Link to home
Start Free TrialLog in
Avatar of dinglydo
dinglydo

asked on

Homepage Keeps changing!!!!

Hi Everyone.
 I keep having problems with my internet explorer. This time its the worst... McAfee virus scan did warn me about a Trojan, and that it deleted it... however, now everytime i start my internet explorer my home page changes to mk:@MSITStore:C:\WINDOWS\start.chm::/start.html... what do i do, everytime i delete the file, it reapears... Please help.

Thanks
ding!
Avatar of sunray_2003
sunray_2003
Flag of United States of America image

Use spybot ,ad-ware ,CWshredder and post the log from Hijackthis here

After installing them, First Update them and then run

Spyware/Adware removal tools:
------------------------------

What is spyware : http://www.spychecker.com/spyware.html

SpyBot-S&D : http://www.webattack.com/download/dlspybot.shtml 

Ad-aware : http://www.webattack.com/download/dladaware.shtml 

CWShredder: http://www.softpedia.com/public/cat/10/17/10-17-150.shtml

HijackThis : http://www.webattack.com/download/dlhijackthis.shtml 

Pest Patrol : http://www.pestpatrol.com/
Check these registry entries

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
HKCU\Software\Microsoft\Internet Explorer\SearchURL
HKCU\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
HKCU\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
HKCU\Software\Microsoft\Internet Explorer\Search\SearchAssistant
HKCU\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar


and remove start.html

Avatar of shailendra_patankar
shailendra_patankar

HI..

First, check whether any unwanted packages is installed...

delete all the unknown packages installed by the virus

go to .. control panel->add/remove program->

update the antivirus and the lastest patches from the microsoft site..

go to internet explorer->tools->windows updates

del all the *.tmp files and all the internet cookies and temporary files..

go to windows explorer->and delete the all the folder and file from temporary internet files...

set the home page to blank and reboot ur machine...

check the help sunray

Hopefully the posts above have already solved your problem, but you may still need this registry fix:

http://www.kellys-korner-xp.com/regs_edits/iegentabs.reg

Zee
You'll need to edit your Registry for this tip.


Changes to the Registry are permanent. Back it up or you'll be outta luck if something goes wrong.


Navigate to this string:
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel

If the keys for Internet Explorer and Control Panel are not present, add them manually.


Right-click the Microsoft key folder, click New, and choose Key.
Name it Internet Explorer.
Right-click the Internet Explorer key folder, click New, and choose Key.
Name it Control Panel.


Right-click the Control Panel key folder and choose "new DWORD value." Rename the value "Homepage."


Right-click the Homepage value, choose Modify, and change the value from "0" to "1."

Now go into your Internet Explorer options. Your homepage is locked and unmodifiable!

Here's a shortcut if you'd rather not edit the Registry yourself. Download and double-click my file. It will make the above changes to your Registry automatically.

http://downloads.techtv.com/binaries/2004/homepagelock.zip
Avatar of dinglydo

ASKER

Hey! guys!
thanks for all your help.
But actually nothing is working,
what happens is a seemingly non-malicious start.chm file keeps materializing even after i delete it, so no adware, nothing detects it. I tried the regediting, but that didn't work either.
Start --> run --> Type in "msconfig" and press "Enter"
goto Startup tab
Disable all the applications there.Reboot the machine and check if the error occurs.
If not, then enable one at a time in the same startup tab and find the application that might cause this
at startup
hey sunray!
a friend did the msconfig thing, there doesn't seem to be anything there that is doing this...

here is my hijack log


Logfile of HijackThis v1.97.7
Scan saved at 11:14:58 AM, on 4/8/2004
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\CFusionMX\db\slserver52\bin\swagent.exe
C:\CFusionMX\db\slserver52\bin\swstrtr.exe
C:\CFusionMX\db\slserver52\bin\swsoc.exe
E:\Program Files\Network Associates\Common Framework\FrameworkService.exe
E:\Program Files\Network Associates\VirusScan\mcshield.exe
E:\Program Files\Network Associates\VirusScan\vstskmgr.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\WINDOWS\System32\tcpsvcs.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\SOUNDMAN.EXE
E:\PROGRA~1\MI948F~1\GAMECO~1\common\swtrayv4.exe
E:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
E:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
E:\Program Files\MSN Messenger\MsnMsgr.Exe
E:\Program Files\Magic Notes\Sticky32.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
E:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe
E:\Documents and Settings\User Name\Desktop\Junk\Spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:E:\WINDOWS\start.chm::/start.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:E:\WINDOWS\start.chm::/start.html
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (E:\Documents and Settings\User Name\Application Data\Mozilla\Profiles\default\bvarp6hn.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (E:\Documents and Settings\User Name\Application Data\Mozilla\Profiles\default\bvarp6hn.slt\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6427806D-3820-11D5-9939-00B0D0522EB5} - E:\Program Files\Palm\FireConverterBrowserHelperObject.dll
O2 - BHO: (no name) - {B930BA63-9E5A-11D3-A288-0000E80E2EDE} - E:\Program Files\Mass Downloader\MDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SideWinderTrayV4] E:\PROGRA~1\MI948F~1\GAMECO~1\common\swtrayv4.exe
O4 - HKLM\..\Run: [ShStatEXE] "E:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "E:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [STYLEXP] E:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [Magic Notes] "E:\Program Files\Magic Notes\Sticky32.exe"
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\System32\ctfmon.exe
O4 - Startup: Stardock ObjectDock.lnk = E:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Acrobat Assistant.lnk = E:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Download with &DAP - E:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - E:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Download with &Shareaza - res://E:\Program Files\Shareaza\Plugins\RazaWebHook.dll/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Decompiler - E:\Program Files\SourceTec\Sothink SWF Decompiler\InternetExplorer.htm
O9 - Extra button: SWFDecompiler (HKLM)
O9 - Extra 'Tools' menuitem: Sothink SWF Decompiler (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/vet_install_popup.pl?1&04.00.07.02&http://www.samsungusa.com/viewpoint/duocam/popup.html
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38076.7365162037
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/exterior/Outside.cab
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D3D83E08-54D1-4E9D-8EAF-9F979D139294} (MaxisSimCityScapeTeleX Control) - http://simcity.ea.com/scape/teleport/MaxisSimCityScapeTeleX.cab
O16 - DPF: {EDD6C042-E583-42FA-9211-282AC1A99195} (OTAutoInstall Class) - https://streaming.endeavors.com/appx/clientdownloads/OTAI.CAB

Its right here...

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:E:\WINDOWS\start.chm::/start.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:E:\WINDOWS\start.chm::/start.html

Use startup control panel.
http://www.mlin.net/StartupCPL.shtml

Disable those startups from the registry and reboot.

Hmm not sure what happened.. I posted the registry ones as above but didnot get displayed... weird

anyway delete the things aindelicato has said
Its right here...

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:E:\WINDOWS\start.chm::/start.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:E:\WINDOWS\start.chm::/start.html


deleting it doesn't work, it keeps regenerating that code after a while..
i also noticed, the start.chm file gets created when an access[1].exe file executes (found out from its temporary appearance in the task manager)
however my computer doesn't have any access[1].exe, its like it deletes itself...
HELp!!
Disable System Restore before you run any AV or Spyware/bot removal, or do any of the above, otherwise it will always creep itsway back.

|start menu|all programs|accessories|system tools|system restore|system restore settings|

tick "turn off system systore"

run all the AV and spyware/bot utils you can get your hands on.

I tried everything. It seems to be affecting everything on my pc...
here is a filesystem log....


57515      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System\crlds3d.dll      SUCCESS      Offset: 760632 Length: 112      
57516      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57517      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57518      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57519      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57520      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57521      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57522      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57523      7:26:12 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\F6ATV1E7\google[1]      SUCCESS      Options: Open Sequential  Access: All      
57524      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\F6ATV1E7\google[1]      SUCCESS      Length: 3090      
57525      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57526      7:26:12 PM      IEXPLORE.EXE:2344      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\F6ATV1E7\google[1]      SUCCESS      Offset: 0 Length: 2048      
57527      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\F6ATV1E7\google[1]      SUCCESS      Offset: 2048 Length: 1042      
57528      7:26:12 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\F6ATV1E7\google[1]      SUCCESS      Options: Open  Access: All      
57529      7:26:12 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\F6ATV1E7\google[1]      SUCCESS            
57530      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57531      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57532      7:26:12 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\F6ATV1E7\google[1]      SUCCESS      Options: Open  Access: All      
57533      7:26:12 PM      IEXPLORE.EXE:2344      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\F6ATV1E7\google[1]      SUCCESS      Offset: 0 Length: 3090      
57534      7:26:12 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\F6ATV1E7\google[1]      SUCCESS            
57535      7:26:12 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\iepeers.dll      SUCCESS            
57536      7:26:12 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\F6ATV1E7\google[1]      SUCCESS            
57537      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57538      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57539      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57540      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57541      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57542      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57543      7:26:12 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Options: Open  Access: All      
57544      7:26:12 PM      IEXPLORE.EXE:2344      READ       E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 0 Length: 64      
57545      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 240 Length: 4      
57546      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 244 Length: 20      
57547      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 488 Length: 40      
57548      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 528 Length: 40      
57549      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 568 Length: 40      
57550      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 159744 Length: 16      
57551      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 159760 Length: 8      
57552      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 161530 Length: 2      
57553      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 159768 Length: 8      
57554      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 161512 Length: 2      
57555      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 159776 Length: 8      
57556      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 161538 Length: 2      
57557      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 161540 Length: 14      
57558      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 160048 Length: 16      
57559      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 160064 Length: 8      
57560      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 160784 Length: 16      
57561      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 160800 Length: 8      
57562      7:26:12 PM      IEXPLORE.EXE:2344      READ      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Offset: 161368 Length: 16      
57563      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Length: 230400      
57564      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\iepeers.dll      SUCCESS      Length: 230400      
57565      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57566      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57567      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57568      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57569      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57570      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57571      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57572      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57573      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57574      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57575      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57576      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57577      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57578      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57579      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57580      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57581      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57582      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57583      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57584      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57585      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57586      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57587      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57588      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57589      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57590      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57591      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57592      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57593      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57594      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57595      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57596      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57597      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57598      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57599      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57600      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57601      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57602      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57603      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57604      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57605      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57606      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57607      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57608      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57609      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57610      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57611      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57612      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57613      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57614      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57615      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57616      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\MSHist012004040820040409\index.dat      SUCCESS      Length: 81920      
57617      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57618      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57619      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57620      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57621      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57622      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\MSHist012004040820040409\index.dat      SUCCESS      Length: 81920      
57623      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57624      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57625      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57626      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57627      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Program Files\Microsoft Office\Office10\EXCEL.EXE      SUCCESS      Attributes: RA      
57628      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\PROGRA~1\MICROS~2\Office10\FRONTPG.EXE      SUCCESS      Attributes: RA      
57629      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\notepad.exe      SUCCESS      Attributes: A      
57630      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Program Files\Microsoft Office\Office10\WINWORD.EXE      SUCCESS      Attributes: RA      
57631      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\PROGRA~1\MICROS~2\Office10\FRONTPG.EXE      SUCCESS      Attributes: RA      
57632      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\PROGRA~1\MICROS~2\Office10\FRONTPG.EXE      SUCCESS      Attributes: RA      
57633      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57634      7:26:12 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\History\History.IE5\index.dat      SUCCESS      Length: 4292608      
57635      7:26:13 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57636      7:26:13 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57637      7:26:13 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57638      7:26:13 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57639      7:26:15 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57640      7:26:15 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57641      7:26:15 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57642      7:26:15 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57643      7:26:17 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS      Attributes: A      
57644      7:26:17 PM      explorer.exe:3188      OPEN      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS      Options: Open  Access: Execute      
57645      7:26:17 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS      Length: 194810      
57646      7:26:17 PM      explorer.exe:3188      CLOSE      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS            
57647      7:26:17 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57648      7:26:17 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57649      7:26:17 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57650      7:26:17 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57651      7:26:19 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57652      7:26:19 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57653      7:26:19 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57654      7:26:19 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57655      7:26:21 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57656      7:26:21 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57657      7:26:21 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57658      7:26:21 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57659      7:26:23 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57660      7:26:23 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57661      7:26:23 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57662      7:26:23 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57663      7:26:25 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57664      7:26:25 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57665      7:26:25 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57666      7:26:25 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57667      7:26:27 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57668      7:26:27 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57669      7:26:27 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57670      7:26:27 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57671      7:26:29 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57672      7:26:29 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57673      7:26:29 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57674      7:26:29 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57675      7:26:31 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57676      7:26:31 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57677      7:26:31 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57678      7:26:31 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57679      7:26:32 PM      explorer.exe:3188      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
57680      7:26:32 PM      explorer.exe:3188      QUERY INFORMATION      C:\      SUCCESS      FileFsQuotaSetInformation      
57681      7:26:32 PM      explorer.exe:3188      CLOSE      C:\      SUCCESS            
57682      7:26:32 PM      explorer.exe:3188      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
57683      7:26:32 PM      explorer.exe:3188      QUERY INFORMATION      E:\      SUCCESS      FileFsQuotaSetInformation      
57684      7:26:32 PM      explorer.exe:3188      CLOSE      E:\      SUCCESS            
57685      7:26:32 PM      explorer.exe:3188      OPEN      F:\      SUCCESS      Options: Open Directory  Access: All      
57686      7:26:32 PM      explorer.exe:3188      QUERY INFORMATION      F:\      SUCCESS      FileFsQuotaSetInformation      
57687      7:26:32 PM      explorer.exe:3188      CLOSE      F:\      SUCCESS            
57688      7:26:32 PM      explorer.exe:3188      OPEN      G:\      SUCCESS      Options: Open Directory  Access: All      
57689      7:26:32 PM      explorer.exe:3188      QUERY INFORMATION      G:\      SUCCESS      FileFsQuotaSetInformation      
57690      7:26:32 PM      explorer.exe:3188      CLOSE      G:\      SUCCESS            
57691      7:26:32 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS      Attributes: A      
57692      7:26:32 PM      explorer.exe:3188      OPEN      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS      Options: Open  Access: Execute      
57693      7:26:32 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS      Length: 194810      
57694      7:26:32 PM      explorer.exe:3188      CLOSE      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS            
57695      7:26:33 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57696      7:26:33 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57697      7:26:33 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57698      7:26:33 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57699      7:26:35 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57700      7:26:35 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57701      7:26:35 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57702      7:26:35 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57703      7:26:37 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57704      7:26:37 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57705      7:26:37 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57706      7:26:37 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57707      7:26:39 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57708      7:26:39 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57709      7:26:39 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57710      7:26:39 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57711      7:26:40 PM      vsmon.exe:3948      OPEN      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      SUCCESS      Options: Open Directory  Access: All      
57712      7:26:40 PM      vsmon.exe:3948      DIRECTORY      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      SUCCESS      FileBothDirectoryInformation: *.pbk      
57713      7:26:40 PM      vsmon.exe:3948      OPEN      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      SUCCESS      Options: Open Directory  Access: All      
57714      7:26:40 PM      vsmon.exe:3948      DIRECTORY      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      SUCCESS      FileBothDirectoryInformation: rasphone.pbk      
57715      7:26:40 PM      vsmon.exe:3948      CLOSE      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      SUCCESS            
57716      7:26:40 PM      vsmon.exe:3948      OPEN      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk      SUCCESS      Options: Open  Access: All      
57717      7:26:40 PM      vsmon.exe:3948      READ       E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk      END OF FILE      Offset: 0 Length: 2048      
57718      7:26:40 PM      vsmon.exe:3948      CLOSE      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk      SUCCESS            
57719      7:26:40 PM      vsmon.exe:3948      DIRECTORY      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      NO MORE FILES      FileBothDirectoryInformation      
57720      7:26:40 PM      vsmon.exe:3948      CLOSE      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      SUCCESS            
57721      7:26:40 PM      vsmon.exe:3948      OPEN      E:\WINDOWS\System32\Ras\      SUCCESS      Options: Open Directory  Access: All      
57722      7:26:40 PM      vsmon.exe:3948      DIRECTORY      E:\WINDOWS\System32\Ras\      NO SUCH FILE      FileBothDirectoryInformation: *.pbk      
57723      7:26:40 PM      vsmon.exe:3948      CLOSE      E:\WINDOWS\System32\Ras\      SUCCESS            
57724      7:26:40 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\TEMP      SUCCESS      Attributes: D      
57725      7:26:40 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\TEMP      SUCCESS      Attributes: D      
57726      7:26:40 PM      vsmon.exe:3948      OPEN      C:\autoexec.bat      SUCCESS      Options: Open  Access: All      
57727      7:26:40 PM      vsmon.exe:3948      QUERY INFORMATION      C:\autoexec.bat      SUCCESS      Attributes: A      
57728      7:26:40 PM      vsmon.exe:3948      CLOSE      C:\autoexec.bat      SUCCESS            
57729      7:26:40 PM      vsmon.exe:3948      OPEN      C:\autoexec.bat      SUCCESS      Options: Open  Access: All      
57730      7:26:40 PM      vsmon.exe:3948      QUERY INFORMATION      C:\autoexec.bat      SUCCESS      Length: 0      
57731      7:26:40 PM      vsmon.exe:3948      READ       C:\autoexec.bat      SUCCESS      Offset: 0 Length: 0      
57732      7:26:40 PM      vsmon.exe:3948      CLOSE      C:\autoexec.bat      SUCCESS            
57733      7:26:40 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\config\systemprofile\Local Settings\Temp      SUCCESS      Attributes: D      
57734      7:26:40 PM      vsmon.exe:3948      OPEN      E:\WINDOWS\system32\config\      SUCCESS      Options: Open Directory  Access: All      
57735      7:26:40 PM      vsmon.exe:3948      DIRECTORY      E:\WINDOWS\system32\config\      SUCCESS      FileBothDirectoryInformation: systemprofile      
57736      7:26:40 PM      vsmon.exe:3948      CLOSE      E:\WINDOWS\system32\config\      SUCCESS            
57737      7:26:40 PM      vsmon.exe:3948      OPEN      E:\WINDOWS\system32\config\systemprofile\      SUCCESS      Options: Open Directory  Access: All      
57738      7:26:40 PM      vsmon.exe:3948      DIRECTORY      E:\WINDOWS\system32\config\systemprofile\      SUCCESS      FileBothDirectoryInformation: Local Settings      
57739      7:26:40 PM      vsmon.exe:3948      CLOSE      E:\WINDOWS\system32\config\systemprofile\      SUCCESS            
57740      7:26:40 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\config\systemprofile\Local Settings\Temp      SUCCESS      Attributes: D      
57741      7:26:40 PM      vsmon.exe:3948      OPEN      E:\WINDOWS\system32\config\      SUCCESS      Options: Open Directory  Access: All      
57742      7:26:40 PM      vsmon.exe:3948      DIRECTORY      E:\WINDOWS\system32\config\      SUCCESS      FileBothDirectoryInformation: systemprofile      
57743      7:26:40 PM      vsmon.exe:3948      CLOSE      E:\WINDOWS\system32\config\      SUCCESS            
57744      7:26:40 PM      vsmon.exe:3948      OPEN      E:\WINDOWS\system32\config\systemprofile\      SUCCESS      Options: Open Directory  Access: All      
57745      7:26:40 PM      vsmon.exe:3948      DIRECTORY      E:\WINDOWS\system32\config\systemprofile\      SUCCESS      FileBothDirectoryInformation: Local Settings      
57746      7:26:40 PM      vsmon.exe:3948      CLOSE      E:\WINDOWS\system32\config\systemprofile\      SUCCESS            
57747      7:26:40 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\config\systemprofile\Application Data      SUCCESS      Attributes: DRH      
57748      7:26:40 PM      vsmon.exe:3948      OPEN      E:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Network\Connections\Pbk\      PATH NOT FOUND      Options: Open Directory  Access: All      
57749      7:26:41 PM      IEXPLORE.EXE:2344      READ       E:\WINDOWS\system32\urlmon.dll      SUCCESS      Offset: 136192 Length: 16384      
57750      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57751      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57752      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57753      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57754      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Program Files\Internet Explorer\RASAPI32.DLL      FILE NOT FOUND      Attributes: Error      
57755      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\RASAPI32.DLL      FILE NOT FOUND      Attributes: Error      
57756      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\RASAPI32.DLL      SUCCESS      Attributes: A      
57757      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\RASAPI32.DLL      SUCCESS      Options: Open  Access: Execute      
57758      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\RASAPI32.DLL      SUCCESS            
57759      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\rasapi32.dll      SUCCESS      Attributes: A      
57760      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\RASAPI32.DLL      SUCCESS      Attributes: A      
57761      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Program Files\Internet Explorer\rasman.dll      FILE NOT FOUND      Attributes: Error      
57762      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\rasman.dll      FILE NOT FOUND      Attributes: Error      
57763      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\rasman.dll      SUCCESS      Attributes: A      
57764      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\rasman.dll      SUCCESS      Options: Open  Access: Execute      
57765      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\rasman.dll      SUCCESS            
57766      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\rasman.dll      SUCCESS      Attributes: A      
57767      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\RASMAN.DLL      SUCCESS      Attributes: A      
57768      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Program Files\Internet Explorer\NETAPI32.dll      FILE NOT FOUND      Attributes: Error      
57769      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\NETAPI32.dll      FILE NOT FOUND      Attributes: Error      
57770      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\NETAPI32.dll      SUCCESS      Attributes: A      
57771      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\NETAPI32.dll      SUCCESS      Options: Open  Access: Execute      
57772      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\NETAPI32.dll      SUCCESS            
57773      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\netapi32.dll      SUCCESS      Attributes: A      
57774      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\NETAPI32.DLL      SUCCESS      Attributes: A      
57775      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Program Files\Internet Explorer\TAPI32.dll      FILE NOT FOUND      Attributes: Error      
57776      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\TAPI32.dll      FILE NOT FOUND      Attributes: Error      
57777      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\TAPI32.dll      SUCCESS      Attributes: A      
57778      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\TAPI32.dll      SUCCESS      Options: Open  Access: Execute      
57779      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\TAPI32.dll      SUCCESS            
57780      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\tapi32.dll      SUCCESS      Attributes: A      
57781      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\TAPI32.DLL      SUCCESS      Attributes: A      
57782      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Program Files\Internet Explorer\rtutils.dll      FILE NOT FOUND      Attributes: Error      
57783      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\rtutils.dll      FILE NOT FOUND      Attributes: Error      
57784      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\rtutils.dll      SUCCESS      Attributes: A      
57785      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\rtutils.dll      SUCCESS      Options: Open  Access: Execute      
57786      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\rtutils.dll      SUCCESS            
57787      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\rtutils.dll      SUCCESS      Attributes: A      
57788      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\RTUTILS.DLL      SUCCESS      Attributes: A      
57789      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\TAPI32.dll      SUCCESS      Options: Open  Access: All      
57790      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\TAPI32.dll      SUCCESS      Length: 163328      
57791      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\TAPI32.dll.124.Manifest      FILE NOT FOUND      Options: Open  Access: All      
57792      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\TAPI32.dll.124.Config      FILE NOT FOUND      Options: Open  Access: All      
57793      7:26:41 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_en-US_580a28ff\      PATH NOT FOUND      Options: Open Directory  Access: All      
57794      7:26:41 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\System32\en-US      FILE NOT FOUND      Attributes: Error      
57795      7:26:41 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\System32\en      FILE NOT FOUND      Attributes: Error      
57796      7:26:41 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\System32\      SUCCESS      Attributes: D      
57797      7:26:41 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\System32\      SUCCESS      Attributes: D      
57798      7:26:41 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_en-US_f6b1e800.Manifest      FILE NOT FOUND      Attributes: Error      
57799      7:26:41 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_en_66c5eee6\      PATH NOT FOUND      Options: Open Directory  Access: All      
57800      7:26:41 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_en_5cce9bd9.Manifest      FILE NOT FOUND      Attributes: Error      
57801      7:26:41 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\      PATH NOT FOUND      Options: Open Directory  Access: All      
57802      7:26:41 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS      Attributes: A      
57803      7:26:41 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS      Attributes: A      
57804      7:26:41 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_en-US_186470ec\      PATH NOT FOUND      Options: Open Directory  Access: All      
57805      7:26:41 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_6.0.0.0_en-US_fc180953.Manifest      FILE NOT FOUND      Attributes: Error      
57806      7:26:41 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_en_272036d3\      PATH NOT FOUND      Options: Open Directory  Access: All      
57807      7:26:41 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_6.0.0.0_en_6234bd2c.Manifest      FILE NOT FOUND      Attributes: Error      
57808      7:26:41 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS      Options: Open Sequential  Access: All      
57809      7:26:41 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      BUFFER OVERFLOW      FileFsVolumeInformation      
57810      7:26:41 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      BUFFER OVERFLOW      FileAllInformation      
57811      7:26:41 PM      csrss.exe:480      READ       E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS      Offset: 0 Length: 4095      
57812      7:26:41 PM      csrss.exe:480      READ      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      END OF FILE      Offset: 1784 Length: 8178      
57813      7:26:41 PM      csrss.exe:480      CLOSE      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS            
57814      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\TAPI32.dll      SUCCESS            
57815      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Program Files\Internet Explorer\iexplore.exe.Local\      FILE NOT FOUND      Attributes: Error      
57816      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a      SUCCESS      Attributes: D      
57817      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a      SUCCESS      Options: Open Directory  Access: Traverse      
57818      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Program Files\Internet Explorer\sensapi.dll      FILE NOT FOUND      Attributes: Error      
57819      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\sensapi.dll      FILE NOT FOUND      Attributes: Error      
57820      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\sensapi.dll      SUCCESS      Attributes: A      
57821      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\sensapi.dll      SUCCESS      Options: Open  Access: Execute      
57822      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\sensapi.dll      SUCCESS            
57823      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\sensapi.dll      SUCCESS      Attributes: A      
57824      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SENSAPI.DLL      SUCCESS      Attributes: A      
57825      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57826      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\userenv.dll      SUCCESS      Attributes: A      
57827      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\USERENV.DLL      SUCCESS      Attributes: A      
57828      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\TEMP      SUCCESS      Attributes: D      
57829      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\TEMP      SUCCESS      Attributes: D      
57830      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      C:\autoexec.bat      SUCCESS      Options: Open  Access: All      
57831      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      C:\autoexec.bat      SUCCESS      Attributes: A      
57832      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      C:\autoexec.bat      SUCCESS            
57833      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      C:\autoexec.bat      SUCCESS      Options: Open  Access: All      
57834      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      C:\autoexec.bat      SUCCESS      Length: 0      
57835      7:26:41 PM      IEXPLORE.EXE:2344      READ       C:\autoexec.bat      SUCCESS      Offset: 0 Length: 0      
57836      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      C:\autoexec.bat      SUCCESS            
57837      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\Temp      SUCCESS      Attributes: D      
57838      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
57839      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
57840      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\      SUCCESS            
57841      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
57842      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
57843      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\      SUCCESS            
57844      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\      SUCCESS      Options: Open Directory  Access: All      
57845      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\      SUCCESS      FileBothDirectoryInformation: Local Settings      
57846      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\      SUCCESS            
57847      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\Temp      SUCCESS      Attributes: D      
57848      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
57849      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
57850      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\      SUCCESS            
57851      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
57852      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
57853      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\      SUCCESS            
57854      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\      SUCCESS      Options: Open Directory  Access: All      
57855      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\      SUCCESS      FileBothDirectoryInformation: Local Settings      
57856      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\      SUCCESS            
57857      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\All Users\Application Data      SUCCESS      Attributes: DRH      
57858      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      SUCCESS      Options: Open Directory  Access: All      
57859      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      SUCCESS      FileBothDirectoryInformation: *.pbk      
57860      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      SUCCESS      Options: Open Directory  Access: All      
57861      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      SUCCESS      FileBothDirectoryInformation: rasphone.pbk      
57862      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      SUCCESS            
57863      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk      SUCCESS      Options: Open  Access: All      
57864      7:26:41 PM      IEXPLORE.EXE:2344      READ       E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk      END OF FILE      Offset: 0 Length: 2048      
57865      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk      SUCCESS            
57866      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      NO MORE FILES      FileBothDirectoryInformation      
57867      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\      SUCCESS            
57868      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\Ras\      SUCCESS      Options: Open Directory  Access: All      
57869      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\WINDOWS\System32\Ras\      NO SUCH FILE      FileBothDirectoryInformation: *.pbk      
57870      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\Ras\      SUCCESS            
57871      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\TEMP      SUCCESS      Attributes: D      
57872      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\TEMP      SUCCESS      Attributes: D      
57873      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      C:\autoexec.bat      SUCCESS      Options: Open  Access: All      
57874      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      C:\autoexec.bat      SUCCESS      Attributes: A      
57875      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      C:\autoexec.bat      SUCCESS            
57876      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      C:\autoexec.bat      SUCCESS      Options: Open  Access: All      
57877      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      C:\autoexec.bat      SUCCESS      Length: 0      
57878      7:26:41 PM      IEXPLORE.EXE:2344      READ       C:\autoexec.bat      SUCCESS      Offset: 0 Length: 0      
57879      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      C:\autoexec.bat      SUCCESS            
57880      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\Temp      SUCCESS      Attributes: D      
57881      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
57882      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
57883      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\      SUCCESS            
57884      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
57885      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
57886      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\      SUCCESS            
57887      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\      SUCCESS      Options: Open Directory  Access: All      
57888      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\      SUCCESS      FileBothDirectoryInformation: Local Settings      
57889      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\      SUCCESS            
57890      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Local Settings\Temp      SUCCESS      Attributes: D      
57891      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
57892      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
57893      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\      SUCCESS            
57894      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
57895      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
57896      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\      SUCCESS            
57897      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\      SUCCESS      Options: Open Directory  Access: All      
57898      7:26:41 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\      SUCCESS      FileBothDirectoryInformation: Local Settings      
57899      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\      SUCCESS            
57900      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Application Data      SUCCESS      Attributes: DA      
57901      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Application Data\Microsoft\Network\Connections\Pbk\      PATH NOT FOUND      Options: Open Directory  Access: All      
57902      7:26:41 PM      IEXPLORE.EXE:2344      SET INFORMATION       E:\Documents and Settings\User Name\NTUSER.DAT.LOG      SUCCESS      Length: 8192      
57903      7:26:41 PM      IEXPLORE.EXE:2344      SET INFORMATION       E:\Documents and Settings\User Name\NTUSER.DAT.LOG      SUCCESS      Length: 8192      
57904      7:26:41 PM      IEXPLORE.EXE:2344      SET INFORMATION       E:\Documents and Settings\User Name\NTUSER.DAT.LOG      SUCCESS      Length: 16384      
57905      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57906      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57907      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Cookies\index.dat      SUCCESS      Length: 262144      
57908      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Cookies\index.dat      SUCCESS      Length: 262144      
57909      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Cookies\index.dat      SUCCESS      Length: 262144      
57910      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57911      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\mswsock.dll      SUCCESS      Attributes: A      
57912      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Program Files\Internet Explorer\DNSAPI.dll      FILE NOT FOUND      Attributes: Error      
57913      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\DNSAPI.dll      FILE NOT FOUND      Attributes: Error      
57914      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\DNSAPI.dll      SUCCESS      Attributes: A      
57915      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\DNSAPI.dll      SUCCESS      Options: Open  Access: Execute      
57916      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\DNSAPI.dll      SUCCESS            
57917      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\dnsapi.dll      SUCCESS      Attributes: A      
57918      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\DNSAPI.DLL      SUCCESS      Attributes: A      
57919      7:26:41 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57920      7:26:41 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57921      7:26:41 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57922      7:26:41 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
57923      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\winrnr.dll      SUCCESS      Attributes: A      
57924      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\winrnr.dll      SUCCESS      Options: Open  Access: Execute      
57925      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\winrnr.dll      SUCCESS      Length: 14848      
57926      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\winrnr.dll      SUCCESS            
57927      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\winrnr.dll      SUCCESS      Attributes: A      
57928      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\winrnr.dll      SUCCESS      Options: Open  Access: Execute      
57929      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\winrnr.dll      SUCCESS            
57930      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\winrnr.dll      SUCCESS      Attributes: A      
57931      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\WINRNR.DLL      SUCCESS      Attributes: A      
57932      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\wldap32.dll      SUCCESS      Attributes: A      
57933      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\WLDAP32.DLL      SUCCESS      Attributes: A      
57934      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\mswsock.dll      SUCCESS      Attributes: A      
57935      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Program Files\Internet Explorer\rasadhlp.dll      FILE NOT FOUND      Attributes: Error      
57936      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\rasadhlp.dll      FILE NOT FOUND      Attributes: Error      
57937      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\System32\rasadhlp.dll      SUCCESS      Attributes: A      
57938      7:26:41 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\System32\rasadhlp.dll      SUCCESS      Options: Open  Access: Execute      
57939      7:26:41 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\System32\rasadhlp.dll      SUCCESS            
57940      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\rasadhlp.dll      SUCCESS      Attributes: A      
57941      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\RASADHLP.DLL      SUCCESS      Attributes: A      
57942      7:26:41 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\system32\mswsock.dll      SUCCESS      Attributes: A      
57943      7:26:41 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\mswsock.dll      SUCCESS      Attributes: A      
57944      7:26:42 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57945      7:26:42 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
57946      7:26:42 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      FILE NOT FOUND      Attributes: Error      
57947      7:26:42 PM      IEXPLORE.EXE:2344      CREATE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Create  Access: All      
57948      7:26:42 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop      NOTIFY ENUM DIR      Change Notify      
57949      7:26:42 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 0 Length: 778      
57950      7:26:42 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 778 Length: 1270      
57951      7:26:42 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 2048 Length: 2086      
57952      7:26:42 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
57953      7:26:42 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
57954      7:26:42 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
57955      7:26:42 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
57956      7:26:42 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileStandardInformation      
57957      7:26:42 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
57958      7:26:42 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
57959      7:26:42 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
57960      7:26:42 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileStandardInformation      
57961      7:26:42 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
57962      7:26:42 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
57963      7:26:42 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
57964      7:26:42 PM      mcshield.exe:1336      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 0 Length: 4096      
57965      7:26:42 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 4096 Length: 4096      
57966      7:26:42 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      END OF FILE      Offset: 4134 Length: 4058      
57967      7:26:42 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
57968      7:26:42 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
57969      7:26:42 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
57970      7:26:42 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
57971      7:26:42 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
57972      7:26:42 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
57973      7:26:42 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
57974      7:26:42 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
57975      7:26:42 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
57976      7:26:42 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileStandardInformation      
57977      7:26:42 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
57978      7:26:42 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
57979      7:26:42 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
57980      7:26:42 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileStandardInformation      
57981      7:26:42 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
57982      7:26:42 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
57983      7:26:42 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
57984      7:26:42 PM      mcshield.exe:1336      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 0 Length: 4096      
57985      7:26:42 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 4096 Length: 4096      
57986      7:26:42 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      END OF FILE      Offset: 4134 Length: 4058      
57987      7:26:42 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
57988      7:26:42 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
57989      7:26:42 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
57990      7:26:42 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
57991      7:26:42 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
57992      7:26:42 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Length: 4134      
57993      7:26:42 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
57994      7:26:42 PM      IEXPLORE.EXE:2344      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 0 Length: 8192      
57995      7:26:42 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 4134 Length: 4380      
57996      7:26:42 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 8514 Length: 3812      
57997      7:26:42 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 12326 Length: 568      
57998      7:26:42 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 4134 Length: 8192      
57999      7:26:42 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 12894 Length: 4380      
58000      7:26:42 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 12326 Length: 8192      
58001      7:26:42 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 17274 Length: 4380      
58002      7:26:42 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 17274 Length: 8192      
58003      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 21654 Length: 4380      
58004      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 21654 Length: 8192      
58005      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 26034 Length: 4380      
58006      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 26034 Length: 8192      
58007      7:26:43 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 30414 Length: 4380      
58008      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 30414 Length: 8192      
58009      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 34794 Length: 1460      
58010      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 34794 Length: 8192      
58011      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 36254 Length: 4380      
58012      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 36254 Length: 8192      
58013      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 40634 Length: 4380      
58014      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 40634 Length: 8192      
58015      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\      SUCCESS      Options: Open Directory  Access: All      
58016      7:26:43 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      SUCCESS      FileBothDirectoryInformation: *      
58017      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\All Users\Desktop\      SUCCESS      Options: Open Directory  Access: All      
58018      7:26:43 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\All Users\Desktop\      SUCCESS      FileBothDirectoryInformation: *      
58019      7:26:43 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      SUCCESS      FileBothDirectoryInformation      
58020      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
58021      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
58022      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58023      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
58024      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
58025      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58026      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
58027      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
58028      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
58029      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58030      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
58031      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
58032      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58033      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
58034      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
58035      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
58036      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58037      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
58038      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
58039      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58040      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
58041      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
58042      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
58043      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58044      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
58045      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
58046      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58047      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
58048      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
58049      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
58050      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58051      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
58052      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
58053      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58054      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
58055      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
58056      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
58057      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58058      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
58059      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
58060      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58061      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
58062      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
58063      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
58064      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58065      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
58066      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
58067      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58068      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
58069      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
58070      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
58071      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58072      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
58073      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
58074      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58075      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
58076      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
58077      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
58078      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58079      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
58080      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
58081      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58082      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
58083      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
58084      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
58085      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58086      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
58087      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
58088      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58089      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
58090      7:26:43 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      NO MORE FILES      FileBothDirectoryInformation      
58091      7:26:43 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\All Users\Desktop\      SUCCESS      FileBothDirectoryInformation      
58092      7:26:43 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\All Users\Desktop\      NO MORE FILES      FileBothDirectoryInformation      
58093      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\      SUCCESS            
58094      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\All Users\Desktop\      SUCCESS            
58095      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 45014 Length: 4380      
58096      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 45014 Length: 8192      
58097      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 49394 Length: 4380      
58098      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 49394 Length: 8192      
58099      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 53774 Length: 2920      
58100      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 53774 Length: 8192      
58101      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 56694 Length: 650      
58102      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 56694 Length: 8192      
58103      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 57344 Length: 4380      
58104      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 57344 Length: 8192      
58105      7:26:43 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 61724 Length: 4380      
58106      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 61724 Length: 8192      
58107      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 66104 Length: 4380      
58108      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 66104 Length: 8192      
58109      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 70484 Length: 4380      
58110      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 70484 Length: 8192      
58111      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 74864 Length: 7300      
58112      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 74864 Length: 8192      
58113      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 82164 Length: 4380      
58114      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 82164 Length: 8192      
58115      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 86544 Length: 4380      
58116      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 86544 Length: 8192      
58117      7:26:43 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
58118      7:26:43 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
58119      7:26:43 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
58120      7:26:43 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
58121      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 90924 Length: 4380      
58122      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 90924 Length: 8192      
58123      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 95304 Length: 4380      
58124      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 95304 Length: 8192      
58125      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 99684 Length: 4380      
58126      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 99684 Length: 8192      
58127      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 104064 Length: 4380      
58128      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 104064 Length: 8192      
58129      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 108444 Length: 4380      
58130      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 108444 Length: 8192      
58131      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 112824 Length: 4380      
58132      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 112824 Length: 8192      
58133      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 117204 Length: 1460      
58134      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 117204 Length: 8192      
58135      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 118664 Length: 4216      
58136      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 118664 Length: 8192      
58137      7:26:43 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Attributes: A      
58138      7:26:43 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Options: Open  Access: Execute      
58139      7:26:43 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Length: 259072      
58140      7:26:43 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\system32\rpcss.dll      SUCCESS            
58141      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Attributes: A      
58142      7:26:43 PM      explorer.exe:3188      OPEN      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Options: Open  Access: Execute      
58143      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Length: 259072      
58144      7:26:43 PM      explorer.exe:3188      CLOSE      E:\WINDOWS\system32\rpcss.dll      SUCCESS            
58145      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk      SUCCESS      Attributes: DR      
58146      7:26:43 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 122880 Length: 8192      
58147      7:26:43 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 131072 Length: 2028      
58148      7:26:43 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 122880 Length: 8192      
58149      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Attributes: A      
58150      7:26:43 PM      explorer.exe:3188      OPEN      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Options: Open  Access: Execute      
58151      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Length: 259072      
58152      7:26:43 PM      explorer.exe:3188      CLOSE      E:\WINDOWS\system32\rpcss.dll      SUCCESS            
58153      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\      SUCCESS      Options: Open Directory  Access: All      
58154      7:26:43 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      SUCCESS      FileBothDirectoryInformation: *      
58155      7:26:43 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      SUCCESS      FileBothDirectoryInformation      
58156      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
58157      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
58158      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58159      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
58160      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
58161      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58162      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
58163      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
58164      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
58165      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58166      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
58167      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
58168      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58169      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
58170      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
58171      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
58172      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58173      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
58174      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
58175      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58176      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
58177      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
58178      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
58179      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58180      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
58181      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
58182      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58183      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
58184      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
58185      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
58186      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58187      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
58188      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
58189      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58190      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
58191      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
58192      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
58193      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58194      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
58195      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
58196      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58197      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
58198      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
58199      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
58200      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58201      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
58202      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
58203      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58204      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
58205      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
58206      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
58207      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58208      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
58209      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
58210      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58211      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
58212      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
58213      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
58214      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58215      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
58216      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
58217      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58218      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
58219      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
58220      7:26:43 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
58221      7:26:43 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
58222      7:26:43 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
58223      7:26:43 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
58224      7:26:43 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
58225      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
58226      7:26:43 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      NO MORE FILES      FileBothDirectoryInformation      
58227      7:26:43 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\      SUCCESS            
58228      7:26:44 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 133100 Length: 4380      
58229      7:26:44 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 131072 Length: 8192      
58230      7:26:44 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Paint Shop Pro.exe      SUCCESS      Attributes: A      
58231      7:26:44 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\Jasc Software Inc\Animation Shop 3\anim.exe      SUCCESS      Attributes: A      
58232      7:26:44 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 137480 Length: 4380      
58233      7:26:44 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 137480 Length: 8192      
58234      7:26:44 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 141860 Length: 4380      
58235      7:26:44 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 141860 Length: 8192      
58236      7:26:44 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Paint Shop Pro.exe      SUCCESS      Attributes: A      
58237      7:26:44 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe      SUCCESS      Attributes: A      
58238      7:26:44 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\SmartFTP\SmartFTP.exe      SUCCESS      Attributes: A      
58239      7:26:44 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 146240 Length: 4380      
58240      7:26:44 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 146240 Length: 8192      
58241      7:26:44 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 150620 Length: 4380      
58242      7:26:44 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 150620 Length: 8192      
58243      7:26:44 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 155000 Length: 4380      
58244      7:26:44 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 155000 Length: 8192      
58245      7:26:44 PM      IEXPLORE.EXE:2344      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 159380 Length: 8192      
58246      7:26:44 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 167572 Length: 8192      
58247      7:26:44 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 175764 Length: 8192      
58248      7:26:44 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 183956 Length: 8192      
58249      7:26:44 PM      IEXPLORE.EXE:2344      WRITE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 192148 Length: 4460      
58250      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58251      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
58252      7:26:44 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
58253      7:26:44 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
58254      7:26:44 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
58255      7:26:44 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileStandardInformation      
58256      7:26:44 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
58257      7:26:44 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
58258      7:26:44 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
58259      7:26:44 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileStandardInformation      
58260      7:26:44 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
58261      7:26:44 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
58262      7:26:44 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
58263      7:26:44 PM      mcshield.exe:1336      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 0 Length: 4096      
58264      7:26:44 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 4096 Length: 4096      
58265      7:26:44 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 8192 Length: 4096      
58266      7:26:44 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 36864 Length: 8192      
58267      7:26:44 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 12288 Length: 57344      
58268      7:26:44 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 155648 Length: 4096      
58269      7:26:44 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 73728 Length: 4096      
58270      7:26:44 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 192512 Length: 4096      
58271      7:26:44 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 69632 Length: 4096      
58272      7:26:44 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
58273      7:26:44 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
58274      7:26:44 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
58275      7:26:44 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
58276      7:26:44 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
58277      7:26:44 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop      NOTIFY ENUM DIR      Change Notify      
58278      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
58279      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
58280      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
58281      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
58282      7:26:44 PM      IEXPLORE.EXE:2344      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 159380 Length: 8192      
58283      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
58284      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
58285      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\index.dat      SUCCESS      Length: 32768      
58286      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
58287      7:26:44 PM      IEXPLORE.EXE:2344      READ       E:\WINDOWS\system32\kernel32.dll      SUCCESS      Offset: 271360 Length: 8192      
58288      7:26:44 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\PBStudio3\PBStudio3.chm      SUCCESS      Attributes: A      
58289      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
58290      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Length: 196608      
58291      7:26:44 PM      IEXPLORE.EXE:2344      WRITE       E:\$ConvertToNonresident      SUCCESS      Offset: 77824 Length: 65536      
58292      7:26:44 PM      IEXPLORE.EXE:2344      WRITE       E:\$ConvertToNonresident      SUCCESS      Offset: 143360 Length: 53248      
58293      7:26:44 PM      IEXPLORE.EXE:2344      WRITE       E:\$ConvertToNonresident      SUCCESS      Offset: 77824 Length: 65536      
58294      7:26:44 PM      IEXPLORE.EXE:2344      WRITE       E:\$ConvertToNonresident      SUCCESS      Offset: 143360 Length: 53248      
58295      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\system32\Apphelp.dll      SUCCESS      Attributes: A      
58296      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\AppPatch\sysmain.sdb      SUCCESS      Options: Open  Access: All      
58297      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\AppPatch\sysmain.sdb      SUCCESS      Length: 1026828      
58298      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\AppPatch\sysmain.sdb      SUCCESS      Length: 1026828      
58299      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\AppPatch\sysmain.sdb      SUCCESS      Length: 1026828      
58300      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\AppPatch\systest.sdb      FILE NOT FOUND      Options: Open  Access: All      
58301      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58302      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58303      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58304      7:26:44 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop      NOTIFY ENUM DIR      Change Notify      
58305      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58306      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\      SUCCESS      Options: Open Directory  Access: All      
58307      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\      SUCCESS      FileBothDirectoryInformation: Desktop      
58308      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\      SUCCESS            
58309      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\      SUCCESS      Options: Open Directory  Access: All      
58310      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      SUCCESS      FileBothDirectoryInformation: Junk      
58311      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\      SUCCESS            
58312      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\      SUCCESS      Options: Open Directory  Access: All      
58313      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\      SUCCESS      FileBothDirectoryInformation: Content.IE5      
58314      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\      SUCCESS            
58315      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\      SUCCESS      Options: Open Directory  Access: All      
58316      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\      SUCCESS      FileBothDirectoryInformation: 5STYUYRS      
58317      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\      SUCCESS            
58318      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58319      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\      SUCCESS      Options: Open Directory  Access: All      
58320      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\      SUCCESS      FileBothDirectoryInformation: Desktop      
58321      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\      SUCCESS            
58322      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\      SUCCESS      Options: Open Directory  Access: All      
58323      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      SUCCESS      FileBothDirectoryInformation: Junk      
58324      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\      SUCCESS            
58325      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\      SUCCESS      Options: Open Directory  Access: All      
58326      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\      SUCCESS      FileBothDirectoryInformation: Content.IE5      
58327      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\      SUCCESS            
58328      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\      SUCCESS      Options: Open Directory  Access: All      
58329      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\      SUCCESS      FileBothDirectoryInformation: 5STYUYRS      
58330      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\      SUCCESS            
58331      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58332      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Length: 196608      
58333      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\AppPatch\sysmain.sdb      SUCCESS            
58334      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileNameInformation      
58335      7:26:44 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58336      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\      SUCCESS      Options: Open Directory  Access: All      
58337      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\      SUCCESS      FileBothDirectoryInformation: Desktop      
58338      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\      SUCCESS            
58339      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\      SUCCESS      Options: Open Directory  Access: All      
58340      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      SUCCESS      FileBothDirectoryInformation: Junk      
58341      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\      SUCCESS            
58342      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\      SUCCESS      Options: Open Directory  Access: All      
58343      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\      SUCCESS      FileBothDirectoryInformation: Content.IE5      
58344      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\      SUCCESS            
58345      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\      SUCCESS      Options: Open Directory  Access: All      
58346      7:26:44 PM      IEXPLORE.EXE:2344      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\      SUCCESS      FileBothDirectoryInformation: 5STYUYRS      
58347      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\      SUCCESS            
58348      7:26:44 PM      IEXPLORE.EXE:2344      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe.Manifest      FILE NOT FOUND      Options: Open  Access: All      
58349      7:26:44 PM      access[1].exe:2344      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 36864 Length: 16384      
58350      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58351      7:26:44 PM      vsmon.exe:3948      OPEN      E:\Documents and Settings\User Name\      SUCCESS      Options: Open Directory  Access: All      
58352      7:26:44 PM      vsmon.exe:3948      DIRECTORY      E:\Documents and Settings\User Name\      SUCCESS      FileBothDirectoryInformation: Desktop      
58353      7:26:44 PM      vsmon.exe:3948      CLOSE      E:\Documents and Settings\User Name\      SUCCESS            
58354      7:26:44 PM      vsmon.exe:3948      OPEN      E:\Documents and Settings\User Name\Desktop\      SUCCESS      Options: Open Directory  Access: All      
58355      7:26:44 PM      vsmon.exe:3948      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      SUCCESS      FileBothDirectoryInformation: Junk      
58356      7:26:44 PM      vsmon.exe:3948      CLOSE      E:\Documents and Settings\User Name\Desktop\      SUCCESS            
58357      7:26:44 PM      vsmon.exe:3948      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\      SUCCESS      Options: Open Directory  Access: All      
58358      7:26:44 PM      vsmon.exe:3948      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\      SUCCESS      FileBothDirectoryInformation: Content.IE5      
58359      7:26:44 PM      vsmon.exe:3948      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\      SUCCESS            
58360      7:26:44 PM      vsmon.exe:3948      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\      SUCCESS      Options: Open Directory  Access: All      
58361      7:26:44 PM      vsmon.exe:3948      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\      SUCCESS      FileBothDirectoryInformation: 5STYUYRS      
58362      7:26:44 PM      vsmon.exe:3948      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\      SUCCESS            
58363      7:26:44 PM      IEXPLORE.EXE:2344      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
58364      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileNameInformation      
58365      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\NTDLL.DLL      SUCCESS      Attributes: A      
58366      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileNameInformation      
58367      7:26:44 PM      access[1].exe:2872      OPEN      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      FILE NOT FOUND      Options: Open  Access: All      
58368      7:26:44 PM      access[1].exe:2872      OPEN      E:\Documents and Settings\User Name\Desktop\      SUCCESS      Options: Open Directory  Access: Traverse      
58369      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe.Local      FILE NOT FOUND      Attributes: Error      
58370      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\kernel32.dll      SUCCESS      Attributes: A      
58371      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\KERNEL32.DLL      SUCCESS      Attributes: A      
58372      7:26:44 PM      access[1].exe:2872      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 20480 Length: 4096      
58373      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\advapi32.dll      SUCCESS      Attributes: A      
58374      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\ADVAPI32.DLL      SUCCESS      Attributes: A      
58375      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\rpcrt4.dll      SUCCESS      Attributes: A      
58376      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\RPCRT4.DLL      SUCCESS      Attributes: A      
58377      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\shell32.dll      SUCCESS      Attributes: A      
58378      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SHELL32.DLL      SUCCESS      Attributes: A      
58379      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\msvcrt.dll      SUCCESS      Attributes: A      
58380      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\MSVCRT.DLL      SUCCESS      Attributes: A      
58381      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\gdi32.dll      SUCCESS      Attributes: A      
58382      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\GDI32.DLL      SUCCESS      Attributes: A      
58383      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\user32.dll      SUCCESS      Attributes: A      
58384      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\USER32.DLL      SUCCESS      Attributes: A      
58385      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\shlwapi.dll      SUCCESS      Attributes: A      
58386      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SHLWAPI.DLL      SUCCESS      Attributes: A      
58387      7:26:44 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\SHELL32.dll      SUCCESS      Options: Open  Access: All      
58388      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\SHELL32.dll      SUCCESS      Length: 8322560      
58389      7:26:44 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\SHELL32.dll.124.Manifest      FILE NOT FOUND      Options: Open  Access: All      
58390      7:26:44 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\SHELL32.dll.124.Config      FILE NOT FOUND      Options: Open  Access: All      
58391      7:26:44 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_en-US_580a28ff\      PATH NOT FOUND      Options: Open Directory  Access: All      
58392      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\system32\en-US      FILE NOT FOUND      Attributes: Error      
58393      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\system32\en      FILE NOT FOUND      Attributes: Error      
58394      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\system32\      SUCCESS      Attributes: D      
58395      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\system32\      SUCCESS      Attributes: D      
58396      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_en-US_f6b1e800.Manifest      FILE NOT FOUND      Attributes: Error      
58397      7:26:44 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_en_66c5eee6\      PATH NOT FOUND      Options: Open Directory  Access: All      
58398      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_en_5cce9bd9.Manifest      FILE NOT FOUND      Attributes: Error      
58399      7:26:44 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\      PATH NOT FOUND      Options: Open Directory  Access: All      
58400      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS      Attributes: A      
58401      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS      Attributes: A      
58402      7:26:44 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_en-US_186470ec\      PATH NOT FOUND      Options: Open Directory  Access: All      
58403      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_6.0.0.0_en-US_fc180953.Manifest      FILE NOT FOUND      Attributes: Error      
58404      7:26:44 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_en_272036d3\      PATH NOT FOUND      Options: Open Directory  Access: All      
58405      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_6.0.0.0_en_6234bd2c.Manifest      FILE NOT FOUND      Attributes: Error      
58406      7:26:44 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS      Options: Open Sequential  Access: All      
58407      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      BUFFER OVERFLOW      FileFsVolumeInformation      
58408      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      BUFFER OVERFLOW      FileAllInformation      
58409      7:26:44 PM      csrss.exe:480      READ       E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS      Offset: 0 Length: 4095      
58410      7:26:44 PM      csrss.exe:480      READ      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      END OF FILE      Offset: 1784 Length: 8178      
58411      7:26:44 PM      csrss.exe:480      CLOSE      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS            
58412      7:26:44 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\system32\SHELL32.dll      SUCCESS            
58413      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe.Local\      FILE NOT FOUND      Attributes: Error      
58414      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a      SUCCESS      Attributes: D      
58415      7:26:44 PM      access[1].exe:2872      OPEN      E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a      SUCCESS      Options: Open Directory  Access: Traverse      
58416      7:26:44 PM      access[1].exe:2872      OPEN      E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll      SUCCESS      Options: Open  Access: Execute      
58417      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll      SUCCESS      Length: 921088      
58418      7:26:44 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll      SUCCESS            
58419      7:26:44 PM      access[1].exe:2872      OPEN      E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll      SUCCESS      Options: Open  Access: Execute      
58420      7:26:44 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll      SUCCESS            
58421      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll      SUCCESS      Attributes: A      
58422      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.0.0_X-WW_1382D70A\COMCTL32.DLL      SUCCESS      Attributes: A      
58423      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\WindowsShell.Manifest      SUCCESS      Attributes: RHA      
58424      7:26:44 PM      access[1].exe:2872      OPEN      E:\WINDOWS\WindowsShell.Manifest      SUCCESS      Options: Open  Access: Execute      
58425      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\WindowsShell.Manifest      SUCCESS      Length: 749      
58426      7:26:44 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\WindowsShell.Manifest      SUCCESS            
58427      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\WindowsShell.Manifest      SUCCESS      Attributes: RHA      
58428      7:26:44 PM      access[1].exe:2872      OPEN      E:\WINDOWS\WindowsShell.Manifest      SUCCESS      Options: Open  Access: All      
58429      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\WindowsShell.Manifest      SUCCESS      Length: 749      
58430      7:26:44 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\WindowsShell.Manifest      SUCCESS            
58431      7:26:44 PM      access[1].exe:2872      OPEN      E:\WINDOWS\WindowsShell.Manifest      SUCCESS      Options: Open  Access: All      
58432      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\WindowsShell.Manifest      SUCCESS      Length: 749      
58433      7:26:44 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\WindowsShell.Manifest      SUCCESS      FileNetworkOpenInformation      
58434      7:26:44 PM      access[1].exe:2872      OPEN      E:\WINDOWS\WindowsShell.Config      FILE NOT FOUND      Options: Open  Access: All      
58435      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WindowsShell.Manifest      SUCCESS      Attributes: RHA      
58436      7:26:44 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_en-US_580a28ff\      PATH NOT FOUND      Options: Open Directory  Access: All      
58437      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\en-US      FILE NOT FOUND      Attributes: Error      
58438      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\en      FILE NOT FOUND      Attributes: Error      
58439      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\      SUCCESS      Attributes: D      
58440      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\      SUCCESS      Attributes: D      
58441      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_en-US_f6b1e800.Manifest      FILE NOT FOUND      Attributes: Error      
58442      7:26:44 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_en_66c5eee6\      PATH NOT FOUND      Options: Open Directory  Access: All      
58443      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_en_5cce9bd9.Manifest      FILE NOT FOUND      Attributes: Error      
58444      7:26:44 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\      PATH NOT FOUND      Options: Open Directory  Access: All      
58445      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS      Attributes: A      
58446      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS      Attributes: A      
58447      7:26:44 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_en-US_186470ec\      PATH NOT FOUND      Options: Open Directory  Access: All      
58448      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_6.0.0.0_en-US_fc180953.Manifest      FILE NOT FOUND      Attributes: Error      
58449      7:26:44 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_en_272036d3\      PATH NOT FOUND      Options: Open Directory  Access: All      
58450      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_6.0.0.0_en_6234bd2c.Manifest      FILE NOT FOUND      Attributes: Error      
58451      7:26:44 PM      csrss.exe:480      OPEN      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS      Options: Open Sequential  Access: All      
58452      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      BUFFER OVERFLOW      FileFsVolumeInformation      
58453      7:26:44 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      BUFFER OVERFLOW      FileAllInformation      
58454      7:26:44 PM      csrss.exe:480      READ       E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS      Offset: 0 Length: 4095      
58455      7:26:44 PM      csrss.exe:480      READ      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      END OF FILE      Offset: 1784 Length: 8178      
58456      7:26:44 PM      csrss.exe:480      CLOSE      E:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest      SUCCESS            
58457      7:26:44 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\WindowsShell.Manifest      SUCCESS            
58458      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\comctl32.dll      SUCCESS      Attributes: A      
58459      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\COMCTL32.DLL      SUCCESS      Attributes: A      
58460      7:26:44 PM      access[1].exe:2872      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 4096 Length: 16384      
58461      7:26:44 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\PBStudio3\PBStudio3.exe      SUCCESS      Attributes: A      
58462      7:26:44 PM      access[1].exe:2872      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 24576 Length: 12288      
58463      7:26:44 PM      access[1].exe:2872      CREATE      E:\WINDOWS\start.chm      SUCCESS      Options: OverwriteIf  Access: All      
58464      7:26:44 PM      access[1].exe:2872      WRITE       E:\WINDOWS\start.chm      SUCCESS      Offset: 0 Length: 157865      
58465      7:26:44 PM      access[1].exe:2872      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 53248 Length: 16384      
58466      7:26:44 PM      winlogon.exe:504      DIRECTORY      E:\WINDOWS      SUCCESS      Change Notify      
58467      7:26:44 PM      access[1].exe:2872      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 69632 Length: 16384      
58468      7:26:44 PM      access[1].exe:2872      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 86016 Length: 16384      
58469      7:26:44 PM      access[1].exe:2872      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 102400 Length: 16384      
58470      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58471      7:26:44 PM      vsmon.exe:3948      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: Execute      
58472      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Length: 196608      
58473      7:26:44 PM      vsmon.exe:3948      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
58474      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58475      7:26:44 PM      vsmon.exe:3948      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
58476      7:26:44 PM      vsmon.exe:3948      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Length: 196608      
58477      7:26:44 PM      vsmon.exe:3948      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
58478      7:26:44 PM      access[1].exe:2872      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 118784 Length: 16384      
58479      7:26:45 PM      access[1].exe:2872      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 135168 Length: 16384      
58480      7:26:45 PM      access[1].exe:2872      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 151552 Length: 16384      
58481      7:26:45 PM      access[1].exe:2872      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 167936 Length: 16384      
58482      7:26:45 PM      access[1].exe:2872      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 184320 Length: 12288      
58483      7:26:45 PM      access[1].exe:2872      CREATE      E:\WINDOWS\start.html      SUCCESS      Options: OverwriteIf  Access: All      
58484      7:26:45 PM      access[1].exe:2872      WRITE       E:\WINDOWS\start.html      SUCCESS      Offset: 0 Length: 1115      
58485      7:26:45 PM      winlogon.exe:504      DIRECTORY      E:\WINDOWS      SUCCESS      Change Notify      
58486      7:26:45 PM      access[1].exe:2872      SET INFORMATION       E:\Documents and Settings\User Name\NTUSER.DAT.LOG      SUCCESS      Length: 20480      
58487      7:26:45 PM      access[1].exe:2872      SET INFORMATION       E:\Documents and Settings\User Name\NTUSER.DAT.LOG      SUCCESS      Length: 24576      
58488      7:26:45 PM      access[1].exe:2872      SET INFORMATION       E:\Documents and Settings\User Name\NTUSER.DAT.LOG      SUCCESS      Length: 28672      
58489      7:26:45 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\start.chm      SUCCESS            
58490      7:26:45 PM      winlogon.exe:504      DIRECTORY      E:\WINDOWS      SUCCESS      Change Notify      
58491      7:26:45 PM      mcshield.exe:1336      OPEN      E:\WINDOWS\start.chm      SUCCESS      Options: Open  Access: All      
58492      7:26:45 PM      mcshield.exe:1336      QUERY INFORMATION      E:\WINDOWS\start.chm      SUCCESS      FileBasicInformation      
58493      7:26:45 PM      mcshield.exe:1336      SET INFORMATION       E:\WINDOWS\start.chm      SUCCESS      FileBasicInformation      
58494      7:26:45 PM      mcshield.exe:1336      QUERY INFORMATION      E:\WINDOWS\start.chm      SUCCESS      FileStandardInformation      
58495      7:26:45 PM      mcshield.exe:1336      CLOSE      E:\WINDOWS\start.chm      SUCCESS            
58496      7:26:45 PM      mcshield.exe:1336      OPEN      E:\WINDOWS\start.chm      SUCCESS      Options: Open  Access: All      
58497      7:26:45 PM      mcshield.exe:1336      SET INFORMATION       E:\WINDOWS\start.chm      SUCCESS      FileBasicInformation      
58498      7:26:45 PM      mcshield.exe:1336      QUERY INFORMATION      E:\WINDOWS\start.chm      SUCCESS      FileStandardInformation      
58499      7:26:45 PM      mcshield.exe:1336      CLOSE      E:\WINDOWS\start.chm      SUCCESS            
58500      7:26:45 PM      mcshield.exe:1336      OPEN      E:\WINDOWS\start.chm      SUCCESS      Options: Open  Access: All      
58501      7:26:45 PM      mcshield.exe:1336      SET INFORMATION       E:\WINDOWS\start.chm      SUCCESS      FileBasicInformation      
58502      7:26:45 PM      mcshield.exe:1336      READ       E:\WINDOWS\start.chm      SUCCESS      Offset: 0 Length: 4096      
58503      7:26:45 PM      mcshield.exe:1336      READ      E:\WINDOWS\start.chm      SUCCESS      Offset: 4096 Length: 4096      
58504      7:26:45 PM      mcshield.exe:1336      READ      E:\WINDOWS\start.chm      SUCCESS      Offset: 8192 Length: 4096      
58505      7:26:45 PM      mcshield.exe:1336      READ      E:\WINDOWS\start.chm      SUCCESS      Offset: 49152 Length: 4096      
58506      7:26:45 PM      mcshield.exe:1336      READ      E:\WINDOWS\start.chm      SUCCESS      Offset: 20480 Length: 4096      
58507      7:26:45 PM      mcshield.exe:1336      READ      E:\WINDOWS\start.chm      SUCCESS      Offset: 16384 Length: 4096      
58508      7:26:45 PM      mcshield.exe:1336      READ      E:\WINDOWS\start.chm      SUCCESS      Offset: 61440 Length: 4096      
58509      7:26:45 PM      mcshield.exe:1336      CLOSE      E:\WINDOWS\start.chm      SUCCESS            
58510      7:26:45 PM      mcshield.exe:1336      OPEN      E:\WINDOWS\start.chm      SUCCESS      Options: Open  Access: All      
58511      7:26:45 PM      mcshield.exe:1336      SET INFORMATION       E:\WINDOWS\start.chm      SUCCESS      FileBasicInformation      
58512      7:26:45 PM      mcshield.exe:1336      QUERY INFORMATION      E:\WINDOWS\start.chm      SUCCESS      FileBasicInformation      
58513      7:26:45 PM      mcshield.exe:1336      CLOSE      E:\WINDOWS\start.chm      SUCCESS            
58514      7:26:45 PM      access[1].exe:2872      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      SUCCESS      Options: Open Directory  Access: All      
58515      7:26:45 PM      access[1].exe:2872      DIRECTORY      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      NO SUCH FILE      FileBothDirectoryInformation: hmkc.bat      
58516      7:26:45 PM      access[1].exe:2872      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      SUCCESS            
58517      7:26:45 PM      access[1].exe:2872      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: OpenIf  Access: All      
58518      7:26:45 PM      access[1].exe:2872      WRITE       E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Offset: 0 Length: 70      
58519      7:26:45 PM      access[1].exe:2872      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
58520      7:26:45 PM      mcshield.exe:1336      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: Open  Access: All      
58521      7:26:45 PM      mcshield.exe:1336      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      FileBasicInformation      
58522      7:26:45 PM      mcshield.exe:1336      SET INFORMATION       E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      FileBasicInformation      
58523      7:26:45 PM      mcshield.exe:1336      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      FileStandardInformation      
58524      7:26:45 PM      mcshield.exe:1336      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
58525      7:26:45 PM      mcshield.exe:1336      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58526      7:26:45 PM      mcshield.exe:1336      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: DOCUME~1      
58527      7:26:45 PM      mcshield.exe:1336      CLOSE      E:\      SUCCESS            
58528      7:26:45 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58529      7:26:45 PM      mcshield.exe:1336      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: USER~1      
58530      7:26:45 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\      SUCCESS            
58531      7:26:45 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\      SUCCESS      Options: Open Directory  Access: All      
58532      7:26:45 PM      mcshield.exe:1336      DIRECTORY      E:\Documents and Settings\User Name\      SUCCESS      FileBothDirectoryInformation: LOCALS~1      
58533      7:26:45 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\      SUCCESS            
58534      7:26:45 PM      mcshield.exe:1336      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: Open  Access: All      
58535      7:26:45 PM      mcshield.exe:1336      SET INFORMATION       E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      FileBasicInformation      
58536      7:26:45 PM      mcshield.exe:1336      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      FileStandardInformation      
58537      7:26:45 PM      mcshield.exe:1336      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
58538      7:26:45 PM      mcshield.exe:1336      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: Open  Access: All      
58539      7:26:45 PM      mcshield.exe:1336      SET INFORMATION       E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      FileBasicInformation      
58540      7:26:45 PM      mcshield.exe:1336      READ       E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Offset: 0 Length: 4096      
58541      7:26:45 PM      mcshield.exe:1336      READ      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      END OF FILE      Offset: 70 Length: 4026      
58542      7:26:45 PM      mcshield.exe:1336      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
58543      7:26:45 PM      mcshield.exe:1336      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: Open  Access: All      
58544      7:26:45 PM      mcshield.exe:1336      SET INFORMATION       E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      FileBasicInformation      
58545      7:26:45 PM      mcshield.exe:1336      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      FileBasicInformation      
58546      7:26:45 PM      mcshield.exe:1336      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
58547      7:26:45 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\ole32.dll      SUCCESS      Attributes: A      
58548      7:26:45 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\OLE32.DLL      SUCCESS      Attributes: A      
58549      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58550      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58551      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58552      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58553      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58554      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58555      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58556      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58557      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58558      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58559      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58560      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58561      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58562      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58563      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58564      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58565      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Program Files\Adobe\Acrobat 6.0\Acrobat\Acrobat.exe      SUCCESS      Attributes: A      
58566      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58567      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Program Files      
58568      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58569      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\Adobe\      SUCCESS      Options: Open Directory  Access: All      
58570      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\Adobe\      SUCCESS      FileBothDirectoryInformation: Acrobat 6.0      
58571      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\Adobe\      SUCCESS            
58572      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58573      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58574      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58575      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58576      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58577      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58578      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58579      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58580      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58581      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58582      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58583      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58584      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58585      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58586      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58587      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58588      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\WINDOWS\system32\csrss.exe      SUCCESS      Attributes: A      
58589      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58590      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58591      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58592      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58593      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58594      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58595      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58596      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58597      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58598      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58599      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58600      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58601      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58602      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58603      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58604      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58605      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\WINDOWS\system32\ctfmon.exe      SUCCESS      Attributes: A      
58606      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58607      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58608      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58609      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58610      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58611      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58612      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58613      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58614      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and SettingsUser Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58615      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58616      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58617      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58618      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58619      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58620      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58621      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58622      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\Filemon.exe      SUCCESS      Attributes: A      
58623      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58624      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58625      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58626      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58627      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58628      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58629      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58630      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58631      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58632      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58633      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58634      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58635      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58636      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58637      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58638      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58639      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58640      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58641      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58642      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58643      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58644      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58645      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Filemon.exe      FILE NOT FOUND      Attributes: Error      
58646      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58647      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58648      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58649      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58650      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58651      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58652      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58653      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58654      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58655      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58656      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58657      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58658      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58659      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58660      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58661      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58662      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\WINDOWS\system32\svchost.exe      SUCCESS      Attributes: A      
58663      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58664      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58665      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58666      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58667      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58668      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58669      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58670      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58671      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58672      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58673      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58674      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58675      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58676      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58677      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58678      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58679      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Program Files\Internet Explorer\IEXPLORE.EXE      SUCCESS      Attributes: A      
58680      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58681      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Program Files      
58682      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58683      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\      SUCCESS      Options: Open Directory  Access: All      
58684      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\      SUCCESS      FileBothDirectoryInformation: Internet Explorer      
58685      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\      SUCCESS            
58686      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58687      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58688      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58689      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58690      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58691      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58692      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58693      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58694      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58695      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58696      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58697      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58698      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58699      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58700      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58701      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58702      7:26:45 PM      zlclient.exe:3384      OPEN      C:\CFusionMX\runtime\bin\jrun.exe      SUCCESS      Options: Open  Access: All      
58703      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      C:\CFusionMX\runtime\bin\jrun.exe      SUCCESS      Attributes: A      
58704      7:26:45 PM      zlclient.exe:3384      CLOSE      C:\CFusionMX\runtime\bin\jrun.exe      SUCCESS            
58705      7:26:45 PM      zlclient.exe:3384      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
58706      7:26:45 PM      zlclient.exe:3384      DIRECTORY      C:\      SUCCESS      FileBothDirectoryInformation: CFusionMX      
58707      7:26:45 PM      zlclient.exe:3384      CLOSE      C:\      SUCCESS            
58708      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58709      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58710      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58711      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58712      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58713      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58714      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58715      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58716      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58717      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58718      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58719      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58720      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58721      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58722      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58723      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58724      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Program Files\RoadRunner Rhapsody\Rhapsody.exe      SUCCESS      Attributes: A      
58725      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58726      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Program Files      
58727      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58728      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\      SUCCESS      Options: Open Directory  Access: All      
58729      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\      SUCCESS      FileBothDirectoryInformation: RoadRunner Rhapsody      
58730      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\      SUCCESS            
58731      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58732      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58733      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58734      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58735      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58736      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58737      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58738      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58739      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58740      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58741      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58742      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58743      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58744      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58745      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58746      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58747      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS      Attributes: A      
58748      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58749      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Program Files      
58750      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58751      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\      SUCCESS      Options: Open Directory  Access: All      
58752      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\      SUCCESS      FileBothDirectoryInformation: Magic Notes      
58753      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\      SUCCESS            
58754      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58755      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58756      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58757      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58758      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58759      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58760      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58761      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58762      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58763      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58764      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58765      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58766      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58767      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58768      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58769      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58770      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Program Files\MSN Messenger\msnmsgr.exe      SUCCESS      Attributes: A      
58771      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58772      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Program Files      
58773      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58774      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\      SUCCESS      Options: Open Directory  Access: All      
58775      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\      SUCCESS      FileBothDirectoryInformation: MSN Messenger      
58776      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\      SUCCESS            
58777      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58778      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58779      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58780      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58781      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58782      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58783      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58784      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58785      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58786      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58787      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58788      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58789      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58790      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58791      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58792      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58793      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE      SUCCESS      Attributes: RA      
58794      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58795      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Program Files      
58796      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58797      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\      SUCCESS      Options: Open Directory  Access: All      
58798      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\      SUCCESS      FileBothDirectoryInformation: Microsoft Office      
58799      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\      SUCCESS            
58800      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58801      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58802      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58803      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58804      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58805      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58806      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58807      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58808      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58809      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58810      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58811      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58812      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58813      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58814      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58815      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58816      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Program Files\Stardock\ObjectDock\ObjectDock.exe      SUCCESS      Attributes: A      
58817      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58818      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Program Files      
58819      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58820      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\Stardock\      SUCCESS      Options: Open Directory  Access: All      
58821      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\Stardock\      SUCCESS      FileBothDirectoryInformation: ObjectDock      
58822      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\Stardock\      SUCCESS            
58823      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\Stardock\ObjectDock\      SUCCESS      Options: Open Directory  Access: All      
58824      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\Stardock\ObjectDock\      SUCCESS      FileBothDirectoryInformation: ObjectDock.exe      
58825      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\Stardock\ObjectDock\      SUCCESS            
58826      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58827      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58828      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58829      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58830      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58831      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58832      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58833      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58834      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58835      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58836      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58837      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58838      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58839      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58840      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58841      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58842      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Program Files\Common Files\Real\Update_OB\realevent.exe      SUCCESS      Attributes: A      
58843      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58844      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Program Files      
58845      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58846      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\      SUCCESS      Options: Open Directory  Access: All      
58847      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\      SUCCESS      FileBothDirectoryInformation: Common Files      
58848      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\      SUCCESS            
58849      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\Common Files\Real\      SUCCESS      Options: Open Directory  Access: All      
58850      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\Common Files\Real\      SUCCESS      FileBothDirectoryInformation: Update_OB      
58851      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\Common Files\Real\      SUCCESS            
58852      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\Common Files\Real\Update_OB\      SUCCESS      Options: Open Directory  Access: All      
58853      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\Common Files\Real\Update_OB\      SUCCESS      FileBothDirectoryInformation: realevent.exe      
58854      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\Common Files\Real\Update_OB\      SUCCESS            
58855      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58856      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58857      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58858      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58859      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58860      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58861      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58862      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58863      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58864      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58865      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58866      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58867      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58868      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58869      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58870      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58871      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\WINDOWS\system32\dumprep.exe      SUCCESS      Attributes: A      
58872      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58873      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58874      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58875      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58876      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58877      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58878      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58879      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58880      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58881      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58882      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58883      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58884      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58885      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58886      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58887      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58888      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\WINDOWS\explorer.exe      SUCCESS      Attributes: A      
58889      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58890      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58891      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58892      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58893      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58894      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58895      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58896      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58897      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58898      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58899      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58900      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58901      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58902      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58903      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58904      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58905      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Program Files\Windows Media Player\wmplayer.exe      SUCCESS      Attributes: A      
58906      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58907      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Program Files      
58908      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58909      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\      SUCCESS      Options: Open Directory  Access: All      
58910      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\      SUCCESS      FileBothDirectoryInformation: Windows Media Player      
58911      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\      SUCCESS            
58912      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58913      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58914      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58915      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58916      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58917      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58918      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58919      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58920      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58921      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58922      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58923      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58924      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58925      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58926      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58927      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58928      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\WINDOWS\system32\taskmgr.exe      SUCCESS      Attributes: A      
58929      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58930      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58931      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
58932      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58933      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
58934      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
58935      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\      SUCCESS            
58936      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      Options: Open Directory  Access: All      
58937      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS      FileBothDirectoryInformation: _XP Changer      
58938      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\      SUCCESS            
58939      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      Options: Open Directory  Access: All      
58940      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS      FileBothDirectoryInformation: Temporary Internet Files      
58941      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\      SUCCESS            
58942      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
58943      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
58944      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
58945      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe      SUCCESS      Attributes: A      
58946      7:26:45 PM      zlclient.exe:3384      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
58947      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Program Files      
58948      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\      SUCCESS            
58949      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\      SUCCESS      Options: Open Directory  Access: All      
58950      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\      SUCCESS      FileBothDirectoryInformation: Zone Labs      
58951      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\      SUCCESS            
58952      7:26:45 PM      zlclient.exe:3384      OPEN      E:\Program Files\Zone Labs\      SUCCESS      Options: Open Directory  Access: All      
58953      7:26:45 PM      zlclient.exe:3384      DIRECTORY      E:\Program Files\Zone Labs\      SUCCESS      FileBothDirectoryInformation: ZoneAlarm      
58954      7:26:45 PM      zlclient.exe:3384      CLOSE      E:\Program Files\Zone Labs\      SUCCESS            
58955      7:26:45 PM      zlclient.exe:3384      QUERY INFORMATION      E:\WINDOWS\Internet Logs\tvDebug.log      SUCCESS      Length: 45117      
58956      7:26:45 PM      zlclient.exe:3384      WRITE      E:\WINDOWS\Internet Logs\tvDebug.log      SUCCESS      Offset: 45117 Length: 22      
58957      7:26:45 PM      zlclient.exe:3384      WRITE      E:\WINDOWS\Internet Logs\tvDebug.log      SUCCESS      Offset: 45139 Length: 202      
58958      7:26:45 PM      zlclient.exe:3384      WRITE      E:\WINDOWS\Internet Logs\tvDebug.log      SUCCESS      Offset: 45341 Length: 1      
58959      7:26:45 PM      zlclient.exe:3384      WRITE      E:\WINDOWS\Internet Logs\tvDebug.log      SUCCESS      Offset: 45342 Length: 1      
58960      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Attributes: A      
58961      7:26:45 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Options: Open  Access: Execute      
58962      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Length: 259072      
58963      7:26:45 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\system32\rpcss.dll      SUCCESS            
58964      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      BUFFER OVERFLOW      FileNameInformation      
58965      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileNameInformation      
58966      7:26:45 PM      access[1].exe:2872      SET INFORMATION       E:\WINDOWS\system32\config\software.LOG      SUCCESS      Length: 12288      
58967      7:26:45 PM      access[1].exe:2872      SET INFORMATION       E:\WINDOWS\system32\config\software.LOG      SUCCESS      Length: 12288      
58968      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\uxtheme.dll      SUCCESS      Attributes: A      
58969      7:26:45 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\uxtheme.dll      SUCCESS      Options: Open  Access: Execute      
58970      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\uxtheme.dll      SUCCESS      Length: 202752      
58971      7:26:45 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\system32\uxtheme.dll      SUCCESS            
58972      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\uxtheme.dll      SUCCESS      Attributes: A      
58973      7:26:45 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\uxtheme.dll      SUCCESS      Options: Open  Access: Execute      
58974      7:26:45 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\system32\uxtheme.dll      SUCCESS            
58975      7:26:45 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\uxtheme.dll      SUCCESS      Attributes: A      
58976      7:26:45 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\UXTHEME.DLL      SUCCESS      Attributes: A      
58977      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\UxTheme.dll      FILE NOT FOUND      Attributes: Error      
58978      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\UxTheme.dll      FILE NOT FOUND      Attributes: Error      
58979      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\System32\UxTheme.dll      SUCCESS      Attributes: A      
58980      7:26:45 PM      vsmon.exe:3948      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58981      7:26:45 PM      vsmon.exe:3948      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: Execute      
58982      7:26:45 PM      vsmon.exe:3948      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Length: 196608      
58983      7:26:45 PM      vsmon.exe:3948      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
58984      7:26:45 PM      vsmon.exe:3948      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
58985      7:26:45 PM      vsmon.exe:3948      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
58986      7:26:45 PM      vsmon.exe:3948      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Length: 196608      
58987      7:26:45 PM      vsmon.exe:3948      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
58988      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\uxtheme.dll      SUCCESS      Attributes: A      
58989      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\uxtheme.dll      SUCCESS      Attributes: A      
58990      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\uxtheme.dll      SUCCESS      Attributes: A      
58991      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\System32\MSCTF.dll      SUCCESS      Attributes: A      
58992      7:26:45 PM      access[1].exe:2872      OPEN      E:\WINDOWS\System32\MSCTF.dll      SUCCESS      Options: Open  Access: Execute      
58993      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\System32\MSCTF.dll      SUCCESS      Length: 293888      
58994      7:26:45 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\System32\MSCTF.dll      SUCCESS            
58995      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\System32\MSCTF.dll      SUCCESS      Attributes: A      
58996      7:26:45 PM      access[1].exe:2872      OPEN      E:\WINDOWS\System32\MSCTF.dll      SUCCESS      Options: Open  Access: Execute      
58997      7:26:45 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\System32\MSCTF.dll      SUCCESS            
58998      7:26:45 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\MSCTF.dll      SUCCESS      Attributes: A      
58999      7:26:45 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\MSCTF.DLL      SUCCESS      Attributes: A      
59000      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\netapi32.dll      FILE NOT FOUND      Attributes: Error      
59001      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\netapi32.dll      FILE NOT FOUND      Attributes: Error      
59002      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\System32\netapi32.dll      SUCCESS      Attributes: A      
59003      7:26:45 PM      access[1].exe:2872      OPEN      E:\WINDOWS\System32\netapi32.dll      SUCCESS      Options: Open  Access: Execute      
59004      7:26:45 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\System32\netapi32.dll      SUCCESS            
59005      7:26:45 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\netapi32.dll      SUCCESS      Attributes: A      
59006      7:26:45 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\NETAPI32.DLL      SUCCESS      Attributes: A      
59007      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop      SUCCESS      Attributes: D      
59008      7:26:45 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Attributes: A      
59009      7:26:45 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\      SUCCESS      Options: Open Directory  Access: All      
59010      7:26:45 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      SUCCESS      FileBothDirectoryInformation: *      
59011      7:26:45 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\All Users\Desktop\      SUCCESS      Options: Open Directory  Access: All      
59012      7:26:45 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\All Users\Desktop\      SUCCESS      FileBothDirectoryInformation: *      
59013      7:26:45 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
59014      7:26:45 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
59015      7:26:45 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
59016      7:26:45 PM      StyleXPService.:812      QUERY INFORMATION      E:\WINDOWS\system32\UXTHEME.DLL      SUCCESS      Attributes: A      
59017      7:26:45 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Attributes: A      
59018      7:26:45 PM      IEXPLORE.EXE:2344      OPEN      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Options: Open  Access: Execute      
59019      7:26:45 PM      IEXPLORE.EXE:2344      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Length: 259072      
59020      7:26:45 PM      IEXPLORE.EXE:2344      CLOSE      E:\WINDOWS\system32\rpcss.dll      SUCCESS            
59021      7:26:45 PM      explorer.exe:3188      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Attributes: A      
59022      7:26:45 PM      explorer.exe:3188      OPEN      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Options: Open  Access: Execute      
59023      7:26:45 PM      explorer.exe:3188      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Length: 259072      
59024      7:26:45 PM      explorer.exe:3188      CLOSE      E:\WINDOWS\system32\rpcss.dll      SUCCESS            
59025      7:26:45 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk      SUCCESS      Attributes: DR      
59026      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\SHELL32.dll      SUCCESS      Attributes: A      
59027      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\PBStudio3\Readme.txt      SUCCESS      Attributes: A      
59028      7:26:46 PM      access[1].exe:2872      OPEN      G:\      SUCCESS      Options: Open  Access: All      
59029      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      G:\      SUCCESS      Attributes: D      
59030      7:26:46 PM      access[1].exe:2872      CLOSE      G:\      SUCCESS            
59031      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Attributes: A      
59032      7:26:46 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Options: Open  Access: Execute      
59033      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Length: 259072      
59034      7:26:46 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\system32\rpcss.dll      SUCCESS            
59035      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\SETUPAPI.dll      FILE NOT FOUND      Attributes: Error      
59036      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\SETUPAPI.dll      FILE NOT FOUND      Attributes: Error      
59037      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\System32\SETUPAPI.dll      SUCCESS      Attributes: A      
59038      7:26:46 PM      access[1].exe:2872      OPEN      E:\WINDOWS\System32\SETUPAPI.dll      SUCCESS      Options: Open  Access: Execute      
59039      7:26:46 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\System32\SETUPAPI.dll      SUCCESS            
59040      7:26:46 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\setupapi.dll      SUCCESS      Attributes: A      
59041      7:26:46 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SETUPAPI.DLL      SUCCESS      Attributes: A      
59042      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\      SUCCESS      Attributes: D      
59043      7:26:46 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      SUCCESS      FileBothDirectoryInformation      
59044      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
59045      7:26:46 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
59046      7:26:46 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59047      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
59048      7:26:46 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
59049      7:26:46 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59050      7:26:46 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
59051      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
59052      7:26:46 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
59053      7:26:46 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59054      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
59055      7:26:46 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
59056      7:26:46 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59057      7:26:46 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
59058      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
59059      7:26:46 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
59060      7:26:46 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59061      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
59062      7:26:46 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
59063      7:26:46 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59064      7:26:46 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
59065      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
59066      7:26:46 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
59067      7:26:46 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59068      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
59069      7:26:46 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
59070      7:26:46 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59071      7:26:46 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
59072      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Attributes: HS      
59073      7:26:46 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Options: Open  Access: All      
59074      7:26:46 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59075      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Length: 71      
59076      7:26:46 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS      Offset: 0 Length: 71      
59077      7:26:46 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59078      7:26:46 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Exercise\desktop.ini      SUCCESS            
59079      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
59080      7:26:46 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
59081      7:26:46 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59082      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
59083      7:26:46 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
59084      7:26:46 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59085      7:26:46 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
59086      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
59087      7:26:46 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
59088      7:26:46 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59089      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
59090      7:26:46 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
59091      7:26:46 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59092      7:26:46 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
59093      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
59094      7:26:46 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
59095      7:26:46 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59096      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
59097      7:26:46 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
59098      7:26:46 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59099      7:26:46 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
59100      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
59101      7:26:46 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
59102      7:26:46 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59103      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
59104      7:26:46 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
59105      7:26:46 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59106      7:26:46 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
59107      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Attributes: HS      
59108      7:26:46 PM      explorer.exe:3188      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Options: Open  Access: All      
59109      7:26:46 PM      explorer.exe:3188      LOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59110      7:26:46 PM      explorer.exe:3188      QUERY INFORMATION      E:\Documents and SettingsUser Name\Desktop\Junk\desktop.ini      SUCCESS      Length: 108      
59111      7:26:46 PM      explorer.exe:3188      READ       E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS      Offset: 0 Length: 108      
59112      7:26:46 PM      explorer.exe:3188      UNLOCK      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59113      7:26:46 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\desktop.ini      SUCCESS            
59114      7:26:46 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop\      NO MORE FILES      FileBothDirectoryInformation      
59115      7:26:46 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\All Users\Desktop\      SUCCESS      FileBothDirectoryInformation      
59116      7:26:46 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\All Users\Desktop\      NO MORE FILES      FileBothDirectoryInformation      
59117      7:26:46 PM      access[1].exe:2872      OPEN      G:\Desktop.ini      SUCCESS      Options: Open  Access: All      
59118      7:26:46 PM      access[1].exe:2872      LOCK      G:\Desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59119      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      G:\Desktop.ini      SUCCESS      Length: 84      
59120      7:26:46 PM      access[1].exe:2872      READ       G:\Desktop.ini      SUCCESS      Offset: 0 Length: 84      
59121      7:26:46 PM      access[1].exe:2872      UNLOCK      G:\Desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59122      7:26:46 PM      access[1].exe:2872      CLOSE      G:\Desktop.ini      SUCCESS            
59123      7:26:46 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\User Name\Desktop\      SUCCESS            
59124      7:26:46 PM      explorer.exe:3188      CLOSE      E:\Documents and Settings\All Users\Desktop\      SUCCESS            
59125      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\All Users\Documents      SUCCESS      Attributes: DR      
59126      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Attributes: A      
59127      7:26:46 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Options: Open  Access: Execute      
59128      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Length: 259072      
59129      7:26:46 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\system32\rpcss.dll      SUCCESS            
59130      7:26:46 PM      access[1].exe:2872      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
59131      7:26:46 PM      access[1].exe:2872      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
59132      7:26:46 PM      access[1].exe:2872      CLOSE      E:\      SUCCESS            
59133      7:26:46 PM      access[1].exe:2872      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
59134      7:26:46 PM      access[1].exe:2872      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: All Users      
59135      7:26:46 PM      access[1].exe:2872      CLOSE      E:\Documents and Settings\      SUCCESS            
59136      7:26:46 PM      access[1].exe:2872      OPEN      E:\Documents and Settings\All Users\      SUCCESS      Options: Open Directory  Access: All      
59137      7:26:46 PM      access[1].exe:2872      DIRECTORY      E:\Documents and Settings\All Users\      SUCCESS      FileBothDirectoryInformation: Documents      
59138      7:26:46 PM      access[1].exe:2872      CLOSE      E:\Documents and Settings\All Users\      SUCCESS            
59139      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Attributes: HSA      
59140      7:26:46 PM      access[1].exe:2872      OPEN      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Options: Open  Access: All      
59141      7:26:46 PM      access[1].exe:2872      LOCK      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59142      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Length: 131      
59143      7:26:46 PM      access[1].exe:2872      READ       E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Offset: 0 Length: 131      
59144      7:26:46 PM      access[1].exe:2872      UNLOCK      E:\Documents and Settings\All Users\Documents\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59145      7:26:46 PM      access[1].exe:2872      CLOSE      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS            
59146      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Attributes: HSA      
59147      7:26:46 PM      access[1].exe:2872      OPEN      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Options: Open  Access: All      
59148      7:26:46 PM      access[1].exe:2872      LOCK      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59149      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Length: 131      
59150      7:26:46 PM      access[1].exe:2872      READ       E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Offset: 0 Length: 131      
59151      7:26:46 PM      access[1].exe:2872      UNLOCK      E:\Documents and Settings\All Users\Documents\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59152      7:26:46 PM      access[1].exe:2872      CLOSE      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS            
59153      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Attributes: HSA      
59154      7:26:46 PM      access[1].exe:2872      OPEN      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Options: Open  Access: All      
59155      7:26:46 PM      access[1].exe:2872      LOCK      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59156      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Length: 131      
59157      7:26:46 PM      access[1].exe:2872      READ       E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Offset: 0 Length: 131      
59158      7:26:46 PM      access[1].exe:2872      UNLOCK      E:\Documents and Settings\All Users\Documents\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59159      7:26:46 PM      access[1].exe:2872      CLOSE      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS            
59160      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Attributes: HSA      
59161      7:26:46 PM      access[1].exe:2872      OPEN      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Options: Open  Access: All      
59162      7:26:46 PM      access[1].exe:2872      LOCK      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59163      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Length: 131      
59164      7:26:46 PM      access[1].exe:2872      READ       E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Offset: 0 Length: 131      
59165      7:26:46 PM      access[1].exe:2872      UNLOCK      E:\Documents and Settings\All Users\Documents\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59166      7:26:46 PM      access[1].exe:2872      CLOSE      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS            
59167      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Attributes: HSA      
59168      7:26:46 PM      access[1].exe:2872      OPEN      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Options: Open  Access: All      
59169      7:26:46 PM      access[1].exe:2872      LOCK      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Excl: No Offset: 0 Length: -1      
59170      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Length: 131      
59171      7:26:46 PM      access[1].exe:2872      READ       E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS      Offset: 0 Length: 131      
59172      7:26:46 PM      access[1].exe:2872      UNLOCK      E:\Documents and Settings\All Users\Documents\desktop.ini      RANGE NOT LOCKED      Offset: 0 Length: -1      
59173      7:26:46 PM      access[1].exe:2872      CLOSE      E:\Documents and Settings\All Users\Documents\desktop.ini      SUCCESS            
59174      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop      SUCCESS      Attributes: D      
59175      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Attributes: A      
59176      7:26:46 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Options: Open  Access: Execute      
59177      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Length: 259072      
59178      7:26:46 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\system32\rpcss.dll      SUCCESS            
59179      7:26:46 PM      access[1].exe:2872      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
59180      7:26:46 PM      access[1].exe:2872      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
59181      7:26:46 PM      access[1].exe:2872      CLOSE      E:\      SUCCESS            
59182      7:26:46 PM      access[1].exe:2872      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
59183      7:26:46 PM      access[1].exe:2872      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
59184      7:26:46 PM      access[1].exe:2872      CLOSE      E:\Documents and Settings\      SUCCESS            
59185      7:26:46 PM      access[1].exe:2872      OPEN      E:\Documents and Settings\User Name\      SUCCESS      Options: Open Directory  Access: All      
59186      7:26:46 PM      access[1].exe:2872      DIRECTORY      E:\Documents and Settings\User Name\      SUCCESS      FileBothDirectoryInformation: Desktop      
59187      7:26:46 PM      access[1].exe:2872      CLOSE      E:\Documents and Settings\User Name\      SUCCESS            
59188      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\All Users\Desktop      SUCCESS      Attributes: D      
59189      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Attributes: A      
59190      7:26:46 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Options: Open  Access: Execute      
59191      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\rpcss.dll      SUCCESS      Length: 259072      
59192      7:26:46 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\system32\rpcss.dll      SUCCESS            
59193      7:26:46 PM      access[1].exe:2872      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
59194      7:26:46 PM      access[1].exe:2872      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
59195      7:26:46 PM      access[1].exe:2872      CLOSE      E:\      SUCCESS            
59196      7:26:46 PM      access[1].exe:2872      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
59197      7:26:46 PM      access[1].exe:2872      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: All Users      
59198      7:26:46 PM      access[1].exe:2872      CLOSE      E:\Documents and Settings\      SUCCESS            
59199      7:26:46 PM      access[1].exe:2872      OPEN      E:\Documents and Settings\All Users\      SUCCESS      Options: Open Directory  Access: All      
59200      7:26:46 PM      access[1].exe:2872      DIRECTORY      E:\Documents and Settings\All Users\      SUCCESS      FileBothDirectoryInformation: Desktop      
59201      7:26:46 PM      access[1].exe:2872      CLOSE      E:\Documents and Settings\All Users\      SUCCESS            
59202      7:26:46 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\apphelp.dll      SUCCESS      Attributes: A      
59203      7:26:46 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\APPHELP.DLL      SUCCESS      Attributes: A      
59204      7:26:46 PM      access[1].exe:2872      OPEN      E:\Program Files\Qualcomm\Eudora\EuShlExt.dll      FILE NOT FOUND      Options: Open  Access: All      
59205      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\CLBCATQ.DLL      FILE NOT FOUND      Attributes: Error      
59206      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\CLBCATQ.DLL      FILE NOT FOUND      Attributes: Error      
59207      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\System32\CLBCATQ.DLL      SUCCESS      Attributes: A      
59208      7:26:46 PM      access[1].exe:2872      OPEN      E:\WINDOWS\System32\CLBCATQ.DLL      SUCCESS      Options: Open  Access: Execute      
59209      7:26:46 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\System32\CLBCATQ.DLL      SUCCESS            
59210      7:26:46 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\clbcatq.dll      SUCCESS      Attributes: A      
59211      7:26:46 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\CLBCATQ.DLL      SUCCESS      Attributes: A      
59212      7:26:46 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\oleaut32.dll      SUCCESS      Attributes: A      
59213      7:26:46 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\OLEAUT32.DLL      SUCCESS      Attributes: A      
59214      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\COMRes.dll      FILE NOT FOUND      Attributes: Error      
59215      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\COMRes.dll      FILE NOT FOUND      Attributes: Error      
59216      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\System32\COMRes.dll      SUCCESS      Attributes: A      
59217      7:26:46 PM      access[1].exe:2872      OPEN      E:\WINDOWS\System32\COMRes.dll      SUCCESS      Options: Open  Access: Execute      
59218      7:26:46 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\System32\COMRes.dll      SUCCESS            
59219      7:26:46 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\comres.dll      SUCCESS      Attributes: A      
59220      7:26:46 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\COMRES.DLL      SUCCESS      Attributes: A      
59221      7:26:46 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\version.dll      SUCCESS      Attributes: A      
59222      7:26:46 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\VERSION.DLL      SUCCESS      Attributes: A      
59223      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\Registration      SUCCESS      Attributes: D      
59224      7:26:46 PM      vstskmgr.exe:1360      SET INFORMATION       E:\WINDOWS\system32\config\software.LOG      SUCCESS      Length: 20480      
59225      7:26:46 PM      vstskmgr.exe:1360      SET INFORMATION       E:\WINDOWS\system32\config\software.LOG      SUCCESS      Length: 24576      
59226      7:26:46 PM      vstskmgr.exe:1360      SET INFORMATION       E:\WINDOWS\system32\config\software.LOG      SUCCESS      Length: 28672      
59227      7:26:46 PM      vstskmgr.exe:1360      SET INFORMATION       E:\WINDOWS\system32\config\software.LOG      SUCCESS      Length: 32768      
59228      7:26:46 PM      vstskmgr.exe:1360      SET INFORMATION       E:\WINDOWS\system32\config\software.LOG      SUCCESS      Length: 36864      
59229      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Program Files\Qualcomm\Eudora\EuShlExt.dll      FILE NOT FOUND      Attributes: Error      
59230      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\Program Files\Qualcomm\Eudora\EuShlExt.dll      FILE NOT FOUND      Attributes: Error      
59231      7:26:46 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Attributes: A      
59232      7:26:47 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\cmd.exe      SUCCESS      Options: Open  Access: All      
59233      7:26:47 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Attributes: A      
59234      7:26:47 PM      access[1].exe:2872      SET INFORMATION       E:\WINDOWS\system32\cmd.exe      SUCCESS      FileBasicInformation      
59235      7:26:47 PM      access[1].exe:2872      READ       E:\WINDOWS\system32\cmd.exe      SUCCESS      Offset: 0 Length: 64      
59236      7:26:47 PM      access[1].exe:2872      READ       E:\WINDOWS\system32\cmd.exe      SUCCESS      Offset: 0 Length: 4096      
59237      7:26:47 PM      access[1].exe:2872      READ      E:\WINDOWS\system32\cmd.exe      SUCCESS      Offset: 224 Length: 64      
59238      7:26:47 PM      access[1].exe:2872      READ      E:\WINDOWS\system32\cmd.exe      SUCCESS      Offset: 296 Length: 4      
59239      7:26:47 PM      access[1].exe:2872      READ      E:\WINDOWS\system32\cmd.exe      SUCCESS      Offset: 316 Length: 4      
59240      7:26:47 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\system32\cmd.exe      SUCCESS            
59241      7:26:47 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Attributes: A      
59242      7:26:47 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Attributes: A      
59243      7:26:47 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\cmd.exe      SUCCESS      Options: Open  Access: All      
59244      7:26:47 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Length: 375808      
59245      7:26:47 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Attributes: A      
59246      7:26:47 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Length: 375808      
59247      7:26:47 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      FileNameInformation      
59248      7:26:47 PM      access[1].exe:2872      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Attributes: A      
59249      7:26:47 PM      access[1].exe:2872      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
59250      7:26:47 PM      access[1].exe:2872      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: WINDOWS      
59251      7:26:47 PM      access[1].exe:2872      CLOSE      E:\      SUCCESS            
59252      7:26:47 PM      access[1].exe:2872      OPEN      E:\WINDOWS\      SUCCESS      Options: Open Directory  Access: All      
59253      7:26:47 PM      access[1].exe:2872      DIRECTORY      E:\WINDOWS\      SUCCESS      FileBothDirectoryInformation: system32      
59254      7:26:47 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\      SUCCESS            
59255      7:26:47 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\      SUCCESS      Options: Open Directory  Access: All      
59256      7:26:47 PM      access[1].exe:2872      DIRECTORY      E:\WINDOWS\system32\      SUCCESS      FileBothDirectoryInformation: cmd.exe      
59257      7:26:47 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\system32\      SUCCESS            
59258      7:26:47 PM      access[1].exe:2872      OPEN      E:\WINDOWS\system32\cmd.exe.Manifest      FILE NOT FOUND      Options: Open  Access: All      
59259      7:26:47 PM      cmd.exe:2872      READ       E:\WINDOWS\system32\cmd.exe      SUCCESS      Offset: 233984 Length: 16384      
59260      7:26:47 PM      access[1].exe:2872      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop      SUCCESS      Attributes: D      
59261      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Attributes: A      
59262      7:26:47 PM      vsmon.exe:3948      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
59263      7:26:47 PM      vsmon.exe:3948      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: WINDOWS      
59264      7:26:47 PM      vsmon.exe:3948      CLOSE      E:\      SUCCESS            
59265      7:26:47 PM      vsmon.exe:3948      OPEN      E:\WINDOWS\      SUCCESS      Options: Open Directory  Access: All      
59266      7:26:47 PM      vsmon.exe:3948      DIRECTORY      E:\WINDOWS\      SUCCESS      FileBothDirectoryInformation: system32      
59267      7:26:47 PM      vsmon.exe:3948      CLOSE      E:\WINDOWS\      SUCCESS            
59268      7:26:47 PM      vsmon.exe:3948      OPEN      E:\WINDOWS\system32\      SUCCESS      Options: Open Directory  Access: All      
59269      7:26:47 PM      vsmon.exe:3948      DIRECTORY      E:\WINDOWS\system32\      SUCCESS      FileBothDirectoryInformation: cmd.exe      
59270      7:26:47 PM      vsmon.exe:3948      CLOSE      E:\WINDOWS\system32\      SUCCESS            
59271      7:26:47 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\system32\cmd.exe      SUCCESS            
59272      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      FileNameInformation      
59273      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\NTDLL.DLL      SUCCESS      Attributes: A      
59274      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      FileNameInformation      
59275      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\Prefetch\CMD.EXE-034B0549.pf      SUCCESS      Options: Open  Access: All      
59276      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\Prefetch\CMD.EXE-034B0549.pf      SUCCESS      Length: 7562      
59277      7:26:47 PM      cmd.exe:2544      READ       E:\WINDOWS\Prefetch\CMD.EXE-034B0549.pf      SUCCESS      Offset: 0 Length: 7562      
59278      7:26:47 PM      cmd.exe:2544      READ       E:\WINDOWS\Prefetch\CMD.EXE-034B0549.pf      SUCCESS      Offset: 0 Length: 8192      
59279      7:26:47 PM      access[1].exe:2872      CLOSE      E:\Documents and Settings\User Name\Desktop\      SUCCESS            
59280      7:26:47 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a      SUCCESS            
59281      7:26:47 PM      access[1].exe:2872      CLOSE      E:\WINDOWS\start.html      SUCCESS            
59282      7:26:47 PM      winlogon.exe:504      DIRECTORY      E:\WINDOWS            Change Notify      
59283      7:26:47 PM      mcshield.exe:1336      OPEN      E:\WINDOWS\start.html      SUCCESS      Options: Open  Access: All      
59284      7:26:47 PM      mcshield.exe:1336      QUERY INFORMATION      E:\WINDOWS\start.html      SUCCESS      FileBasicInformation      
59285      7:26:47 PM      mcshield.exe:1336      SET INFORMATION       E:\WINDOWS\start.html      SUCCESS      FileBasicInformation      
59286      7:26:47 PM      mcshield.exe:1336      QUERY INFORMATION      E:\WINDOWS\start.html      SUCCESS      FileStandardInformation      
59287      7:26:47 PM      mcshield.exe:1336      CLOSE      E:\WINDOWS\start.html      SUCCESS            
59288      7:26:47 PM      mcshield.exe:1336      OPEN      E:\WINDOWS\start.html      SUCCESS      Options: Open  Access: All      
59289      7:26:47 PM      mcshield.exe:1336      SET INFORMATION       E:\WINDOWS\start.html      SUCCESS      FileBasicInformation      
59290      7:26:47 PM      mcshield.exe:1336      QUERY INFORMATION      E:\WINDOWS\start.html      SUCCESS      FileStandardInformation      
59291      7:26:47 PM      mcshield.exe:1336      CLOSE      E:\WINDOWS\start.html      SUCCESS            
59292      7:26:47 PM      mcshield.exe:1336      OPEN      E:\WINDOWS\start.html      SUCCESS      Options: Open  Access: All      
59293      7:26:47 PM      mcshield.exe:1336      SET INFORMATION       E:\WINDOWS\start.html      SUCCESS      FileBasicInformation      
59294      7:26:47 PM      mcshield.exe:1336      READ       E:\WINDOWS\start.html      SUCCESS      Offset: 0 Length: 4096      
59295      7:26:47 PM      mcshield.exe:1336      READ      E:\WINDOWS\start.html      END OF FILE      Offset: 1115 Length: 2981      
59296      7:26:47 PM      mcshield.exe:1336      CLOSE      E:\WINDOWS\start.html      SUCCESS            
59297      7:26:47 PM      mcshield.exe:1336      OPEN      E:\WINDOWS\start.html      SUCCESS      Options: Open  Access: All      
59298      7:26:47 PM      mcshield.exe:1336      SET INFORMATION       E:\WINDOWS\start.html      SUCCESS      FileBasicInformation      
59299      7:26:47 PM      mcshield.exe:1336      QUERY INFORMATION      E:\WINDOWS\start.html      SUCCESS      FileBasicInformation      
59300      7:26:47 PM      mcshield.exe:1336      CLOSE      E:\WINDOWS\start.html      SUCCESS            
59301      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      FILE NOT FOUND      Options: Open  Access: All      
59302      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\DESKTOP.INI      SUCCESS      Attributes: HSA      
59303      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\DESKTOP.INI      SUCCESS      Options: Open  Access: All      
59304      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\DESKTOP.INI      SUCCESS      FileInternalInformation      
59305      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\DESKTOP.INI      SUCCESS            
59306      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\User Name\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\CONTENT.IE5\5STYUYRS\ACCESS[1].EXE      SUCCESS      Attributes: A      
59307      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUMENTS AND SETTINGS\User Name\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\CONTENT.IE5\5STYUYRS\ACCESS[1].EXE      SUCCESS      Options: Open  Access: All      
59308      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\User Name\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\CONTENT.IE5\5STYUYRS\ACCESS[1].EXE      SUCCESS      FileInternalInformation      
59309      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUMENTS AND SETTINGS\User Name\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\CONTENT.IE5\5STYUYRS\ACCESS[1].EXE      SUCCESS            
59310      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\TEMP\HMKC.BAT      SUCCESS      Attributes: A      
59311      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\TEMP\HMKC.BAT      SUCCESS      Options: Open  Access: All      
59312      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\TEMP\HMKC.BAT      SUCCESS      FileInternalInformation      
59313      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\TEMP\HMKC.BAT      SUCCESS            
59314      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\REGISTRATION\R000000000013.CLB      SUCCESS      Attributes: A      
59315      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\REGISTRATION\R000000000013.CLB      SUCCESS      Options: Open  Access: All      
59316      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\REGISTRATION\R000000000013.CLB      SUCCESS      FileInternalInformation      
59317      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\REGISTRATION\R000000000013.CLB      SUCCESS            
59318      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\ADVAPI32.DLL      SUCCESS      Attributes: A      
59319      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\ADVAPI32.DLL      SUCCESS      Options: Open  Access: All      
59320      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\ADVAPI32.DLL      SUCCESS      FileInternalInformation      
59321      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\ADVAPI32.DLL      SUCCESS            
59322      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\APPHELP.DLL      SUCCESS      Attributes: A      
59323      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\APPHELP.DLL      SUCCESS      Options: Open  Access: All      
59324      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\APPHELP.DLL      SUCCESS      FileInternalInformation      
59325      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\APPHELP.DLL      SUCCESS            
59326      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\CLBCATQ.DLL      SUCCESS      Attributes: A      
59327      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\CLBCATQ.DLL      SUCCESS      Options: Open  Access: All      
59328      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\CLBCATQ.DLL      SUCCESS      FileInternalInformation      
59329      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\CLBCATQ.DLL      SUCCESS            
59330      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\CMD.EXE      SUCCESS      Attributes: A      
59331      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\CMD.EXE      SUCCESS      Options: Open  Access: All      
59332      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\CMD.EXE      SUCCESS      FileInternalInformation      
59333      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\CMD.EXE      SUCCESS            
59334      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\COMCTL32.DLL      SUCCESS      Attributes: A      
59335      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\COMCTL32.DLL      SUCCESS      Options: Open  Access: All      
59336      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\COMCTL32.DLL      SUCCESS      FileInternalInformation      
59337      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\COMCTL32.DLL      SUCCESS            
59338      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\COMRES.DLL      SUCCESS      Attributes: A      
59339      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\COMRES.DLL      SUCCESS      Options: Open  Access: All      
59340      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\COMRES.DLL      SUCCESS      FileInternalInformation      
59341      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\COMRES.DLL      SUCCESS            
59342      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\CTYPE.NLS      SUCCESS      Attributes: CA      
59343      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\CTYPE.NLS      SUCCESS      Options: Open  Access: All      
59344      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\CTYPE.NLS      SUCCESS      FileInternalInformation      
59345      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\CTYPE.NLS      SUCCESS            
59346      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\GDI32.DLL      SUCCESS      Attributes: A      
59347      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\GDI32.DLL      SUCCESS      Options: Open  Access: All      
59348      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\GDI32.DLL      SUCCESS      FileInternalInformation      
59349      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\GDI32.DLL      SUCCESS            
59350      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\KERNEL32.DLL      SUCCESS      Attributes: A      
59351      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\KERNEL32.DLL      SUCCESS      Options: Open  Access: All      
59352      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\KERNEL32.DLL      SUCCESS      FileInternalInformation      
59353      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\KERNEL32.DLL      SUCCESS            
59354      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\LOCALE.NLS      SUCCESS      Attributes: CA      
59355      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\LOCALE.NLS      SUCCESS      Options: Open  Access: All      
59356      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\LOCALE.NLS      SUCCESS      FileInternalInformation      
59357      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\LOCALE.NLS      SUCCESS            
59358      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\MSCTF.DLL      SUCCESS      Attributes: A      
59359      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\MSCTF.DLL      SUCCESS      Options: Open  Access: All      
59360      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\MSCTF.DLL      SUCCESS      FileInternalInformation      
59361      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\MSCTF.DLL      SUCCESS            
59362      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\MSVCRT.DLL      SUCCESS      Attributes: A      
59363      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\MSVCRT.DLL      SUCCESS      Options: Open  Access: All      
59364      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\MSVCRT.DLL      SUCCESS      FileInternalInformation      
59365      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\MSVCRT.DLL      SUCCESS            
59366      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\NETAPI32.DLL      SUCCESS      Attributes: A      
59367      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\NETAPI32.DLL      SUCCESS      Options: Open  Access: All      
59368      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\NETAPI32.DLL      SUCCESS      FileInternalInformation      
59369      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\NETAPI32.DLL      SUCCESS            
59370      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\NTDLL.DLL      SUCCESS      Attributes: A      
59371      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\NTDLL.DLL      SUCCESS      Options: Open  Access: All      
59372      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\NTDLL.DLL      SUCCESS      FileInternalInformation      
59373      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\NTDLL.DLL      SUCCESS            
59374      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\OLE32.DLL      SUCCESS      Attributes: A      
59375      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\OLE32.DLL      SUCCESS      Options: Open  Access: All      
59376      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\OLE32.DLL      SUCCESS      FileInternalInformation      
59377      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\OLE32.DLL      SUCCESS            
59378      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\OLEAUT32.DLL      SUCCESS      Attributes: A      
59379      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\OLEAUT32.DLL      SUCCESS      Options: Open  Access: All      
59380      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\OLEAUT32.DLL      SUCCESS      FileInternalInformation      
59381      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\OLEAUT32.DLL      SUCCESS            
59382      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\RPCRT4.DLL      SUCCESS      Attributes: A      
59383      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\RPCRT4.DLL      SUCCESS      Options: Open  Access: All      
59384      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\RPCRT4.DLL      SUCCESS      FileInternalInformation      
59385      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\RPCRT4.DLL      SUCCESS            
59386      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\RPCSS.DLL      SUCCESS      Attributes: A      
59387      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\RPCSS.DLL      SUCCESS      Options: Open  Access: All      
59388      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\RPCSS.DLL      SUCCESS      FileInternalInformation      
59389      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\RPCSS.DLL      SUCCESS            
59390      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SETUPAPI.DLL      SUCCESS      Attributes: A      
59391      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\SETUPAPI.DLL      SUCCESS      Options: Open  Access: All      
59392      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SETUPAPI.DLL      SUCCESS      FileInternalInformation      
59393      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\SETUPAPI.DLL      SUCCESS            
59394      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SHELL32.DLL      SUCCESS      Attributes: A      
59395      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\SHELL32.DLL      SUCCESS      Options: Open  Access: All      
59396      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SHELL32.DLL      SUCCESS      FileInternalInformation      
59397      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\SHELL32.DLL      SUCCESS            
59398      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SHLWAPI.DLL      SUCCESS      Attributes: A      
59399      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\SHLWAPI.DLL      SUCCESS      Options: Open  Access: All      
59400      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SHLWAPI.DLL      SUCCESS      FileInternalInformation      
59401      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\SHLWAPI.DLL      SUCCESS            
59402      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SORTKEY.NLS      SUCCESS      Attributes: CA      
59403      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\SORTKEY.NLS      SUCCESS      Options: Open  Access: All      
59404      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SORTKEY.NLS      SUCCESS      FileInternalInformation      
59405      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\SORTKEY.NLS      SUCCESS            
59406      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SORTTBLS.NLS      SUCCESS      Attributes: CA      
59407      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\SORTTBLS.NLS      SUCCESS      Options: Open  Access: All      
59408      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SORTTBLS.NLS      SUCCESS      FileInternalInformation      
59409      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\SORTTBLS.NLS      SUCCESS            
59410      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\UNICODE.NLS      SUCCESS      Attributes: CA      
59411      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\UNICODE.NLS      SUCCESS      Options: Open  Access: All      
59412      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\UNICODE.NLS      SUCCESS      FileInternalInformation      
59413      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\UNICODE.NLS      SUCCESS            
59414      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\USER32.DLL      SUCCESS      Attributes: A      
59415      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\USER32.DLL      SUCCESS      Options: Open  Access: All      
59416      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\USER32.DLL      SUCCESS      FileInternalInformation      
59417      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\USER32.DLL      SUCCESS            
59418      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\UXTHEME.DLL      SUCCESS      Attributes: A      
59419      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\UXTHEME.DLL      SUCCESS      Options: Open  Access: All      
59420      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\UXTHEME.DLL      SUCCESS      FileInternalInformation      
59421      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\UXTHEME.DLL      SUCCESS            
59422      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\VERSION.DLL      SUCCESS      Attributes: A      
59423      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\VERSION.DLL      SUCCESS      Options: Open  Access: All      
59424      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\VERSION.DLL      SUCCESS      FileInternalInformation      
59425      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\VERSION.DLL      SUCCESS            
59426      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\WINDOWSSHELL.MANIFEST      SUCCESS      Attributes: RHA      
59427      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\WINDOWSSHELL.MANIFEST      SUCCESS      Options: Open  Access: All      
59428      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\WINDOWSSHELL.MANIFEST      SUCCESS      FileInternalInformation      
59429      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\WINDOWSSHELL.MANIFEST      SUCCESS            
59430      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.0.0_X-WW_1382D70A\COMCTL32.DLL      SUCCESS      Attributes: A      
59431      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.0.0_X-WW_1382D70A\COMCTL32.DLL      SUCCESS      Options: Open  Access: All      
59432      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.0.0_X-WW_1382D70A\COMCTL32.DLL      SUCCESS      FileInternalInformation      
59433      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.0.0_X-WW_1382D70A\COMCTL32.DLL      SUCCESS            
59434      7:26:47 PM      svchost.exe:788      OPEN      G:\DESKTOP.INI      SUCCESS      Options: Open  Access: All      
59435      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      G:\DESKTOP.INI      SUCCESS      Attributes: HSA      
59436      7:26:47 PM      svchost.exe:788      CLOSE      G:\DESKTOP.INI      SUCCESS            
59437      7:26:47 PM      svchost.exe:788      OPEN      G:\DESKTOP.INI      SUCCESS      Options: Open  Access: All      
59438      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      G:\DESKTOP.INI      SUCCESS      FileInternalInformation      
59439      7:26:47 PM      svchost.exe:788      CLOSE      G:\DESKTOP.INI      SUCCESS            
59440      7:26:47 PM      svchost.exe:788      OPEN      E:\      SUCCESS      Options: Open  Access: All      
59441      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\      SUCCESS      FileInternalInformation      
59442      7:26:47 PM      svchost.exe:788      CLOSE      E:\      SUCCESS            
59443      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUMENTS AND SETTINGS\      SUCCESS      Options: Open  Access: All      
59444      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\      SUCCESS      FileInternalInformation      
59445      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUMENTS AND SETTINGS\      SUCCESS            
59446      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUMENTS AND SETTINGS\ALL USERS\      SUCCESS      Options: Open  Access: All      
59447      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\ALL USERS\      SUCCESS      FileInternalInformation      
59448      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUMENTS AND SETTINGS\ALL USERS\      SUCCESS            
59449      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\      SUCCESS      Options: Open  Access: All      
59450      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\      SUCCESS      FileInternalInformation      
59451      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\      SUCCESS            
59452      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUMENTS AND SETTINGS\USER NAME\      SUCCESS      Options: Open  Access: All      
59453      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\USER NAME\      SUCCESS      FileInternalInformation      
59454      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUMENTS AND SETTINGS\USER NAME\      SUCCESS            
59455      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\      SUCCESS      Options: Open  Access: All      
59456      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\      SUCCESS      FileInternalInformation      
59457      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\      SUCCESS            
59458      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\      SUCCESS      Options: Open  Access: All      
59459      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\      SUCCESS      FileInternalInformation      
59460      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\      SUCCESS            
59461      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\_XP CHANGER\      SUCCESS      Options: Open  Access: All      
59462      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\_XP CHANGER\      SUCCESS      FileInternalInformation      
59463      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\_XP CHANGER\      SUCCESS            
59464      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\      SUCCESS      Options: Open  Access: All      
59465      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\      SUCCESS      FileInternalInformation      
59466      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\      SUCCESS            
59467      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\CONTENT.IE5\      SUCCESS      Options: Open  Access: All      
59468      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\CONTENT.IE5\      SUCCESS      FileInternalInformation      
59469      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\CONTENT.IE5\      SUCCESS            
59470      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\CONTENT.IE5\5STYUYRS\      SUCCESS      Options: Open  Access: All      
59471      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\CONTENT.IE5\5STYUYRS\      SUCCESS      FileInternalInformation      
59472      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUMENTS AND SETTINGS\USER NAME\DESKTOP\JUNK\_XP CHANGER\TEMPORARY INTERNET FILES\CONTENT.IE5\5STYUYRS\      SUCCESS            
59473      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUME~1\      SUCCESS      Options: Open  Access: All      
59474      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUME~1\      SUCCESS      FileInternalInformation      
59475      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUME~1\      SUCCESS            
59476      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUME~1\USER~1\      SUCCESS      Options: Open  Access: All      
59477      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUME~1\USER~1\      SUCCESS      FileInternalInformation      
59478      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUME~1\USER~1\      SUCCESS            
59479      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\      SUCCESS      Options: Open  Access: All      
59480      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\      SUCCESS      FileInternalInformation      
59481      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\      SUCCESS            
59482      7:26:47 PM      svchost.exe:788      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\TEMP\      SUCCESS      Options: Open  Access: All      
59483      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\TEMP\      SUCCESS      FileInternalInformation      
59484      7:26:47 PM      svchost.exe:788      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\TEMP\      SUCCESS            
59485      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\      SUCCESS      Options: Open  Access: All      
59486      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\      SUCCESS      FileInternalInformation      
59487      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\      SUCCESS            
59488      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\REGISTRATION\      SUCCESS      Options: Open  Access: All      
59489      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\REGISTRATION\      SUCCESS      FileInternalInformation      
59490      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\REGISTRATION\      SUCCESS            
59491      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\SYSTEM32\      SUCCESS      Options: Open  Access: All      
59492      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\      SUCCESS      FileInternalInformation      
59493      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\SYSTEM32\      SUCCESS            
59494      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\WINSXS\      SUCCESS      Options: Open  Access: All      
59495      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\WINSXS\      SUCCESS      FileInternalInformation      
59496      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\WINSXS\      SUCCESS            
59497      7:26:47 PM      svchost.exe:788      OPEN      E:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.0.0_X-WW_1382D70A\      SUCCESS      Options: Open  Access: All      
59498      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      E:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.0.0_X-WW_1382D70A\      SUCCESS      FileInternalInformation      
59499      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.0.0_X-WW_1382D70A\      SUCCESS            
59500      7:26:47 PM      svchost.exe:788      OPEN      G:\      SUCCESS      Options: Open  Access: All      
59501      7:26:47 PM      svchost.exe:788      QUERY INFORMATION      G:\      SUCCESS      FileInternalInformation      
59502      7:26:47 PM      svchost.exe:788      CLOSE      G:\      SUCCESS            
59503      7:26:47 PM      svchost.exe:788      CREATE      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      Options: OverwriteIf  Access: All      
59504      7:26:47 PM      svchost.exe:788      WRITE       E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      Offset: 0 Length: 15204      
59505      7:26:47 PM      svchost.exe:788      CLOSE      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS            
59506      7:26:47 PM      mcshield.exe:1336      OPEN      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      Options: Open  Access: All      
59507      7:26:47 PM      mcshield.exe:1336      QUERY INFORMATION      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      FileBasicInformation      
59508      7:26:47 PM      mcshield.exe:1336      SET INFORMATION       E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      FileBasicInformation      
59509      7:26:47 PM      mcshield.exe:1336      QUERY INFORMATION      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      FileStandardInformation      
59510      7:26:47 PM      mcshield.exe:1336      CLOSE      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS            
59511      7:26:47 PM      mcshield.exe:1336      OPEN      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      Options: Open  Access: All      
59512      7:26:47 PM      mcshield.exe:1336      SET INFORMATION       E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      FileBasicInformation      
59513      7:26:47 PM      mcshield.exe:1336      QUERY INFORMATION      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      FileStandardInformation      
59514      7:26:47 PM      mcshield.exe:1336      CLOSE      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS            
59515      7:26:47 PM      mcshield.exe:1336      OPEN      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      Options: Open  Access: All      
59516      7:26:47 PM      mcshield.exe:1336      SET INFORMATION       E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      FileBasicInformation      
59517      7:26:47 PM      mcshield.exe:1336      READ       E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      Offset: 0 Length: 4096      
59518      7:26:47 PM      mcshield.exe:1336      CLOSE      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS            
59519      7:26:47 PM      mcshield.exe:1336      OPEN      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      Options: Open  Access: All      
59520      7:26:47 PM      mcshield.exe:1336      SET INFORMATION       E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      FileBasicInformation      
59521      7:26:47 PM      mcshield.exe:1336      QUERY INFORMATION      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS      FileBasicInformation      
59522      7:26:47 PM      mcshield.exe:1336      CLOSE      E:\WINDOWS\Prefetch\ACCESS[1].EXE-13246262.pf      SUCCESS            
59523      7:26:47 PM      cmd.exe:2544      OPEN      E:      SUCCESS      Options: Open  Access: All      
59524      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:      BUFFER OVERFLOW      FileFsVolumeInformation      
59525      7:26:47 PM      cmd.exe:2544      OPEN      G:      SUCCESS      Options: Open  Access: All      
59526      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      G:      BUFFER OVERFLOW      FileFsVolumeInformation      
59527      7:26:47 PM      cmd.exe:2544      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
59528      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\      SUCCESS      FileNamesInformation      
59529      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\      NO MORE FILES      FileNamesInformation      
59530      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUMENTS AND SETTINGS\      SUCCESS      Options: Open Directory  Access: All      
59531      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUMENTS AND SETTINGS\      SUCCESS      FileNamesInformation      
59532      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUMENTS AND SETTINGS\      NO MORE FILES      FileNamesInformation      
59533      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUMENTS AND SETTINGS\User Name\      SUCCESS      Options: Open Directory  Access: All      
59534      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUMENTS AND SETTINGS\USER NAME\      SUCCESS      FileNamesInformation      
59535      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUMENTS AND SETTINGS\USER NAME\      NO MORE FILES      FileNamesInformation      
59536      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUMENTS AND SETTINGS\USER NAME\LOCAL SETTINGS\      SUCCESS      Options: Open Directory  Access: All      
59537      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUMENTS AND SETTINGS\USER NAME\LOCAL SETTINGS\      SUCCESS      FileNamesInformation      
59538      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUMENTS AND SETTINGS\USER NAME\LOCAL SETTINGS\      NO MORE FILES      FileNamesInformation      
59539      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUMENTS AND SETTINGS\USER NAME\LOCAL SETTINGS\TEMPORARY INTERNET FILES\      SUCCESS      Options: Open Directory  Access: All      
59540      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUMENTS AND SETTINGS\USER NAME\LOCAL SETTINGS\TEMPORARY INTERNET FILES\      SUCCESS      FileNamesInformation      
59541      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUMENTS AND SETTINGS\USER NAME\LOCAL SETTINGS\TEMPORARY INTERNET FILES\      NO MORE FILES      FileNamesInformation      
59542      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUMENTS AND SETTINGS\USER NAME\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\      SUCCESS      Options: Open Directory  Access: All      
59543      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUMENTS AND SETTINGS\USER NAME\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\      SUCCESS      FileNamesInformation      
59544      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUMENTS AND SETTINGS\USER NAME\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\      NO MORE FILES      FileNamesInformation      
59545      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUMENTS AND SETTINGS\USER NAME\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\0P234PYJ\      FILE NOT FOUND      Options: Open Directory  Access: All      
59546      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\      SUCCESS      Options: Open Directory  Access: All      
59547      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\WINDOWS\      SUCCESS      FileNamesInformation      
59548      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\WINDOWS\      NO MORE FILES      FileNamesInformation      
59549      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\      SUCCESS      Options: Open Directory  Access: All      
59550      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\WINDOWS\SYSTEM32\      SUCCESS      FileNamesInformation      
59551      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\WINDOWS\SYSTEM32\      SUCCESS      FileNamesInformation      
59552      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\WINDOWS\SYSTEM32\      SUCCESS      FileNamesInformation      
59553      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\WINDOWS\SYSTEM32\      SUCCESS      FileNamesInformation      
59554      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\WINDOWS\SYSTEM32\      SUCCESS      FileNamesInformation      
59555      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\WINDOWS\SYSTEM32\      NO MORE FILES      FileNamesInformation      
59556      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\NTDLL.DLL      SUCCESS      Options: Open  Access: All      
59557      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\NTDLL.DLL      SUCCESS      Length: 674304      
59558      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\KERNEL32.DLL      SUCCESS      Options: Open  Access: All      
59559      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\KERNEL32.DLL      SUCCESS      Length: 926720      
59560      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\UNICODE.NLS      SUCCESS      Options: Open  Access: All      
59561      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\UNICODE.NLS      SUCCESS      Length: 89588      
59562      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\LOCALE.NLS      SUCCESS      Options: Open  Access: All      
59563      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\LOCALE.NLS      SUCCESS      Length: 209012      
59564      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\SORTTBLS.NLS      SUCCESS      Options: Open  Access: All      
59565      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\SORTTBLS.NLS      SUCCESS      Length: 21116      
59566      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\MSVCRT.DLL      SUCCESS      Options: Open  Access: All      
59567      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\MSVCRT.DLL      SUCCESS      Length: 322560      
59568      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\USER32.DLL      SUCCESS      Options: Open  Access: All      
59569      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\USER32.DLL      SUCCESS      Length: 561152      
59570      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\GDI32.DLL      SUCCESS      Options: Open  Access: All      
59571      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\GDI32.DLL      SUCCESS      Length: 250880      
59572      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\ADVAPI32.DLL      SUCCESS      Options: Open  Access: All      
59573      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\ADVAPI32.DLL      SUCCESS      Length: 549888      
59574      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\RPCRT4.DLL      SUCCESS      Options: Open  Access: All      
59575      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\RPCRT4.DLL      SUCCESS      Length: 463872      
59576      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\CTYPE.NLS      SUCCESS      Options: Open  Access: All      
59577      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\CTYPE.NLS      SUCCESS      Length: 8386      
59578      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\CMD.EXE      SUCCESS      Options: Open  Access: All      
59579      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\CMD.EXE      SUCCESS      Length: 375808      
59580      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\NTDLL.DLL      SUCCESS      Options: Open  Access: Execute      
59581      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\KERNEL32.DLL      SUCCESS      Options: Open  Access: Execute      
59582      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\MSVCRT.DLL      SUCCESS      Options: Open  Access: Execute      
59583      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\USER32.DLL      SUCCESS      Options: Open  Access: Execute      
59584      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\GDI32.DLL      SUCCESS      Options: Open  Access: Execute      
59585      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\ADVAPI32.DLL      SUCCESS      Options: Open  Access: Execute      
59586      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\RPCRT4.DLL      SUCCESS      Options: Open  Access: Execute      
59587      7:26:47 PM      cmd.exe:2544      OPEN      E:\WINDOWS\SYSTEM32\CMD.EXE      SUCCESS      Options: Open  Access: Execute      
59588      7:26:47 PM      cmd.exe:2544      READ       E:\WINDOWS\SYSTEM32\CMD.EXE      SUCCESS      Offset: 1024 Length: 114688      
59589      7:26:47 PM      cmd.exe:2544      READ       E:\WINDOWS\SYSTEM32\CMD.EXE      SUCCESS      Offset: 117760 Length: 114688      
59590      7:26:47 PM      cmd.exe:2544      READ       E:\WINDOWS\SYSTEM32\CMD.EXE      SUCCESS      Offset: 258560 Length: 8192      
59591      7:26:47 PM      cmd.exe:2544      OPEN      E:\Documents and Settings\User Name\Desktop      SUCCESS      Options: Open Directory  Access: Traverse      
59592      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe.Local      FILE NOT FOUND      Attributes: Error      
59593      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\kernel32.dll      SUCCESS      Attributes: A      
59594      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\KERNEL32.DLL      SUCCESS      Attributes: A      
59595      7:26:47 PM      csrss.exe:480      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\cmd.exe      FILE NOT FOUND      Attributes: Error      
59596      7:26:47 PM      csrss.exe:480      QUERY INFORMATION      E:\??\E:\WINDOWS\system32\cmd.exe      NAME INVALID      Attributes: Error      
59597      7:26:47 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Attributes: A      
59598      7:26:47 PM      csrss.exe:480      OPEN      E:\WINDOWS\system32\cmd.exe      SUCCESS      Options: Open  Access: All      
59599      7:26:47 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Attributes: A      
59600      7:26:47 PM      csrss.exe:480      SET INFORMATION       E:\WINDOWS\system32\cmd.exe      SUCCESS      FileBasicInformation      
59601      7:26:47 PM      csrss.exe:480      READ       E:\WINDOWS\system32\cmd.exe      SUCCESS      Offset: 0 Length: 12      
59602      7:26:47 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Length: 375808      
59603      7:26:47 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\system32\cmd.exe      SUCCESS      Length: 375808      
59604      7:26:47 PM      csrss.exe:480      READ       E:\WINDOWS\system32\cmd.exe      SUCCESS      Offset: 233472 Length: 32768      
59605      7:26:47 PM      csrss.exe:480      CLOSE      E:\WINDOWS\system32\cmd.exe      SUCCESS            
59606      7:26:47 PM      csrss.exe:480      READ       E:      SUCCESS      Offset: 21504 Length: 4096      
59607      7:26:47 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\PBStudio3\Install.exe      SUCCESS      Attributes: A      
59608      7:26:47 PM      csrss.exe:480      READ       E:      SUCCESS      Offset: 58368 Length: 12288      
59609      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\msvcrt.dll      SUCCESS      Attributes: A      
59610      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\MSVCRT.DLL      SUCCESS      Attributes: A      
59611      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\user32.dll      SUCCESS      Attributes: A      
59612      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\USER32.DLL      SUCCESS      Attributes: A      
59613      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\gdi32.dll      SUCCESS      Attributes: A      
59614      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\GDI32.DLL      SUCCESS      Attributes: A      
59615      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\advapi32.dll      SUCCESS      Attributes: A      
59616      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\ADVAPI32.DLL      SUCCESS      Attributes: A      
59617      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\system32\rpcrt4.dll      SUCCESS      Attributes: A      
59618      7:26:47 PM      vsmon.exe:3948      QUERY INFORMATION      E:\WINDOWS\SYSTEM32\RPCRT4.DLL      SUCCESS      Attributes: A      
59619      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop      SUCCESS      Attributes: D      
59620      7:26:47 PM      cmd.exe:2544      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
59621      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: Documents and Settings      
59622      7:26:47 PM      cmd.exe:2544      CLOSE      E:\      SUCCESS            
59623      7:26:47 PM      cmd.exe:2544      OPEN      E:\Documents and Settings\      SUCCESS      Options: Open Directory  Access: All      
59624      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\Documents and Settings\      SUCCESS      FileBothDirectoryInformation: User Name      
59625      7:26:47 PM      cmd.exe:2544      CLOSE      E:\Documents and Settings\      SUCCESS            
59626      7:26:47 PM      cmd.exe:2544      OPEN      E:\Documents and Settings\User Name\      SUCCESS      Options: Open Directory  Access: All      
59627      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\Documents and Settings\User Name\      SUCCESS      FileBothDirectoryInformation: Desktop      
59628      7:26:47 PM      cmd.exe:2544      CLOSE      E:\Documents and Settings\User Name\      SUCCESS            
59629      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop      SUCCESS      Attributes: D      
59630      7:26:47 PM      cmd.exe:2544      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
59631      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\      SUCCESS      FileNameInformation      
59632      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\      SUCCESS      FileFsVolumeInformation      
59633      7:26:47 PM      cmd.exe:2544      CLOSE      E:\      SUCCESS            
59634      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      SUCCESS      Options: Open Directory  Access: All      
59635      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      SUCCESS      FileBothDirectoryInformation: hmkc.bat      
59636      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      SUCCESS            
59637      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: Open  Access: All      
59638      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      FileNameInformation      
59639      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Attributes: A      
59640      7:26:47 PM      cmd.exe:2544      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
59641      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\      SUCCESS      FileBothDirectoryInformation: DOCUME~1      
59642      7:26:47 PM      cmd.exe:2544      CLOSE      E:\      SUCCESS            
59643      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\      SUCCESS      Options: Open Directory  Access: All      
59644      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUME~1\      SUCCESS      FileBothDirectoryInformation: USER~1      
59645      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\      SUCCESS            
59646      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\      SUCCESS      Options: Open Directory  Access: All      
59647      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUME~1\USER~1\      SUCCESS      FileBothDirectoryInformation: LOCALS~1      
59648      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\      SUCCESS            
59649      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\      SUCCESS      Options: Open Directory  Access: All      
59650      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUME~1\USER~1\LOCALS~1\      SUCCESS      FileBothDirectoryInformation: Temp      
59651      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\      SUCCESS            
59652      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      SUCCESS      Options: Open Directory  Access: All      
59653      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      SUCCESS      FileBothDirectoryInformation: hmkc.bat      
59654      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      SUCCESS            
59655      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
59656      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: Open  Access: All      
59657      7:26:47 PM      cmd.exe:2544      READ       E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Offset: 0 Length: 8192      
59658      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
59659      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: Open  Access: All      
59660      7:26:47 PM      cmd.exe:2544      READ       E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Offset: 11 Length: 8192      
59661      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
59662      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: Open  Access: All      
59663      7:26:47 PM      cmd.exe:2544      READ       E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Offset: 19 Length: 8192      
59664      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
59665      7:26:47 PM      cmd.exe:2544      CREATE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: OverwriteIf  Access: All      
59666      7:26:47 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop      NOTIFY ENUM DIR      Change Notify      
59667      7:26:47 PM      cmd.exe:2544      WRITE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 0 Length: 14      
59668      7:26:47 PM      cmd.exe:2544      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
59669      7:26:47 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop      NOTIFY ENUM DIR      Change Notify      
59670      7:26:47 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
59671      7:26:47 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
59672      7:26:47 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
59673      7:26:47 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileStandardInformation      
59674      7:26:47 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
59675      7:26:47 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
59676      7:26:47 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
59677      7:26:47 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileStandardInformation      
59678      7:26:47 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
59679      7:26:47 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
59680      7:26:47 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
59681      7:26:47 PM      mcshield.exe:1336      READ       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Offset: 0 Length: 4096      
59682      7:26:47 PM      mcshield.exe:1336      READ      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      END OF FILE      Offset: 14 Length: 4082      
59683      7:26:47 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
59684      7:26:47 PM      mcshield.exe:1336      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Options: Open  Access: All      
59685      7:26:47 PM      mcshield.exe:1336      SET INFORMATION       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
59686      7:26:47 PM      mcshield.exe:1336      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      FileBasicInformation      
59687      7:26:47 PM      mcshield.exe:1336      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS            
59688      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: Open  Access: All      
59689      7:26:47 PM      cmd.exe:2544      READ       E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Offset: 30 Length: 8192      
59690      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
59691      7:26:47 PM      cmd.exe:2544      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
59692      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\      SUCCESS      FileNameInformation      
59693      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\      SUCCESS      FileFsAttributeInformation      
59694      7:26:47 PM      cmd.exe:2544      CLOSE      E:\      SUCCESS            
59695      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
59696      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS      SUCCESS      Attributes: DS      
59697      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\access[1].exe      SUCCESS      Attributes: A      
59698      7:26:47 PM      cmd.exe:2544      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
59699      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      FileBothDirectoryInformation: access[1].exe      
59700      7:26:47 PM      cmd.exe:2544      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\ACCESS~1.EXE      SUCCESS      Options: Open  Access: All      
59701      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\ACCESS~1.EXE      SUCCESS      FileObjectIdInformation      
59702      7:26:47 PM      cmd.exe:2544      DELETE       E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\ACCESS~1.EXE      SUCCESS            
59703      7:26:47 PM      cmd.exe:2544      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\ACCESS~1.EXE      SUCCESS            
59704      7:26:47 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop      NOTIFY ENUM DIR      Change Notify      
59705      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      NO MORE FILES      FileBothDirectoryInformation      
59706      7:26:47 PM      cmd.exe:2544      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
59707      7:26:47 PM      explorer.exe:3188      DIRECTORY      E:\Documents and Settings\User Name\Desktop            Change Notify      
59708      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: Open  Access: All      
59709      7:26:47 PM      cmd.exe:2544      READ       E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Offset: 38 Length: 8192      
59710      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
59711      7:26:47 PM      cmd.exe:2544      OPEN      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS      Options: Open Directory  Access: All      
59712      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      NO SUCH FILE      FileBothDirectoryInformation: access[1].exe      
59713      7:26:47 PM      cmd.exe:2544      CLOSE      E:\Documents and Settings\User Name\Desktop\Junk\_XP Changer\Temporary Internet Files\Content.IE5\5STYUYRS\      SUCCESS            
59714      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: Open  Access: All      
59715      7:26:47 PM      cmd.exe:2544      READ       E:\DOCUME~1\User Name~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Offset: 62 Length: 8192      
59716      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
59717      7:26:47 PM      cmd.exe:2544      OPEN      E:\      SUCCESS      Options: Open Directory  Access: All      
59718      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\      SUCCESS      FileNameInformation      
59719      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\      SUCCESS      FileFsAttributeInformation      
59720      7:26:47 PM      cmd.exe:2544      CLOSE      E:\      SUCCESS            
59721      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Attributes: A      
59722      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\Temp      SUCCESS      Attributes: D      
59723      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Attributes: A      
59724      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      SUCCESS      Options: Open Directory  Access: All      
59725      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      SUCCESS      FileBothDirectoryInformation: hmkc.bat      
59726      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      Options: Open  Access: All      
59727      7:26:47 PM      cmd.exe:2544      QUERY INFORMATION      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS      FileObjectIdInformation      
59728      7:26:47 PM      cmd.exe:2544      DELETE       E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
59729      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      SUCCESS            
59730      7:26:47 PM      cmd.exe:2544      DIRECTORY      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      NO MORE FILES      FileBothDirectoryInformation      
59731      7:26:47 PM      cmd.exe:2544      CLOSE      E:\DOCUME~1\USER~1\LOCALS~1\Temp\      SUCCESS            
59732      7:26:47 PM      cmd.exe:2544      OPEN      E:\DOCUME~1\USER~1\LOCALS~1\Temp\hmkc.bat      FILE NOT FOUND      Options: Open  Access: All      
59733      7:26:47 PM      csrss.exe:480      OPEN      E:\WINDOWS\FONTS\VGAOEM.FON      SUCCESS      Options: Open  Access: All      
59734      7:26:47 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\FONTS\VGAOEM.FON      SUCCESS      Length: 5168      
59735      7:26:47 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\FONTS\VGAOEM.FON      SUCCESS      Attributes: H      
59736      7:26:47 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\FONTS\VGAOEM.FON      SUCCESS      FileFsAttributeInformation      
59737      7:26:47 PM      csrss.exe:480      QUERY INFORMATION      E:\WINDOWS\FONTS\VGAOEM.FON      SUCCESS      Length: 5168      
59738      7:26:47 PM      csrss.exe:480      CLOSE      E:\WINDOWS\FONTS\VGAOEM.FON      SUCCESS            
59739      7:26:47 PM      csrss.exe:480      READ       E:\WINDOWS\FONTS\VGAOEM.FON      SUCCESS      Offset: 0 Length: 8192      
59740      7:26:47 PM      cmd.exe:2544      CLOSE      E:\Documents and Settings\User Name\Desktop      SUCCESS            
59741      7:26:47 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS      Attributes: A      
59742      7:26:47 PM      explorer.exe:3188      OPEN      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS      Options: Open  Access: Execute      
59743      7:26:47 PM      explorer.exe:3188      QUERY INFORMATION      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS      Length: 194810      
59744      7:26:47 PM      explorer.exe:3188      CLOSE      E:\Program Files\Magic Notes\Sticky32.exe      SUCCESS      



As you can see access[1].exe is generated somehow,
then cmd.exe which keeps reappearing, deletes this, there is no spyware, antivirus tool that removes this...
and i can't seem to be able to go to safe mode
help please! guys!
I tried everything. It seems to be affecting everything on my pc...
here is a filesystem log....
Take it to a local shop and let them fix it.
screw it. backup you email, your documents, wipe the system and reinstall
yeah i'll do that then...
darn!

thanks blue zee,
that didn't work either... i'll wait and see if there are any more answers, I'm waiting to finish a few projects, then i'm formating the hard-disk.
thanks tho
ding!
Do not open your IE.

Right Click it, manually change your homepage to what you want.

Then delete ALL your Temporary Internet Files (not just using the button) but going into the folder itself and delete everything out.
Hey dinglydo, was on google and I came across the forum.

The exact same thing has taken over my internet explorer. The reason norton doesn't detect it at first is because the access[1].exe puts fake definitions to hide it. At least I think so because it showed up in Filemon tampering with norton definition files. Pest Patrol, ad aware, spybot-search and destroy, cwshredder.... none of these detect anything to do with this problem. I've been battling with this for a couple days now and the closest I got to ridding of it was today, when I came across a remove.exe hosted by the same site that made the spyware(master-search.com). I was obviously a bit suspicious of it but it was worth a shot. I set a restore point, and loaded up filemon before I ran it to see what it was actually doing. I still have the log of this for those who want to see it. It basicly went around gathering information (internet history, dialup accounts etc...) and then attempted to send it back to master-search.com which I stopped. then it said "successfuly removed"
and to my suprise the homepage was set back to msn.com. This was short lived as I came back several hours later only to find that start.chm and start.html were back in action. I hope there is a fix for it soon, reformatting is sounding better and better.
Hey Mephitic,
how do we get the word out, we really need help...
To the person who developed this irritant.... i'm having violent thoughts.... Who the F*&#@ do the think they are trying to attract?

So how did u stop it from sending to master-search.com?
now my windows picture and fax viewer isn't working
my administrator account has disappeared...
formating is what i got at the moment, but oh my goodness, lots of documents, lots to backup,

I think its affected the index.dat for internet explorer... we could delete that going into safe boot, but that doesn't seem to work anymore...
Your admin account disappeared? wow that didn't happen to me.
the remove.exe popped up on my firewall and I said block.

I can see why nothing detects this, it uses legit system.dll's to do its bidding. the only thing I could see that could be detectable is the access[1].exe and some .bats in makes. but they just delete themselves anyway, need to figure out where those are getting generated.
I had same problem and got rid of it with this link. I was desperate and i ran the little remove.exe program and it worked. Know I can't offcourse guarantee that nothing else is on the pc after this. I scanned the program using every spyware, ad-aware and trojan remover I had and they came up with no infections in it. I ran the program and so far 3days and nothing so check it out

Chatting

http://www.master-search.com/ 
Sry

Didn't see that it was already posted. Anyway, seems to work for me though. Might just be lucky or they might start again I see.
Be careful with that remove.exe, its up to no good. Im waiting for a legit remove.exe
i used remove.exe, for temporary relief... i prevented it from sending anything to the internet
but now i guess its back in full force...
i send the info to symantec... no response yet...
Maybe the remove.exe only removes itself if you let it send all that info back to master search.
I'm definately not gonna test that theory ;)

"Having problems?
Please use this utility for the removal

Please wait up to 2 hours for the removal process to complete.
"

2hours is probably how long it takes for a really slow dialup to send all that info back to them?
symantec or someone should disect the remove.exe and make one that just removes the master search stuff.
formatted drive,
everything fine so far!
hmm... where was i... oh office xp... well, thanks guys
take care!
ding! (george)
Hey guys
This remove.exe still seems to have done the trick on my pc. I forgot to say that the with the tip I got, I was told to remove 2 files in C:\WINDOWS : start.chm and start.html.

I'll let you know later wether I'm still good or everythings gone wrong
...one more thing in case anyone's interested.   I've seen this problem and a program called StartPageguard prevented the startpage from changing.
http://www.webattack.com/get/startpageguard.shtml

However, it didn't solve the underlying problem.  Something kept trying to change the start page and this just stopped it.

The path that these experts were originally on (spyware) is what ultimately solved the problem.
Many times ActiveX scripts can cause the internet explorer settings to change.
Can you try disabling all Active X and other scripts within your IE settings ?

You can even set the "security" to High in your Internet Explorer properties for now.
I don't think your problem is coming from a "normal" file or registry setting at this point considering all that you have already done.

Further, I would like to know what items you have listed in:
C:\WINDOWS\Downloaded Program Files

This is where any downloaded active x plug-ins go.

Most people pay lots of attention to "real exe's" and such, but we all forget that Internet Explorer has full access to our cpu with various scripting technologies, activex being the biggest !

hope this helps,
haresh
I had the same problem with a page named motor-search.com.  I pinged their IP address several times to see if something was there.  Then wrote them an emphatic email... admin seemed to work for that domain.  The response I got was that there was a link at the bottom of the page that would remove the offending material.  It was far enough down that most of would not have seen it and it sort of keeps them from prosecution.  You might just want to scroll down the page if you see something like this.

I looked at the source which appeared to be benign and it appeared to do the job.  This was several days ago and I have not seen their nonsense since.  However I am keeping copies of my notes for reference if I have to deal with them later.  

richmondeagle
I was aware of the active x scripts, and deleted all my e:\windows\downloaded files... i guess it wasn't any of that... I went into dos using NTFS commander and deleted the internet explorer program file and most folders in documents and settings... well... i think master-search should be procecuted... big time.
anyway.
these i'm loaded with antispyware software like ad-ware and mcafee stinger.
i think cwshreader ain't so powerful as it used to be...
ASKER CERTIFIED SOLUTION
Avatar of zigg2k
zigg2k

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial