heh, now here's another question. How can prodecutors get the info needed to get the evidence needed to know it was not a trojan? Like you said, that would be tough, but can data recovery tools see if the skiddot tools were there, or is that really circumstantial evidence than direct?