1].jpg [MODIFIED] C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf [MODIFIED] C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\camtasia[1].msi [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tgar[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\jquery-ui-core+tabs+accordion-1.6r4[1].js [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\21182046.system [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\automal.mnin[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\automal.mnin[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\automal.mnin[1].htm [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\automal.mnin[1].htm [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\21182046.system [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\21182046.system [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\21182046.system [ADDED] C:\WINDOWS\system32\msszbmuf.dll [MODIFIED] C:\WINDOWS\system32\msszbmuf.dll [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\suspendDisabled-16x16[1].png [MODIFIED] C:\WINDOWS\system32\rundll32.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\information-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\manifest[1].xml [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\print-2[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\ui.tabs[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\trac_logo_mini[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\nav-company-01[1].gif [MODIFIED] C:\WINDOWS\system32\rundll32.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [MODIFIED] C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf [MODIFIED] C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\drapeau_ru[1].gif [MODIFIED] C:\WINDOWS\system32\rundll32.exe [MODIFIED] C:\WINDOWS\system32\rundll32.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\whatshot-bar[1].png [MODIFIED] C:\WINDOWS\system32\rundll32.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[4] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\spupdateids[1].js [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp953e237f.bat [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp953e237f.bat [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp953e237f.bat [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\toc_expanded[1].gif [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\news_bg_righttop[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\news_bg_rightmiddle[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\error-16x16[1].png [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\camtasia6[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\loader.white[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\remaining-lg[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\su[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\project[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\nav-products-00[1].gif [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REMOVED] C:\WINDOWS\Temp\tmp70.tmp [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\debugger-logo[1].png [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp953e237f.bat [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[5] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\tsclogo_shadow-gray[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\au_shieldyellow[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\news_bg_bottommiddle[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ui.allplugins[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\host-warning-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\pointy[1].gif [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\toc[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\tgar[5].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\expanded-9x9[1].png [ADDED] C:\Documents and Settings\Administrator\Desktop\21187562.BAT [MODIFIED] C:\Documents and Settings\Administrator\Desktop\21187562.BAT [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\Initiator-2.08-build3825-x86fre[1].exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[8] [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\addthis_widget[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\homepage_slider_UI[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\tgar[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\content[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\news_bg_leftmiddle[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\tgar[4].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\tgar[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\clear[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\3gz47YX4DrY[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[2] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\reset[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\hdr_welcome[1].jpg [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\MUICache [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tgar[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\freetraining-header[1].gif [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [MODIFIED] C:\WINDOWS\system32\cmd.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\au_bg_bottommiddle[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\SiteRecruit_PageConfiguration_2944mt-WU[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\welcome-bg[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\au_button_left[2].gif [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\au_button_middle[2].gif [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7681593.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[7] [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [REMOVED] C:\Documents and Settings\Administrator\Desktop\21187562.BAT [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[2] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\homepage_slider_rome2[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\webcomtop[1].js [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\errorinformation[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\errorinformation[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\errorinformation[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\errorinformation[1].htm [MODIFIED] C:\WINDOWS\explorer.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\banner[1].png [MODIFIED] C:\WINDOWS\explorer.exe [MODIFIED] C:\WINDOWS\explorer.exe [MODIFIED] C:\WINDOWS\explorer.exe [MODIFIED] C:\WINDOWS\explorer.exe [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2998897.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ui.accordion[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ui.resizable[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[2] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\cr-highslide[1].css [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2998897.exe [MODIFIED] C:\WINDOWS\system32\lowsec\user.ds.lll [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\au_bg_leftmiddle[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\cace-pilot-2.1[1].png [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\powerOffTransient-16x16[1].png [MODIFIED] C:\WINDOWS\system32\lowsec\user.ds.lll [REMOVED] C:\WINDOWS\system32\lowsec\user.ds.lll [ADDED] C:\WINDOWS\Temp\1F7.tmp [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\location[2].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\location[2].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\location[2].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\location[2].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[2].js [REGISTRY] \{d16b2f52-20be-11de-85f0-806d6172696f} [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\toc[1].js [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d1b7d7a8-8374-11de-9db7-806d6172696f} [REGISTRY] \{d16b2f55-20be-11de-85f0-806d6172696f} [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\news_bg_lefttop[2].gif [REGISTRY] \{d1b7d7a8-8374-11de-9db7-806d6172696f} [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[7] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\snapshot-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\wt[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\Tauntaun_300x100[1].jpg [MODIFIED] C:\WINDOWS\Temp\1F7.tmp [MODIFIED] C:\Program Files\Process Hacker\ProcessHacker.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\nav-education-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\SprySlidingPanels[1].js [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\3067749.tmp [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Internet Explorer\Desktop\Components\0 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\mu_getstarted-center[1].gif [MODIFIED] C:\Program Files\Process Hacker\ProcessHacker.exe [MODIFIED] C:\Program Files\Process Hacker\ProcessHacker.exe [MODIFIED] C:\Program Files\Process Hacker\ProcessHacker.exe [MODIFIED] C:\Program Files\Process Hacker\ProcessHacker.exe [MODIFIED] C:\WINDOWS\Temp\1F7.tmp [MODIFIED] C:\Program Files\DComSoft\Dump Flash Decompiler\wx1.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\3067749.tmp [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\3067749.tmp [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\blank[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\au_bg_rightbottom[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\toc_collapsed[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\jquery.hoverIntent.minified[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\powerOnTransient-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\mu_getstarted-part2middle_ltr[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\mu_getstarted-part2bottom_ltr[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\arrow[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\goldbar2[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\broker[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\superfish[1].js [MODIFIED] C:\WINDOWS\Temp\1F7.tmp [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\NumericUtils[1].properties [MODIFIED] C:\WINDOWS\Temp\1F7.tmp [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\home[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\oldversions[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\dlarrow[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[10] [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fThailand[1].png [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Cookies [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\txt[2].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\ms_masthead_ltr[1].gif [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ui.progressbar[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\mgyhp_sm[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\header-back-proj[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\header03[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\immdbg-startrl[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[12] [MODIFIED] C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf [MODIFIED] C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ui.datepicker[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\menuHilight[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\coin5[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ESQ409_RedCosts_Offer_300x250_rev[1].swf [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\ewtrack_8[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\google[1].htm [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\dl_btn_right[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\welcome-right[1].jpg [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\softpedia_clean_award_f[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\broker[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\h1tsc[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\news[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\success-sm[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ui.all[1].css [MODIFIED] C:\Program Files\DComSoft\Dump Flash Decompiler\wx1.exe [MODIFIED] C:\Program Files\DComSoft\Dump Flash Decompiler\wx1.exe [MODIFIED] C:\Program Files\DComSoft\Dump Flash Decompiler\wx1.exe [MODIFIED] C:\Program Files\DComSoft\Dump Flash Decompiler\wx1.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\SharpToolbox_Tool.big[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\reset-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[2] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\content[2].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\broker[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\content[4].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\au_bg_righttop[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\.wbc[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\wtkx[1].properties [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\slider[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\homepage_slider_screencast[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\webcomtop[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\au_button_left[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\toc[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\trac[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\widget13[2].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\laptop-trainingvideo[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\zoomout[1].cur [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\4589cc[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fullscreen-normal[1].png [MODIFIED] C:\Program Files\Notepad++\notepad++.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\athena[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\olympics10-curling-hp[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\jquery[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\mu_getstarted-part2top_ltr[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\news_bg_rightmiddle[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\tgar[4].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\tgar[3].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\spupdateids[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\au_shieldyellow[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\openid_sm[1].gif [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ab83be13.linkbucks[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\au_shieldred[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\news_bg_topmiddle[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[6] [MODIFIED] C:\WINDOWS\Prefetch\VERCLSID.EXE-3667BD89.pf [MODIFIED] C:\WINDOWS\Prefetch\VERCLSID.EXE-3667BD89.pf [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\notch[2].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\processor-16x16[1].png [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ab83be13.linkbucks[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\location[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\titre_download[1].jpg [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\news_bg_leftmiddle[2].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\cse-search-box[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\e6e3da[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\win32-16x16[1].png [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\5174436.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\arrow_px_up[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\directory[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\debugger-logo[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[3] [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\style[1].css [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\style[1].css [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\style[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\grey-footer[1].gif [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ads_ie[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\homepage_slider_smartfocus-1[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\hcp[1].css [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ads[1].css [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ads[1].css [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ads_ie[1].css [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ads[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\au_button_middle[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\hdr_custominstall[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ui.theme[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[5] [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\link[1].js [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\link[1].js [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\link[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\au_shieldgreen[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\news_info[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\content[3].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\spupdateids[2].js [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\render_ads[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\drapeau_de[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\slider_nav_matrix[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\news_bg_rightbottom[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\tgar[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\tgar[3].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\content[3].js [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\reset[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\e0fdff_256x240_icons_icons[1].png [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\reset[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\wireshark-win32-1.2.2[1].exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\blank[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\mu_getstarted-part1bottom_ltr[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\resultslist[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\au_bg_leftmiddle[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\plugin[1].properties [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\networkAdapterDisconnected-16x16[1].png [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\vmware-vmrc-win32-x86[1].exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\ga[3].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\divider_hr[1].png [MODIFIED] C:\Program Files\Notepad++\notepad++.exe [MODIFIED] C:\Program Files\Notepad++\notepad++.exe [MODIFIED] C:\Program Files\Notepad++\notepad++.exe [MODIFIED] C:\Program Files\Notepad++\notepad++.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\hdr_options_left[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\welcome-right[1].jpg [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\winappdbg[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\winappdbg[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\winappdbg[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\winappdbg[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\CACVW3W9.net%2Fprojects%2Fwinappdbg%2Ffiles%2F&fu=0&ifi=2&dtd=0 [MODIFIED] C:\WINDOWS\Installer\{555589D7-F580-422A-B55C-3605EFDE855A}\DHTMLSpy.exe1_555589D7F580422AB55C3605EFDE855A.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\quant[1].js [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\bg[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ul-gray[1].gif [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\lb[1].gif [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\5174436.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\homepage_navbar[1].png [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\bg[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\failed-lg[1].gif [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\lb[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\au_bg_bottommiddle[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\hdr_options_left[2].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[9] [MODIFIED] C:\WINDOWS\Installer\{555589D7-F580-422A-B55C-3605EFDE855A}\DHTMLSpy.exe1_555589D7F580422AB55C3605EFDE855A.exe [MODIFIED] C:\WINDOWS\Installer\{555589D7-F580-422A-B55C-3605EFDE855A}\DHTMLSpy.exe1_555589D7F580422AB55C3605EFDE855A.exe [MODIFIED] C:\WINDOWS\Installer\{555589D7-F580-422A-B55C-3605EFDE855A}\DHTMLSpy.exe1_555589D7F580422AB55C3605EFDE855A.exe [MODIFIED] C:\WINDOWS\Installer\{555589D7-F580-422A-B55C-3605EFDE855A}\DHTMLSpy.exe1_555589D7F580422AB55C3605EFDE855A.exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\try_blue[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\au_bg_leftbottom[1].gif [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\news[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\news[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\news[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\news[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\hdr_expressresults_left[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\.jslib[2].js [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\location[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\location[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\location[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\location[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\tree-handle-south-369[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\main[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\au_bg_rightmiddle[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\news_bg_lefttop[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\toc_collapsed[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\redirect[3].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\style[1].css [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\exsuite[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\exsuite[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\exsuite[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\exsuite[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\au_bg_rightbottom[1].gif [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ab83be13.linkbucks[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ab83be13.linkbucks[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ab83be13.linkbucks[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ab83be13.linkbucks[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\banner-right[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\banner-bg[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ui.slider[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\downloads-1.2.2-1.0.9-1.3.0[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\vm-disabled-16x16[1].png [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\5174436.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\application[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\hdr_custominstall[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\8kr0u1ckC24[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\SiteRecruit_PageConfiguration_2944mt1-2943mt60-MU[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[6] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\youAreHere-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tree-handle-south-fff[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\shade-12x12[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\pdfforgeToolbar[1].msi [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\failed-sm[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\host-alert-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\DocumentDotWrite[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\wordpress_sm[2].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search-16[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\nav-resources-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\dl_btn_left[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tsc-announce[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\windowsupdate.microsoft[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\windows_masthead_ltr[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\news_bg_leftbottom[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\webcomtop[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\sharkfest-09-72[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\dl_btn_mid[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\main[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\header[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\arrowsquare[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\content[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tgar[3].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\play_c[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\uxstudy[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\hdr_bckgnd-gray[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\8571[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\bgNavSlct-gray[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\mu_getstarted-part1top_ltr[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\commontop[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\smallT-gray[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\wsus3setup[1].cab [MODIFIED] C:\Program Files\AutoIt3\Extras\v2_to_v3_Converter\AutoItV2toV3.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\au_bg_lefttop[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\content[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\hdr_finish_left[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\remaining-sm[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\wireshark[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\cntnt_nav_grade-gray[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\redirect[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[7] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\datastorebrowser[1].properties [MODIFIED] C:\Program Files\AutoIt3\Extras\v2_to_v3_Converter\AutoItV2toV3.exe [MODIFIED] C:\Program Files\AutoIt3\Extras\v2_to_v3_Converter\AutoItV2toV3.exe [MODIFIED] C:\Program Files\AutoIt3\Extras\v2_to_v3_Converter\AutoItV2toV3.exe [MODIFIED] C:\Program Files\AutoIt3\Extras\v2_to_v3_Converter\AutoItV2toV3.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\topbar_gradient2[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\nav-company-01[2].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\logo[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\au_bg_righttop[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\content[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\tgar[6].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\6eac2c_500x100_textures_12_gloss_wave_50[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\error-32x32[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\arrow_down_white[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\redirect[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\commontop[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\mu_getstarted-part1middle_ltr[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\welcome-bg[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\wsus3setup[2].cab [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\verisign_sm[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\nav-clientlogin-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\au_button_right[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\content[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\hdr_expressresults_left[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\news_bg_rightbottom[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\vmware[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\powerOnDisabled-16x16[1].png [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\location[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\location[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\location[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\location[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\jquery.min[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\footer_graphic[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\hcp[2].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\commontop[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\news_bg_leftbottom[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fp-download-bg[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\jquery.pngFix[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\reyOYXFq4yA[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\817-grey[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\immdbg-dropdown[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\_06[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fChina[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fItaly[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\SourceForgenet-700-500-09NOV240_700X500_336Player-Banner-1206329[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\collapsed-9x9[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\sf.min[2].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\winappdbg[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\tpc=quality_assurance;tpc=swdev_oo;tpc=testing;tpc=python;tpc=softdevlibraries;tpc=education;tpc=debuggers;aud=developers;aud=enduser_qa;ord=5194048907293889 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\winappdbg-1.3.win32[1].exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\DoPc9bORB34[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\folder[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\memory-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\f7f5eb[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\cdDvdDriveDisconnected-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\CA23OB71.exe%2Fdownload&fu=0&ifi=1&dtd=0 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[9] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\nav-news-00[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\bannerInc[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\logo_move[1].swf [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\uk[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\uk[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\uk[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\uk[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\EWTRACK_NEW_V[1].7&per=0&time=14&adtime=1603 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\EWTRACK_NEW_V[1].7&per=20&time=284&adtime=4356 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[13] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\project_default[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\logo2[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\blank_pixel[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\close-8x8[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\suspend-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\dropdown[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\trans_pixel[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\solaris[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[10] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\plus[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\one_pixel_tile_headerV3[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[11] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\drapeau_uk[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\drapeau_hu[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\menu_07[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tpc=sound;tpc=multimedia;tpc=cpp;tpc=editors;aud=enduser_advanced;aud=developers;aud=education;aud=endusers;aud=enduser_qa;aud=sysadmins;ord=7746856790208300 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\EWTRACK_NEW_V[1].7&per=80&time=298&adtime=13197 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\project_web_p85_skybox;pg=default;dcopt=ist;tile=1;tpc=project;tpc=winappdbg;ord=2486219714410744[2].5 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\nav-resources-00[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\drapeau_ca[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fSlovakia[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fUkraine[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\buttons[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\EWTRACK_NEW_V[1].7&per=100&time=298&adtime=16199 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ie_pre7_hacks[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\folder_open[1].png [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\register[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\register[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\register[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\register[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fOccitanie[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\mirror_choices[3].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\dot[1].gif [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\index[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\index[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\index[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\index[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\leaf_dot[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\en-us[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\dap[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\widget29[1].css [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\registrationWelcome[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\registrationWelcome[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\registrationWelcome[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\registrationWelcome[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\dateValidation[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\message_error[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ms_masthead_ltr[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\t1-products[1].gif [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\9156523.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\9156523.tmp [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\9156523.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\5174436.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\5174436.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\5174436.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\5174436.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\5174436.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\immdbg-runpy[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\npp.logo4[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fEgypt[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\Reader9Manifest[1].msi [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\adpportal1[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\tpc=quality_assurance;tpc=swdev_oo;tpc=testing;tpc=python;tpc=softdevlibraries;tpc=education;tpc=debuggers;aud=developers;aud=enduser_qa;ord=9224714909044750 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\blogger_sm[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\menu_05[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\cameleon2[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\MotifExternalScript_01_01[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\mail[1].bmp [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [ADDED] C:\WINDOWS\system32\MSWINSCK.OCX [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\button_right[1].gif [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\tpc=sound;tpc=multimedia;tpc=cpp;tpc=editors;aud=enduser_advanced;aud=developers;aud=education;aud=endusers;aud=enduser_qa;aud=sysadmins;ord=7083109254764044 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Cookies [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\WINDOWS\system32\MSWINSCK.OCX [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fullscreen-hover[1].png [MODIFIED] C:\WINDOWS\Installer\{1BA16E5A-72B9-44B7-9FDA-FB6CE7FF6C0C}\Icon158F1431.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\menujs[1].config&displaylang=en&clicktrax=False [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\js[1].aspx [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[8] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\bullet[2].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\wrapper[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\ewtrack[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\120x240_BGS_fork_101309[1].swf [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\myopenid_sm[1].gif [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\nav-services-00[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\nav-partners-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\immdbg-cmdcli[1].png [MODIFIED] C:\WINDOWS\Installer\{1BA16E5A-72B9-44B7-9FDA-FB6CE7FF6C0C}\Icon158F1431.exe [MODIFIED] C:\WINDOWS\Installer\{1BA16E5A-72B9-44B7-9FDA-FB6CE7FF6C0C}\Icon158F1431.exe [MODIFIED] C:\WINDOWS\Installer\{1BA16E5A-72B9-44B7-9FDA-FB6CE7FF6C0C}\Icon158F1431.exe [MODIFIED] C:\WINDOWS\Installer\{1BA16E5A-72B9-44B7-9FDA-FB6CE7FF6C0C}\Icon158F1431.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\nav_logo8[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\drapeau_tw[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\poweredOn-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\poweredOff-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\txt[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\test_domain[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\nav-products-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fGalicia[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[14] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\vidoop_sm[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\nav-services-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\nav-clientlogin-00[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\slideOutMenus[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fPortugal[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\main[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\code[2].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\logo[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\linux[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\zip[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\chameleon-pencil-small[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\widget15[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\E49D77BF-D5AE-4EC6-9DFA-D7A19DBA995E[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\logo1414[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\immdbg-inputbox[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\immdbg-stackvars[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\nav-partners-00[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\npp.animated.logo[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fArgentine[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\trait_bas[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fGreece[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fSerbia[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\nav-sprite[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\vm-suspended-16x16[2].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\suspended-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fCzech[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fKorea[1].png [ADDED] C:\WINDOWS\Fonts\services.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fPhilippines[1].png [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Classes\MSWinsock.Winsock [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Classes\MSWinsock.Winsock\CLSID [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Classes\MSWinsock.Winsock\CurVer [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Classes\MSWinsock.Winsock.1 [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Classes\MSWinsock.Winsock.1\CLSID [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\menu_01[1].jpg [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{248DD890-BB45-11CF-9ABC-0080C7E7B78D} [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\tasksz[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\tasksz[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\tasksz[1].htm [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{248DD890-BB45-11CF-9ABC-0080C7E7B78D}\1.0 [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{248DD890-BB45-11CF-9ABC-0080C7E7B78D}\1.0\0 [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{248DD890-BB45-11CF-9ABC-0080C7E7B78D}\1.0\0\win32 [MODIFIED] C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf [MODIFIED] C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf [MODIFIED] C:\WINDOWS\Fonts\services.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{248DD890-BB45-11CF-9ABC-0080C7E7B78D}\1.0\FLAGS [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{248DD890-BB45-11CF-9ABC-0080C7E7B78D}\1.0\HELPDIR [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\Fonts\services.exe [MODIFIED] C:\WINDOWS\Fonts\services.exe [MODIFIED] C:\WINDOWS\Fonts\services.exe [MODIFIED] C:\WINDOWS\Fonts\services.exe [MODIFIED] C:\WINDOWS\Fonts\services.exe [MODIFIED] C:\WINDOWS\Fonts\services.exe [MODIFIED] C:\WINDOWS\Fonts\services.exe [ADDED] C:\WINDOWS\Temp\j1ll9kh0.TMP [MODIFIED] C:\WINDOWS\system32\wbem\Logs\wbemess.log [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[2].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[2].htm [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[2].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[2].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fRomania[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\icons-sprite[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\dot[2].gif [REMOVED] C:\WINDOWS\Temp\j1ll9kh0.TMP [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[13] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\showfiles.php;psrch=0;logged_in=0;ptile=1;tpc=paros;tpc=security;tpc=java;aud=informationtechnology;ord=793880066994108[2].1 [MODIFIED] C:\WINDOWS\Installer\{555589D7-F580-422A-B55C-3605EFDE855A}\DHTMLSpy.exe_555589D7F580422AB55C3605EFDE855A.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[6] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\logo[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\MANIFEST[1].xml [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\WebAccess[1].properties [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\vm-poweredOn-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\css[1].css [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\tgar[1].js [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Cookies [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\feed16[1].png [MODIFIED] C:\WINDOWS\Installer\{555589D7-F580-422A-B55C-3605EFDE855A}\DHTMLSpy.exe_555589D7F580422AB55C3605EFDE855A.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\createVM-16x16[1].png [MODIFIED] C:\WINDOWS\Installer\{555589D7-F580-422A-B55C-3605EFDE855A}\DHTMLSpy.exe_555589D7F580422AB55C3605EFDE855A.exe [MODIFIED] C:\WINDOWS\Installer\{555589D7-F580-422A-B55C-3605EFDE855A}\DHTMLSpy.exe_555589D7F580422AB55C3605EFDE855A.exe [MODIFIED] C:\WINDOWS\Installer\{555589D7-F580-422A-B55C-3605EFDE855A}\DHTMLSpy.exe_555589D7F580422AB55C3605EFDE855A.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\warning-32x32[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\arrow_down[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\extlink[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\nav-products-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\DateFormat[1].properties [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\e6e3da[2].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\xplgforsouceforge[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\immdbg-task[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\cameleon3[1].gif [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\gmer[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\gmer[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\gmer[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\gmer[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[2].exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[2].exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[2].exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[2].exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[2].exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[2].exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\blank[2].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\blank[2].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\blank[2].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\blank[2].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\resetDisabled-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\immunity[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\bullet[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\nav-downloads-01[1].gif [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows NT\CurrentVersion\Windows [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\nav-company-00[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[11] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\cdnetworks-small[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\nav-downloads-01[1].gif [MODIFIED] C:\WINDOWS\hh.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\cameleon[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\drapeau_it[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fSweden[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\button_center[1].gif [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History [MODIFIED] C:\WINDOWS\hh.exe [MODIFIED] C:\WINDOWS\hh.exe [MODIFIED] C:\WINDOWS\hh.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\nav-resellers-00[1].gif [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Cookies [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\WINDOWS\hh.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\nav-education-00[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\drapeau_br[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\npp.logo6[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\ch[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\table-sortedUp[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[8] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[2].htm [MODIFIED] C:\WINDDK\3790.1830\srcindex.htm [MODIFIED] C:\WINDDK\3790.1830\srcindex.htm [MODIFIED] C:\WINDDK\3790.1830\srcindex.htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\bg-site[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\immdbg-safeseh[1].png [MODIFIED] C:\WINDDK\3790.1830\install.htm [MODIFIED] C:\WINDDK\3790.1830\install.htm [MODIFIED] C:\WINDDK\3790.1830\install.htm [MODIFIED] C:\WINDDK\3790.1830\relnote.htm [MODIFIED] C:\WINDDK\3790.1830\relnote.htm [MODIFIED] C:\WINDDK\3790.1830\relnote.htm [MODIFIED] C:\WINDDK\3790.1830\bin\x86\prefast\doc\prefast_install.htm [MODIFIED] C:\WINDDK\3790.1830\bin\x86\prefast\doc\prefast_install.htm [MODIFIED] C:\WINDDK\3790.1830\bin\x86\prefast\doc\prefast_install.htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fNorway[1].png [MODIFIED] C:\WINDDK\3790.1830\bin\x86\drvfast\doc\prefast_install.htm [MODIFIED] C:\WINDDK\3790.1830\bin\x86\drvfast\doc\prefast_install.htm [MODIFIED] C:\WINDDK\3790.1830\bin\x86\drvfast\doc\prefast_install.htm [MODIFIED] C:\WINDDK\3790.1830\bin\x86\prefast\doc\cmdline.html [MODIFIED] C:\WINDDK\3790.1830\bin\x86\prefast\doc\cmdline.html [MODIFIED] C:\WINDDK\3790.1830\bin\x86\prefast\doc\cmdline.html [MODIFIED] C:\WINDDK\3790.1830\tools\acpi\pmte\x86\pmte.exe [MODIFIED] C:\WINDDK\3790.1830\tools\acpi\pmte\x86\pmte.exe [MODIFIED] C:\WINDDK\3790.1830\tools\acpi\pmte\x86\pmte.exe [MODIFIED] C:\WINDDK\3790.1830\tools\acpi\pmte\x86\pmte.exe [MODIFIED] C:\WINDDK\3790.1830\tools\acpi\pmte\x86\pmte.exe [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\amcap.exe [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\amcap.exe [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\amcap.exe [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\amcap.exe [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\amcap.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fSouthAfrica[1].png [MODIFIED] C:\WINDDK\3790.1830\tools\devicetree\x86\devicetree.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\powerOn-75x150[1].png [MODIFIED] C:\WINDDK\3790.1830\tools\devicetree\x86\devicetree.exe [MODIFIED] C:\WINDDK\3790.1830\tools\devicetree\x86\devicetree.exe [MODIFIED] C:\WINDDK\3790.1830\tools\devicetree\x86\devicetree.exe [MODIFIED] C:\WINDDK\3790.1830\tools\devicetree\x86\devicetree.exe [MODIFIED] C:\WINDOWS\system32\verifier.exe [MODIFIED] C:\WINDOWS\system32\verifier.exe [MODIFIED] C:\WINDOWS\system32\verifier.exe [MODIFIED] C:\WINDOWS\system32\verifier.exe [MODIFIED] C:\WINDOWS\system32\verifier.exe [MODIFIED] C:\WINDDK\3790.1830\tools\geninf\x86\geninf.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\open-player-hover[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\common[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\logo_inside_transparent[1].gif [MODIFIED] C:\WINDDK\3790.1830\tools\geninf\x86\geninf.exe [MODIFIED] C:\WINDDK\3790.1830\tools\geninf\x86\geninf.exe [MODIFIED] C:\WINDDK\3790.1830\tools\geninf\x86\geninf.exe [MODIFIED] C:\WINDDK\3790.1830\tools\geninf\x86\geninf.exe [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\graphedt.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\broker-config[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\1x1white[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\bas[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tag_green[1].png [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\graphedt.exe [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\graphedt.exe [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\graphedt.exe [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\graphedt.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\file[1].png [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\ksstudio.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ewtrack_wesupport[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\parosproxy[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\banner_next[1].gif [MODIFIED] C:\WINDOWS\system32\wbem\Logs\wbemcore.log [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\footer[2].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ewtrack_9_0_28_0[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\1[1].exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\tpc=quality_assurance;tpc=swdev_oo;tpc=testing;tpc=python;tpc=softdevlibraries;tpc=education;tpc=debuggers;aud=developers;aud=enduser_qa;ord=9224714909044750 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\nav-partners-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\products-immdbg[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\coin2[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\npp.logo3[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fFrance[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fPoland[1].png [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp07055475.bat [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp07055475.bat [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\olympics10-bg[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\hosted[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\buttons[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\coin1[1].gif [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\ksstudio.exe [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\ksstudio.exe [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\ksstudio.exe [MODIFIED] C:\WINDDK\3790.1830\tools\avstream\x86\ksstudio.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\drapeau_bg[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\crystalpp_icons[1].jpg [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\5174436.exe [MODIFIED] C:\WINDDK\3790.1830\tools\pnpdtest\x86\pnpdtest.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\sf.min[2].js [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp07055475.bat [MODIFIED] C:\WINDDK\3790.1830\tools\pnpdtest\x86\pnpdtest.exe [REGISTRY] \Count [MODIFIED] C:\WINDDK\3790.1830\tools\pnpdtest\x86\pnpdtest.exe [MODIFIED] C:\WINDDK\3790.1830\tools\pnpdtest\x86\pnpdtest.exe [MODIFIED] C:\WINDDK\3790.1830\tools\pnpdtest\x86\pnpdtest.exe [MODIFIED] C:\WINDDK\3790.1830\tools\pooltag\x86\pooltag.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\trait[1].gif [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1298782.exe [MODIFIED] C:\WINDDK\3790.1830\tools\pooltag\x86\pooltag.exe [MODIFIED] C:\WINDDK\3790.1830\tools\pooltag\x86\pooltag.exe [MODIFIED] C:\WINDDK\3790.1830\tools\pooltag\x86\pooltag.exe [MODIFIED] C:\WINDDK\3790.1830\tools\pooltag\x86\pooltag.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\titre_about[1].jpg [MODIFIED] C:\WINDDK\3790.1830\tools\print\x86\minidev.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fMalaysia[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tpc=sound;tpc=multimedia;tpc=cpp;tpc=editors;aud=enduser_advanced;aud=developers;aud=education;aud=endusers;aud=enduser_qa;aud=sysadmins;ord=7083109254764044 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[3].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fRussia[1].png [MODIFIED] C:\WINDDK\3790.1830\tools\print\x86\minidev.exe [MODIFIED] C:\WINDDK\3790.1830\tools\print\x86\minidev.exe [MODIFIED] C:\WINDDK\3790.1830\tools\print\x86\minidev.exe [MODIFIED] C:\WINDDK\3790.1830\tools\print\x86\minidev.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fCatalunya[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\red_arrow_compulsary_field[1].gif [MODIFIED] C:\WINDDK\3790.1830\tools\acpi\sleeper\x86\sleeper.exe [REGISTRY] \iexplore [REGISTRY] \iexplore [REGISTRY] \iexplore [REGISTRY] \iexplore [REGISTRY] \iexplore [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\menu_10[1].jpg [MODIFIED] C:\WINDDK\3790.1830\tools\acpi\sleeper\x86\sleeper.exe [MODIFIED] C:\WINDDK\3790.1830\tools\acpi\sleeper\x86\sleeper.exe [MODIFIED] C:\WINDDK\3790.1830\tools\acpi\sleeper\x86\sleeper.exe [MODIFIED] C:\WINDDK\3790.1830\tools\acpi\sleeper\x86\sleeper.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\wiadbgcfg.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fKyrgyzstan[1].png [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\wiadbgcfg.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\wiadbgcfg.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\wiadbgcfg.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\wiadbgcfg.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\dot[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\five[1].gif [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\wialogcfg.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\wialogcfg.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\wialogcfg.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\wialogcfg.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\wialogcfg.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\scanpanl.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\scanpanl.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\scanpanl.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\scanpanl.exe [MODIFIED] C:\WINDDK\3790.1830\tools\wia\x86\scanpanl.exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[1].exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[1].exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[1].exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[1].exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1298782.exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[1].exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\1[1].exe [MODIFIED] C:\Program Files\NTCore\Explorer Suite\Signature Explorer.exe [MODIFIED] C:\Program Files\NTCore\Explorer Suite\Signature Explorer.exe [MODIFIED] C:\Program Files\NTCore\Explorer Suite\Signature Explorer.exe [MODIFIED] C:\Program Files\NTCore\Explorer Suite\Signature Explorer.exe [MODIFIED] C:\Program Files\NTCore\Explorer Suite\Signature Explorer.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[10] [MODIFIED] C:\Program Files\NTCore\Explorer Suite\Task Explorer.exe [MODIFIED] C:\WINDOWS\system32\wbem\Logs\wbemess.log [MODIFIED] C:\Program Files\NTCore\Explorer Suite\Task Explorer.exe [MODIFIED] C:\Program Files\NTCore\Explorer Suite\Task Explorer.exe [MODIFIED] C:\Program Files\NTCore\Explorer Suite\Task Explorer.exe [MODIFIED] C:\Program Files\NTCore\Explorer Suite\Task Explorer.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[11] [MODIFIED] C:\Program Files\NTCore\Explorer Suite\PE Detective.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\_08[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fBrazil[1].png [MODIFIED] C:\Program Files\NTCore\Explorer Suite\PE Detective.exe [MODIFIED] C:\Program Files\NTCore\Explorer Suite\PE Detective.exe [MODIFIED] C:\Program Files\NTCore\Explorer Suite\PE Detective.exe [MODIFIED] C:\Program Files\NTCore\Explorer Suite\PE Detective.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fIsrael[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\default[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\nav-resources-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\zip[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[14] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\f5e175_256x240_icons_icons[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\vm-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\module[2].properties [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\module[2].properties [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1298782.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\open-player-normal[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\sf.min[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\FY10WindowsAzure_CloudWManFAMILIAR_D_300x250_V1R1[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\bullet[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\style[1].css [MODIFIED] C:\WINDOWS\system32\mmc.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\module[1].properties [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\notch[1].png [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d1b7d7a8-8374-11de-9db7-806d6172696f} [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\4589cc[2].png [REGISTRY] \Shell [REGISTRY] \AutoRun [MODIFIED] C:\WINDOWS\system32\mmc.exe [MODIFIED] C:\WINDOWS\system32\mmc.exe [REGISTRY] \command [REGISTRY] \_Autorun [REGISTRY] \DefaultIcon [MODIFIED] C:\WINDOWS\system32\mmc.exe [MODIFIED] C:\WINDOWS\system32\mmc.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\powerOff-16x16[1].png [MODIFIED] C:\Program Files\SWFTools\uninstall.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\toolsNotAvailable-16x16[1].png [MODIFIED] C:\Program Files\SWFTools\uninstall.exe [MODIFIED] C:\Program Files\SWFTools\uninstall.exe [MODIFIED] C:\Program Files\SWFTools\uninstall.exe [MODIFIED] C:\Program Files\SWFTools\uninstall.exe [MODIFIED] C:\Program Files\PDFCreator\PDFCreator.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\pdf[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\show_ads[2].js [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1298782.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\mac[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\claimid_sm[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\immunity[1].js [MODIFIED] C:\Program Files\PDFCreator\PDFCreator.exe [MODIFIED] C:\Program Files\PDFCreator\PDFCreator.exe [MODIFIED] C:\Program Files\PDFCreator\PDFCreator.exe [MODIFIED] C:\Program Files\PDFCreator\PDFCreator.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\header01b[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\immdbg-combobox[1].png [MODIFIED] C:\Program Files\PDFCreator\languages\TransTool.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\bg-footer[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fFriuli[1].png [MODIFIED] C:\Program Files\PDFCreator\languages\TransTool.exe [MODIFIED] C:\Program Files\PDFCreator\languages\TransTool.exe [MODIFIED] C:\Program Files\PDFCreator\languages\TransTool.exe [MODIFIED] C:\Program Files\PDFCreator\languages\TransTool.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fAlbania[1].png [MODIFIED] C:\Program Files\Process Hacker\Help.htm [MODIFIED] C:\Program Files\Process Hacker\Help.htm [MODIFIED] C:\Program Files\Process Hacker\Help.htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fBasque[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fUzbekistan[1].png [MODIFIED] C:\Python25\Lib\site-packages\pythonwin\Pythonwin.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\Python25\Lib\site-packages\pythonwin\Pythonwin.exe [MODIFIED] C:\Python25\Lib\site-packages\pythonwin\Pythonwin.exe [MODIFIED] C:\Python25\Lib\site-packages\pythonwin\Pythonwin.exe [MODIFIED] C:\Python25\Lib\site-packages\pythonwin\Pythonwin.exe [MODIFIED] C:\WINDOWS\Installer\{DA0BF7AB-88EB-4675-8FA1-531EAD938821}\Icon55367664.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\vm-suspended-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\sf_google_afc[2].js [MODIFIED] C:\WINDOWS\Installer\{DA0BF7AB-88EB-4675-8FA1-531EAD938821}\Icon55367664.exe [MODIFIED] C:\WINDOWS\Installer\{DA0BF7AB-88EB-4675-8FA1-531EAD938821}\Icon55367664.exe [MODIFIED] C:\WINDOWS\Installer\{DA0BF7AB-88EB-4675-8FA1-531EAD938821}\Icon55367664.exe [MODIFIED] C:\WINDOWS\Installer\{DA0BF7AB-88EB-4675-8FA1-531EAD938821}\Icon55367664.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[9] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\immdbg-pyscript[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fTaiwan[1].png [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1298782.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\chameleon-pencil-big[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fIndonesia[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\default2[2].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\dots[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\nav00[1].gif [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\nav-resellers-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\coin6[1].gif [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [MODIFIED] C:\Program Files\Internet Explorer\IEXPLORE.EXE [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\directory[1].png [MODIFIED] C:\Documents and Settings\Administrator\Desktop\pdftk.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\novell700x500[1].swf [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\virtualDisk-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\CAYBZO6K.net%2Fprojects%2Fwinappdbg%2Ffiles%2F&fu=0&ifi=1&dtd=125 [REGISTRY] \Enum [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[11] [MODIFIED] C:\Documents and Settings\Administrator\Desktop\pdftk.exe [MODIFIED] C:\Documents and Settings\Administrator\Desktop\pdftk.exe [MODIFIED] C:\Documents and Settings\Administrator\Desktop\pdftk.exe [REGISTRY] \Enum [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU\1 [MODIFIED] C:\Documents and Settings\Administrator\Desktop\pdftk.exe [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\9500733.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\9500733.tmp [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU\1\5 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags\250 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags\250\Shell [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags\2\Shell [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\9500733.tmp [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\haut[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\application[2].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\4095335807-common[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\tpc=quality_assurance;tpc=swdev_oo;tpc=testing;tpc=python;tpc=softdevlibraries;tpc=education;tpc=debuggers;aud=developers;aud=enduser_qa;ord=5194048907293889 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\header02b[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\nav-news-01[2].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\menu_09[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fHungary[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fIran[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\icons-sprite[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\CAI3S3XA.gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\immdbg-graphing2[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fond_menu[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\drapeau_fr[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fValdAran[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\tag_red[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\immdbg-apidoc[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\npp.logo2[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\downloading[2].5 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\npp.5.6.8.Installer[1].exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\app_logo[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ADPUIV3[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\jY-394LEXwQ[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\wtkx[1].properties [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\split-vert[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[8] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\mirror_choices[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[12] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\nav-clientlogin-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\warning-32x32[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\npp.logo.80x15[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\themeDemo[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\PID_1261816_main_300[1].swf [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ui[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ui[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ui[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ui[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\leaf[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\arrowLTR[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\downBtn[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\nav-education-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\nav-resellers-01[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\version_en_win_ax[1].xml [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\module[2].properties [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\open-150x150[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\Search_icon[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\topbar_gradient[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\bsd[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\piwik[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fMacedonia[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\widget32[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ewmp_trk[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\rustock[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[13] [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\showfiles[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\showfiles[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\showfiles[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\showfiles[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\bg-body[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\immdbg-menubar[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\macFold[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\EWTRACK_NEW_V[1].7&per=40&time=303&adtime=7357 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\dot[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[12] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fKazakhstan[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\tpc=sound;tpc=multimedia;tpc=cpp;tpc=editors;aud=enduser_advanced;aud=developers;aud=education;aud=endusers;aud=enduser_qa;aud=sysadmins;ord=7746856790208300 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\black_bullet[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ok-16x16[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[9] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\immdbg-graphing[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fFinland[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\697174003-classic[2].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\three[1].gif [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\location[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\location[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\location[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\location[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\trac[2].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\whatshot-bar[1].png [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\Shell\Bags\1\Desktop [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags\250\Shell [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\google_sm[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\npp.logo5[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fSlovenia[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\project[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\registration[1].css [MODIFIED] C:\WINDOWS\system32\verclsid.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\openWin[1].js [MODIFIED] C:\WINDOWS\system32\verclsid.exe [MODIFIED] C:\WINDOWS\system32\verclsid.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\verclsid.exe [MODIFIED] C:\WINDOWS\system32\verclsid.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\btn_background_wht[1].jpg [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\header[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\header[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\header[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\header[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\fExtremadura[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\sf.min[2].css [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\PID_1261816_IBM_SPP1_HS22_300x250[1].swf [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU\1\5 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU\1\5\0 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[2].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[13] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\portal.adp[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\bot_nav_arrow[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\footer_arrow[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\message_confirm[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fBelarus[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\superb-small[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[14] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\four[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\EWTRACK_TIME[1] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[15] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\two[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\required_field_arrow[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[16] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\macUnfold[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\yahoo_sm[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\flickr_sm[2].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\aol_sm[2].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\site[1].htm [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\fCroatia[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ewtrack_onload[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\search[14] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\immunity[2].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\immdbg-info[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fGeorgia[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\registration[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[12] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\drapeau_nl[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\menu_04[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fSpain[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\EW_BANDWIDTH[1] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\search[15] [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[3].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[3].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[3].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\download[3].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\search[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\bg-footer[1].gif [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\about[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\about[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\about[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\about[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\ewtrack_9[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\folder_open[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\splash_image[1].swf [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\tpc=sound;tpc=multimedia;tpc=cpp;tpc=editors;aud=enduser_advanced;aud=developers;aud=education;aud=endusers;aud=enduser_qa;aud=sysadmins;ord=7746856790208300 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\EWTRACK_TIME[1] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\EWTRACK_NEW_V[1].7&per=60&time=282&adtime=10149 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\global[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\showfiles.php;psrch=0;logged_in=0;ptile=3;tpc=paros;tpc=security;tpc=java;aud=informationtechnology;ord=793880066994108[2].1 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\adp_red[1].gif [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\1[1].exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\1[1].exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\1[1].exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\1[1].exe [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\1[1].exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\1[1].exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fNetherlands[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fSamogitia[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fLuxembourgish[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\cameleon4[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\flashwrite_1_2[2].js [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\index[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\index[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\index[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\index[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\adp_logo[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\globalTemplate_27_02[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\EWTRACK_TIME[2] [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\gmer[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\bg-body[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\drapeau_es[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\menu_03[1].jpg [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\showfiles[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\showfiles[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\showfiles[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\showfiles[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\sh14[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\sh14[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\sh14[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\sh14[1].htm [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\fLithuania[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\fJapan[1].png [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\downloading[2].5 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ewtrack_v[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\showfiles.php;psrch=0;logged_in=0;ptile=2;tpc=paros;tpc=security;tpc=java;aud=informationtechnology;ord=793880066994108[2].1 [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\download[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\livejournal_sm[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\nav-downloads-00[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\one[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\HoOBKyOK_Uw[2].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2I9MHJAG\bullet[1].gif [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU\1\5\0 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU\1\5\0\0 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags\251\Shell [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags\252 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags\252\Shell [MODIFIED] C:\WINDOWS\system32 [MODIFIED] C:\WINDOWS\system32\drivers [MODIFIED] C:\WINDOWS\system32 [MODIFIED] C:\WINDOWS\system32\drivers [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1273861599_res.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1273861599_res.tmp [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1273861599_res.tmp [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1273861599_res.tmp [ADDED] C:\WINDOWS\system32\6to4ex.dll [MODIFIED] C:\WINDOWS\system32\6to4ex.dll [MODIFIED] C:\WINDOWS\system32\6to4ex.dll [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [ADDED] C:\WINDOWS\system32\winstartup.log [MODIFIED] C:\WINDOWS\system32\winstartup.log [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\WBEM [MODIFIED] C:\WINDOWS\system32\wbem\Logs\wbemess.log [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU\1\5\0\0 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU\1\5\0\0\0 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags\253 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags\253\Shell [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU\1\5\0\0\0 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\BagMRU\1\5\0\0\0\0 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags\253\Shell [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1298782.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1298782.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1298782.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1298782.exe [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1298782.exe [REMOVED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1298782.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Internet Explorer\International [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\d[1].bin [ADDED] C:\WINDOWS\system32\t1p0_60648296702.b1k [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\d[1].bin [MODIFIED] C:\WINDOWS\system32\t1p0_60648296702.b1k [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\d[1].bin [RENAMED (OLD)] C:\WINDOWS\system32\t1p0_60648296702.b1k[RENAMED (NEW)] C:\WINDOWS\system32\6308.exe[MODIFIED] C:\WINDOWS\system32\6308.exe [MODIFIED] C:\WINDOWS\system32\6308.exe [MODIFIED] C:\WINDOWS\system32\6308.exe [MODIFIED] C:\WINDOWS\system32\6308.exe [MODIFIED] C:\WINDOWS\system32\6308.exe [MODIFIED] C:\WINDOWS\system32\6308.exe [MODIFIED] C:\WINDOWS\system32\6308.exe [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\link[1].js [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ads[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\reset[1].css [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\WBEM [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\bg[1].jpg [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CUNYHW7O\ads_ie[1].css [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\lb[1].gif [REMOVED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\d[1].bin [ADDED] C:\WINDOWS\system32\Install.txt [MODIFIED] C:\WINDOWS\system32\Install.txt [MODIFIED] C:\WINDOWS\system32\Install.txt [ADDED] C:\WINDOWS\Install.txt [MODIFIED] C:\WINDOWS\Install.txt [MODIFIED] C:\WINDOWS\Install.txt [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Cookies [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5 [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\portal[1].htm [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ms[1].bin [ADDED] C:\WINDOWS\system32\t1p0_444130798396.b1k [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ms[1].bin [MODIFIED] C:\WINDOWS\system32\t1p0_444130798396.b1k [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\ms[1].bin [RENAMED (OLD)] C:\WINDOWS\system32\t1p0_444130798396.b1k[RENAMED (NEW)] C:\WINDOWS\system32\txpxr_9050530363.b1k[MODIFIED] C:\WINDOWS\system32\txpxr_9050530363.b1k [MODIFIED] C:\WINDOWS\system32\txpxr_9050530363.b1k [RENAMED (OLD)] C:\WINDOWS\system32\txpxr_9050530363.b1k[RENAMED (NEW)] C:\WINDOWS\system32\BtwSvc.dll[MODIFIED] C:\WINDOWS\system32\BtwSvc.dll [MODIFIED] C:\WINDOWS\system32\BtwSvc.dll [ADDED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mta13187.dll [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mta13187.dll [MODIFIED] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mta13187.dll [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\portal[1].htm [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\WBEM [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\portal[1].htm [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [ADDED] C:\WINDOWS\Temp\mta13187.dll [MODIFIED] C:\WINDOWS\Temp\mta13187.dll [MODIFIED] C:\WINDOWS\Temp\mta13187.dll [MODIFIED] C:\WINDOWS\system32\wbem\Logs\wbemess.log [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft\Windows\ShellNoRoam\Bags\254\Shell [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\Documents and Settings\Administrator\My Documents\Visual Studio 2008\Projects\RegFsNotify\Release\RegFsNotify.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [REGISTRY] \REGISTRY\USER\S-1-5-21-1659004503-1606980848-682003330-500\Software\Microsoft [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\system32\svchost.exe [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\so[1].bin [ADDED] C:\WINDOWS\system32\t1p0_784647415982.b1k [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\so[1].bin [MODIFIED] C:\WINDOWS\system32\t1p0_784647415982.b1k [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\so[1].bin [RENAMED (OLD)] C:\WINDOWS\system32\t1p0_784647415982.b1k[RENAMED (NEW)] C:\WINDOWS\system32\txpxr_7707485834.b1k[MODIFIED] C:\WINDOWS\system32\txpxr_7707485834.b1k [MODIFIED] C:\WINDOWS\system32\txpxr_7707485834.b1k [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\style[1].css [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\style[1].css [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\style[1].css [RENAMED (OLD)] C:\WINDOWS\system32\lowsec\user.ds[RENAMED (NEW)] C:\WINDOWS\system32\lowsec\user.ds.lll[MODIFIED] C:\WINDOWS\system32\lowsec\user.ds.lll [ADDED] C:\WINDOWS\system32\lowsec\user.ds [MODIFIED] C:\WINDOWS\system32\lowsec\user.ds.lll [MODIFIED] C:\WINDOWS\system32\lowsec\user.ds.lll [REMOVED] C:\WINDOWS\system32\lowsec\user.ds.lll [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\WBEM [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [RENAMED (OLD)] C:\WINDOWS\system32\txpxr_7707485834.b1k[RENAMED (NEW)] C:\WINDOWS\system32\PereSvc.exe[MODIFIED] C:\WINDOWS\system32\PereSvc.exe [MODIFIED] C:\WINDOWS\system32\PereSvc.exe [MODIFIED] C:\WINDOWS\system32\PereSvc.exe [MODIFIED] C:\WINDOWS\system32\PereSvc.exe [MODIFIED] C:\WINDOWS\system32\PereSvc.exe [MODIFIED] C:\WINDOWS\system32\PereSvc.exe [MODIFIED] C:\WINDOWS\system32\PereSvc.exe [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [MODIFIED] C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\WBEM [ADDED] C:\Documents and Settings\Administrator\Cookies\administrator@search.toptravellingtips[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@search.toptravellingtips[1].txt [MODIFIED] C:\Documents and Settings\Administrator\Cookies\administrator@search.toptravellingtips[1].txt [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[1].htm [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\Cryptography\RNG [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\search[1].htm [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\portal[1].htm [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\style[2].css [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\style[2].css [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\highlighting[1].js [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\highlighting[1].js [MODIFIED] C:\WINDOWS\system32\wbem\Logs\wbemess.log [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\style[2].css [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [MODIFIED] C:\WINDOWS\system32\winlogon.exe [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\redirect[1].js [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4J1HMPB7\redirect[1].js [ADDED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\GetWindowSize[1].js [MODIFIED] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMR39IKD\GetWindowSize[1].js [REGISTRY] \REGISTRY\MACHINE\SOFTWARE\Microsoft\WBEM