HKU\.DEFAULT\Control Panel\International 12/02/2008 22:23 0 bytes Security mismatch. HKU\.DEFAULT\Control Panel\International\Geo 12/02/2008 22:23 0 bytes Security mismatch. HKU\S-1-5-21-1202660629-1177238915-682003330-1003\Control Panel\International 12/02/2008 22:23 0 bytes Security mismatch. HKU\S-1-5-21-1202660629-1177238915-682003330-1003\Control Panel\International\Geo 12/02/2008 22:23 0 bytes Security mismatch. HKU\S-1-5-21-1202660629-1177238915-682003330-1003\Software\Licenses\{I81A067BDE7DB239C} 12/02/2008 22:59 4 bytes Data mismatch between Windows API and raw hive data. HKU\S-1-5-21-1202660629-1177238915-682003330-1003\Software\Licenses\{081A067BDE7DB239C} 12/02/2008 22:59 183 bytes Data mismatch between Windows API and raw hive data. HKU\S-1-5-18\Control Panel\International 12/02/2008 22:23 0 bytes Security mismatch. HKU\S-1-5-18\Control Panel\International\Geo 12/02/2008 22:23 0 bytes Security mismatch. HKLM\SECURITY\Policy\Secrets\SAC* 28/12/2004 17:23 0 bytes Key name contains embedded nulls (*) HKLM\SECURITY\Policy\Secrets\SAI* 28/12/2004 17:23 0 bytes Key name contains embedded nulls (*) HKLM\SOFTWARE\Classes\CLSID\{B613A1DB-61DB-8B80-755F-654BCE7866BB}\dnddycku\ 12/02/2008 22:59 52 bytes Data mismatch between Windows API and raw hive data. HKLM\SOFTWARE\Classes\CLSID\{B613A1DB-61DB-8B80-755F-654BCE7866BB}\lvwbjbuQhwIPb\ 12/02/2008 22:59 32 bytes Data mismatch between Windows API and raw hive data. HKLM\SOFTWARE\Classes\webcal\URL Protocol 13/11/2007 14:43 13 bytes Data mismatch between Windows API and raw hive data. C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-01-30_Log.ALUSchedulerSvc.LiveUpdate 30/01/2008 22:35 10.68 KB Visible in Windows API, but not in MFT or directory index. C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-02-13_Log.ALUSchedulerSvc.LiveUpdate 13/02/2008 00:06 1.08 KB Hidden from Windows API. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\1F8HLXQX 12/02/2008 23:13 0 bytes Hidden from Windows API. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\1F8HLXQX\desktop.ini 12/02/2008 23:13 67 bytes Hidden from Windows API. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\1F8HLXQX\rss[1].xml 12/02/2008 23:13 17.29 KB Hidden from Windows API. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\65MHGJ8F\tinyAddFileButton[1].png 12/02/2008 23:32 480 bytes Hidden from Windows API. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\B2HOONJH\progressBarValue[1].png 12/02/2008 23:34 142 bytes Hidden from Windows API. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\BFCLO4M9\fileUploadProgress[1].htm 12/02/2008 23:34 1.00 KB Hidden from Windows API. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\COXMYQ7R\progressBarBG[1].png 12/02/2008 23:34 142 bytes Hidden from Windows API. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\EBC52HOL\fileUploadFrame[1].htm 12/02/2008 23:34 1.86 KB Hidden from Windows API. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\GXA7WL2N\tinyRemoveFileButton[1].png 12/02/2008 23:33 493 bytes Hidden from Windows API. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OLU7KX6R\fileUploadLanding[1].htm 12/02/2008 23:34 194 bytes Hidden from Windows API. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OXMP4VJA\fileUploadLanding[1].htm 12/02/2008 23:33 189 bytes Hidden from Windows API. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OXMP4VJA\fileUploadProgress[1].htm 12/02/2008 23:33 1.00 KB Hidden from Windows API.