This is my 2nd thread the first Blade helped me out alot on, the link to my previous post is here
http://www.bleepingcomputer.com/forums/ind...p;#entry1403721
i will post my RootRepeal first then my Win32k log
ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/08/28 18:00 Program Version: Version 1.3.5.0 Windows Version: Windows XP Media Center Edition SP3 ================================================== Drivers ------------------- Name: ACPI.sys Image Path: ACPI.sys Address: 0xF733D000 Size: 187776 File Visible: - Signed: - Status: - Name: ACPI_HAL Image Path: \Driver\ACPI_HAL Address: 0x804D7000 Size: 2260992 File Visible: - Signed: - Status: - Name: afd.sys Image Path: C:\WINDOWS\System32\drivers\afd.sys Address: 0xF6E28000 Size: 138496 File Visible: - Signed: - Status: - Name: aswTdi.SYS Image Path: C:\WINDOWS\System32\Drivers\aswTdi.SYS Address: 0xF75A4000 Size: 41664 File Visible: - Signed: - Status: - Name: atapi.sys Image Path: atapi.sys Address: 0xF72CF000 Size: 98304 File Visible: - Signed: - Status: - Name: atapi.sys Image Path: atapi.sys Address: 0x00000000 Size: 0 File Visible: - Signed: - Status: - Name: ATMFD.DLL Image Path: C:\WINDOWS\System32\ATMFD.DLL Address: 0xBFFA0000 Size: 286720 File Visible: - Signed: - Status: - Name: BOOTVID.dll Image Path: C:\WINDOWS\system32\BOOTVID.dll Address: 0xF78B4000 Size: 12288 File Visible: - Signed: - Status: - Name: Cdfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Cdfs.SYS Address: 0xF75F4000 Size: 63744 File Visible: - Signed: - Status: - Name: cdrom.sys Image Path: C:\WINDOWS\system32\DRIVERS\cdrom.sys Address: 0xF7504000 Size: 62976 File Visible: - Signed: - Status: - Name: CLASSPNP.SYS Image Path: C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS Address: 0xF74E4000 Size: 53248 File Visible: - Signed: - Status: - Name: disk.sys Image Path: disk.sys Address: 0xF74D4000 Size: 36352 File Visible: - Signed: - Status: - Name: DLACDBHM.SYS Image Path: C:\WINDOWS\System32\Drivers\DLACDBHM.SYS Address: 0xF79AC000 Size: 5568 File Visible: - Signed: - Status: - Name: DLARTL_N.SYS Image Path: C:\WINDOWS\System32\Drivers\DLARTL_N.SYS Address: 0xF7814000 Size: 22624 File Visible: - Signed: - Status: - Name: dmio.sys Image Path: dmio.sys Address: 0xF72E7000 Size: 153344 File Visible: - Signed: - Status: - Name: dmload.sys Image Path: dmload.sys Address: 0xF79A8000 Size: 5888 File Visible: - Signed: - Status: - Name: DRVMCDB.SYS Image Path: DRVMCDB.SYS Address: 0xF7287000 Size: 87104 File Visible: - Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xF6CAD000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF79D8000 Size: 8192 File Visible: No Signed: - Status: - Name: Dxapi.sys Image Path: C:\WINDOWS\System32\drivers\Dxapi.sys Address: 0xF6ED3000 Size: 12288 File Visible: - Signed: - Status: - Name: dxg.sys Image Path: C:\WINDOWS\System32\drivers\dxg.sys Address: 0xBF000000 Size: 73728 File Visible: - Signed: - Status: - Name: dxgthk.sys Image Path: C:\WINDOWS\System32\drivers\dxgthk.sys Address: 0xF7B60000 Size: 4096 File Visible: - Signed: - Status: - Name: e100b325.sys Image Path: C:\WINDOWS\system32\DRIVERS\e100b325.sys Address: 0xF70D1000 Size: 155648 File Visible: - Signed: - Status: - Name: fltmgr.sys Image Path: fltmgr.sys Address: 0xF72AF000 Size: 129792 File Visible: - Signed: - Status: - Name: framebuf.dll Image Path: C:\WINDOWS\System32\framebuf.dll Address: 0xBFF50000 Size: 12288 File Visible: - Signed: - Status: - Name: Fs_Rec.SYS Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS Address: 0xF79BE000 Size: 7936 File Visible: - Signed: - Status: - Name: FStarForce.sys Image Path: C:\WINDOWS\system32\DRIVERS\FStarForce.sys Address: 0xF77EC000 Size: 28672 File Visible: - Signed: - Status: - Name: ftdisk.sys Image Path: ftdisk.sys Address: 0xF730D000 Size: 125056 File Visible: - Signed: - Status: - Name: GEARAspiWDM.sys Image Path: C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys Address: 0xF7944000 Size: 9984 File Visible: - Signed: - Status: - Name: hal.dll Image Path: C:\WINDOWS\system32\hal.dll Address: 0x806FF000 Size: 134400 File Visible: - Signed: - Status: - Name: HDAudBus.sys Image Path: C:\WINDOWS\system32\DRIVERS\HDAudBus.sys Address: 0xF711B000 Size: 163840 File Visible: - Signed: - Status: - Name: HIDCLASS.SYS Image Path: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS Address: 0xF75E4000 Size: 36864 File Visible: - Signed: - Status: - Name: HIDPARSE.SYS Image Path: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS Address: 0xF7894000 Size: 28672 File Visible: - Signed: - Status: - Name: hidusb.sys Image Path: C:\WINDOWS\system32\DRIVERS\hidusb.sys Address: 0xF6FB4000 Size: 10368 File Visible: - Signed: - Status: - Name: i2omgmt.SYS Image Path: C:\WINDOWS\System32\Drivers\i2omgmt.SYS Address: 0xF7153000 Size: 8576 File Visible: - Signed: - Status: - Name: imapi.sys Image Path: C:\WINDOWS\system32\DRIVERS\imapi.sys Address: 0xF7524000 Size: 42112 File Visible: - Signed: - Status: - Name: ipfltdrv.sys Image Path: C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys Address: 0xF75B4000 Size: 32896 File Visible: - Signed: - Status: - Name: ipnat.sys Image Path: C:\WINDOWS\system32\DRIVERS\ipnat.sys Address: 0xF6E99000 Size: 152832 File Visible: - Signed: - Status: - Name: ipsec.sys Image Path: C:\WINDOWS\system32\DRIVERS\ipsec.sys Address: 0xF6F40000 Size: 75264 File Visible: - Signed: - Status: - Name: isapnp.sys Image Path: isapnp.sys Address: 0xF74A4000 Size: 37248 File Visible: - Signed: - Status: - Name: kbdclass.sys Image Path: C:\WINDOWS\system32\DRIVERS\kbdclass.sys Address: 0xF77D4000 Size: 24576 File Visible: - Signed: - Status: - Name: kbdhid.sys Image Path: C:\WINDOWS\system32\DRIVERS\kbdhid.sys Address: 0xF6FAC000 Size: 14592 File Visible: - Signed: - Status: - Name: KDCOM.DLL Image Path: C:\WINDOWS\system32\KDCOM.DLL Address: 0xF79A4000 Size: 8192 File Visible: - Signed: - Status: - Name: ks.sys Image Path: C:\WINDOWS\system32\DRIVERS\ks.sys Address: 0xF70AE000 Size: 143360 File Visible: - Signed: - Status: - Name: KSecDD.sys Image Path: KSecDD.sys Address: 0xF7270000 Size: 92288 File Visible: - Signed: - Status: - Name: mouclass.sys Image Path: C:\WINDOWS\system32\DRIVERS\mouclass.sys Address: 0xF77DC000 Size: 23040 File Visible: - Signed: - Status: - Name: mouhid.sys Image Path: C:\WINDOWS\system32\DRIVERS\mouhid.sys Address: 0xF715F000 Size: 12160 File Visible: - Signed: - Status: - Name: MountMgr.sys Image Path: MountMgr.sys Address: 0xF74B4000 Size: 42368 File Visible: - Signed: - Status: - Name: Mpfp.sys Image Path: C:\WINDOWS\System32\Drivers\Mpfp.sys Address: 0xF6E72000 Size: 159744 File Visible: - Signed: - Status: - Name: mrxsmb.sys Image Path: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys Address: 0xF6D8D000 Size: 455296 File Visible: - Signed: - Status: - Name: Msfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Msfs.SYS Address: 0xF782C000 Size: 19072 File Visible: - Signed: - Status: - Name: msgpc.sys Image Path: C:\WINDOWS\system32\DRIVERS\msgpc.sys Address: 0xF7564000 Size: 35072 File Visible: - Signed: - Status: - Name: mssmbios.sys Image Path: C:\WINDOWS\system32\DRIVERS\mssmbios.sys Address: 0xF797C000 Size: 15488 File Visible: - Signed: - Status: - Name: Mup.sys Image Path: Mup.sys Address: 0xF719C000 Size: 105344 File Visible: - Signed: - Status: - Name: NDIS.sys Image Path: NDIS.sys Address: 0xF71B6000 Size: 182656 File Visible: - Signed: - Status: - Name: ndistapi.sys Image Path: C:\WINDOWS\system32\DRIVERS\ndistapi.sys Address: 0xF7958000 Size: 10112 File Visible: - Signed: - Status: - Name: ndisuio.sys Image Path: C:\WINDOWS\system32\DRIVERS\ndisuio.sys Address: 0xF6779000 Size: 14592 File Visible: - Signed: - Status: - Name: ndiswan.sys Image Path: C:\WINDOWS\system32\DRIVERS\ndiswan.sys Address: 0xF7097000 Size: 91520 File Visible: - Signed: - Status: - Name: NDProxy.SYS Image Path: C:\WINDOWS\System32\Drivers\NDProxy.SYS Address: 0xF7584000 Size: 40576 File Visible: - Signed: - Status: - Name: netbios.sys Image Path: C:\WINDOWS\system32\DRIVERS\netbios.sys Address: 0xF75C4000 Size: 34688 File Visible: - Signed: - Status: - Name: netbt.sys Image Path: C:\WINDOWS\system32\DRIVERS\netbt.sys Address: 0xF6E4A000 Size: 162816 File Visible: - Signed: - Status: - Name: Npfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Npfs.SYS Address: 0xF783C000 Size: 30848 File Visible: - Signed: - Status: - Name: Ntfs.sys Image Path: Ntfs.sys Address: 0xF71E3000 Size: 574976 File Visible: - Signed: - Status: - Name: ntoskrnl.exe Image Path: C:\WINDOWS\system32\ntoskrnl.exe Address: 0x804D7000 Size: 2260992 File Visible: - Signed: - Status: - Name: Null.SYS Image Path: C:\WINDOWS\System32\Drivers\Null.SYS Address: 0xF7BB6000 Size: 2944 File Visible: - Signed: - Status: - Name: PartMgr.sys Image Path: PartMgr.sys Address: 0xF772C000 Size: 19712 File Visible: - Signed: - Status: - Name: pci.sys Image Path: pci.sys Address: 0xF732C000 Size: 68224 File Visible: - Signed: - Status: - Name: PCI_PNP3994 Image Path: \Driver\PCI_PNP3994 Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: pciide.sys Image Path: pciide.sys Address: 0xF7A6C000 Size: 3328 File Visible: - Signed: - Status: - Name: PCIIDEX.SYS Image Path: C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS Address: 0xF7724000 Size: 28672 File Visible: - Signed: - Status: - Name: PnpManager Image Path: \Driver\PnpManager Address: 0x804D7000 Size: 2260992 File Visible: - Signed: - Status: - Name: psched.sys Image Path: C:\WINDOWS\system32\DRIVERS\psched.sys Address: 0xF7086000 Size: 69120 File Visible: - Signed: - Status: - Name: ptilink.sys Image Path: C:\WINDOWS\system32\DRIVERS\ptilink.sys Address: 0xF77AC000 Size: 17792 File Visible: - Signed: - Status: - Name: PxHelp20.sys Image Path: PxHelp20.sys Address: 0xF7734000 Size: 20000 File Visible: - Signed: - Status: - Name: rasacd.sys Image Path: C:\WINDOWS\system32\DRIVERS\rasacd.sys Address: 0xF7143000 Size: 8832 File Visible: - Signed: - Status: - Name: rasl2tp.sys Image Path: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys Address: 0xF7534000 Size: 51328 File Visible: - Signed: - Status: - Name: raspppoe.sys Image Path: C:\WINDOWS\system32\DRIVERS\raspppoe.sys Address: 0xF7544000 Size: 41472 File Visible: - Signed: - Status: - Name: raspptp.sys Image Path: C:\WINDOWS\system32\DRIVERS\raspptp.sys Address: 0xF7554000 Size: 48384 File Visible: - Signed: - Status: - Name: raspti.sys Image Path: C:\WINDOWS\system32\DRIVERS\raspti.sys Address: 0xF77BC000 Size: 16512 File Visible: - Signed: - Status: - Name: RAW Image Path: \FileSystem\RAW Address: 0x804D7000 Size: 2260992 File Visible: - Signed: - Status: - Name: rdbss.sys Image Path: C:\WINDOWS\system32\DRIVERS\rdbss.sys Address: 0xF6DFD000 Size: 175744 File Visible: - Signed: - Status: - Name: RDPCDD.sys Image Path: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys Address: 0xF79C2000 Size: 4224 File Visible: - Signed: - Status: - Name: rdpdr.sys Image Path: C:\WINDOWS\system32\DRIVERS\rdpdr.sys Address: 0xF702E000 Size: 196224 File Visible: - Signed: - Status: - Name: redbook.sys Image Path: C:\WINDOWS\system32\DRIVERS\redbook.sys Address: 0xF7514000 Size: 57600 File Visible: - Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xF640B000 Size: 49152 File Visible: No Signed: - Status: - Name: SCSIPORT.SYS Image Path: C:\WINDOWS\System32\Drivers\SCSIPORT.SYS Address: 0xF736B000 Size: 98304 File Visible: - Signed: - Status: - Name: spih.sys Image Path: spih.sys Address: 0xF7383000 Size: 1048576 File Visible: No Signed: - Status: - Name: sptd Image Path: \Driver\sptd Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: sr.sys Image Path: sr.sys Address: 0xF729D000 Size: 73472 File Visible: - Signed: - Status: - Name: srv.sys Image Path: C:\WINDOWS\system32\DRIVERS\srv.sys Address: 0xF658B000 Size: 333824 File Visible: - Signed: - Status: - Name: swenum.sys Image Path: C:\WINDOWS\system32\DRIVERS\swenum.sys Address: 0xF79B2000 Size: 4352 File Visible: - Signed: - Status: - Name: tcpip.sys Image Path: C:\WINDOWS\system32\DRIVERS\tcpip.sys Address: 0xF6EE7000 Size: 361600 File Visible: - Signed: - Status: - Name: TDI.SYS Image Path: C:\WINDOWS\system32\DRIVERS\TDI.SYS Address: 0xF779C000 Size: 20480 File Visible: - Signed: - Status: - Name: termdd.sys Image Path: C:\WINDOWS\system32\DRIVERS\termdd.sys Address: 0xF7574000 Size: 40704 File Visible: - Signed: - Status: - Name: update.sys Image Path: C:\WINDOWS\system32\DRIVERS\update.sys Address: 0xF6FD0000 Size: 384768 File Visible: - Signed: - Status: - Name: usbccgp.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbccgp.sys Address: 0xF7874000 Size: 32128 File Visible: - Signed: - Status: - Name: USBD.SYS Image Path: C:\WINDOWS\system32\DRIVERS\USBD.SYS Address: 0xF79BA000 Size: 8192 File Visible: - Signed: - Status: - Name: usbehci.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbehci.sys Address: 0xF7774000 Size: 30208 File Visible: - Signed: - Status: - Name: usbhub.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbhub.sys Address: 0xF7594000 Size: 59520 File Visible: - Signed: - Status: - Name: USBPORT.SYS Image Path: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS Address: 0xF70F7000 Size: 147456 File Visible: - Signed: - Status: - Name: usbprint.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbprint.sys Address: 0xF7884000 Size: 25856 File Visible: - Signed: - Status: - Name: usbuhci.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbuhci.sys Address: 0xF776C000 Size: 20608 File Visible: - Signed: - Status: - Name: vga.sys Image Path: C:\WINDOWS\System32\drivers\vga.sys Address: 0xF781C000 Size: 20992 File Visible: - Signed: - Status: - Name: VIDEOPRT.SYS Image Path: C:\WINDOWS\System32\drivers\VIDEOPRT.SYS Address: 0xF6F94000 Size: 81920 File Visible: - Signed: - Status: - Name: VolSnap.sys Image Path: VolSnap.sys Address: 0xF74C4000 Size: 52352 File Visible: - Signed: - Status: - Name: wanatw4.sys Image Path: C:\WINDOWS\system32\DRIVERS\wanatw4.sys Address: 0xF77C4000 Size: 20512 File Visible: - Signed: - Status: - Name: watchdog.sys Image Path: C:\WINDOWS\System32\watchdog.sys Address: 0xF7744000 Size: 20480 File Visible: - Signed: - Status: - Name: Win32k Image Path: \Driver\Win32k Address: 0xBF800000 Size: 1847296 File Visible: - Signed: - Status: - Name: win32k.sys Image Path: C:\WINDOWS\System32\win32k.sys Address: 0xBF800000 Size: 1847296 File Visible: - Signed: - Status: - Name: win32k.sys:1 Image Path: C:\WINDOWS\win32k.sys:1 Address: 0xF789C000 Size: 20480 File Visible: No Signed: - Status: - Name: win32k.sys:2 Image Path: C:\WINDOWS\win32k.sys:2 Address: 0xF6D25000 Size: 61440 File Visible: No Signed: - Status: - Name: WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\WMILIB.SYS Address: 0xF79A6000 Size: 8192 File Visible: - Signed: - Status: - Name: WMIxWDM Image Path: \Driver\WMIxWDM Address: 0x804D7000 Size: 2260992 File Visible: - Signed: - Status: - Name: ws2ifsl.sys Image Path: C:\WINDOWS\System32\drivers\ws2ifsl.sys Address: 0xF7082000 Size: 12032 File Visible: - Signed: - Status: -
*************************************************
Log file is located at: C:\Documents and Settings\Heidi Diaz\Desktop\Win32kDiag.txt
WARNING: Could not get backup privileges!
Searching 'C:\WINDOWS'...
Found mount point : C:\WINDOWS\$hf_mig$\KB904706\KB904706
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB916281\KB916281
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB918899\KB918899
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB920213\KB920213
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB922760\KB922760
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB924496\KB924496
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB925454\KB925454
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB929338\KB929338
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB931784\KB931784
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB932168\KB932168
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB933729\KB933729
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB941568\KB941568
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB943460\KB943460
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\aolshare\aolshare
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP94D.tmp\ZAP94D.tmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9C2.tmp\ZAP9C2.tmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA7.tmp\ZAPA7.tmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\temp\temp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\tmp\tmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Config\Config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Connection Wizard\Connection Wizard
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d1\d1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d2\d2
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d3\d3
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d4\d4
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d5\d5
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d6\d6
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d7\d7
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d8\d8
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\chsime\applets\applets
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\CHTIME\Applets\Applets
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\imejp\applets\applets
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\imejp98\imejp98
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\imjp8_1\applets\applets
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\imkr6_1\applets\applets
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\imkr6_1\dicts\dicts
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\shared\res\res
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\17400AB28230347339DBAF1833357A38\3.1.21022\3.1.21022
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\1F3B805BA42A0C233B0158879691FE82\2.1.21022\2.1.21022
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\java\classes\classes
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\java\trustlib\trustlib
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Temporary ASP.NET Files\Bind Logs\Bind Logs
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\msapps\msinfo\msinfo
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\msdownld.tmp\msdownld.tmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\occache\occache
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\ERRORREP\UserDumps\UserDumps
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\helpctr\batch\batch
Mount point destination : \Device\__max++>\^
Cannot access: C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe
[1] 2004-08-10 05:00:00 743936 C:\WINDOWS\$NtServicePackUninstall$\helpsvc.exe (Microsoft Corporation)
[1] 2008-04-13 20:12:21 744448 C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe ()
[1] 2008-04-13 20:12:21 744448 C:\WINDOWS\ServicePackFiles\i386\helpsvc.exe (Microsoft Corporation)
[1] 2008-04-13 20:12:21 744448 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\helpsvc.exe (Microsoft Corporation)
Found mount point : C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\helpctr\System\DFS\DFS
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\helpctr\Temp\Temp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\PIF\PIF
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Registration\CRMLog\CRMLog
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\AuthCabs
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\1201b6f74bae1015eceeea43baed9814\backup\backup
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\355f788b6de8a3ec79e9aa172e6317f1\backup\backup
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\10\policy\policy
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\51\msft\msft
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\51\policy\msft\msft
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\msft\msft
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\policy\msft\msft
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\60\msft\msft
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\70\70
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\root\root
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\Registered
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SxsCaPendDel\SxsCaPendDel
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1025\1025
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1028\1028
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1031\1031
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1037\1037
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1041\1041
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1042\1042
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1054\1054
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\2052\2052
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\3076\3076
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\3com_dmi\3com_dmi
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Adobe\update\update
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\appmgmt\MACHINE\MACHINE
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\appmgmt\S-1-5-21-703702550-2982333712-3504602965-1006\S-1-5-21-703702550-2982333712-3504602965-1006
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Identities\{4E3254D7-522A-412A-9296-3F4767B3A2CB}\{4E3254D7-522A-412A-9296-3F4767B3A2CB}
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Identities\{F1C15684-ECB6-4FBC-ACB7-3C90046CAE64}\{F1C15684-ECB6-4FBC-ACB7-3C90046CAE64}
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\S-1-5-21-343818398-1004336348-839522115-500\S-1-5-21-343818398-1004336348-839522115-500
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\S-1-5-21-703702550-2982333712-3504602965-500\S-1-5-21-703702550-2982333712-3504602965-500
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Media Player\Media Player
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\MMC\MMC
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\Certificates\Certificates
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CRLs\CRLs
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CTLs\CTLs
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Sun\Java\Deployment\javaws\cache\cache
Mount point destination : \Device\__max++>\^
Cannot access: C:\WINDOWS\system32\config\systemprofile\Application Data\twain_32\user.ds
[1] 2009-08-28 18:46:29 912 C:\WINDOWS\system32\config\systemprofile\Application Data\twain_32\user.ds ()
[1] 2009-08-26 12:16:41 0 C:\WINDOWS\system32\lowsec\user.ds ()
[1] 2009-08-28 17:11:18 0 C:\WINDOWS\system32\twain_32\user.ds ()
Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\BVRP Software\NetWaiting\NetWaiting
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\CD Burning\CD Burning
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\S-1-5-21-343818398-1004336348-839522115-500\S-1-5-21-343818398-1004336348-839522115-500
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\S-1-5-21-703702550-2982333712-3504602965-500\S-1-5-21-703702550-2982333712-3504602965-500
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\OFFICE\OFFICE
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Musicmatch\Jukebox\Cache\Cache
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\temp\temp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\NetHood\NetHood
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\PrintHood\PrintHood
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\dhcp\dhcp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\drivers\disdn\disdn
Mount point destination : \Device\__max++>\^
Cannot access: C:\WINDOWS\system32\dumprep.exe
[1] 2004-08-10 05:00:00 10752 C:\WINDOWS\$NtServicePackUninstall$\dumprep.exe (Microsoft Corporation)
[1] 2008-04-13 20:12:18 10752 C:\WINDOWS\ServicePackFiles\i386\dumprep.exe (Microsoft Corporation)
[1] 2008-04-13 20:12:18 10752 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\dumprep.exe (Microsoft Corporation)
[1] 2008-04-13 20:12:18 10752 C:\WINDOWS\system32\dumprep.exe ()
[1] 2004-08-10 05:00:00 10752 C:\i386\dumprep.exe (Microsoft Corporation)
Cannot access: C:\WINDOWS\system32\eventlog.dll
[1] 2004-08-10 05:00:00 55808 C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll (Microsoft Corporation)
[1] 2008-04-13 20:11:53 56320 C:\WINDOWS\ServicePackFiles\i386\eventlog.dll (Microsoft Corporation)
[1] 2008-04-13 20:11:53 56320 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll (Microsoft Corporation)
[1] 2008-04-13 20:11:53 62464 C:\WINDOWS\system32\eventlog.dll ()
[2] 2008-04-13 20:11:53 56320 C:\WINDOWS\system32\logevent.dll (Microsoft Corporation)
[1] 2004-08-10 05:00:00 55808 C:\i386\eventlog.dll (Microsoft Corporation)
Found mount point : C:\WINDOWS\system32\export\export
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\FxsTmp\FxsTmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\IME\CINTLGNT\CINTLGNT
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\IME\PINTLGNT\PINTLGNT
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\IME\TINTLGNT\TINTLGNT
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\LogFiles\LogFiles
Mount point destination : \Device\__max++>\^
Cannot access: C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx
[1] 2009-02-02 22:07:18 3866528 C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx ()
Cannot access: C:\WINDOWS\system32\Macromed\Flash\FlashUtil10b.exe
[1] 2009-02-02 22:07:18 240544 C:\WINDOWS\system32\Macromed\Flash\FlashUtil10b.exe ()
Found mount point : C:\WINDOWS\system32\Macromed\Shockwave 10\Xtras\Xtras
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Macromed\update\update
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Microsoft\Crypto\RSA\MachineKeys\MachineKeys
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\mui\dispspec\dispspec
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\html\oemcust\oemcust
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\html\oemhw\oemhw
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\html\oemreg\oemreg
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\sample\sample
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\ShellExt\ShellExt
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\spool\PRINTERS\PRINTERS
Mount point destination : \Device\__max++>\^
Cannot access: C:\WINDOWS\system32\wbem\Logs\FrameWork.log
[1] 2009-08-28 16:56:07 257 C:\WINDOWS\system32\wbem\Logs\FrameWork.log ()
[1] 2006-06-17 17:02:54 2366 C:\i386\FrameWork.log ()
Found mount point : C:\WINDOWS\system32\wbem\mof\bad\bad
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wbem\mof\good\good
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wbem\snmp\snmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wins\wins
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\xircom\xircom
Mount point destination : \Device\__max++>\^
Cannot access: C:\WINDOWS\Temp\Cookies\index.dat
[1] 2008-12-25 21:47:31 88983 C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat ()
[1] 2009-08-28 16:55:33 49152 C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat ()
[1] 2009-08-28 16:55:33 49152 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat ()
[1] 2009-07-08 13:26:21 32768 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009070820090709\index.dat ()
[1] 2009-07-10 08:11:31 32768 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009071020090711\index.dat ()
[1] 2009-08-25 12:18:50 32768 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009082520090826\index.dat ()
[1] 2009-08-28 16:56:23 1802240 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat ()
[1] 2009-08-28 18:46:29 16384 C:\WINDOWS\Temp\Cookies\index.dat ()
[1] 2009-08-28 18:46:29 16384 C:\WINDOWS\Temp\History\History.IE5\index.dat ()
[1] 2009-08-28 18:46:29 32768 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat ()
[1] 2006-06-11 22:06:35 16384 C:\i386\index.dat ()
Found mount point : C:\WINDOWS\Temp\Google Toolbar\Google Toolbar
Mount point destination : \Device\__max++>\^
Cannot access: C:\WINDOWS\Temp\History\History.IE5\index.dat
[1] 2008-12-25 21:47:31 88983 C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat ()
[1] 2009-08-28 16:55:33 49152 C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat ()
[1] 2009-08-28 16:55:33 49152 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat ()
[1] 2009-07-08 13:26:21 32768 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009070820090709\index.dat ()
[1] 2009-07-10 08:11:31 32768 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009071020090711\index.dat ()
[1] 2009-08-25 12:18:50 32768 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009082520090826\index.dat ()
[1] 2009-08-28 16:56:23 1802240 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat ()
[1] 2009-08-28 18:46:29 16384 C:\WINDOWS\Temp\Cookies\index.dat ()
[1] 2009-08-28 18:46:29 16384 C:\WINDOWS\Temp\History\History.IE5\index.dat ()
[1] 2009-08-28 18:46:29 32768 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat ()
[1] 2006-06-11 22:06:35 16384 C:\i386\index.dat ()
Found mount point : C:\WINDOWS\Temp\MCE00000\MCE00000
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00001\MCE00001
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00002\MCE00002
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00003\MCE00003
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00004\MCE00004
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00005\MCE00005
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00006\MCE00006
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00007\MCE00007
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00008\MCE00008
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00009\MCE00009
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0000a\MCE0000a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0000b\MCE0000b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0000c\MCE0000c
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0000d\MCE0000d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0000e\MCE0000e
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0000f\MCE0000f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00010\MCE00010
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00011\MCE00011
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00012\MCE00012
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00013\MCE00013
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00014\MCE00014
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00015\MCE00015
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00016\MCE00016
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00017\MCE00017
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00018\MCE00018
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00019\MCE00019
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0001a\MCE0001a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0001b\MCE0001b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0001c\MCE0001c
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0001d\MCE0001d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0001e\MCE0001e
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0001f\MCE0001f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00020\MCE00020
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00021\MCE00021
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00022\MCE00022
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00023\MCE00023
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00024\MCE00024
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00025\MCE00025
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00026\MCE00026
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00027\MCE00027
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00028\MCE00028
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00029\MCE00029
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0002a\MCE0002a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0002b\MCE0002b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0002c\MCE0002c
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0002d\MCE0002d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0002e\MCE0002e
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0002f\MCE0002f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00030\MCE00030
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00031\MCE00031
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00032\MCE00032
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00033\MCE00033
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00034\MCE00034
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00035\MCE00035
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00036\MCE00036
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00037\MCE00037
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00038\MCE00038
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00039\MCE00039
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0003a\MCE0003a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0003b\MCE0003b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0003c\MCE0003c
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0003d\MCE0003d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0003e\MCE0003e
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0003f\MCE0003f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00040\MCE00040
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00041\MCE00041
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00042\MCE00042
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00043\MCE00043
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00044\MCE00044
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00045\MCE00045
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00046\MCE00046
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00047\MCE00047
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00048\MCE00048
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00049\MCE00049
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0004a\MCE0004a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0004b\MCE0004b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0004c\MCE0004c
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0004d\MCE0004d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0004e\MCE0004e
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0004f\MCE0004f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00050\MCE00050
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00051\MCE00051
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00052\MCE00052
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00053\MCE00053
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00054\MCE00054
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00055\MCE00055
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00056\MCE00056
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00057\MCE00057
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00058\MCE00058
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00059\MCE00059
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0005a\MCE0005a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0005b\MCE0005b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0005c\MCE0005c
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0005d\MCE0005d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0005e\MCE0005e
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0005f\MCE0005f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00060\MCE00060
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00061\MCE00061
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00062\MCE00062
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00063\MCE00063
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00064\MCE00064
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00065\MCE00065
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00066\MCE00066
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00067\MCE00067
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00068\MCE00068
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00069\MCE00069
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0006a\MCE0006a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0006b\MCE0006b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\SEE2ECD.tmp\SEE2ECD.tmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\SEEAF.tmp\SEEAF.tmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\SiteAdvisor\SiteAdvisor
Mount point destination : \Device\__max++>\^
Cannot access: C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DRZPJX7R\desktop.ini
[1] 2005-08-16 04:39:16 227 C:\WINDOWS\assembly\Desktop.ini ()
[1] 2004-08-10 05:00:00 2 C:\WINDOWS\desktop.ini ()
[1] 2005-08-16 04:41:00 65 C:\WINDOWS\Downloaded Program Files\desktop.ini ()
[1] 2005-08-16 04:42:12 67 C:\WINDOWS\Fonts\desktop.ini ()
[1] 2005-08-16 04:41:00 65 C:\WINDOWS\Offline Web Pages\desktop.ini ()
[1] 2005-08-16 04:33:26 62 C:\WINDOWS\system32\config\systemprofile\Application Data\desktop.ini ()
[1] 2005-08-16 21:11:46 170 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini ()
[1] 2005-08-16 04:50:28 122 C:\WINDOWS\system32\config\systemprofile\Favorites\Desktop.ini ()
[1] 2006-05-10 20:47:05 62 C:\WINDOWS\system32\config\systemprofile\Local Settings\desktop.ini ()
[1] 2006-06-11 22:02:30 113 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\desktop.ini ()
[1] 2006-06-11 22:02:30 113 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\desktop.ini ()
[1] 2006-06-11 22:02:30 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\89YZO12R\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C06F4QY2\desktop.ini ()
[1] 2006-06-11 22:02:30 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\TD2N5TAF\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UTP2D7MK\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ZCEI4B1X\desktop.ini ()
[1] 2006-06-11 22:02:30 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\desktop.ini ()
[1] 2005-08-16 04:50:28 84 C:\WINDOWS\system32\config\systemprofile\My Documents\desktop.ini ()
[1] 2005-08-16 04:50:28 189 C:\WINDOWS\system32\config\systemprofile\My Documents\My Music\Desktop.ini ()
[1] 2005-08-16 04:50:28 191 C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures\Desktop.ini ()
[1] 2005-08-16 04:50:28 150 C:\WINDOWS\system32\config\systemprofile\Recent\Desktop.ini ()
[1] 2005-08-16 04:41:02 181 C:\WINDOWS\system32\config\systemprofile\SendTo\desktop.ini ()
[1] 2005-08-16 04:33:26 62 C:\WINDOWS\system32\config\systemprofile\Start Menu\desktop.ini ()
[1] 2005-08-16 04:43:08 348 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\desktop.ini ()
[1] 2005-08-16 04:50:24 542 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\desktop.ini ()
[1] 2005-08-16 04:43:10 84 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Entertainment\desktop.ini ()
[1] 2005-08-16 04:50:30 234 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\desktop.ini ()
[1] 2005-08-16 04:43:08 84 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini ()
[1] 2004-08-10 05:00:00 2 C:\WINDOWS\system32\desktop.ini ()
[1] 2004-08-10 05:00:00 65 C:\WINDOWS\Tasks\desktop.ini ()
[1] 2009-07-04 08:18:17 145 C:\WINDOWS\Temp\History\History.IE5\desktop.ini ()
[1] 2009-07-04 08:18:17 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DRZPJX7R\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IN24NM9F\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\WAG9F543\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\Y0ZZVW4L\desktop.ini ()
[1] 2005-08-16 04:33:26 62 C:\i386\desktop.ini ()
Cannot access: C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IN24NM9F\desktop.ini
[1] 2005-08-16 04:39:16 227 C:\WINDOWS\assembly\Desktop.ini ()
[1] 2004-08-10 05:00:00 2 C:\WINDOWS\desktop.ini ()
[1] 2005-08-16 04:41:00 65 C:\WINDOWS\Downloaded Program Files\desktop.ini ()
[1] 2005-08-16 04:42:12 67 C:\WINDOWS\Fonts\desktop.ini ()
[1] 2005-08-16 04:41:00 65 C:\WINDOWS\Offline Web Pages\desktop.ini ()
[1] 2005-08-16 04:33:26 62 C:\WINDOWS\system32\config\systemprofile\Application Data\desktop.ini ()
[1] 2005-08-16 21:11:46 170 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini ()
[1] 2005-08-16 04:50:28 122 C:\WINDOWS\system32\config\systemprofile\Favorites\Desktop.ini ()
[1] 2006-05-10 20:47:05 62 C:\WINDOWS\system32\config\systemprofile\Local Settings\desktop.ini ()
[1] 2006-06-11 22:02:30 113 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\desktop.ini ()
[1] 2006-06-11 22:02:30 113 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\desktop.ini ()
[1] 2006-06-11 22:02:30 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\89YZO12R\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C06F4QY2\desktop.ini ()
[1] 2006-06-11 22:02:30 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\TD2N5TAF\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UTP2D7MK\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ZCEI4B1X\desktop.ini ()
[1] 2006-06-11 22:02:30 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\desktop.ini ()
[1] 2005-08-16 04:50:28 84 C:\WINDOWS\system32\config\systemprofile\My Documents\desktop.ini ()
[1] 2005-08-16 04:50:28 189 C:\WINDOWS\system32\config\systemprofile\My Documents\My Music\Desktop.ini ()
[1] 2005-08-16 04:50:28 191 C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures\Desktop.ini ()
[1] 2005-08-16 04:50:28 150 C:\WINDOWS\system32\config\systemprofile\Recent\Desktop.ini ()
[1] 2005-08-16 04:41:02 181 C:\WINDOWS\system32\config\systemprofile\SendTo\desktop.ini ()
[1] 2005-08-16 04:33:26 62 C:\WINDOWS\system32\config\systemprofile\Start Menu\desktop.ini ()
[1] 2005-08-16 04:43:08 348 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\desktop.ini ()
[1] 2005-08-16 04:50:24 542 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\desktop.ini ()
[1] 2005-08-16 04:43:10 84 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Entertainment\desktop.ini ()
[1] 2005-08-16 04:50:30 234 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\desktop.ini ()
[1] 2005-08-16 04:43:08 84 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini ()
[1] 2004-08-10 05:00:00 2 C:\WINDOWS\system32\desktop.ini ()
[1] 2004-08-10 05:00:00 65 C:\WINDOWS\Tasks\desktop.ini ()
[1] 2009-07-04 08:18:17 145 C:\WINDOWS\Temp\History\History.IE5\desktop.ini ()
[1] 2009-07-04 08:18:17 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DRZPJX7R\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IN24NM9F\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\WAG9F543\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\Y0ZZVW4L\desktop.ini ()
[1] 2005-08-16 04:33:26 62 C:\i386\desktop.ini ()
Cannot access: C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat
[1] 2008-12-25 21:47:31 88983 C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat ()
[1] 2009-08-28 16:55:33 49152 C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat ()
[1] 2009-08-28 16:55:33 49152 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat ()
[1] 2009-07-08 13:26:21 32768 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009070820090709\index.dat ()
[1] 2009-07-10 08:11:31 32768 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009071020090711\index.dat ()
[1] 2009-08-25 12:18:50 32768 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009082520090826\index.dat ()
[1] 2009-08-28 16:56:23 1802240 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat ()
[1] 2009-08-28 18:46:29 16384 C:\WINDOWS\Temp\Cookies\index.dat ()
[1] 2009-08-28 18:46:29 16384 C:\WINDOWS\Temp\History\History.IE5\index.dat ()
[1] 2009-08-28 18:46:29 32768 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat ()
[1] 2006-06-11 22:06:35 16384 C:\i386\index.dat ()
Cannot access: C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\WAG9F543\desktop.ini
[1] 2005-08-16 04:39:16 227 C:\WINDOWS\assembly\Desktop.ini ()
[1] 2004-08-10 05:00:00 2 C:\WINDOWS\desktop.ini ()
[1] 2005-08-16 04:41:00 65 C:\WINDOWS\Downloaded Program Files\desktop.ini ()
[1] 2005-08-16 04:42:12 67 C:\WINDOWS\Fonts\desktop.ini ()
[1] 2005-08-16 04:41:00 65 C:\WINDOWS\Offline Web Pages\desktop.ini ()
[1] 2005-08-16 04:33:26 62 C:\WINDOWS\system32\config\systemprofile\Application Data\desktop.ini ()
[1] 2005-08-16 21:11:46 170 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini ()
[1] 2005-08-16 04:50:28 122 C:\WINDOWS\system32\config\systemprofile\Favorites\Desktop.ini ()
[1] 2006-05-10 20:47:05 62 C:\WINDOWS\system32\config\systemprofile\Local Settings\desktop.ini ()
[1] 2006-06-11 22:02:30 113 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\desktop.ini ()
[1] 2006-06-11 22:02:30 113 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\desktop.ini ()
[1] 2006-06-11 22:02:30 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\89YZO12R\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C06F4QY2\desktop.ini ()
[1] 2006-06-11 22:02:30 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\TD2N5TAF\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UTP2D7MK\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ZCEI4B1X\desktop.ini ()
[1] 2006-06-11 22:02:30 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\desktop.ini ()
[1] 2005-08-16 04:50:28 84 C:\WINDOWS\system32\config\systemprofile\My Documents\desktop.ini ()
[1] 2005-08-16 04:50:28 189 C:\WINDOWS\system32\config\systemprofile\My Documents\My Music\Desktop.ini ()
[1] 2005-08-16 04:50:28 191 C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures\Desktop.ini ()
[1] 2005-08-16 04:50:28 150 C:\WINDOWS\system32\config\systemprofile\Recent\Desktop.ini ()
[1] 2005-08-16 04:41:02 181 C:\WINDOWS\system32\config\systemprofile\SendTo\desktop.ini ()
[1] 2005-08-16 04:33:26 62 C:\WINDOWS\system32\config\systemprofile\Start Menu\desktop.ini ()
[1] 2005-08-16 04:43:08 348 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\desktop.ini ()
[1] 2005-08-16 04:50:24 542 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\desktop.ini ()
[1] 2005-08-16 04:43:10 84 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Entertainment\desktop.ini ()
[1] 2005-08-16 04:50:30 234 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\desktop.ini ()
[1] 2005-08-16 04:43:08 84 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini ()
[1] 2004-08-10 05:00:00 2 C:\WINDOWS\system32\desktop.ini ()
[1] 2004-08-10 05:00:00 65 C:\WINDOWS\Tasks\desktop.ini ()
[1] 2009-07-04 08:18:17 145 C:\WINDOWS\Temp\History\History.IE5\desktop.ini ()
[1] 2009-07-04 08:18:17 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DRZPJX7R\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IN24NM9F\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\WAG9F543\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\Y0ZZVW4L\desktop.ini ()
[1] 2005-08-16 04:33:26 62 C:\i386\desktop.ini ()
Cannot access: C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\Y0ZZVW4L\desktop.ini
[1] 2005-08-16 04:39:16 227 C:\WINDOWS\assembly\Desktop.ini ()
[1] 2004-08-10 05:00:00 2 C:\WINDOWS\desktop.ini ()
[1] 2005-08-16 04:41:00 65 C:\WINDOWS\Downloaded Program Files\desktop.ini ()
[1] 2005-08-16 04:42:12 67 C:\WINDOWS\Fonts\desktop.ini ()
[1] 2005-08-16 04:41:00 65 C:\WINDOWS\Offline Web Pages\desktop.ini ()
[1] 2005-08-16 04:33:26 62 C:\WINDOWS\system32\config\systemprofile\Application Data\desktop.ini ()
[1] 2005-08-16 21:11:46 170 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini ()
[1] 2005-08-16 04:50:28 122 C:\WINDOWS\system32\config\systemprofile\Favorites\Desktop.ini ()
[1] 2006-05-10 20:47:05 62 C:\WINDOWS\system32\config\systemprofile\Local Settings\desktop.ini ()
[1] 2006-06-11 22:02:30 113 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\desktop.ini ()
[1] 2006-06-11 22:02:30 113 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\desktop.ini ()
[1] 2006-06-11 22:02:30 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\89YZO12R\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C06F4QY2\desktop.ini ()
[1] 2006-06-11 22:02:30 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\TD2N5TAF\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UTP2D7MK\desktop.ini ()
[1] 2009-08-24 07:01:36 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ZCEI4B1X\desktop.ini ()
[1] 2006-06-11 22:02:30 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\desktop.ini ()
[1] 2005-08-16 04:50:28 84 C:\WINDOWS\system32\config\systemprofile\My Documents\desktop.ini ()
[1] 2005-08-16 04:50:28 189 C:\WINDOWS\system32\config\systemprofile\My Documents\My Music\Desktop.ini ()
[1] 2005-08-16 04:50:28 191 C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures\Desktop.ini ()
[1] 2005-08-16 04:50:28 150 C:\WINDOWS\system32\config\systemprofile\Recent\Desktop.ini ()
[1] 2005-08-16 04:41:02 181 C:\WINDOWS\system32\config\systemprofile\SendTo\desktop.ini ()
[1] 2005-08-16 04:33:26 62 C:\WINDOWS\system32\config\systemprofile\Start Menu\desktop.ini ()
[1] 2005-08-16 04:43:08 348 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\desktop.ini ()
[1] 2005-08-16 04:50:24 542 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\desktop.ini ()
[1] 2005-08-16 04:43:10 84 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Entertainment\desktop.ini ()
[1] 2005-08-16 04:50:30 234 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\desktop.ini ()
[1] 2005-08-16 04:43:08 84 C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini ()
[1] 2004-08-10 05:00:00 2 C:\WINDOWS\system32\desktop.ini ()
[1] 2004-08-10 05:00:00 65 C:\WINDOWS\Tasks\desktop.ini ()
[1] 2009-07-04 08:18:17 145 C:\WINDOWS\Temp\History\History.IE5\desktop.ini ()
[1] 2009-07-04 08:18:17 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DRZPJX7R\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IN24NM9F\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\WAG9F543\desktop.ini ()
[1] 2009-08-28 16:49:53 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\Y0ZZVW4L\desktop.ini ()
[1] 2005-08-16 04:33:26 62 C:\i386\desktop.ini ()
Found mount point : C:\WINDOWS\Temp\WERa67b.dir00\WERa67b.dir00
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\~nsu.tmp\~nsu.tmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_c8be176f\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_c8be176f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0(2).0_x-ww_7d5f3790\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0(2).0_x-ww_7d5f3790
Mount point destination : \Device\__max++>\^
Finished!
Attached Files
Edited by SifuMike, 29 August 2009 - 09:54 PM.
insert logs