Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Rootkit variant confirmed by Boopme


  • This topic is locked This topic is locked
28 replies to this topic

#1 SDC0603

SDC0603

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:10:16 PM

Posted 20 October 2009 - 12:02 PM

Hi Team,

My post history can be seen through here (http://www.bleepingcomputer.com/forums/topic265272.html) so I will not go over it all again.

In summary though, I have been referred to this section of the forum (by boopme) as i have a rootkit variant and need the specialist support of the HJT team. The key thing I would point out is that all attempts to run most/all suggested spyware/malware tools have failed and so far, only win32kdiag has proved anything. Very long log posted below FYI. Hoepfully it means something to you!

Please advise next steps. Thankyou in advance for your help!


Running from: C:\Users\Mr J Bloggs\Desktop\Win32kDiag.exe

Log file at : C:\Users\Mr J Bloggs\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\Windows'...



Found mount point : C:\Windows\AppPatch\Custom\Custom

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2DF2.tmp\ZAP2DF2.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3550.tmp\ZAP3550.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP41B5.tmp\ZAP41B5.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP81A.tmp\ZAP81A.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE752.tmp\ZAPE752.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPEEF0.tmp\ZAPEEF0.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\temp\temp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\assembly\tmp\tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ehome\CreateDisc\style\style

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Globalization\Globalization

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Help\Corporate\Corporate

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Help\OEM\OEM

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\5C13C3F8A3C98AA4E8AF1792A0A75D33\1.0.2\1.0.2

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7447A0100000020\7.1.0\7.1.0

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\7A6460EF0D914B142ABBC2536D4472D0\1.0.0\1.0.0

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\C0F8BA8DBEEC92A4E85F12B96084314F\1.1.3\1.1.3

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\C44CC767CBB9D834AB3DDF5459DD41B8\1.0.0\1.0.0

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Installer\$PatchCache$\Managed\D7314F9862C648A4DB8BE2A5B47BE100\1.0.0\1.0.0

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\LiveKernelReports\WATCHDOG\WATCHDOG

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Microsoft.NET\authman\authman

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Minidump\Minidump

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ModemLogs\ModemLogs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\nap\configuration\configuration

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\Panther\setup.exe\setup.exe

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\PCHEALTH\ERRORREP\QHEADLES\QHEADLES

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\PCHEALTH\ERRORREP\QSIGNOFF\QSIGNOFF

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\PLA\Templates\Templates

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\registration\CRMLog\CRMLog

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SchCache\SchCache

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\security\templates\templates

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\GameExplorer\GameExplorer

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\TfsStore\Tfs_DAV\Tfs_DAV

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Media Center Programs\Media Center Programs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Quick Launch

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\Certificates

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\CRLs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\CTLs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\UPnP Device Host\Description Documents\Description Documents

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Network Shortcuts\Network Shortcuts

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\Printer Shortcuts

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Recent\Recent

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Templates\Templates

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Desktop\Desktop

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Documents\Documents

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Downloads\Downloads

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Favorites\Favorites

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Links\Links

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Music\Music

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Pictures\Pictures

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Saved Games\Saved Games

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\LocalService\Videos\Videos

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\GameExplorer\GameExplorer

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Temporary Internet Files

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows Media Player NSS\3.0\SCPD\SCPD

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Media Center Programs\Media Center Programs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Quick Launch

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\Certificates

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\CRLs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\CTLs

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\Cookies

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Network Shortcuts\Network Shortcuts

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\Printer Shortcuts

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Recent\Recent

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Templates\Templates

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Desktop\Desktop

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Documents\Documents

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Downloads\Downloads

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Favorites\Favorites

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Links\Links

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Music\Music

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Pictures\Pictures

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Saved Games\Saved Games

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\ServiceProfiles\NetworkService\Videos\Videos

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\048167a0e1ade3ad1df23834faa1532e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6000.16922_none_c5603d92a849343f\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6000.16922_none_c5603d92a849343f

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\048167a0e1ade3ad1df23834faa1532e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6000.21122_none_c5e9b27fc167074b\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6000.21122_none_c5e9b27fc167074b

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\048167a0e1ade3ad1df23834faa1532e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6001.18326_none_c74a7d60a56c2a8c\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6001.18326_none_c74a7d60a56c2a8c

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\048167a0e1ade3ad1df23834faa1532e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6001.22515_none_c7ddebb3be829235\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6001.22515_none_c7ddebb3be829235

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\048167a0e1ade3ad1df23834faa1532e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6002.18106_none_c9469106a28244f5\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6002.18106_none_c9469106a28244f5

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\048167a0e1ade3ad1df23834faa1532e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6002.22218_none_c9c75e79bba6335e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6002.22218_none_c9c75e79bba6335e

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\1a0b7baeebffa6ce5672fb92bf0f43c5\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16901_none_6a4b28f6b6fb9243\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16901_none_6a4b28f6b6fb9243

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\1a0b7baeebffa6ce5672fb92bf0f43c5\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21101_none_6ad49de3d019654f\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21101_none_6ad49de3d019654f

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\1a0b7baeebffa6ce5672fb92bf0f43c5\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18304_none_6c34687ab41f6f39\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18304_none_6c34687ab41f6f39

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\1a0b7baeebffa6ce5672fb92bf0f43c5\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22489_none_6c6c8757cd796d3e\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22489_none_6c6c8757cd796d3e

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\1a0b7baeebffa6ce5672fb92bf0f43c5\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18082_none_6dc25a6eb1887137\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18082_none_6dc25a6eb1887137

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\1a0b7baeebffa6ce5672fb92bf0f43c5\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22191_none_6e402703caaf139b\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22191_none_6e402703caaf139b

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehepg_31bf3856ad364e35_6.0.6000.16919_none_d9bb3268d1c1d4a1\msil_ehepg_31bf3856ad364e35_6.0.6000.16919_none_d9bb3268d1c1d4a1

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehepg_31bf3856ad364e35_6.0.6000.21119_none_da44a755eadfa7ad\msil_ehepg_31bf3856ad364e35_6.0.6000.21119_none_da44a755eadfa7ad

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehepg_31bf3856ad364e35_6.0.6001.18322_none_db8f9f1ccef6d022\msil_ehepg_31bf3856ad364e35_6.0.6001.18322_none_db8f9f1ccef6d022

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehepg_31bf3856ad364e35_6.0.6001.22511_none_dc230d6fe80d37cb\msil_ehepg_31bf3856ad364e35_6.0.6001.22511_none_dc230d6fe80d37cb

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehepg_31bf3856ad364e35_6.0.6002.18103_none_dd8cb30ccc0c03e2\msil_ehepg_31bf3856ad364e35_6.0.6002.18103_none_dd8cb30ccc0c03e2

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehepg_31bf3856ad364e35_6.0.6002.22215_none_de0d807fe52ff24b\msil_ehepg_31bf3856ad364e35_6.0.6002.22215_none_de0d807fe52ff24b

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehexthost_31bf3856ad364e35_6.0.6000.16919_none_bd00af1ec1b137ec\msil_ehexthost_31bf3856ad364e35_6.0.6000.16919_none_bd00af1ec1b137ec

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehexthost_31bf3856ad364e35_6.0.6000.21119_none_bd8a240bdacf0af8\msil_ehexthost_31bf3856ad364e35_6.0.6000.21119_none_bd8a240bdacf0af8

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehiextens_31bf3856ad364e35_6.0.6000.16919_none_fbe3b60309b695e1\msil_ehiextens_31bf3856ad364e35_6.0.6000.16919_none_fbe3b60309b695e1

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehiextens_31bf3856ad364e35_6.0.6000.21119_none_fc6d2af022d468ed\msil_ehiextens_31bf3856ad364e35_6.0.6000.21119_none_fc6d2af022d468ed

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehrecobj_31bf3856ad364e35_6.0.6000.16919_none_88f94fd24b0cabe6\msil_ehrecobj_31bf3856ad364e35_6.0.6000.16919_none_88f94fd24b0cabe6

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehrecobj_31bf3856ad364e35_6.0.6000.21119_none_8982c4bf642a7ef2\msil_ehrecobj_31bf3856ad364e35_6.0.6000.21119_none_8982c4bf642a7ef2

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehrecobj_31bf3856ad364e35_6.0.6001.18322_none_8acdbc864841a767\msil_ehrecobj_31bf3856ad364e35_6.0.6001.18322_none_8acdbc864841a767

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehrecobj_31bf3856ad364e35_6.0.6001.22511_none_8b612ad961580f10\msil_ehrecobj_31bf3856ad364e35_6.0.6001.22511_none_8b612ad961580f10

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehrecobj_31bf3856ad364e35_6.0.6002.18103_none_8ccad0764556db27\msil_ehrecobj_31bf3856ad364e35_6.0.6002.18103_none_8ccad0764556db27

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehrecobj_31bf3856ad364e35_6.0.6002.22215_none_8d4b9de95e7ac990\msil_ehrecobj_31bf3856ad364e35_6.0.6002.22215_none_8d4b9de95e7ac990

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehshell_31bf3856ad364e35_6.0.6000.16919_none_89ae4da9447562f3\msil_ehshell_31bf3856ad364e35_6.0.6000.16919_none_89ae4da9447562f3

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehshell_31bf3856ad364e35_6.0.6000.21119_none_8a37c2965d9335ff\msil_ehshell_31bf3856ad364e35_6.0.6000.21119_none_8a37c2965d9335ff

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehshell_31bf3856ad364e35_6.0.6001.18322_none_8b82ba5d41aa5e74\msil_ehshell_31bf3856ad364e35_6.0.6001.18322_none_8b82ba5d41aa5e74

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehshell_31bf3856ad364e35_6.0.6001.22511_none_8c1628b05ac0c61d\msil_ehshell_31bf3856ad364e35_6.0.6001.22511_none_8c1628b05ac0c61d

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehshell_31bf3856ad364e35_6.0.6002.18103_none_8d7fce4d3ebf9234\msil_ehshell_31bf3856ad364e35_6.0.6002.18103_none_8d7fce4d3ebf9234

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehshell_31bf3856ad364e35_6.0.6002.22215_none_8e009bc057e3809d\msil_ehshell_31bf3856ad364e35_6.0.6002.22215_none_8e009bc057e3809d

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_mcstore_31bf3856ad364e35_6.0.6000.16919_none_c3b09a0a40ad4247\msil_mcstore_31bf3856ad364e35_6.0.6000.16919_none_c3b09a0a40ad4247

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_mcstore_31bf3856ad364e35_6.0.6000.21119_none_c43a0ef759cb1553\msil_mcstore_31bf3856ad364e35_6.0.6000.21119_none_c43a0ef759cb1553

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_mcstore_31bf3856ad364e35_6.0.6001.18322_none_c58506be3de23dc8\msil_mcstore_31bf3856ad364e35_6.0.6001.18322_none_c58506be3de23dc8

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_mcstore_31bf3856ad364e35_6.0.6001.22511_none_c618751156f8a571\msil_mcstore_31bf3856ad364e35_6.0.6001.22511_none_c618751156f8a571

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_mcstore_31bf3856ad364e35_6.0.6002.18103_none_c7821aae3af77188\msil_mcstore_31bf3856ad364e35_6.0.6002.18103_none_c7821aae3af77188

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_mcstore_31bf3856ad364e35_6.0.6002.22215_none_c802e821541b5ff1\msil_mcstore_31bf3856ad364e35_6.0.6002.22215_none_c802e821541b5ff1

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.16919_none_4eabf
16098b9d989\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.16919_none_4eabf
16098b9d989

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.21119_none_4f356
64db1d7ac95\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.21119_none_4f356
64db1d7ac95

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6001.18322_none_50805
e1495eed50a\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6001.18322_none_50805
e1495eed50a

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6001.22511_none_5113c
c67af053cb3\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6001.22511_none_5113c
c67af053cb3

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6002.18103_none_527d7
204930408ca\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6002.18103_none_527d7
204930408ca

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6002.22215_none_52fe3
f77ac27f733\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6002.22215_none_52fe3
f77ac27f733

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.16919_none_313a4010
5a0dd6a3\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.16919_none_313a4010
5a0dd6a3

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.21119_none_31c3b4fd
732ba9af\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.21119_none_31c3b4fd
732ba9af

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.18322_none_330eacc4
5742d224\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.18322_none_330eacc4
5742d224

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.22511_none_33a21b17
705939cd\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.22511_none_33a21b17
705939cd

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6002.18103_none_350bc0b4
545805e4\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6002.18103_none_350bc0b4
545805e4

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6002.22215_none_358c8e27
6d7bf44d\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6002.22215_none_358c8e27
6d7bf44d

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.16919_none_23959903cf2
642b9\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.16919_none_23959903cf2
642b9

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.21119_none_241f0df0e84
415c5\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.21119_none_241f0df0e84
415c5

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6001.18322_none_256a05b7cc5
b3e3a\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6001.18322_none_256a05b7cc5
b3e3a

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6001.22511_none_25fd740ae57
1a5e3\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6001.22511_none_25fd740ae57
1a5e3

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6002.18103_none_276719a7c97
071fa\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6002.18103_none_276719a7c97
071fa

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6002.22215_none_27e7e71ae29
46063\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6002.22215_none_27e7e71ae29
46063

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6000.16919_none_b4272457a51e9088\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6000.16919_none_b4272457a51e9088

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6000.21119_none_b4b09944be3c6394\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6000.21119_none_b4b09944be3c6394

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6001.18322_none_b5fb910ba2538c09\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6001.18322_none_b5fb910ba2538c09

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6001.22511_none_b68eff5ebb69f3b2\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6001.22511_none_b68eff5ebb69f3b2

Mount point destination : \Device\__max++>\^

Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6000.16919_none_3426e4871c4578dd\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6000.16919_none_3426e4871c4578dd: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6000.21119_none_34b0597435634be9\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6000.21119_none_34b0597435634be9: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6001.18322_none_35fb513b197a745e\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6001.18322_none_35fb513b197a745e: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6001.22511_none_368ebf8e3290dc07\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6001.22511_none_368ebf8e3290dc07: 3
Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6000.16919_none_cc3b9dbbcca0c455\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6000.16919_none_cc3b9dbbcca0c455

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6000.21119_none_ccc512a8e5be9761\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6000.21119_none_ccc512a8e5be9761

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.18322_none_ce100a6fc9d5bfd6\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.18322_none_ce100a6fc9d5bfd6

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.22511_none_cea378c2e2ec277f\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.22511_none_cea378c2e2ec277f

Mount point destination : \Device\__max++>\^

Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.16919_none_12cf71cda28c3451\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.16919_none_12cf71cda28c3451: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.21119_none_1358e6babbaa075d\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.21119_none_1358e6babbaa075d: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.18322_none_14a3de819fc12fd2\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.18322_none_14a3de819fc12fd2: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.22511_none_15374cd4b8d7977b\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.22511_none_15374cd4b8d7977b: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.16919_none_3241e223dcd398af\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.16919_none_3241e223dcd398af: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.21119_none_32cb5710f5f16bbb\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.21119_none_32cb5710f5f16bbb: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.18322_none_34164ed7da089430\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.18322_none_34164ed7da089430: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22511_none_34a9bd2af31efbd9\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22511_none_34a9bd2af31efbd9: 3
Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.16919_none_2df5b0db851b701f\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.16919_none_2df5b0db851b701f

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.21119_none_2e7f25c89e39432b\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.21119_none_2e7f25c89e39432b

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.16919_none_2d53d4336cfb74fa\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.16919_none_2d53d4336cfb74fa

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.21119_none_2ddd492086194806\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.21119_none_2ddd492086194806

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.18322_none_2f2840e76a30707b\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.18322_none_2f2840e76a30707b

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.22511_none_2fbbaf3a8346d824\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.22511_none_2fbbaf3a8346d824

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6000.16919_none_2bd15bd5bbe22a69\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6000.16919_none_2bd15bd5bbe22a69

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6000.21119_none_2c5ad0c2d4fffd75\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6000.21119_none_2c5ad0c2d4fffd75

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.18322_none_2da5c889b91725ea\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.18322_none_2da5c889b91725ea

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.22511_none_2e3936dcd22d8d93\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.22511_none_2e3936dcd22d8d93

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.18103_none_2fa2dc79b62c59aa\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.18103_none_2fa2dc79b62c59aa

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.22215_none_3023a9eccf504813\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.22215_none_3023a9eccf504813

Mount point destination : \Device\__max++>\^

Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.16919_none_24e0915264d38aee\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.16919_none_24e0915264d38aee: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.21119_none_256a063f7df15dfa\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.21119_none_256a063f7df15dfa: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.18322_none_26b4fe066208866f\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.18322_none_26b4fe066208866f: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.22511_none_27486c597b1eee18\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.22511_none_27486c597b1eee18: 3
Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.16919_none_5023fdaf535192a0\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.16919_none_5023fdaf535192a0

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.21119_none_50ad729c6c6f65ac\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.21119_none_50ad729c6c6f65ac

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6001.18322_none_51f86a6350868e21\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6001.18322_none_51f86a6350868e21

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6001.22511_none_528bd8b6699cf5ca\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6001.22511_none_528bd8b6699cf5ca

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6002.18103_none_53f57e534d9bc1e1\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6002.18103_none_53f57e534d9bc1e1

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6002.22215_none_54764bc666bfb04a\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6002.22215_none_54764bc666bfb04a

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.16919_none_36d4c2db16b955b5\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.16919_none_36d4c2db16b955b5

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.21119_none_375e37c82fd728c1\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.21119_none_375e37c82fd728c1

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.16919_none_3a23083c2e16dd5c\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.16919_none_3a23083c2e16dd5c

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.21119_none_3aac7d294734b068\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.21119_none_3aac7d294734b068

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.16919_none_ccdc1605cc4128ba\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.16919_none_ccdc1605cc4128ba

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.21119_none_cd658af2e55efbc6\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.21119_none_cd658af2e55efbc6

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.18322_none_ceb082b9c976243b\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.18322_none_ceb082b9c976243b

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.22511_none_cf43f10ce28c8be4\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.22511_none_cf43f10ce28c8be4

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6000.16919_none_4980b80557951a97\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6000.16919_none_4980b80557951a97

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6000.21119_none_4a0a2cf270b2eda3\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6000.21119_none_4a0a2cf270b2eda3

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.18322_none_4b5524b954ca1618\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.18322_none_4b5524b954ca1618

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.22511_none_4be8930c6de07dc1\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.22511_none_4be8930c6de07dc1

Mount point destination : \Device\__max++>\^

Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.16919_none_3d4262f7625d9044\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.16919_none_3d4262f7625d9044: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.21119_none_3dcbd7e47b7b6350\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.21119_none_3dcbd7e47b7b6350: 3
Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.16919_none_de90102a91400756\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.16919_none_de90102a91400756

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.21119_none_df198517aa5dda62\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.21119_none_df198517aa5dda62

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.18322_none_e0647cde8e7502d7\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.18322_none_e0647cde8e7502d7

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.22511_none_e0f7eb31a78b6a80\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.22511_none_e0f7eb31a78b6a80

Mount point destination : \Device\__max++>\^

Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.16919_none_da1531e459e90b01\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.16919_none_da1531e459e90b01: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.21119_none_da9ea6d17306de0d\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.21119_none_da9ea6d17306de0d: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.18322_none_dbe99e98571e0682\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.18322_none_dbe99e98571e0682: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.22511_none_dc7d0ceb70346e2b\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.22511_none_dc7d0ceb70346e2b: 3
Found mount point : C:\Windows\SoftwareDistribution\Download\91a9b8f920315471a87cc9055727dc6b\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16926_none_f09243146e5e8997\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16926_none_f09243146e5e8997

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\91a9b8f920315471a87cc9055727dc6b\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21126_none_f11bb801877c5ca3\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21126_none_f11bb801877c5ca3

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\91a9b8f920315471a87cc9055727dc6b\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18330_none_f267b0126b929e6f\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18330_none_f267b0126b929e6f

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\91a9b8f920315471a87cc9055727dc6b\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22521_none_f2fd1ef984a738c6\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22521_none_f2fd1ef984a738c6

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\91a9b8f920315471a87cc9055727dc6b\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18111_none_f464c40268a7d22f\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18111_none_f464c40268a7d22f

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\91a9b8f920315471a87cc9055727dc6b\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22224_none_f4e691bf81cad9ef\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22224_none_f4e691bf81cad9ef

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6000.21125_none_395fe8aa98b803ee\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6000.21125_none_395fe8aa98b803ee

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6001.22518_none_3b5421de95d38ed8\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6001.22518_none_3b5421de95d38ed8

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6002.22223_none_3d2ac2689306813a\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6002.22223_none_3d2ac2689306813a

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6000.16926_none_7abd15c3656ef988\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6000.16926_none_7abd15c3656ef988

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6000.21125_none_7b458a667e8db33d\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6000.21125_none_7b458a667e8db33d

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6001.18330_none_7c9282c162a30e60\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6001.18330_none_7c9282c162a30e60

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6001.22518_none_7d39c39a7ba93e27\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6001.22518_none_7d39c39a7ba93e27

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6002.18111_none_7e8f96b15fb84220\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6002.18111_none_7e8f96b15fb84220

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6002.22223_none_7f10642478dc3089\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6002.22223_none_7f10642478dc3089

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.16916_none_a9e05e55f5aca86f\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.16916_none_a9e05e55f5aca86f

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.21116_none_aa69d3430eca7b7b\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.21116_none_aa69d3430eca7b7b

Mount point destination : \Device\__max++>\^

Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_6.0.6000.16916_none_ebdb680516458e6e\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_6.0.6000.16916_none_ebdb680516458e6e: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_6.0.6000.21116_none_ec64dcf22f63617a\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_6.0.6000.21116_none_ec64dcf22f63617a: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.16916_none_b2f810b7d9a605d2\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.16916_none_b2f810b7d9a605d2: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.21116_none_b38185a4f2c3d8de\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.21116_none_b38185a4f2c3d8de: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18319_none_b4e1503bd6c9e2c8\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18319_none_b4e1503bd6c9e2c8: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.22508_none_b574be8eefe04a71\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.22508_none_b574be8eefe04a71: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.18100_none_b6c9915bd3f03513\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.18100_none_b6c9915bd3f03513: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.22212_none_b74a5eceed14237c\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.22212_none_b74a5eceed14237c: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6000.16916_none_deda9f807f4ec541\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6000.16916_none_deda9f807f4ec541: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6000.21116_none_df64146d986c984d\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6000.21116_none_df64146d986c984d: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.18319_none_e0c3df047c72a237\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.18319_none_e0c3df047c72a237: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.22508_none_e1574d57958909e0\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.22508_none_e1574d57958909e0: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..nternetcontrolpanel_31bf3856ad364e35_6.0.6000.16916_none_8d4e9eec54b4aaf6\x86_microsoft-windows-i..nternetcontrolpanel_31bf3856ad364e35_6.0.6000.16916_none_8d4e9eec54b4aaf6: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..nternetcontrolpanel_31bf3856ad364e35_6.0.6000.21116_none_8dd813d96dd27e02\x86_microsoft-windows-i..nternetcontrolpanel_31bf3856ad364e35_6.0.6000.21116_none_8dd813d96dd27e02: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16916_none_fffdec59a4af2c65\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16916_none_fffdec59a4af2c65: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.21116_none_00876146bdccff71\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.21116_none_00876146bdccff71: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18319_none_01e72bdda1d3095b\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18319_none_01e72bdda1d3095b: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22508_none_027a9a30bae97104\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22508_none_027a9a30bae97104: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18100_none_03cf6cfd9ef95ba6\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18100_none_03cf6cfd9ef95ba6: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22212_none_04503a70b81d4a0f\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22212_none_04503a70b81d4a0f: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6000.16916_none_726565555a594d2c\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6000.16916_none_726565555a594d2c: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6000.21116_none_72eeda4273772038\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6000.21116_none_72eeda4273772038: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6001.18319_none_744ea4d9577d2a22\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6001.18319_none_744ea4d9577d2a22: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6001.22508_none_74e2132c709391cb\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6001.22508_none_74e2132c709391cb: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6000.16916_none_ac471aa909a2040b\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6000.16916_none_ac471aa909a2040b: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6000.21116_none_acd08f9622bfd717\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6000.21116_none_acd08f9622bfd717: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18319_none_ae305a2d06c5e101\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18319_none_ae305a2d06c5e101: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.22508_none_aec3c8801fdc48aa\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.22508_none_aec3c8801fdc48aa: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.16916_none_f9a70f336e9aa6b8\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.16916_none_f9a70f336e9aa6b8: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.21116_none_fa30842087b879c4\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.21116_none_fa30842087b879c4: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.18319_none_fb904eb76bbe83ae\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.18319_none_fb904eb76bbe83ae: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.22508_none_fc23bd0a84d4eb57\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.22508_none_fc23bd0a84d4eb57: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.18100_none_fd788fd768e4d5f9\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.18100_none_fd788fd768e4d5f9: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.22212_none_fdf95d4a8208c462\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.22212_none_fdf95d4a8208c462: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.16916_none_95db47eb84802ce6\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.16916_none_95db47eb84802ce6: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.21116_none_9664bcd89d9dfff2\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.21116_none_9664bcd89d9dfff2: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6000.16916_none_5dfb83283d527f1d\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6000.16916_none_5dfb83283d527f1d: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6000.21116_none_5e84f81556705229\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6000.21116_none_5e84f81556705229: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6001.18319_none_5fe4c2ac3a765c13\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6001.18319_none_5fe4c2ac3a765c13: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6001.22508_none_607830ff538cc3bc\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6001.22508_none_607830ff538cc3bc: 3
Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6000.16916_none_692da8c08a37209f\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6000.16916_none_692da8c08a37209f

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6000.21116_none_69b71dada354f3ab\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6000.21116_none_69b71dada354f3ab

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6001.18319_none_6b16e844875afd95\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6001.18319_none_6b16e844875afd95

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6001.22508_none_6baa5697a071653e\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6001.22508_none_6baa5697a071653e

Mount point destination : \Device\__max++>\^

Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6000.16916_none_f1827f5cbd02b6c0\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6000.16916_none_f1827f5cbd02b6c0: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6000.21116_none_f20bf449d62089cc\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6000.21116_none_f20bf449d62089cc: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.18319_none_f36bbee0ba2693b6\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.18319_none_f36bbee0ba2693b6: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.22508_none_f3ff2d33d33cfb5f\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.22508_none_f3ff2d33d33cfb5f: 3
Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.16916_none_463de2434640df73\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.16916_none_463de2434640df73

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.21116_none_46c757305f5eb27f\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.21116_none_46c757305f5eb27f

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16916_none_11580b782505959b\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16916_none_11580b782505959b

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.21116_none_11e180653e2368a7\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.21116_none_11e180653e2368a7

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18319_none_13414afc22297291\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18319_none_13414afc22297291

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22508_none_13d4b94f3b3fda3a\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22508_none_13d4b94f3b3fda3a

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.18100_none_15298c1c1f4fc4dc\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.18100_none_15298c1c1f4fc4dc

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.22212_none_15aa598f3873b345\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.22212_none_15aa598f3873b345

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.16916_none_58b07842671a21a4\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.16916_none_58b07842671a21a4

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.21116_none_5939ed2f8037f4b0\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.21116_none_5939ed2f8037f4b0

Mount point destination : \Device\__max++>\^

Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16916_none_2d76f8e51cda9b48\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16916_none_2d76f8e51cda9b48: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21116_none_2e006dd235f86e54\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21116_none_2e006dd235f86e54: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18319_none_2f60386919fe783e\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18319_none_2f60386919fe783e: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22508_none_2ff3a6bc3314dfe7\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22508_none_2ff3a6bc3314dfe7: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6000.16916_none_353b610816ff3030\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6000.16916_none_353b610816ff3030: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6000.21116_none_35c4d5f5301d033c\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6000.21116_none_35c4d5f5301d033c: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6001.18319_none_3724a08c14230d26\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6001.18319_none_3724a08c14230d26: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6001.22508_none_37b80edf2d3974cf\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6001.22508_none_37b80edf2d3974cf: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6000.16916_none_45b8a3358f604ac2\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6000.16916_none_45b8a3358f604ac2: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6000.21116_none_46421822a87e1dce\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6000.21116_none_46421822a87e1dce: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18319_none_47a1e2b98c8427b8\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18319_none_47a1e2b98c8427b8: 3
Could not open reparse point C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.22508_none_4835510ca59a8f61\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.22508_none_4835510ca59a8f61: 3
Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16916_none_c3e5ae00615563ed\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16916_none_c3e5ae00615563ed

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.21116_none_c46f22ed7a7336f9\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.21116_none_c46f22ed7a7336f9

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.16916_none_2a0ac4706805394a\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.16916_none_2a0ac4706805394a

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.21116_none_2a94395d81230c56\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.21116_none_2a94395d81230c56

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16916_none_62b7657bb0fb23c8\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16916_none_62b7657bb0fb23c8

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.21116_none_6340da68ca18f6d4\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.21116_none_6340da68ca18f6d4

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18319_none_64a0a4ffae1f00be\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18319_none_64a0a4ffae1f00be

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22508_none_65341352c7356867\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22508_none_65341352c7356867

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.18100_none_6688e61fab455309\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.18100_none_6688e61fab455309

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.22212_none_6709b392c4694172\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.22212_none_6709b392c4694172

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.16916_none_e6b0d1fa947e7800\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.16916_none_e6b0d1fa947e7800

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.21116_none_e73a46e7ad9c4b0c\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.21116_none_e73a46e7ad9c4b0c

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.16916_none_0b590716d6f937b2\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.16916_none_0b590716d6f937b2

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.21116_none_0be27c03f0170abe\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.21116_none_0be27c03f0170abe

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-common_31bf3856ad364e35_6.0.6001.22522_none_044c3353295315ad\x86_microsoft-windows-smbserver-common_31bf3856ad364e35_6.0.6001.22522_none_044c3353295315ad

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6000.16927_none_d7f7c2a8f95f038d\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6000.16927_none_d7f7c2a8f95f038d

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6000.21127_none_d8813796127cd699\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6000.21127_none_d8813796127cd699

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.18331_none_d9cd2fa6f6931865\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.18331_none_d9cd2fa6f6931865

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.22522_none_da629e8e0fa7b2bc\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.22522_none_da629e8e0fa7b2bc

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.18112_none_dbca4396f3a84c25\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.18112_none_dbca4396f3a84c25

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.22225_none_dc4c11540ccb53e5\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.22225_none_dc4c11540ccb53e5

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\f01c4bbfa608298ce96317823815654c\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6000.16838_none_f831274072c7bd51\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6000.16838_none_f831274072c7bd51

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\f01c4bbfa608298ce96317823815654c\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6000.21033_none_f8b59abb8bea11aa\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6000.21033_none_f8b59abb8bea11aa

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\f01c4bbfa608298ce96317823815654c\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6001.18234_none_fa1364be6ff1e8e6\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6001.18234_none_fa1364be6ff1e8e6

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\f01c4bbfa608298ce96317823815654c\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6001.22403_none_fabc72e988f818ad\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6001.22403_none_fabc72e988f818ad

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\f01c4bbfa608298ce96317823815654c\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6002.18034_none_fbf9d88c6d183b31\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6002.18034_none_fbf9d88c6d183b31

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\Download\f01c4bbfa608298ce96317823815654c\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6002.22131_none_fc80747986388ef6\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6002.22131_none_fc80747986388ef6

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\PostRebootEventCache\PostRebootEventCache

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\SoftwareDistribution\ScanFile\ScanFile

Mount point destination : \Device\__max++>\^

Cannot access: C:\Windows\System32\cngaudit.dll

[1] 2006-11-02 10:46:03 61952 C:\Windows\System32\cngaudit.dll ()

[2] 2006-11-02 10:46:03 11776 C:\Windows\System32\logevent.dll (Microsoft Corporation)

[1] 2006-11-02 10:46:03 11776 C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll (Microsoft Corporation)



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl

[1] 2009-10-19 21:15:19 26771960 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl ()



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl

[1] 2009-10-19 18:02:34 0 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl ()



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl

[1] 2009-10-19 18:02:41 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl ()



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl

[1] 2009-10-19 18:02:41 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl ()



Cannot access: C:\Windows\System32\mrt.exe

[1] 2008-01-05 12:37:43 52696 C:\Windows\SoftwareDistribution\Download\10caef54f115a84895c68fbc95676a0c\x86_microsoft-windows-malwareremovaltool_31bf3856ad364e35_6.0.6001.18000_none_d3909ca1dd6bb475\mrt.exe (Microsoft Corporation)

[1] 2009-08-28 14:38:22 24689600 C:\Windows\System32\mrt.exe ()

[1] 2006-09-18 22:42:35 6757792 C:\Windows\winsxs\x86_microsoft-windows-malwareremovaltool_31bf3856ad364e35_6.0.6000.16386_none_d159daa5e080a3a1\mrt.exe (Microsoft Corporation)

[1] 2008-01-05 12:37:43 52696 C:\Windows\winsxs\x86_microsoft-windows-malwareremovaltool_31bf3856ad364e35_6.0.6001.18000_none_d3909ca1dd6bb475\mrt.exe (Microsoft Corporation)



Found mount point : C:\Windows\Temp\Temp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\tracing\tracing

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\winsxs\InstallTemp\InstallTemp

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\winsxs\Temp\PendingDeletes\PendingDeletes

Mount point destination : \Device\__max++>\^

Found mount point : C:\Windows\winsxs\Temp\PendingRenames\PendingRenames

Mount point destination : \Device\__max++>\^



Finished!

BC AdBot (Login to Remove)

 


#2 thcbytes

thcbytes

  • Malware Response Team
  • 14,790 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:16 PM

Posted 20 October 2009 - 09:11 PM

Hi and welcome to the HijackThis Logs and Virus/Trojan/Spyware/Malware Removal forum,

I am Posted Image and I am here to help you!

I ask that you refrain from running tools other than those I suggest to you while I am cleaning up your computer. The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.

Please perform all steps in the order received and do not proceed if you need clarification.

In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond to your topic and facilitate the cleaning of your machine.

After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.

I would also like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please be courteous and appreciative for the assistance provided!

==========

You have a very nasty new rootkit. Please follow my directions exactely as I have outlined!!!

Step 1

Please save this file to your desktop. Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here.
"%userprofile%\desktop\win32kdiag.exe" -f -r

==========

Step 2

Please do this:
  • Click on the Start button, then click on Run...
  • In the empty "Open:" box provided, type cmd and press Enter
    • This will launch a Command Prompt window (looks like DOS).
  • Copy the entire blue text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).
    copy C:\Windows\System32\logevent.dll C:\ /y
  • In the Command Prompt window, paste the copied text by right-clicking and selecting Paste.
  • Press Enter.When successfully, you should get this message within the Command Prompt: "1 file(s) copied"
    NOTE: If you didn't get this message, stop and tell me first. Executing The Avenger script (step #3) won't work if the file copy was not successful.
  • Exit the Command Prompt window.
==========

Step 3

:( Warning to others reading this thread!: The Avenger is a VERY POWERFUL program, and can easily be misused.
Certain misuses of this program can prevent your system from ever starting again.
For this reason, it is strongly recommended to use The Avenger only as directed and under qualified supervision.
We can accept no responsibility for damage caused by misuse of the program.
:(

  • Download The Avenger by Swandog46 from here.
  • Unzip/extract it to a folder on your desktop.
  • Double click on avenger.exe to run The Avenger.
  • Click OK.
  • Make sure that the box next to Scan for rootkits has a tick in it and that the box next to Automatically disable any rootkits found does not have a tick in it.
  • Copy all of the text in the below code box to the clipboard by highlighting it and then pressing Ctrl+C.
    Files to move:C:\logevent.dll | C:\Windows\System32\cngaudit.dll
  • In the avenger window, click the Paste Script from Clipboard, Posted Image button.
  • Click the Execute button.
  • You will be asked Are you sure you want to execute the current script?.
  • Click Yes.
  • You will now be asked First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?.
  • Click Yes.
  • Your PC will now be rebooted.
  • Note: If the above script contains Drivers to delete: or Drivers to disable:, then The Avenger will require two reboots to complete its operation.
  • After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%\avenger.txt (typically C:\avenger.txt).
  • Please post this log in your next reply.
==========

Download and Run ComboFix (by sUBs)

You must rename it before saving it.

Posted Image

Posted Image

Please download ComboFix from one of these locations:

Link 1
Link 2

Save thcbytes.exe to your Desktop <-- Important!!!
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Please refer to this link for instructions.

  • Double click on thcbytes.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


==========

Again I would like to remind you to make no further changes to your computer unless I direct you to do so. Your computer fix will be based on the current condition of your computer! Any changes might delay my ability to help you.

==========

With your next post please provide:

* Win32kDiag log
* Avenger log
* Combofix log

Kind regards,
~t
Proud member - Unified Network of Instructors and Trained Eliminators
Posted Image

I do not accept personal donations for assistance provided. I would ask that you instead consider donating the greatest gift - Organ Donation. Your organs are of no use to you when your gone. You will save a life that would otherwise be lost!

http://donatelife.net/register-now/

#3 SDC0603

SDC0603
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:10:16 PM

Posted 21 October 2009 - 04:58 AM

Hi Thcbytes.

Thanks for taking this challenge on!!!

Quick question before I try all of this tonight, I assume I have to run all of this as administrator?? My normal log-in to Vista is as administrator, but I think the rootkit is messing with my administrator rights.....

All previous efforts with Boopme have been right click, and run as administrator, but thought I would check before I advance tonight.

Thanks......

#4 thcbytes

thcbytes

  • Malware Response Team
  • 14,790 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:16 PM

Posted 21 October 2009 - 07:00 AM

You are absolutely correct!!! Here are the revised instructions.....

Step 1

Please save this file to your desktop.
  • Select Posted Image
  • Select All Programs
  • Select Accessories
  • Right click Command Prompt and choose Run as administrator

    Posted Image
    • If you have the User Account Control (UAC) enabled you will be asked for authorization prior to the command prompt opening.
    • You may simply need to press the Continue button if you are the administrator or insert the administrator password.
    Copy-paste the following command (the bolded text) into the "cmd" box, and click enter. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here.
    "%userprofile%\desktop\win32kdiag.exe" -f -r

    ==========

    Step 2

    Next do this:
    • Select Posted Image
    • Select All Programs
    • Select Accessories
    • Right click Command Prompt and choose Run as administrator
    Posted Image
    • If you have the User Account Control (UAC) enabled you will be asked for authorization prior to the command prompt opening.
    • You may simply need to press the Continue button if you are the administrator or insert the administrator password.
  • Copy the entire blue text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).
    copy C:\Windows\System32\logevent.dll C:\ /y
  • In the Command Prompt window, paste the copied text by right-clicking and selecting Paste.
  • Press Enter.When successfully, you should get this message within the Command Prompt: "1 file(s) copied"
    NOTE: If you didn't get this message, stop and tell me first. Executing The Avenger script (step #3) won't work if the file copy was not successful.
  • Exit the Command Prompt window.
==========

Step 3

:( Warning to others reading this thread!: The Avenger is a VERY POWERFUL program, and can easily be misused.
Certain misuses of this program can prevent your system from ever starting again.
For this reason, it is strongly recommended to use The Avenger only as directed and under qualified supervision.
We can accept no responsibility for damage caused by misuse of the program.
:(
  • Download The Avenger by Swandog46 from here.
  • Unzip/extract it to a folder on your desktop.
  • Right click and run as Admin on avenger.exe to run The Avenger.
  • Click OK.
  • Make sure that the box next to Scan for rootkits has a tick in it and that the box next to Automatically disable any rootkits found does not have a tick in it.
  • Copy all of the text in the below code box to the clipboard by highlighting it and then pressing Ctrl+C.
    Files to move:C:\logevent.dll | C:\Windows\System32\cngaudit.dll
  • In the avenger window, click the Paste Script from Clipboard, Posted Image button.
  • Click the Execute button.
  • You will be asked Are you sure you want to execute the current script?.
  • Click Yes.
  • You will now be asked First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?.
  • Click Yes.
  • Your PC will now be rebooted.
  • Note: If the above script contains Drivers to delete: or Drivers to disable:, then The Avenger will require two reboots to complete its operation.
  • After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%\avenger.txt (typically C:\avenger.txt).
  • Please post this log in your next reply.
==========

Download and Run ComboFix (by sUBs)

You must rename it before saving it.

Posted Image

Posted Image

Please download ComboFix from one of these locations:

Link 1
Link 2

Save thcbytes.exe to your Desktop <-- Important!!!
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Please refer to this link for instructions.

  • Right click and run as Admin on thcbytes.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


==========

Again I would like to remind you to make no further changes to your computer unless I direct you to do so. Your computer fix will be based on the current condition of your computer! Any changes might delay my ability to help you.

==========

With your next post please provide:

* Win32kDiag log
* Avenger log
* Combofix log

Kind regards,
~t
Proud member - Unified Network of Instructors and Trained Eliminators
Posted Image

I do not accept personal donations for assistance provided. I would ask that you instead consider donating the greatest gift - Organ Donation. Your organs are of no use to you when your gone. You will save a life that would otherwise be lost!

http://donatelife.net/register-now/

#5 SDC0603

SDC0603
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:10:16 PM

Posted 21 October 2009 - 04:35 PM

Hi,

Step 1 win32kdiag worked OK, and attached is the log file.

Step 2 worked OK with 1 file copied.

Step 3, i had some issues unzipping the avenger file as it resulted in a blank folder (with rootkit deleting avenger.exe?). I finally managed to rename avenger.exe within winrar, and subsequently unzipped to desktop folder OK.

Ran as admin, copied all the text as requested, got a few errors (as you will see from the log file). The syntax when copied exactly was missing a carriage return for some reason. With a new manual return from me, it ran at this point, and rebooted once with the attached log file.

I started running combofix as per described. Firstly disabling mcafee security suite and spyware doctor. I got an interesting error when proceeding. It stated that superantispyware was running and i should disable!!

I did have SAS installed as one of many other programs trying to find the spyware/malware, however, the rootkit stopped the app after a few seconds and now I cannot restart as it is r/w protected. When I previously tried to uninstall, vista left the sas.exe and I cannot manually delete this file. I have since re-installed SAS into another directory to see if I could run OK from a fresh install. This is the version currently installed (listed in control panel) but not working again.

Shall I uninstall? Is there a file I can end task because there is nothing in my taskbar either?? Can you help to delete the leftover locked SAS files?

Also, how do I exit the combofix program to do the above? I tried clicking the red x, but it progressed to the next screen stating it would continue with SAS still being active, and this is at my discretion (or something similar).....

Thanks......

Attached Files



#6 thcbytes

thcbytes

  • Malware Response Team
  • 14,790 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:16 PM

Posted 21 October 2009 - 04:40 PM

Just go ahead with the Combofix run. :(
Proud member - Unified Network of Instructors and Trained Eliminators
Posted Image

I do not accept personal donations for assistance provided. I would ask that you instead consider donating the greatest gift - Organ Donation. Your organs are of no use to you when your gone. You will save a life that would otherwise be lost!

http://donatelife.net/register-now/

#7 SDC0603

SDC0603
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:10:16 PM

Posted 21 October 2009 - 05:11 PM

Combofix ran OK, with log file attached.

Let me know what I need to do next.

Thanks......

Attached Files



#8 thcbytes

thcbytes

  • Malware Response Team
  • 14,790 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:16 PM

Posted 21 October 2009 - 10:53 PM

Well done :(

Lets continue....................

:( Warning: This script was specifically written and designed for this user only. Unsupervised use of this tool could render your computer unbootable permanently!! :)

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\windows\win32k.sys

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000000


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

==========

Please do this:
  • Select Posted Image
  • Select All Programs
  • Select Accessories
  • Right click Command Prompt and choose Run as administrator
Posted Image
  • If you have the User Account Control (UAC) enabled you will be asked for authorization prior to the command prompt opening.
  • You may simply need to press the Continue button if you are the administrator or insert the administrator password.
  • Copy the entire green text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).
    cmd /c junction -s c:\ >jlog.txt&jlog.txt
  • In the Command Prompt window, paste the copied text by right-clicking and selecting Paste and then press the enter button and let the program run. Do nothing until the log appears.
  • Exit the Command Prompt window.
You will find the log here...

C:\Documents and Settings\User\jlog.txt

==========

We need to create an OTL Report
  • Please download OTL from one of the following mirrors:
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Under "Extra Registry" please check "Use Safelist" and also check "LOP Check" and "Purity Check" as pictured.Posted Image
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
    • OTListIt.txt <-- Will be opened
    • Extra.txt <-- Will be minimized
==========

With your next post please provide:

* Combofix.txt
* Junction log
* OTL.txt
* OTL Extra.txt
* How is your computer running now?

Kind regards,
~t
Proud member - Unified Network of Instructors and Trained Eliminators
Posted Image

I do not accept personal donations for assistance provided. I would ask that you instead consider donating the greatest gift - Organ Donation. Your organs are of no use to you when your gone. You will save a life that would otherwise be lost!

http://donatelife.net/register-now/

#9 SDC0603

SDC0603
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:10:16 PM

Posted 22 October 2009 - 05:45 AM

Hi,

OK, so next steps followed........

CFScript with combofix ran OK, and log file is attached.

Jlog failed, and attached is a screenshot of the problem reported - effectively stating that junction is not a recognised command.

I haven't gone on to run OTL yet until jlog is sorted....

Attached Files



#10 thcbytes

thcbytes

  • Malware Response Team
  • 14,790 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:16 PM

Posted 22 October 2009 - 08:04 AM

Nice screenshot. Thanks.

It helps if I give you the application 1st!!!!!!! :(

Do this .........

We need to scan the system with this special tool:

First...........

* Please download and save:

Junction.zip

* Unzip it and place Junction.exe in the Windows directory (C:\Windows).

Next...........
  • Select Posted Image
  • Select All Programs
  • Select Accessories
  • Right click Command Prompt and choose Run as administrator
Posted Image
  • If you have the User Account Control (UAC) enabled you will be asked for authorization prior to the command prompt opening.
  • You may simply need to press the Continue button if you are the administrator or insert the administrator password.
  • Copy the entire green text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).
    cmd /c junction -s c:\ >jlog.txt&jlog.txt
  • In the Command Prompt window, paste the copied text by right-clicking and selecting Paste and then press the enter button and let the program run. Do nothing until the log appears.
  • Exit the Command Prompt window.
You will find the log here...

C:\Documents and Settings\User\jlog.txt


Thanks,
~t
Proud member - Unified Network of Instructors and Trained Eliminators
Posted Image

I do not accept personal donations for assistance provided. I would ask that you instead consider donating the greatest gift - Organ Donation. Your organs are of no use to you when your gone. You will save a life that would otherwise be lost!

http://donatelife.net/register-now/

#11 SDC0603

SDC0603
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:10:16 PM

Posted 22 October 2009 - 09:02 AM

Hi,

Thanks for this. Junction completed its task, with the attached output....

I started running OTL, but have a few questions:

Do I run this as admin?

You only mention safelist for extra registry (which is incidentally the default). What about process, services, drivers, standard registry?? (all=safelist as default).

There are also lots of other selectable buttons/boxes, i.e. output, file age, skip microsoft, etc. What do I do with these? The fact you didn't state what to select would suggest leaving as default, but thought I had better check :(

Attached Files

  • Attached File  jlog.txt   99.43KB   2 downloads


#12 thcbytes

thcbytes

  • Malware Response Team
  • 14,790 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:16 PM

Posted 22 October 2009 - 09:13 AM

I appreciate your attention to detail!!!!!! Run as Admin for safety sake. Leave the preset defaults "as is".
Thanks,
~t
Proud member - Unified Network of Instructors and Trained Eliminators
Posted Image

I do not accept personal donations for assistance provided. I would ask that you instead consider donating the greatest gift - Organ Donation. Your organs are of no use to you when your gone. You will save a life that would otherwise be lost!

http://donatelife.net/register-now/

#13 SDC0603

SDC0603
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:10:16 PM

Posted 22 October 2009 - 10:47 AM

me again....

OK, OTL finished. I've ran out of attachment space :( so I have attached one, and pasted the other one below.

I think I have completed all requested steps now. So did anything show up in the logs I posted? Anything abnormal?

Am I clean?? Any other steps to follow??

>>>>>>>>>>>>>>>>

OTL Extras logfile created on: 22/10/2009 16:25:23 - Run 1
OTL by OldTimer - Version 3.0.21.0 Folder = C:\Users\Mr j bloggs\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 60.91% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): c:\pagefile.sys 3067 3067 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 14.27 Gb Free Space | 4.79% Space Free | Partition Type: NTFS
Drive D: | 6.04 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 232.83 Gb Total Space | 25.01 Gb Free Space | 10.74% Space Free | Partition Type: FAT32
Drive F: | 967.22 Mb Total Space | 967.20 Mb Free Space | 100.00% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
Drive H: | 117.24 Mb Total Space | 33.99 Mb Free Space | 29.00% Space Free | Partition Type: FAT
I: Drive not present or media not loaded

Computer Name: HOMEPC
Current User Name: Mr j bloggs
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC1.0.1\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC1.0.1\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{92E47F11-C0EC-4D2F-B7D8-D05A07715881}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BCEF7554-A9C7-44B8-956A-BE13429BE46C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00DFF24D-BFF9-4AB3-96C5-F83329CFA0D8}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{01067234-4A88-40C9-8E69-04F75ABB9D37}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{06A8A6E1-399C-45DD-B306-C0D9BFBB8F4E}" = protocol=6 | dir=in | app=c:\program files\fear\fearxp\fearxp.exe |
"{1324DED5-8313-433B-A002-5F94F8BEEA6D}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{17C83E06-154C-400A-8DC4-0ABE41693611}" = protocol=6 | dir=in | app=c:\program files\world in conflict\wic_ds.exe |
"{367F896D-DAB2-4B3C-BE72-0A8522FB3573}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{3A146990-F908-4405-A03E-E7DE9B4D13A2}" = dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{3BBC946E-15DB-45EC-89B1-0F913FA11422}" = protocol=17 | dir=in | app=c:\program files\fear\fearxp\fearxp.exe |
"{49735443-154E-491A-A261-E6914CC18BFF}" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{5098339E-342D-4F72-844B-F4A16B3F27B2}" = protocol=17 | dir=in | app=c:\program files\world in conflict\wic_online.exe |
"{5BEF0FE3-F80B-44A4-AE18-A61D6FF11E49}" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{6445174A-DC11-4B52-A22A-EE21E35DADA2}" = protocol=6 | dir=in | app=c:\program files\fear\fearmp.exe |
"{776C6C5D-4714-4FA1-9369-E513AAF75DFE}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{77D08BF6-FAEF-4C74-AFBE-7319B7DF4624}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{7B4229F8-518C-4115-A759-470DF795A951}" = protocol=6 | dir=in | app=c:\program files\crysis\bin32\crysisdedicatedserver.exe |
"{86D80E40-523A-46CC-8D1F-1E7C171977C0}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx10.exe |
"{8A28D561-024A-4BEC-A796-9F47AF276011}" = protocol=17 | dir=in | app=c:\program files\fear\fearmp.exe |
"{8E1078AE-AC0A-4ADC-87F1-51FF0154DDD4}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{94C58036-008A-401D-B674-9D7307217029}" = protocol=6 | dir=in | app=c:\program files\crysis\bin32\crysis.exe |
"{94CBDE5C-A0BA-4457-85A1-4BC84F90E06B}" = protocol=17 | dir=in | app=c:\program files\crysis\bin32\crysisdedicatedserver.exe |
"{975CC17A-8A65-40A2-B77B-C86747A9A36F}" = protocol=6 | dir=in | app=c:\program files\fear\fear.exe |
"{99674ACC-634F-4436-8040-E668553C9F28}" = protocol=6 | dir=in | app=c:\program files\world in conflict\wic_online.exe |
"{9B871544-31EF-4D87-881E-15FBE113B7B2}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{9DE22E95-5551-4E7B-B85A-3301432375AA}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe |
"{A0B1870B-0DDE-4E8A-B07A-17083C39A7E7}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A1B67BFF-0DE7-451F-A8A7-17F69EE31A26}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx10.exe |
"{A9DB5179-70ED-4BB9-8C81-0381232806FF}" = protocol=17 | dir=in | app=c:\program files\fear\fear.exe |
"{ADA5166B-BFF5-41B0-AC06-2CAFD1957E22}" = protocol=17 | dir=in | app=c:\program files\world in conflict\wic.exe |
"{BA45F590-69F1-4915-BB30-3DB870DC05CF}" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{BD44D3D7-6A12-44F1-B322-E79917632763}" = protocol=17 | dir=in | app=c:\program files\world in conflict\wic_ds.exe |
"{C50E8B7A-042E-4B0F-995A-165FC5DF2237}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C7453811-294B-4F50-83CF-8504B861AD0E}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe |
"{CD040E07-6991-4110-80FB-8C09642D8BA5}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{D98851E8-41A7-4AF9-AA94-03C305EB728B}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{E00E719A-60EA-4E7F-AD31-A0F70CEACD1F}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{E07A7C7C-034C-440B-95B7-8807297CD658}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe |
"{E0B67A96-6C1B-4210-A0A7-E6A6D18092D4}" = protocol=6 | dir=in | app=c:\program files\world in conflict\wic.exe |
"{E4881220-D7CE-4BA0-BD33-577E1C75C423}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{E6B9D316-6720-47F9-9023-53A8E63C449D}" = protocol=17 | dir=in | app=c:\program files\crysis\bin32\crysis.exe |
"{F0CB5233-C4F4-47A1-9C71-4E24C8DA8D5C}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{F2038157-CEC0-4F57-9DDC-6E3F3E8C2009}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{F2212693-7FA7-46BC-98C2-D978CF78BADA}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{F32B468C-0CC2-4B9C-8185-9426CCC39FED}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe |
"{FB7BA35E-8FF0-407D-8AD6-6520591DDAB9}" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{FDADD090-79FF-4331-8E14-39001D208E2B}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{74DBCF82-2BB5-49FD-A1AC-6229EBBAB3B3}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{F0E64FC0-AC8C-4E25-B052-FCB8CE6D1D32}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis®
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02DFB3FD-CF52-4183-8BCA-2A127D4888F4}" = iTunes
"{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}" = Call of Duty® 4 - Modern Warfare™ 1.3 Patch
"{06C32EA0-4A22-4919-979A-8700715865B8}" = Microsoft LifeCam
"{0965D484-1777-4BA5-8C3A-095A6B0D2696}_is1" = Driver Sweeper 1.5.5
"{0E4BC542-9CFD-4E97-B586-9F1E5516E7B9}" = Microsoft IntelliPoint 6.1
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty® - World at War™ 1.3 Patch
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty® - World at War™ 1.2 Patch
"{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}" = Microsoft Games for Windows - LIVE Redistributable
"{3248F0A8-6813-11D6-A77B-00B0D0150070}" = J2SE Runtime Environment 5.0 Update 7
"{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty® 4 - Modern Warfare™ 1.4 Patch
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{4FC19392-E4A5-4CCB-B45A-AB7E8126D3C9}" = Microsoft Easy Assist
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5D7767FA-7FE8-4627-9F09-AEF7A25F1E07}" = Call of Duty® 4 - Modern Warfare™ 1.1 Patch
"{619B8475-0F48-41B7-A370-5147F7092989}" = Virtual Earth 3D (Beta)
"{62369F2F77534556AEF4C58152E3BDE5}" =
"{65A92AAA-3D05-4C94-9F70-731C05E60C16}" = NVIDIA System Update
"{66F78C51-D108-4F0C-A93C-1CBE74CE338F}" = Company of Heroes
"{68108E66-D13A-4EE8-A6F4-40E4B90C2A26}" = Windows Live Toolbar Feed Detector (Windows Live Toolbar)
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7353BAE6-5E49-46C4-A9B5-8A269A313789}" = Crysis WARHEAD®
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA Performance
"{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty® 4 - Modern Warfare™ 1.5 Patch
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty® 4 - Modern Warfare™ 1.6 Patch
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8CFA9151-6404-409A-AF22-4632D04582FD}" = Assassin's Creed
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty® 4 - Modern Warfare™ 1.7 Patch
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{974530D2-AE96-4C99-B549-99CADA653CE5}" = Garmin MapSource
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{97EA42A5-3FAB-4948-B74D-F3C44B13F5CE}" = Crysis WARHEAD® Patch
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty® - World at War™ 1.4 Patch
"{A182077A-8D6B-4194-B48A-B4DC37C69907}" = RealSpeak Solo for UK English Emily
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{A98AFBC7-D5A7-46A1-8795-EABE2F55A7D6}" = Microsoft Office Live Meeting 2007
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-0000-7EC8-7489-000000000603}" = Adobe Acrobat and Reader 6.0.3 Update
"{AC76BA86-0000-7EC8-7489-000000000604}" = Adobe Acrobat and Reader 6.0.4 Update
"{AC76BA86-0000-7EC8-7489-000000000605}" = Adobe Acrobat and Reader 6.0.5 Update
"{AC76BA86-0000-7EC8-7489-000000000606}" = Adobe Acrobat and Reader 6.0.6 Update
"{AC76BA86-1033-F400-7760-000000000001}" = Adobe Acrobat 6.0.1 Professional - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty® - World at War™ 1.1 Patch
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B3FB6B55-C271-44FC-BA03-BBD8B2EA6EEF}" = Memory-Map OS Edition Version 5
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B820CB04-D21E-48A4-A110-1A783A86EAA3}" = Garmin StreetPilot c320 Europe
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{BD1F8143-C678-43CD-A296-A3A32A8C2976}" = Memeo AutoBackup
"{BFD96B89-B769-4CD6-B11E-E79FFD46F067}" = QuickTime
"{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty® - World at War™ 1.5 Patch
"{C82185E8-C27B-4EF4-2007-3333BC2C2B6D}" = Microsoft AutoRoute 2007 with GPS Locator
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D10FF038-7941-4B62-8051-17D3E2BC150A}" = Garmin City Navigator Europe NT+ v8.02
"{D5A145FC-D00C-4F1A-9119-EB4D9D659750}" = Windows Live Toolbar
"{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty® - World at War™
"{D8AB8F0C-CEEB-4A29-8EF5-219B064813F4}" = Apple Mobile Device Support
"{DFA1E2C8-A9DE-4B99-8B3C-866664B5F67C}" = Garmin POI Loader
"{E0783143-EAE2-4047-A8D6-E155523C594C}" = Garmin WebUpdater
"{E280923D-C5D9-4728-8C79-AC9A0DC75875}" = BioShock
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty® 4 - Modern Warfare™
"{E5141379-B2D9-4BBC-BB2A-5805541571DD}" = Call of Duty® 4 - Modern Warfare™ 1.2 Patch
"{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}" = NVIDIA System Monitor
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F112F66E-25CA-42DD-983C-6118EB38F606}" = Microsoft Games for Windows - LIVE
"{F14B8ECC-BDA0-4987-9201-D7B7DBE11033}" = Nero 7 Premium
"{FFA2B2B6-3BDE-4728-B404-A16E0F853F6A}" = Microsoft Office Live Meeting 2005
"45A7283175C62FAC673F913C1F532C5361F97841" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
"8461-7759-5462-8226" = Vuze
"AddressBook" =
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"BackWeb-8876480 Uninstaller" =
"BearFlix" = BearFlix
"BearShare" = BearShare
"Connection Manager" =
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.52.1
"Crysis WARHEAD®" = Crysis WARHEAD®
"Crysis WARHEAD® Patch" = Crysis WARHEAD® Patch
"DirectDrawEx" =
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DXM_Runtime" =
"EADM" = EA Download Manager
"File Shredder_is1" = File Shredder 2.0
"Fontcore" =
"GameSpotDownloadManager" = GameSpot Download Manager
"IE40" =
"IE4Data" =
"IE5BAKEX" =
"IEData" =
"InstallShield_{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}" = Call of Duty® 4 - Modern Warfare™ 1.3 Patch
"InstallShield_{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty® - World at War™ 1.3 Patch
"InstallShield_{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty® - World at War™ 1.2 Patch
"InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty® 4 - Modern Warfare™ 1.4 Patch
"InstallShield_{5D7767FA-7FE8-4627-9F09-AEF7A25F1E07}" = Call of Duty® 4 - Modern Warfare™ 1.1 Patch
"InstallShield_{65A92AAA-3D05-4C94-9F70-731C05E60C16}" = NVIDIA System Update
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA Performance
"InstallShield_{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty® 4 - Modern Warfare™ 1.5 Multiplayer Patch
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty® 4 - Modern Warfare™ 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty® 4 - Modern Warfare™ 1.7 Patch
"InstallShield_{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty® - World at War™ 1.4 Patch
"InstallShield_{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty® - World at War™ 1.1 Patch
"InstallShield_{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty® - World at War™ 1.5 Patch
"InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty® - World at War™
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty® 4 - Modern Warfare™
"InstallShield_{E5141379-B2D9-4BBC-BB2A-5805541571DD}" = Call of Duty® 4 - Modern Warfare™ 1.2 Patch
"InstallShield_{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}" = NVIDIA System Monitor
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MobileOptionPack" =
"MPlayer2" =
"MSC" = McAfee SecurityCenter
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"PunkBusterSvc" = PunkBuster Services
"SchedulingAgent" =
"Shockwave" = Shockwave
"Spyware Doctor" = Spyware Doctor 7.0
"Switch" = Switch Sound File Converter
"SystemRequirementsLab" = System Requirements Lab
"TomTom HOME" = TomTom HOME 2.7.1.1812
"UltraISO_is1" = UltraISO Premium V9.35
"UN080325" = BUFFALO TurboUSB for FLASH/HDD
"VLC media player" = VLC media player 1.0.1
"WavePad" = WavePad Sound Editor
"Windows Live Toolbar" = Windows Live Toolbar
"WinRAR archiver" = WinRAR archiver

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2380594860-1575461441-4214207244-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"InstallShield_{BD1F8143-C678-43CD-A296-A3A32A8C2976}" = Memeo AutoBackup

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/08/2009 07:27:19 | Computer Name = HomePC | Source = VSS | ID = 8194
Description =

Error - 11/08/2009 07:34:54 | Computer Name = HomePC | Source = McLogEvent | ID = 5051
Description = A thread in process C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe took
longer than 90000 ms to complete a request. The process will be terminated. Thread
id : 2240 (0x8c0) Thread address : 0x021608E5 Thread message : Build VSCORE.14.0.0.423
/ 5301.4018 Object being scanned = \Device\HarddiskVolume1\Users\Mr j bloggs\AppData\Local\Microsoft\Windows\Temporary
Internet Files\Low\Content.IE5\VY4Q0TA0\CoDWaW-1.2-1.4-PatchSetup[1].exe by C:\Program
Files\Internet Explorer\iexplore.exe 4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0)

7004(0)(0) 5006(0)(0) 5004(0)(0)

Error - 11/08/2009 07:37:16 | Computer Name = HomePC | Source = VSS | ID = 8194
Description =

Error - 11/08/2009 07:42:21 | Computer Name = HomePC | Source = VSS | ID = 8194
Description =

Error - 11/08/2009 07:47:59 | Computer Name = HomePC | Source = VSS | ID = 8194
Description =

Error - 11/08/2009 08:54:21 | Computer Name = HomePC | Source = McLogEvent | ID = 5051
Description = A thread in process C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe took
longer than 90000 ms to complete a request. The process will be terminated. Thread
id : 3428 (0xd64) Thread address : 0x77A75E74 Thread message : Build VSCORE.14.0.0.423
/ 5301.4018 Object being scanned = \Device\HarddiskVolume1\Windows\TEMP\CoDF205.tmp

by C:\Windows\system32\svchost.exe 4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0)

7004(0)(0) 5006(0)(0) 5004(0)(0)

Error - 11/08/2009 09:01:35 | Computer Name = HomePC | Source = VSS | ID = 8194
Description =

Error - 21/08/2009 10:34:11 | Computer Name = HomePC | Source = TomTomHOMEService | ID = 10000
Description =

Error - 30/08/2009 07:39:24 | Computer Name = HomePC | Source = TomTomHOMEService | ID = 10000
Description =

Error - 01/09/2009 13:46:36 | Computer Name = HomePC | Source = Application Error | ID = 1000
Description = Faulting application Explorer.EXE, version 6.0.6002.18005, time stamp
0x49e01da5, faulting module fsshell.dll_unloaded, version 0.0.0.0, time stamp 0x2a425e19,
exception code 0xc0000005, fault offset 0x083833ec, process id 0x728, application
start time 0x01ca2b239887cc76.

[ System Events ]
Error - 21/10/2009 17:59:46 | Computer Name = HomePC | Source = Service Control Manager | ID = 7026
Description =

Error - 22/10/2009 05:59:50 | Computer Name = HomePC | Source = Service Control Manager | ID = 7000
Description =

Error - 22/10/2009 05:59:50 | Computer Name = HomePC | Source = Service Control Manager | ID = 7026
Description =

Error - 22/10/2009 06:10:00 | Computer Name = HomePC | Source = Service Control Manager | ID = 7030
Description =

Error - 22/10/2009 06:10:02 | Computer Name = HomePC | Source = Service Control Manager | ID = 7009
Description =

Error - 22/10/2009 06:14:23 | Computer Name = HomePC | Source = Service Control Manager | ID = 7031
Description =

Error - 22/10/2009 06:17:41 | Computer Name = HomePC | Source = Service Control Manager | ID = 7030
Description =

Error - 22/10/2009 06:17:41 | Computer Name = HomePC | Source = Service Control Manager | ID = 7009
Description =

Error - 22/10/2009 09:19:57 | Computer Name = HomePC | Source = Service Control Manager | ID = 7000
Description =

Error - 22/10/2009 09:19:57 | Computer Name = HomePC | Source = Service Control Manager | ID = 7026
Description =


< End of report >

Attached Files

  • Attached File  OTL.Txt   100.79KB   3 downloads


#14 thcbytes

thcbytes

  • Malware Response Team
  • 14,790 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:16 PM

Posted 22 October 2009 - 11:12 AM

Let me review the logs now that all the steps are completed!! I will let you know when your clear. I will also guide you as to recommendations and prevention. :(

I copy and pasted them to make it easier for me to review.

ComboFix 09-10-20.03 - Mr S Cross 22/10/2009 11:11.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2046.1390 [GMT 1:00]
Running from: c:\users\Mr S Cross\Desktop\thcbytes.exe
Command switches used :: c:\users\Mr S Cross\Desktop\CFScript.txt
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\windows\win32k.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\win32k.sys

.
((((((((((((((((((((((((( Files Created from 2009-09-22 to 2009-10-22 )))))))))))))))))))))))))))))))
.

2009-10-22 10:17 . 2009-10-22 10:17 -------- d-----w- c:\users\Mr S Cross\AppData\Local\temp
2009-10-22 10:17 . 2009-10-22 10:17 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-10-22 10:17 . 2009-10-22 10:17 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-20 11:05 . 2009-10-20 11:05 -------- d-----w- c:\users\Mr S Cross\AppData\Roaming\.clamwin
2009-10-20 10:27 . 2009-10-20 10:27 -------- d-----w- c:\users\Mr S Cross\AppData\Local\Adobe
2009-10-19 16:41 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-19 16:41 . 2009-10-19 16:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-19 16:41 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-19 16:15 . 2009-10-19 16:15 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2009-10-19 16:15 . 2009-10-19 16:15 -------- d-----w- c:\program files\Super-AS2
2009-10-19 15:44 . 2009-10-19 15:44 -------- d-----w- c:\program files\Windows Installer Clean Up
2009-10-19 15:42 . 2009-10-19 15:43 -------- d-----w- C:\WINSSLog
2009-10-19 14:11 . 2009-10-19 14:11 -------- d-----w- c:\users\Mr S Cross\DoctorWeb
2009-10-16 17:30 . 2009-10-19 15:59 -------- d-----w- c:\programdata\Malwarebytes
2009-10-16 16:39 . 2009-10-22 10:15 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-16 16:39 . 2009-10-16 16:39 -------- d-----w- c:\users\Mr S Cross\AppData\Roaming\SUPERAntiSpyware.com
2009-10-16 15:05 . 2009-10-19 15:59 -------- d-----w- c:\users\Mr S Cross\AppData\Roaming\Malwarebytes
2009-10-16 11:22 . 2009-10-16 15:12 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-16 11:04 . 2009-10-16 11:04 -------- d-----w- c:\windows\Downloaded Installations
2009-10-15 18:45 . 2009-10-15 18:45 -------- d-----w- c:\users\Mr S Cross\AppData\Local\Threat Expert
2009-10-15 18:23 . 2009-09-24 07:55 97208 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2009-10-15 18:23 . 2009-09-24 07:55 229304 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-10-15 18:23 . 2009-09-23 15:10 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-10-15 18:23 . 2009-10-06 15:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-10-15 18:23 . 2009-09-03 08:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-10-15 18:23 . 2009-10-21 20:35 -------- d-----w- c:\program files\Spyware Doctor
2009-10-15 18:23 . 2009-10-15 18:30 -------- d-----w- c:\program files\Common Files\PC Tools
2009-10-15 18:23 . 2009-10-15 18:23 -------- d-----w- c:\users\Mr S Cross\AppData\Roaming\PC Tools
2009-10-15 18:23 . 2009-10-15 18:23 -------- d-----w- c:\programdata\PC Tools
2009-10-15 14:34 . 2009-10-15 14:34 -------- d-----w- c:\users\Mr S Cross\AppData\Roaming\Uniblue
2009-10-14 13:13 . 2009-08-27 12:40 834048 ----a-w- c:\windows\system32\wininet.dll
2009-10-14 13:13 . 2009-08-27 13:29 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-14 13:13 . 2009-09-04 11:41 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-14 13:12 . 2009-08-04 12:34 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-14 13:12 . 2009-08-04 12:34 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-14 13:12 . 2009-09-10 16:48 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-14 13:12 . 2009-09-14 09:29 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-14 13:09 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-09 14:17 . 2009-10-09 14:17 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-09 13:23 . 2009-10-15 14:22 -------- d-----w- c:\program files\Windows Live Safety Center

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-22 09:59 . 2009-07-26 18:34 33354 ----a-w- c:\programdata\nvModes.dat
2009-10-22 09:59 . 2009-07-26 18:29 -------- d-----w- c:\programdata\NVIDIA
2009-10-21 20:54 . 2009-04-02 15:04 -------- d-----w- c:\program files\McAfee
2009-10-19 15:43 . 2007-10-22 08:43 -------- d-----w- c:\program files\MSECache
2009-10-19 13:38 . 2008-11-26 17:47 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-16 15:26 . 2008-12-29 19:14 -------- d-----w- c:\users\Mr S Cross\AppData\Roaming\Azureus
2009-10-14 16:07 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-08 17:25 . 2008-04-05 18:28 -------- d-----w- c:\program files\TomTom HOME 2
2009-10-05 14:12 . 2007-03-17 19:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-05 13:34 . 2009-09-02 14:20 -------- d-----w- c:\users\Mr S Cross\AppData\Roaming\vlc
2009-10-01 16:16 . 2007-10-09 13:30 -------- d-----w- c:\users\Mr S Cross\AppData\Roaming\Bioshock
2009-09-21 13:18 . 2007-10-09 13:25 -------- d-----w- c:\programdata\Media Center Programs
2009-09-16 09:22 . 2009-04-02 15:04 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 09:22 . 2009-04-02 15:04 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 09:22 . 2009-04-02 15:04 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 09:22 . 2009-01-16 19:04 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 09:22 . 2009-04-02 15:00 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-16 02:20 . 2009-10-15 18:23 7383 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-09-15 05:20 . 2009-10-15 18:23 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat
2009-09-15 01:12 . 2009-10-15 18:23 7412 ----a-w- c:\windows\system32\drivers\PCTAppEvent.cat
2009-09-15 00:01 . 2009-10-15 18:23 7387 ----a-w- c:\windows\system32\drivers\pctgntdi.cat
2009-09-11 15:41 . 2008-03-12 16:14 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-02 14:36 . 2009-09-02 14:36 -------- d-----w- c:\program files\Common Files\EZB Systems
2009-09-02 14:36 . 2009-09-02 14:36 -------- d-----w- c:\program files\UltraISO
2009-09-02 14:28 . 2008-12-29 19:10 -------- d-----w- c:\program files\Vuze
2009-09-02 02:09 . 2009-09-02 02:09 176128 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2009-08-30 11:33 . 2009-02-12 14:52 -------- d-----w- c:\program files\VideoLAN
2009-08-29 00:27 . 2009-09-02 14:10 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-02 14:10 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-20 14:09 . 2009-08-20 14:09 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 16:27 . 2009-09-10 14:31 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 15:53 . 2009-09-10 14:31 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49 . 2009-09-10 14:31 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49 . 2009-09-10 14:31 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49 . 2009-09-10 14:31 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49 . 2009-09-10 14:31 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49 . 2009-09-10 14:31 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49 . 2009-09-10 14:31 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49 . 2009-09-10 14:31 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:48 . 2009-09-10 14:31 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48 . 2009-09-10 14:31 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-10 14:58 . 2008-04-04 13:58 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-08-10 14:58 . 2007-11-30 15:38 22328 ----a-w- c:\users\Mr S Cross\AppData\Roaming\PnkBstrK.sys
2009-08-10 14:57 . 2008-04-04 13:58 107832 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-08-10 14:57 . 2009-08-10 14:57 682280 ----a-w- c:\windows\system32\pbsvc.exe
2009-08-07 18:51 . 2009-08-07 18:51 15308424 ----a-w- c:\windows\system32\xlive.dll
2009-08-07 18:51 . 2009-08-07 18:51 13642888 ----a-w- c:\windows\system32\xlivefnt.dll
2009-07-26 18:22 . 2007-03-15 15:23 1356 ----a-w- c:\users\Mr S Cross\AppData\Local\d3d9caps.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-10-21_21.59.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-11-02 13:02 . 2009-10-22 10:01 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-10-21 20:57 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-10-21 20:57 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-10-22 10:01 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:02 . 2009-10-21 20:57 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 13:02 . 2009-10-22 10:01 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-22 09:59 . 2009-10-22 09:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-10-22 09:59 . 2009-10-22 09:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-10-22 10:04 622516 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-10-21 20:59 622516 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-10-22 10:04 107948 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-10-21 20:59 107948 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-10-12 2000112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\Super-AS2\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 ----a-w- c:\program files\Super-AS2\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Mr S Cross^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Memeo AutoBackup Launcher.lnk]
path=c:\users\Mr S Cross\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Memeo AutoBackup Launcher.lnk
backup=c:\windows\pss\Memeo AutoBackup Launcher.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(:(:92,f6,27,46,e8,f0,c9,01

R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [15/10/2009 19:23 207280]
R0 vburner;vburner;c:\windows\System32\drivers\vburner.sys [07/11/2008 15:57 15872]
R1 SASDIFSV;SASDIFSV;c:\program files\Super-AS2\sasdifsv.sys [12/10/2009 21:24 9968]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [02/04/2009 16:06 203280]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [14/07/2009 12:28 239648]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [27/08/2009 16:05 92008]
R3 nvoclock;NVIDIA Enthusiasts Platform KDM;c:\windows\System32\drivers\nvoclock.sys [09/03/2009 12:25 38304]
S3 bfturboh;BUFFALO TurboUSB for HD Filter;c:\windows\System32\drivers\bfturboh.sys [19/02/2009 14:14 15872]
S3 cpuz132;cpuz132;c:\windows\System32\drivers\cpuz132_x32.sys [26/07/2009 16:44 12672]
S3 SASENUM;SASENUM;c:\program files\Super-AS2\SASENUM.SYS [12/10/2009 21:24 7408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [15/10/2009 19:23 358600]
.
Contents of the 'Scheduled Tasks' folder

2009-10-21 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]

2009-09-17 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 11:22]

2009-04-03 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 11:22]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: inetpsa.com\portail
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-22 11:17
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2380594860-1575461441-4214207244-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:cc,cd,d6,af,9a,0f,c8,bd,a1,c6,26,53,e2,63,03,01,2f,b2,2d,25,b9,8e,94,
ec,63,56,cd,98,f7,61,1e,ab,6f,11,08,fb,01,ce,92,b2,91,f5,3d,b8,48,97,f1,48,\
"??"=hex:cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b,19,52,fe,22

[HKEY_USERS\S-1-5-21-2380594860-1575461441-4214207244-1000\Software\SecuROM\License information*]
"datasecu"=hex:75,c3,02,95,f5,af,5c,21,20,fb,22,05,0a,48,ec,7c,59,6a,f6,41,c8,
8e,0d,5f,b0,e8,a7,af,35,7e,b8,17,f8,60,68,4e,17,91,7d,65,1d,00,fe,a1,37,bb,\
"rkeysecu"=hex:79,87,d9,a1,80,eb,83,64,32,23,2f,9e,0a,4e,d5,7a
.
Completion time: 2009-10-22 11:19
ComboFix-quarantined-files.txt 2009-10-22 10:19
ComboFix2.txt 2009-10-21 22:03

Pre-Run: 15,412,338,688 bytes free
Post-Run: 15,375,581,184 bytes free

- - End Of File - - 3BD9995655F07A0E4A6AB130B3C35F59

========================

Junction v1.05 - Windows junction creator and reparse point viewer
Copyright © 2000-2007 Mark Russinovich
Systems Internals - http://www.sysinternals.com

\\?\c:\\Documents and Settings: JUNCTION
Print Name : C:\Users
Substitute Name: C:\Users


Failed to open \\?\c:\\pagefile.sys: The process cannot access the file because it is being used by another process.


...

...

...

...

...

...

...

...


Failed to open \\?\c:\\Program Files\Malwarebytes' Anti-Malware\mbam.exe: Access is denied.


...

...

...

...


Failed to open \\?\c:\\Program Files\Spybot - Search & Destroy\SpybotSD.exe: Access is denied.


.
Failed to open \\?\c:\\Program Files\Super-AS2\SUPERAntiSpyware.exe: Access is denied.



Failed to open \\?\c:\\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe: Access is denied.


..


Failed to open \\?\c:\\Program Files\Windows Live Safety Center\wlschost.exe: Access is denied.


..\\?\c:\\ProgramData\Application Data: JUNCTION
Print Name : C:\ProgramData
Substitute Name: C:\ProgramData

\\?\c:\\ProgramData\Desktop: JUNCTION
Print Name : C:\Users\Public\Desktop
Substitute Name: C:\Users\Public\Desktop

\\?\c:\\ProgramData\Documents: JUNCTION
Print Name : C:\Users\Public\Documents
Substitute Name: C:\Users\Public\Documents

\\?\c:\\ProgramData\Favorites: JUNCTION
Print Name : C:\Users\Public\Favorites
Substitute Name: C:\Users\Public\Favorites

\\?\c:\\ProgramData\Start Menu: JUNCTION
Print Name : C:\ProgramData\Microsoft\Windows\Start Menu
Substitute Name: C:\ProgramData\Microsoft\Windows\Start Menu

\\?\c:\\ProgramData\Templates: JUNCTION
Print Name : C:\ProgramData\Microsoft\Windows\Templates
Substitute Name: C:\ProgramData\Microsoft\Windows\Templates

.

...
Failed to open \\?\c:\\System Volume Information\MountPointManagerRemoteDatabase: Access is denied.



Failed to open \\?\c:\\System Volume Information\{19b38917-b4e1-11de-a0c6-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{1b4dbcc3-ba71-11de-99d1-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{1d5951fd-bcb6-11de-aac6-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{1f67d5f8-bc0e-11de-9ace-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{35bf7057-ba48-11de-b1b5-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{3f65d79d-b8c1-11de-b0f7-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{5d6b5927-b9bc-11de-b8b2-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{5d6b592d-b9bc-11de-b8b2-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{cdfa467b-b4ce-11de-ad06-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{d66cf82c-bcbd-11de-8151-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{daeade22-bcc8-11de-932a-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{f08a711a-b996-11de-8071-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\{fea0547c-ba44-11de-a352-00508d988b43}{3808876b-c176-4e48-b7ae-04046e6cc752}: Access is denied.



Failed to open \\?\c:\\System Volume Information\SystemRestore\System Volume Information: Access is denied.


\\?\c:\\Users\All Users: UNKNOWN MICROSOFT REPARSE POINT

\\?\c:\\Users\Default User: JUNCTION
Print Name : C:\Users\Default
Substitute Name: C:\Users\Default

\\?\c:\\Users\All Users\Application Data: JUNCTION
Print Name : C:\ProgramData
Substitute Name: C:\ProgramData

\\?\c:\\Users\All Users\Desktop: JUNCTION
Print Name : C:\Users\Public\Desktop
Substitute Name: C:\Users\Public\Desktop

\\?\c:\\Users\All Users\Documents: JUNCTION
Print Name : C:\Users\Public\Documents
Substitute Name: C:\Users\Public\Documents

\\?\c:\\Users\All Users\Favorites: JUNCTION
Print Name : C:\Users\Public\Favorites
Substitute Name: C:\Users\Public\Favorites

\\?\c:\\Users\All Users\Start Menu: JUNCTION
Print Name : C:\ProgramData\Microsoft\Windows\Start Menu
Substitute Name: C:\ProgramData\Microsoft\Windows\Start Menu

\\?\c:\\Users\All Users\Templates: JUNCTION
Print Name : C:\ProgramData\Microsoft\Windows\Templates
Substitute Name: C:\ProgramData\Microsoft\Windows\Templates



...

\\?\c:\\Users\Default\Application Data: JUNCTION
Print Name : C:\Users\Default\AppData\Roaming
Substitute Name: C:\Users\Default\AppData\Roaming

\\?\c:\\Users\Default\Local Settings: JUNCTION
Print Name : C:\Users\Default\AppData\Local
Substitute Name: C:\Users\Default\AppData\Local

\\?\c:\\Users\Default\My Documents: JUNCTION
Print Name : C:\Users\Default\Documents
Substitute Name: C:\Users\Default\Documents

\\?\c:\\Users\Default\NetHood: JUNCTION
Print Name : C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts
Substitute Name: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts

\\?\c:\\Users\Default\PrintHood: JUNCTION
Print Name : C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
Substitute Name: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts

\\?\c:\\Users\Default\Recent: JUNCTION
Print Name : C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent
Substitute Name: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent

\\?\c:\\Users\Default\SendTo: JUNCTION
Print Name : C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo
Substitute Name: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo

\\?\c:\\Users\Default\Start Menu: JUNCTION
Print Name : C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu
Substitute Name: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu

\\?\c:\\Users\Default\Templates: JUNCTION
Print Name : C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates
Substitute Name: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates

\\?\c:\\Users\Default\AppData\Local\Application Data: JUNCTION
Print Name : C:\Users\Default\AppData\Local
Substitute Name: C:\Users\Default\AppData\Local

\\?\c:\\Users\Default\AppData\Local\History: JUNCTION
Print Name : C:\Users\Default\AppData\Local\Microsoft\Windows\History
Substitute Name: C:\Users\Default\AppData\Local\Microsoft\Windows\History

\\?\c:\\Users\Default\AppData\Local\Temporary Internet Files: JUNCTION
Print Name : C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files
Substitute Name: C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files

\\?\c:\\Users\Default\Documents\My Music: JUNCTION
Print Name : C:\Users\Default\Music
Substitute Name: C:\Users\Default\Music

\\?\c:\\Users\Default\Documents\My Pictures: JUNCTION
Print Name : C:\Users\Default\Pictures
Substitute Name: C:\Users\Default\Pictures

\\?\c:\\Users\Default\Documents\My Videos: JUNCTION
Print Name : C:\Users\Default\Videos
Substitute Name: C:\Users\Default\Videos

\\?\c:\\Users\Mr j bloggs\Application Data: JUNCTION
Print Name : C:\Users\Mr j bloggs\AppData\Roaming
Substitute Name: C:\Users\Mr j bloggs\AppData\Roaming

\\?\c:\\Users\Mr j bloggs\Cookies: JUNCTION
Print Name : C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\Cookies
Substitute Name: C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\Cookies

\\?\c:\\Users\Mr j bloggs\Local Settings: JUNCTION
Print Name : C:\Users\Mr j bloggs\AppData\Local
Substitute Name: C:\Users\Mr j bloggs\AppData\Local

\\?\c:\\Users\Mr j bloggs\My Documents: JUNCTION
Print Name : C:\Users\Mr j bloggs\Documents
Substitute Name: C:\Users\Mr j bloggs\Documents

\\?\c:\\Users\Mr j bloggs\NetHood: JUNCTION
Print Name : C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\Network Shortcuts
Substitute Name: C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\Network Shortcuts

\\?\c:\\Users\Mr j bloggs\PrintHood: JUNCTION
Print Name : C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
Substitute Name: C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\Printer Shortcuts

\\?\c:\\Users\Mr j bloggs\Recent: JUNCTION
Print Name : C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\Recent
Substitute Name: C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\Recent

\\?\c:\\Users\Mr j bloggs\SendTo: JUNCTION
Print Name : C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\SendTo
Substitute Name: C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\SendTo

\\?\c:\\Users\Mr j bloggs\Start Menu: JUNCTION
Print Name : C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\Start Menu
Substitute Name: C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\Start Menu

\\?\c:\\Users\Mr j bloggs\Templates: JUNCTION
Print Name : C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\Templates
Substitute Name: C:\Users\Mr j bloggs\AppData\Roaming\Microsoft\Windows\Templates

\\?\c:\\Users\Mr j bloggs\AppData\Local\Application Data: JUNCTION
Print Name : C:\Users\Mr j bloggs\AppData\Local
Substitute Name: C:\Users\Mr j bloggs\AppData\Local

\\?\c:\\Users\Mr j bloggs\AppData\Local\History: JUNCTION
Print Name : C:\Users\Mr j bloggs\AppData\Local\Microsoft\Windows\History
Substitute Name: C:\Users\Mr j bloggs\AppData\Local\Microsoft\Windows\History

\\?\c:\\Users\Mr j bloggs\AppData\Local\Temporary Internet Files: JUNCTION
Print Name : C:\Users\Mr j bloggs\AppData\Local\Microsoft\Windows\Temporary Internet Files
Substitute Name: C:\Users\Mr j bloggs\AppData\Local\Microsoft\Windows\Temporary Internet Files

...

...

...

...

...


Failed to open \\?\c:\\Users\Mr j bloggs\Desktop\spyware tools\RootRepeal2.exe: Access is denied.


\\?\c:\\Users\Mr j bloggs\Documents\My Music: JUNCTION
Print Name : C:\Users\Mr j bloggs\Music
Substitute Name: C:\Users\Mr j bloggs\Music

\\?\c:\\Users\Mr j bloggs\Documents\My Pictures: JUNCTION
Print Name : C:\Users\Mr j bloggs\Pictures
Substitute Name: C:\Users\Mr j bloggs\Pictures

\\?\c:\\Users\Mr j bloggs\Documents\My Videos: JUNCTION
Print Name : C:\Users\Mr j bloggs\Videos
Substitute Name: C:\Users\Mr j bloggs\Videos

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

..\\?\c:\\Users\Public\Documents\My Music: JUNCTION
Print Name : C:\Users\Public\Music
Substitute Name: C:\Users\Public\Music

\\?\c:\\Users\Public\Documents\My Pictures: JUNCTION
Print Name : C:\Users\Public\Pictures
Substitute Name: C:\Users\Public\Pictures

\\?\c:\\Users\Public\Documents\My Videos: JUNCTION
Print Name : C:\Users\Public\Videos
Substitute Name: C:\Users\Public\Videos

.\\?\c:\\Windows\AppPatch\Custom\Custom: MOUNT POINT
Substitute Name: \Device\__max++>\^



.\\?\c:\\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2DF2.tmp\ZAP2DF2.tmp: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3550.tmp\ZAP3550.tmp: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP41B5.tmp\ZAP41B5.tmp: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP81A.tmp\ZAP81A.tmp: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE752.tmp\ZAPE752.tmp: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPEEF0.tmp\ZAPEEF0.tmp: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\assembly\temp\temp: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\assembly\tmp\tmp: MOUNT POINT
Substitute Name: \Device\__max++>\^

.\\?\c:\\Windows\ehome\CreateDisc\style\style: MOUNT POINT
Substitute Name: \Device\__max++>\^

.\\?\c:\\Windows\Globalization\Globalization: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\Help\Corporate\Corporate: MOUNT POINT
Substitute Name: \Device\__max++>\^



\\?\c:\\Windows\Help\OEM\OEM: MOUNT POINT
Substitute Name: \Device\__max++>\^

...\\?\c:\\Windows\Installer\$PatchCache$\Managed\5C13C3F8A3C98AA4E8AF1792A0A75D33\1.0.2\1.0.2: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7447A0100000020\7.1.0\7.1.0: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\Installer\$PatchCache$\Managed\7A6460EF0D914B142ABBC2536D4472D0\1.0.0\1.0.0: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\Installer\$PatchCache$\Managed\C0F8BA8DBEEC92A4E85F12B96084314F\1.1.3\1.1.3: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\Installer\$PatchCache$\Managed\C44CC767CBB9D834AB3DDF5459DD41B8\1.0.0\1.0.0: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\Installer\$PatchCache$\Managed\D7314F9862C648A4DB8BE2A5B47BE100\1.0.0\1.0.0: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\LiveKernelReports\WATCHDOG\WATCHDOG: MOUNT POINT
Substitute Name: \Device\__max++>\^



\\?\c:\\Windows\Microsoft.NET\authman\authman: MOUNT POINT
Substitute Name: \Device\__max++>\^

.\\?\c:\\Windows\Minidump\Minidump: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ModemLogs\ModemLogs: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\nap\configuration\configuration: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\Panther\setup.exe\setup.exe: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\PCHEALTH\ERRORREP\QHEADLES\QHEADLES: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\PCHEALTH\ERRORREP\QSIGNOFF\QSIGNOFF: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\PLA\Templates\Templates: MOUNT POINT
Substitute Name: \Device\__max++>\^

.\\?\c:\\Windows\registration\CRMLog\CRMLog: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SchCache\SchCache: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\security\templates\templates: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\GameExplorer\GameExplorer: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\TfsStore\Tfs_DAV\Tfs_DAV: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\AppData\Roaming\Media Center Programs\Media Center Programs: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Quick Launch: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\Certificates: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\CRLs: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\CTLs: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\UPnP Device Host\Description Documents\Description Documents: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Network Shortcuts\Network Shortcuts: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\Printer Shortcuts: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Recent\Recent: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Templates\Templates: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\Desktop\Desktop: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\Documents\Documents: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\Downloads\Downloads: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\Favorites\Favorites: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\Links\Links: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\Music\Music: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\Pictures\Pictures: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\Saved Games\Saved Games: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\LocalService\Videos\Videos: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\GameExplorer\GameExplorer: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Temporary Internet Files: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows Media Player NSS\3.0\SCPD\SCPD: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Media Center Programs\Media Center Programs: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Quick Launch: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\Certificates: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\CRLs: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\CTLs: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\Cookies: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Network Shortcuts\Network Shortcuts: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\Printer Shortcuts: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Recent\Recent: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Templates\Templates: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\Desktop\Desktop: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\Documents\Documents: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\Downloads\Downloads: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\Favorites\Favorites: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\Links\Links: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\Music\Music: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\Pictures\Pictures: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\Saved Games\Saved Games: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\ServiceProfiles\NetworkService\Videos\Videos: MOUNT POINT
Substitute Name: \Device\__max++>\^

.

...\\?\c:\\Windows\SoftwareDistribution\AuthCabs\Downloaded\Downloaded: MOUNT POINT
Substitute Name: \Device\__max++>\^



\\?\c:\\Windows\SoftwareDistribution\Download\048167a0e1ade3ad1df23834faa1532e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6000.16922_none_c5603d92a849343f\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6000.16922_none_c5603d92a849343f: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\048167a0e1ade3ad1df23834faa1532e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6000.21122_none_c5e9b27fc167074b\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6000.21122_none_c5e9b27fc167074b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\048167a0e1ade3ad1df23834faa1532e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6001.18326_none_c74a7d60a56c2a8c\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6001.18326_none_c74a7d60a56c2a8c: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\048167a0e1ade3ad1df23834faa1532e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6001.22515_none_c7ddebb3be829235\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6001.22515_none_c7ddebb3be829235: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\048167a0e1ade3ad1df23834faa1532e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6002.18106_none_c9469106a28244f5\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6002.18106_none_c9469106a28244f5: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\048167a0e1ade3ad1df23834faa1532e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6002.22218_none_c9c75e79bba6335e\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6002.22218_none_c9c75e79bba6335e: MOUNT POINT
Substitute Name: \Device\__max++>\^

...

...

...

...

...\\?\c:\\Windows\SoftwareDistribution\Download\1a0b7baeebffa6ce5672fb92bf0f43c5\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16901_none_6a4b28f6b6fb9243\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16901_none_6a4b28f6b6fb9243: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\1a0b7baeebffa6ce5672fb92bf0f43c5\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21101_none_6ad49de3d019654f\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21101_none_6ad49de3d019654f: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\1a0b7baeebffa6ce5672fb92bf0f43c5\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18304_none_6c34687ab41f6f39\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18304_none_6c34687ab41f6f39: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\1a0b7baeebffa6ce5672fb92bf0f43c5\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22489_none_6c6c8757cd796d3e\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22489_none_6c6c8757cd796d3e: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\1a0b7baeebffa6ce5672fb92bf0f43c5\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18082_none_6dc25a6eb1887137\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18082_none_6dc25a6eb1887137: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\1a0b7baeebffa6ce5672fb92bf0f43c5\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22191_none_6e402703caaf139b\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22191_none_6e402703caaf139b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehepg_31bf3856ad364e35_6.0.6000.16919_none_d9bb3268d1c1d4a1\msil_ehepg_31bf3856ad364e35_6.0.6000.16919_none_d9bb3268d1c1d4a1: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehepg_31bf3856ad364e35_6.0.6000.21119_none_da44a755eadfa7ad\msil_ehepg_31bf3856ad364e35_6.0.6000.21119_none_da44a755eadfa7ad: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehepg_31bf3856ad364e35_6.0.6001.18322_none_db8f9f1ccef6d022\msil_ehepg_31bf3856ad364e35_6.0.6001.18322_none_db8f9f1ccef6d022: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehepg_31bf3856ad364e35_6.0.6001.22511_none_dc230d6fe80d37cb\msil_ehepg_31bf3856ad364e35_6.0.6001.22511_none_dc230d6fe80d37cb: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehepg_31bf3856ad364e35_6.0.6002.18103_none_dd8cb30ccc0c03e2\msil_ehepg_31bf3856ad364e35_6.0.6002.18103_none_dd8cb30ccc0c03e2: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehepg_31bf3856ad364e35_6.0.6002.22215_none_de0d807fe52ff24b\msil_ehepg_31bf3856ad364e35_6.0.6002.22215_none_de0d807fe52ff24b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehexthost_31bf3856ad364e35_6.0.6000.16919_none_bd00af1ec1b137ec\msil_ehexthost_31bf3856ad364e35_6.0.6000.16919_none_bd00af1ec1b137ec: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehexthost_31bf3856ad364e35_6.0.6000.21119_none_bd8a240bdacf0af8\msil_ehexthost_31bf3856ad364e35_6.0.6000.21119_none_bd8a240bdacf0af8: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehiextens_31bf3856ad364e35_6.0.6000.16919_none_fbe3b60309b695e1\msil_ehiextens_31bf3856ad364e35_6.0.6000.16919_none_fbe3b60309b695e1: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehiextens_31bf3856ad364e35_6.0.6000.21119_none_fc6d2af022d468ed\msil_ehiextens_31bf3856ad364e35_6.0.6000.21119_none_fc6d2af022d468ed: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehrecobj_31bf3856ad364e35_6.0.6000.16919_none_88f94fd24b0cabe6\msil_ehrecobj_31bf3856ad364e35_6.0.6000.16919_none_88f94fd24b0cabe6: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehrecobj_31bf3856ad364e35_6.0.6000.21119_none_8982c4bf642a7ef2\msil_ehrecobj_31bf3856ad364e35_6.0.6000.21119_none_8982c4bf642a7ef2: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehrecobj_31bf3856ad364e35_6.0.6001.18322_none_8acdbc864841a767\msil_ehrecobj_31bf3856ad364e35_6.0.6001.18322_none_8acdbc864841a767: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehrecobj_31bf3856ad364e35_6.0.6001.22511_none_8b612ad961580f10\msil_ehrecobj_31bf3856ad364e35_6.0.6001.22511_none_8b612ad961580f10: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehrecobj_31bf3856ad364e35_6.0.6002.18103_none_8ccad0764556db27\msil_ehrecobj_31bf3856ad364e35_6.0.6002.18103_none_8ccad0764556db27: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehrecobj_31bf3856ad364e35_6.0.6002.22215_none_8d4b9de95e7ac990\msil_ehrecobj_31bf3856ad364e35_6.0.6002.22215_none_8d4b9de95e7ac990: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehshell_31bf3856ad364e35_6.0.6000.16919_none_89ae4da9447562f3\msil_ehshell_31bf3856ad364e35_6.0.6000.16919_none_89ae4da9447562f3: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehshell_31bf3856ad364e35_6.0.6000.21119_none_8a37c2965d9335ff\msil_ehshell_31bf3856ad364e35_6.0.6000.21119_none_8a37c2965d9335ff: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehshell_31bf3856ad364e35_6.0.6001.18322_none_8b82ba5d41aa5e74\msil_ehshell_31bf3856ad364e35_6.0.6001.18322_none_8b82ba5d41aa5e74: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehshell_31bf3856ad364e35_6.0.6001.22511_none_8c1628b05ac0c61d\msil_ehshell_31bf3856ad364e35_6.0.6001.22511_none_8c1628b05ac0c61d: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehshell_31bf3856ad364e35_6.0.6002.18103_none_8d7fce4d3ebf9234\msil_ehshell_31bf3856ad364e35_6.0.6002.18103_none_8d7fce4d3ebf9234: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_ehshell_31bf3856ad364e35_6.0.6002.22215_none_8e009bc057e3809d\msil_ehshell_31bf3856ad364e35_6.0.6002.22215_none_8e009bc057e3809d: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_mcstore_31bf3856ad364e35_6.0.6000.16919_none_c3b09a0a40ad4247\msil_mcstore_31bf3856ad364e35_6.0.6000.16919_none_c3b09a0a40ad4247: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_mcstore_31bf3856ad364e35_6.0.6000.21119_none_c43a0ef759cb1553\msil_mcstore_31bf3856ad364e35_6.0.6000.21119_none_c43a0ef759cb1553: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_mcstore_31bf3856ad364e35_6.0.6001.18322_none_c58506be3de23dc8\msil_mcstore_31bf3856ad364e35_6.0.6001.18322_none_c58506be3de23dc8: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_mcstore_31bf3856ad364e35_6.0.6001.22511_none_c618751156f8a571\msil_mcstore_31bf3856ad364e35_6.0.6001.22511_none_c618751156f8a571: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_mcstore_31bf3856ad364e35_6.0.6002.18103_none_c7821aae3af77188\msil_mcstore_31bf3856ad364e35_6.0.6002.18103_none_c7821aae3af77188: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_mcstore_31bf3856ad364e35_6.0.6002.22215_none_c802e821541b5ff1\msil_mcstore_31bf3856ad364e35_6.0.6002.22215_none_c802e821541b5ff1: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.16919_none_4eabf16098b9d989\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.16919_none_4eabf16098b9d989: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.21119_none_4f35664db1d7ac95\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.21119_none_4f35664db1d7ac95: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6001.18322_none_50805e1495eed50a\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6001.18322_none_50805e1495eed50a: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6001.22511_none_5113cc67af053cb3\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6001.22511_none_5113cc67af053cb3: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6002.18103_none_527d7204930408ca\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6002.18103_none_527d7204930408ca: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6002.22215_none_52fe3f77ac27f733\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6002.22215_none_52fe3f77ac27f733: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.16919_none_313a40105a0dd6a3\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.16919_none_313a40105a0dd6a3: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.21119_none_31c3b4fd732ba9af\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.21119_none_31c3b4fd732ba9af: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.18322_none_330eacc45742d224\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.18322_none_330eacc45742d224: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.22511_none_33a21b17705939cd\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.22511_none_33a21b17705939cd: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6002.18103_none_350bc0b4545805e4\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6002.18103_none_350bc0b4545805e4: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6002.22215_none_358c8e276d7bf44d\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6002.22215_none_358c8e276d7bf44d: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.16919_none_23959903cf2642b9\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.16919_none_23959903cf2642b9: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.21119_none_241f0df0e84415c5\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.21119_none_241f0df0e84415c5: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6001.18322_none_256a05b7cc5b3e3a\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6001.18322_none_256a05b7cc5b3e3a: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6001.22511_none_25fd740ae571a5e3\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6001.22511_none_25fd740ae571a5e3: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6002.18103_none_276719a7c97071fa\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6002.18103_none_276719a7c97071fa: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6002.22215_none_27e7e71ae2946063\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6002.22215_none_27e7e71ae2946063: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6000.16919_none_b4272457a51e9088\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6000.16919_none_b4272457a51e9088: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6000.21119_none_b4b09944be3c6394\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6000.21119_none_b4b09944be3c6394: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6001.18322_none_b5fb910ba2538c09\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6001.18322_none_b5fb910ba2538c09: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6001.22511_none_b68eff5ebb69f3b2\x86_microsoft-windows-directshow-mpeg2_31bf3856ad364e35_6.0.6001.22511_none_b68eff5ebb69f3b2: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6000.16919_none_3426e4871c4578dd\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6000.16919_none_3426e4871c4578dd: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6000.21119_none_34b0597435634be9\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6000.21119_none_34b0597435634be9: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6001.18322_none_35fb513b197a745e\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6001.18322_none_35fb513b197a745e: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6001.22511_none_368ebf8e3290dc07\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6001.22511_none_368ebf8e3290dc07: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6000.16919_none_cc3b9dbbcca0c455\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6000.16919_none_cc3b9dbbcca0c455: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6000.21119_none_ccc512a8e5be9761\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6000.21119_none_ccc512a8e5be9761: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.18322_none_ce100a6fc9d5bfd6\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.18322_none_ce100a6fc9d5bfd6: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.22511_none_cea378c2e2ec277f\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.22511_none_cea378c2e2ec277f: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.16919_none_12cf71cda28c3451\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.16919_none_12cf71cda28c3451: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.21119_none_1358e6babbaa075d\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.21119_none_1358e6babbaa075d: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.18322_none_14a3de819fc12fd2\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.18322_none_14a3de819fc12fd2: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.22511_none_15374cd4b8d7977b\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.22511_none_15374cd4b8d7977b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.16919_none_3241e223dcd398af\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.16919_none_3241e223dcd398af: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.21119_none_32cb5710f5f16bbb\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.21119_none_32cb5710f5f16bbb: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.18322_none_34164ed7da089430\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.18322_none_34164ed7da089430: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22511_none_34a9bd2af31efbd9\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22511_none_34a9bd2af31efbd9: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.16919_none_2df5b0db851b701f\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.16919_none_2df5b0db851b701f: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.21119_none_2e7f25c89e39432b\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.21119_none_2e7f25c89e39432b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.16919_none_2d53d4336cfb74fa\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.16919_none_2d53d4336cfb74fa: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.21119_none_2ddd492086194806\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.21119_none_2ddd492086194806: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.18322_none_2f2840e76a30707b\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.18322_none_2f2840e76a30707b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.22511_none_2fbbaf3a8346d824\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.22511_none_2fbbaf3a8346d824: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6000.16919_none_2bd15bd5bbe22a69\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6000.16919_none_2bd15bd5bbe22a69: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6000.21119_none_2c5ad0c2d4fffd75\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6000.21119_none_2c5ad0c2d4fffd75: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.18322_none_2da5c889b91725ea\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.18322_none_2da5c889b91725ea: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.22511_none_2e3936dcd22d8d93\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.22511_none_2e3936dcd22d8d93: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.18103_none_2fa2dc79b62c59aa\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.18103_none_2fa2dc79b62c59aa: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.22215_none_3023a9eccf504813\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.22215_none_3023a9eccf504813: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.16919_none_24e0915264d38aee\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.16919_none_24e0915264d38aee: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.21119_none_256a063f7df15dfa\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.21119_none_256a063f7df15dfa: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.18322_none_26b4fe066208866f\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.18322_none_26b4fe066208866f: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.22511_none_27486c597b1eee18\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.22511_none_27486c597b1eee18: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.16919_none_5023fdaf535192a0\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.16919_none_5023fdaf535192a0: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.21119_none_50ad729c6c6f65ac\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.21119_none_50ad729c6c6f65ac: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6001.18322_none_51f86a6350868e21\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6001.18322_none_51f86a6350868e21: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6001.22511_none_528bd8b6699cf5ca\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6001.22511_none_528bd8b6699cf5ca: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6002.18103_none_53f57e534d9bc1e1\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6002.18103_none_53f57e534d9bc1e1: MOUNT POINT
Substitute Name: \Device\__max++>\^



\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6002.22215_none_54764bc666bfb04a\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6002.22215_none_54764bc666bfb04a: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.16919_none_36d4c2db16b955b5\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.16919_none_36d4c2db16b955b5: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.21119_none_375e37c82fd728c1\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.21119_none_375e37c82fd728c1: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.16919_none_3a23083c2e16dd5c\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.16919_none_3a23083c2e16dd5c: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.21119_none_3aac7d294734b068\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.21119_none_3aac7d294734b068: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.16919_none_ccdc1605cc4128ba\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.16919_none_ccdc1605cc4128ba: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.21119_none_cd658af2e55efbc6\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.21119_none_cd658af2e55efbc6: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.18322_none_ceb082b9c976243b\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.18322_none_ceb082b9c976243b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.22511_none_cf43f10ce28c8be4\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.22511_none_cf43f10ce28c8be4: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6000.16919_none_4980b80557951a97\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6000.16919_none_4980b80557951a97: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6000.21119_none_4a0a2cf270b2eda3\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6000.21119_none_4a0a2cf270b2eda3: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.18322_none_4b5524b954ca1618\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.18322_none_4b5524b954ca1618: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.22511_none_4be8930c6de07dc1\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.22511_none_4be8930c6de07dc1: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.16919_none_3d4262f7625d9044\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.16919_none_3d4262f7625d9044: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.21119_none_3dcbd7e47b7b6350\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.21119_none_3dcbd7e47b7b6350: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.16919_none_de90102a91400756\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.16919_none_de90102a91400756: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.21119_none_df198517aa5dda62\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.21119_none_df198517aa5dda62: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.18322_none_e0647cde8e7502d7\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.18322_none_e0647cde8e7502d7: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.22511_none_e0f7eb31a78b6a80\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.22511_none_e0f7eb31a78b6a80: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.16919_none_da1531e459e90b01\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.16919_none_da1531e459e90b01: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.21119_none_da9ea6d17306de0d\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.21119_none_da9ea6d17306de0d: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.18322_none_dbe99e98571e0682\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.18322_none_dbe99e98571e0682: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\471f83cd4b9c2294c1f02fbc9be65d35\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.22511_none_dc7d0ceb70346e2b\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.22511_none_dc7d0ceb70346e2b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\91a9b8f920315471a87cc9055727dc6b\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16926_none_f09243146e5e8997\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16926_none_f09243146e5e8997: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\91a9b8f920315471a87cc9055727dc6b\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21126_none_f11bb801877c5ca3\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21126_none_f11bb801877c5ca3: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\91a9b8f920315471a87cc9055727dc6b\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18330_none_f267b0126b929e6f\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18330_none_f267b0126b929e6f: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\91a9b8f920315471a87cc9055727dc6b\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22521_none_f2fd1ef984a738c6\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22521_none_f2fd1ef984a738c6: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\91a9b8f920315471a87cc9055727dc6b\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18111_none_f464c40268a7d22f\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18111_none_f464c40268a7d22f: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\91a9b8f920315471a87cc9055727dc6b\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22224_none_f4e691bf81cad9ef\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22224_none_f4e691bf81cad9ef: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6000.21125_none_395fe8aa98b803ee\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6000.21125_none_395fe8aa98b803ee: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6001.22518_none_3b5421de95d38ed8\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6001.22518_none_3b5421de95d38ed8: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6002.22223_none_3d2ac2689306813a\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6002.22223_none_3d2ac2689306813a: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6000.16926_none_7abd15c3656ef988\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6000.16926_none_7abd15c3656ef988: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6000.21125_none_7b458a667e8db33d\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6000.21125_none_7b458a667e8db33d: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6001.18330_none_7c9282c162a30e60\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6001.18330_none_7c9282c162a30e60: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6001.22518_none_7d39c39a7ba93e27\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6001.22518_none_7d39c39a7ba93e27: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6002.18111_none_7e8f96b15fb84220\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6002.18111_none_7e8f96b15fb84220: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\b3da37d1490a6f1e10a887a163a78ba5\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6002.22223_none_7f10642478dc3089\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6002.22223_none_7f10642478dc3089: MOUNT POINT
Substitute Name: \Device\__max++>\^

.\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.16916_none_a9e05e55f5aca86f\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.16916_none_a9e05e55f5aca86f: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.21116_none_aa69d3430eca7b7b\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.21116_none_aa69d3430eca7b7b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_6.0.6000.16916_none_ebdb680516458e6e\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_6.0.6000.16916_none_ebdb680516458e6e: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_6.0.6000.21116_none_ec64dcf22f63617a\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_6.0.6000.21116_none_ec64dcf22f63617a: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.16916_none_b2f810b7d9a605d2\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.16916_none_b2f810b7d9a605d2: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.21116_none_b38185a4f2c3d8de\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.21116_none_b38185a4f2c3d8de: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18319_none_b4e1503bd6c9e2c8\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18319_none_b4e1503bd6c9e2c8: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.22508_none_b574be8eefe04a71\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.22508_none_b574be8eefe04a71: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.18100_none_b6c9915bd3f03513\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.18100_none_b6c9915bd3f03513: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.22212_none_b74a5eceed14237c\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.22212_none_b74a5eceed14237c: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6000.16916_none_deda9f807f4ec541\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6000.16916_none_deda9f807f4ec541: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6000.21116_none_df64146d986c984d\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6000.21116_none_df64146d986c984d: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.18319_none_e0c3df047c72a237\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.18319_none_e0c3df047c72a237: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.22508_none_e1574d57958909e0\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.22508_none_e1574d57958909e0: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..nternetcontrolpanel_31bf3856ad364e35_6.0.6000.16916_none_8d4e9eec54b4aaf6\x86_microsoft-windows-i..nternetcontrolpanel_31bf3856ad364e35_6.0.6000.16916_none_8d4e9eec54b4aaf6: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..nternetcontrolpanel_31bf3856ad364e35_6.0.6000.21116_none_8dd813d96dd27e02\x86_microsoft-windows-i..nternetcontrolpanel_31bf3856ad364e35_6.0.6000.21116_none_8dd813d96dd27e02: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16916_none_fffdec59a4af2c65\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16916_none_fffdec59a4af2c65: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.21116_none_00876146bdccff71\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.21116_none_00876146bdccff71: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18319_none_01e72bdda1d3095b\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18319_none_01e72bdda1d3095b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22508_none_027a9a30bae97104\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22508_none_027a9a30bae97104: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18100_none_03cf6cfd9ef95ba6\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18100_none_03cf6cfd9ef95ba6: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22212_none_04503a70b81d4a0f\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22212_none_04503a70b81d4a0f: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6000.16916_none_726565555a594d2c\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6000.16916_none_726565555a594d2c: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6000.21116_none_72eeda4273772038\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6000.21116_none_72eeda4273772038: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6001.18319_none_744ea4d9577d2a22\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6001.18319_none_744ea4d9577d2a22: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6001.22508_none_74e2132c709391cb\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6001.22508_none_74e2132c709391cb: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6000.16916_none_ac471aa909a2040b\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6000.16916_none_ac471aa909a2040b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6000.21116_none_acd08f9622bfd717\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6000.21116_none_acd08f9622bfd717: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18319_none_ae305a2d06c5e101\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18319_none_ae305a2d06c5e101: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.22508_none_aec3c8801fdc48aa\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.22508_none_aec3c8801fdc48aa: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.16916_none_f9a70f336e9aa6b8\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.16916_none_f9a70f336e9aa6b8: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.21116_none_fa30842087b879c4\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.21116_none_fa30842087b879c4: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.18319_none_fb904eb76bbe83ae\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.18319_none_fb904eb76bbe83ae: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.22508_none_fc23bd0a84d4eb57\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.22508_none_fc23bd0a84d4eb57: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.18100_none_fd788fd768e4d5f9\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.18100_none_fd788fd768e4d5f9: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.22212_none_fdf95d4a8208c462\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.22212_none_fdf95d4a8208c462: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.16916_none_95db47eb84802ce6\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.16916_none_95db47eb84802ce6: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.21116_none_9664bcd89d9dfff2\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.21116_none_9664bcd89d9dfff2: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6000.16916_none_5dfb83283d527f1d\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6000.16916_none_5dfb83283d527f1d: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6000.21116_none_5e84f81556705229\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6000.21116_none_5e84f81556705229: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6001.18319_none_5fe4c2ac3a765c13\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6001.18319_none_5fe4c2ac3a765c13: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6001.22508_none_607830ff538cc3bc\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6001.22508_none_607830ff538cc3bc: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6000.16916_none_692da8c08a37209f\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6000.16916_none_692da8c08a37209f: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6000.21116_none_69b71dada354f3ab\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6000.21116_none_69b71dada354f3ab: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6001.18319_none_6b16e844875afd95\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6001.18319_none_6b16e844875afd95: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6001.22508_none_6baa5697a071653e\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_6.0.6001.22508_none_6baa5697a071653e: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6000.16916_none_f1827f5cbd02b6c0\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6000.16916_none_f1827f5cbd02b6c0: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6000.21116_none_f20bf449d62089cc\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6000.21116_none_f20bf449d62089cc: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.18319_none_f36bbee0ba2693b6\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.18319_none_f36bbee0ba2693b6: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.22508_none_f3ff2d33d33cfb5f\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.22508_none_f3ff2d33d33cfb5f: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.16916_none_463de2434640df73\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.16916_none_463de2434640df73: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.21116_none_46c757305f5eb27f\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.21116_none_46c757305f5eb27f: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16916_none_11580b782505959b\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16916_none_11580b782505959b: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.21116_none_11e180653e2368a7\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.21116_none_11e180653e2368a7: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18319_none_13414afc22297291\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18319_none_13414afc22297291: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22508_none_13d4b94f3b3fda3a\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22508_none_13d4b94f3b3fda3a: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.18100_none_15298c1c1f4fc4dc\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.18100_none_15298c1c1f4fc4dc: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.22212_none_15aa598f3873b345\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.22212_none_15aa598f3873b345: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.16916_none_58b07842671a21a4\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.16916_none_58b07842671a21a4: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.21116_none_5939ed2f8037f4b0\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.21116_none_5939ed2f8037f4b0: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16916_none_2d76f8e51cda9b48\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16916_none_2d76f8e51cda9b48: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21116_none_2e006dd235f86e54\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21116_none_2e006dd235f86e54: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18319_none_2f60386919fe783e\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18319_none_2f60386919fe783e: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22508_none_2ff3a6bc3314dfe7\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22508_none_2ff3a6bc3314dfe7: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6000.16916_none_353b610816ff3030\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6000.16916_none_353b610816ff3030: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6000.21116_none_35c4d5f5301d033c\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6000.21116_none_35c4d5f5301d033c: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6001.18319_none_3724a08c14230d26\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6001.18319_none_3724a08c14230d26: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6001.22508_none_37b80edf2d3974cf\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6001.22508_none_37b80edf2d3974cf: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6000.16916_none_45b8a3358f604ac2\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6000.16916_none_45b8a3358f604ac2: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6000.21116_none_46421822a87e1dce\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6000.21116_none_46421822a87e1dce: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18319_none_47a1e2b98c8427b8\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18319_none_47a1e2b98c8427b8: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.22508_none_4835510ca59a8f61\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.22508_none_4835510ca59a8f61: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16916_none_c3e5ae00615563ed\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16916_none_c3e5ae00615563ed: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.21116_none_c46f22ed7a7336f9\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.21116_none_c46f22ed7a7336f9: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.16916_none_2a0ac4706805394a\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.16916_none_2a0ac4706805394a: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.21116_none_2a94395d81230c56\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.21116_none_2a94395d81230c56: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16916_none_62b7657bb0fb23c8\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16916_none_62b7657bb0fb23c8: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.21116_none_6340da68ca18f6d4\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.21116_none_6340da68ca18f6d4: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18319_none_64a0a4ffae1f00be\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18319_none_64a0a4ffae1f00be: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22508_none_65341352c7356867\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22508_none_65341352c7356867: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.18100_none_6688e61fab455309\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.18100_none_6688e61fab455309: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.22212_none_6709b392c4694172\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.22212_none_6709b392c4694172: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.16916_none_e6b0d1fa947e7800\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.16916_none_e6b0d1fa947e7800: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.21116_none_e73a46e7ad9c4b0c\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.21116_none_e73a46e7ad9c4b0c: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.16916_none_0b590716d6f937b2\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.16916_none_0b590716d6f937b2: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\d465720e0e6d39d4c8c1f6d80acfbc81\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.21116_none_0be27c03f0170abe\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.21116_none_0be27c03f0170abe: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-common_31bf3856ad364e35_6.0.6001.22522_none_044c3353295315ad\x86_microsoft-windows-smbserver-common_31bf3856ad364e35_6.0.6001.22522_none_044c3353295315ad: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6000.16927_none_d7f7c2a8f95f038d\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6000.16927_none_d7f7c2a8f95f038d: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6000.21127_none_d8813796127cd699\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6000.21127_none_d8813796127cd699: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.18331_none_d9cd2fa6f6931865\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.18331_none_d9cd2fa6f6931865: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.22522_none_da629e8e0fa7b2bc\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.22522_none_da629e8e0fa7b2bc: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.18112_none_dbca4396f3a84c25\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.18112_none_dbca4396f3a84c25: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\e299352e102f0c24faf167d1ff954d68\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.22225_none_dc4c11540ccb53e5\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.22225_none_dc4c11540ccb53e5: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\f01c4bbfa608298ce96317823815654c\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6000.16838_none_f831274072c7bd51\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6000.16838_none_f831274072c7bd51: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\f01c4bbfa608298ce96317823815654c\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6000.21033_none_f8b59abb8bea11aa\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6000.21033_none_f8b59abb8bea11aa: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\f01c4bbfa608298ce96317823815654c\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6001.18234_none_fa1364be6ff1e8e6\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6001.18234_none_fa1364be6ff1e8e6: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\f01c4bbfa608298ce96317823815654c\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6001.22403_none_fabc72e988f818ad\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6001.22403_none_fabc72e988f818ad: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\f01c4bbfa608298ce96317823815654c\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6002.18034_none_fbf9d88c6d183b31\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6002.18034_none_fbf9d88c6d183b31: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\Download\f01c4bbfa608298ce96317823815654c\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6002.22131_none_fc80747986388ef6\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6002.22131_none_fc80747986388ef6: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\PostRebootEventCache\PostRebootEventCache: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\SoftwareDistribution\ScanFile\ScanFile: MOUNT POINT
Substitute Name: \Device\__max++>\^

..\\?\c:\\Windows\System32\config\systemprofile\Application Data: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\AppData\Roaming
Substitute Name: C:\Windows\system32\config\systemprofile\AppData\Roaming

\\?\c:\\Windows\System32\config\systemprofile\Local Settings: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\AppData\Local
Substitute Name: C:\Windows\system32\config\systemprofile\AppData\Local

\\?\c:\\Windows\System32\config\systemprofile\My Documents: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\Documents
Substitute Name: C:\Windows\system32\config\systemprofile\Documents

\\?\c:\\Windows\System32\config\systemprofile\NetHood: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts
Substitute Name: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts

\\?\c:\\Windows\System32\config\systemprofile\PrintHood: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
Substitute Name: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts

\\?\c:\\Windows\System32\config\systemprofile\Recent: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent
Substitute Name: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent

\\?\c:\\Windows\System32\config\systemprofile\SendTo: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo
Substitute Name: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo

\\?\c:\\Windows\System32\config\systemprofile\Start Menu: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu
Substitute Name: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu

\\?\c:\\Windows\System32\config\systemprofile\Templates: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates
Substitute Name: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates

\\?\c:\\Windows\System32\config\systemprofile\AppData\Local\Application Data: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\AppData\Local
Substitute Name: C:\Windows\system32\config\systemprofile\AppData\Local

\\?\c:\\Windows\System32\config\systemprofile\AppData\Local\History: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History
Substitute Name: C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History

\\?\c:\\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
Substitute Name: C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files

\\?\c:\\Windows\System32\config\systemprofile\Documents\My Music: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\Music
Substitute Name: C:\Windows\system32\config\systemprofile\Music

\\?\c:\\Windows\System32\config\systemprofile\Documents\My Pictures: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\Pictures
Substitute Name: C:\Windows\system32\config\systemprofile\Pictures

\\?\c:\\Windows\System32\config\systemprofile\Documents\My Videos: JUNCTION
Print Name : C:\Windows\system32\config\systemprofile\Videos
Substitute Name: C:\Windows\system32\config\systemprofile\Vid

Failed to open \\?\c:\\Windows\System32\LogFiles\WMI\RtBackup: Access is denied.

..\\?\c:\\Windows\tracing\tracing: MOUNT POINT
Substitute Name: \Device\__max++>\^

..\\?\c:\\Windows\winsxs\InstallTemp\InstallTemp: MOUNT POINT
Substitute Name: \Device\__max++>\^

..\\?\c:\\Windows\winsxs\Temp\PendingDeletes\PendingDeletes: MOUNT POINT
Substitute Name: \Device\__max++>\^

\\?\c:\\Windows\winsxs\Temp\PendingRenames\PendingRenames: MOUNT POINT
Substitute Name: \Device\__max++>\^

====================================

OTL logfile created on: 22/10/2009 16:25:18 - Run 1
OTL by OldTimer - Version 3.0.21.0 Folder = C:\Users\Mr j bloggs\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 60.91% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): c:\pagefile.sys 3067 3067 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 14.27 Gb Free Space | 4.79% Space Free | Partition Type: NTFS
Drive D: | 6.04 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 232.83 Gb Total Space | 25.01 Gb Free Space | 10.74% Space Free | Partition Type: FAT32
Drive F: | 967.22 Mb Total Space | 967.20 Mb Free Space | 100.00% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
Drive H: | 117.24 Mb Total Space | 33.99 Mb Free Space | 29.00% Space Free | Partition Type: FAT
I: Drive not present or media not loaded

Computer Name: HOMEPC
Current User Name: Mr j bloggs
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2009/10/22 11:30:13 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Users\Mr j bloggs\Desktop\OTL.exe
PRC - [2009/09/17 14:29:04 | 00,645,328 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2009/09/16 10:22:08 | 00,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe
PRC - [2009/09/16 09:28:38 | 00,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/09/15 10:23:54 | 00,894,136 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MPFSrv.exe
PRC - [2009/08/19 16:37:40 | 00,092,008 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2009/08/10 15:57:49 | 00,107,832 | ---- | M] () -- C:\Windows\System32\PnkBstrB.exe
PRC - [2009/07/14 13:29:06 | 00,215,584 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe
PRC - [2009/07/14 12:28:00 | 00,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/07/10 00:26:20 | 00,865,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe
PRC - [2009/07/08 11:54:34 | 00,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009/07/07 19:10:02 | 02,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2009/04/27 11:39:50 | 00,121,376 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
PRC - [2009/04/15 09:42:54 | 00,186,912 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
PRC - [2009/04/15 09:42:52 | 00,133,664 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe
PRC - [2009/04/11 07:28:15 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wmiprvse.exe
PRC - [2009/04/11 07:28:08 | 00,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe
PRC - [2009/04/11 07:27:39 | 00,299,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\ieuser.exe
PRC - [2009/04/11 07:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE
PRC - [2009/01/23 10:46:14 | 00,203,280 | ---- | M] () -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2008/04/04 14:59:17 | 00,066,872 | ---- | M] () -- C:\Windows\System32\PnkBstrA.exe
PRC - [2008/01/19 08:33:09 | 00,125,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehtray.exe
PRC - [2008/01/19 08:33:09 | 00,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehmsas.exe
PRC - [2007/02/05 15:52:12 | 00,849,280 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliPoint\ipoint.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/09/23 13:33:42 | 01,141,200 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService [On_Demand | Stopped])
SRV - [2009/09/23 12:17:22 | 00,358,600 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService [On_Demand | Stopped])
SRV - [2009/09/16 11:23:32 | 00,365,072 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS [On_Demand | Stopped])
SRV - [2009/09/16 10:22:08 | 00,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield [Unknown | Running])
SRV - [2009/09/16 09:28:38 | 00,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon [On_Demand | Running])
SRV - [2009/09/15 10:23:54 | 00,894,136 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService [Auto | Running])
SRV - [2009/08/19 16:37:40 | 00,092,008 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService [Auto | Running])
SRV - [2009/08/10 15:57:49 | 00,107,832 | ---- | M] () -- C:\Windows\System32\PnkBstrB.exe -- (PnkBstrB [Auto | Running])
SRV - [2009/07/14 13:29:06 | 00,215,584 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe -- (nvsvc [Auto | Running])
SRV - [2009/07/14 12:28:00 | 00,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service [Auto | Running])
SRV - [2009/07/10 00:26:20 | 00,865,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc [Auto | Running])
SRV - [2009/07/08 11:54:34 | 00,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy [Auto | Running])
SRV - [2009/07/07 19:10:02 | 02,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc [Auto | Running])
SRV - [2009/04/27 11:39:50 | 00,121,376 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe -- (UpdateCenterService [Auto | Running])
SRV - [2009/04/15 09:42:54 | 00,186,912 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService [Auto | Running])
SRV - [2009/04/11 07:28:25 | 01,017,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtsvc.dll -- (Eventlog [Auto | Running])
SRV - [2009/03/30 05:42:14 | 00,066,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009/02/18 19:39:20 | 00,043,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009/02/18 19:38:43 | 00,129,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2009/02/18 19:38:42 | 00,879,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2009/01/23 10:46:14 | 00,203,280 | ---- | M] () -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service [Auto | Running])
SRV - [2008/04/04 14:59:17 | 00,066,872 | ---- | M] () -- C:\Windows\System32\PnkBstrA.exe -- (PnkBstrA [Auto | Running])
SRV - [2008/02/04 15:18:32 | 00,504,104 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Stopped])
SRV - [2008/01/19 08:38:24 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Stopped])
SRV - [2008/01/19 08:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [Disabled | Stopped])
SRV - [2008/01/19 08:33:09 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [Disabled | Stopped])
SRV - [2008/01/15 03:40:04 | 00,110,592 | ---- | M] (Apple, Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Disabled | Stopped])
SRV - [2007/07/24 16:17:08 | 00,229,376 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Disabled | Stopped])
SRV - [2007/01/19 12:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])
SRV - [2007/01/04 14:13:56 | 00,240,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc [On_Demand | Stopped])
SRV - [2006/11/02 13:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [Disabled | Stopped])
SRV - [2006/11/02 13:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Disabled | Stopped])
SRV - [2006/10/09 22:11:08 | 00,724,992 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService [On_Demand | Stopped])
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2009/10/12 21:24:56 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\Super-AS2\SASENUM.SYS -- (SASENUM [On_Demand | Stopped])
DRV - [2009/10/12 21:24:54 | 00,009,968 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\Super-AS2\SASDIFSV.SYS -- (SASDIFSV [System | Running])
DRV - [2009/09/23 16:10:06 | 00,207,280 | ---- | M] (PC Tools) -- C:\Windows\system32\drivers\PCTCore.sys -- (PCTCore [Boot | Running])
DRV - [2009/09/16 10:22:48 | 00,214,664 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk [System | Running])
DRV - [2009/09/16 10:22:48 | 00,079,816 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk [On_Demand | Running])
DRV - [2009/09/16 10:22:48 | 00,040,552 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfesmfk.sys -- (mfesmfk [On_Demand | Running])
DRV - [2009/09/16 10:22:48 | 00,035,272 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk [On_Demand | Running])
DRV - [2009/09/16 10:22:14 | 00,034,248 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mferkdk.sys -- (mferkdk [On_Demand | Stopped])
DRV - [2009/09/02 03:09:24 | 00,176,128 | ---- | M] (Realtek ) -- C:\Windows\System32\DRIVERS\Rtlh86.sys -- (RTL8169 [On_Demand | Running])
DRV - [2009/07/16 12:32:26 | 00,130,424 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\Drivers\Mpfp.sys -- (MPFP [System | Running])
DRV - [2009/07/14 19:54:00 | 09,557,216 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\DRIVERS\nvlddmkm.sys -- (nvlddmkm [On_Demand | Running])
DRV - [2009/04/11 05:46:08 | 00,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DRIVERS\usb8023.sys -- (USB_RNDIS [On_Demand | Stopped])
DRV - [2009/04/11 05:42:54 | 00,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Stopped])
DRV - [2009/03/27 01:16:28 | 00,012,672 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\System32\drivers\cpuz132_x32.sys -- (cpuz132 [On_Demand | Stopped])
DRV - [2009/03/09 12:25:12 | 00,038,304 | ---- | M] (NVIDIA Corp.) -- C:\Windows\System32\DRIVERS\nvoclock.sys -- (nvoclock [On_Demand | Running])
DRV - [2009/02/10 17:23:02 | 00,082,320 | ---- | M] (EZB Systems, Inc.) -- C:\Program Files\UltraISO\drivers\ISODrive.sys -- (ISODrive [System | Running])
DRV - [2008/04/16 15:51:56 | 00,022,784 | ---- | M] (Research In Motion Limited) -- C:\Windows\System32\Drivers\RimUsb.sys -- (RimUsb [On_Demand | Stopped])
DRV - [2008/03/26 12:19:28 | 00,015,872 | ---- | M] () -- C:\Windows\system32\DRIVERS\vburner.sys -- (vburner [Boot | Running])
DRV - [2007/10/03 22:55:36 | 00,019,240 | ---- | M] (Silicon Image, Inc) -- C:\Windows\system32\DRIVERS\SiWinAcc.sys -- (SiFilter [Boot | Running])
DRV - [2007/10/03 22:55:28 | 00,015,400 | ---- | M] (Silicon Image, Inc) -- C:\Windows\system32\DRIVERS\SiRemFil.sys -- (SiRemFil [Boot | Running])
DRV - [2007/10/03 22:55:08 | 00,080,424 | ---- | M] (Silicon Image, Inc) -- C:\Windows\system32\DRIVERS\SI3132.sys -- (SI3132 [Boot | Running])
DRV - [2007/05/18 17:04:16 | 00,015,872 | ---- | M] () -- C:\Windows\System32\drivers\bfturboh.sys -- (bfturboh [On_Demand | Stopped])
DRV - [2007/03/08 23:18:00 | 00,008,320 | ---- | M] (GARMIN Corp.) -- C:\Windows\System32\drivers\grmnusb.sys -- (grmnusb [On_Demand | Stopped])
DRV - [2007/01/09 10:22:28 | 00,006,144 | ---- | M] (Chic) -- C:\Windows\System32\DRIVERS\moufiltr.sys -- (moufiltr [On_Demand | Stopped])
DRV - [2006/12/05 15:39:12 | 01,963,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DRIVERS\VX1000.sys -- (VX1000 [On_Demand | Stopped])
DRV - [2006/11/07 23:02:40 | 00,024,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DRIVERS\point32k.sys -- (Point32 [On_Demand | Running])
DRV - [2006/11/02 10:51:45 | 00,900,712 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300 [Disabled | Stopped])
DRV - [2006/11/02 10:51:38 | 00,420,968 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx [Disabled | Stopped])
DRV - [2006/11/02 10:51:34 | 00,316,520 | ---- | M] (Emulex) -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor [Disabled | Stopped])
DRV - [2006/11/02 10:51:32 | 00,297,576 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci [Disabled | Stopped])
DRV - [2006/11/02 10:51:25 | 00,235,112 | ---- | M] (ULi Electronics Inc.) -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci [Disabled | Stopped])
DRV - [2006/11/02 10:51:25 | 00,232,040 | ---- | M] (Intel Corporation) -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV [Disabled | Stopped])
DRV - [2006/11/02 10:51:00 | 00,147,048 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320 [Disabled | Stopped])
DRV - [2006/11/02 10:50:45 | 00,115,816 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2 [Disabled | Stopped])
DRV - [2006/11/02 10:50:41 | 00,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid [Disabled | Stopped])
DRV - [2006/11/02 10:50:35 | 00,106,088 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx [Disabled | Stopped])
DRV - [2006/11/02 10:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata [Disabled | Stopped])
DRV - [2006/11/02 10:50:35 | 00,098,408 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m [Disabled | Stopped])
DRV - [2006/11/02 10:50:19 | 00,045,160 | ---- | M] (IBM Corporation) -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960 [Disabled | Stopped])
DRV - [2006/11/02 10:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp [Disabled | Stopped])
DRV - [2006/11/02 10:50:16 | 00,071,784 | ---- | M] (Silicon Integrated Systems) -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4 [Disabled | Stopped])
DRV - [2006/11/02 10:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx [Disabled | Stopped])
DRV - [2006/11/02 10:50:10 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas [Disabled | Stopped])
DRV - [2006/11/02 10:50:10 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI [Disabled | Stopped])
DRV - [2006/11/02 10:50:10 | 00,038,504 | ---- | M] (Silicon Integrated Systems Corp.) -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2 [Disabled | Stopped])
DRV - [2006/11/02 10:50:10 | 00,037,480 | ---- | M] (Hewlett-Packard Company) -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs [Disabled | Stopped])
DRV - [2006/11/02 10:50:09 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arc.sys -- (arc [Disabled | Stopped])
DRV - [2006/11/02 10:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid [Disabled | Stopped])
DRV - [2006/11/02 10:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi [Disabled | Stopped])
DRV - [2006/11/02 10:50:05 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS [Disabled | Stopped])
DRV - [2006/11/02 10:50:05 | 00,035,944 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx [Disabled | Stopped])
DRV - [2006/11/02 10:50:04 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC [Disabled | Stopped])
DRV - [2006/11/02 10:50:03 | 00,034,920 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3 [Disabled | Stopped])
DRV - [2006/11/02 10:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation) -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x [Disabled | Stopped])
DRV - [2006/11/02 10:49:56 | 00,031,848 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi [Disabled | Stopped])
DRV - [2006/11/02 10:49:53 | 00,028,776 | ---- | M] (LSI Logic Corporation) -- C:\Windows\system32\drivers\megasas.sys -- (megasas [Disabled | Stopped])
DRV - [2006/11/02 10:49:30 | 00,017,512 | ---- | M] (VIA Technologies, Inc.) -- C:\Windows\system32\drivers\viaide.sys -- (viaide [Disabled | Stopped])
DRV - [2006/11/02 10:49:28 | 00,016,488 | ---- | M] (CMD Technology, Inc.) -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide [Disabled | Stopped])
DRV - [2006/11/02 10:49:20 | 00,014,952 | ---- | M] (Acer Laboratories Inc.) -- C:\Windows\system32\drivers\aliide.sys -- (aliide [Disabled | Stopped])
DRV - [2006/11/02 09:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserid.sys -- (Brserid [Disabled | Stopped])
DRV - [2006/11/02 09:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer [On_Demand | Stopped])
DRV - [2006/11/02 09:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp [On_Demand | Stopped])
DRV - [2006/11/02 09:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo [On_Demand | Stopped])
DRV - [2006/11/02 09:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm [Disabled | Stopped])
DRV - [2006/11/02 09:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm [Disabled | Stopped])
DRV - [2006/11/02 08:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies) -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi [Disabled | Stopped])
DRV - [2006/11/02 08:30:54 | 00,117,760 | ---- | M] (Intel Corporation) -- C:\Windows\System32\DRIVERS\E1G60I32.sys -- (E1G60 [On_Demand | Stopped])
DRV - [2006/11/02 07:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv [Auto | Running])
DRV - [2006/09/19 15:44:04 | 00,015,664 | ---- | M] (GEAR Software Inc.) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\S-1-5-21-2380594860-1575461441-4214207244-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\S-1-5-21-2380594860-1575461441-4214207244-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/01/30 14:46:24 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2009/08/30 12:17:25 | 00,000,000 | ---D | M]


O1 HOSTS File: (27 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat Pro 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat Pro 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat Pro 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat Pro 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\..Trusted Domains: inetpsa.com ([portail] https in Trusted sites)
O15 - HKU\S-1-5-21-2380594860-1575461441-4214207244-1000\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\Super-AS2\SASWINLO.dll - C:\Program Files\Super-AS2\SASWINLO.dll (SUPERAntiSpyware.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\Super-AS2\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2007/07/20 15:41:52 | 00,000,049 | R--- | M] () - D:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2009/10/20 11:14:42 | 00,000,000 | ---D | M] - F:\autorun.inf -- [ FAT ]
O32 - AutoRun File - [2009/02/02 15:14:58 | 20,954,704 | ---- | M] () - H:\autobackupinternational.exe -- [ FAT ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/10/16 18:30:21 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/10/15 19:23:33 | 00,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2009/10/19 17:15:50 | 00,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2009/10/20 12:05:13 | 00,000,000 | ---D | C] -- C:\Users\Mr j bloggs\AppData\Roaming\.clamwin
[2009/10/16 16:05:44 | 00,000,000 | ---D | C] -- C:\Users\Mr j bloggs\AppData\Roaming\Malwarebytes
[2009/10/15 19:23:33 | 00,000,000 | ---D | C] -- C:\Users\Mr j bloggs\AppData\Roaming\PC Tools
[2009/10/16 17:39:49 | 00,000,000 | ---D | C] -- C:\Users\Mr j bloggs\AppData\Roaming\SUPERAntiSpyware.com
[2009/10/15 15:34:12 | 00,000,000 | ---D | C] -- C:\Users\Mr j bloggs\AppData\Roaming\Uniblue
[2009/10/20 11:27:17 | 00,000,000 | ---D | C] -- C:\Users\Mr j bloggs\AppData\Local\Adobe
[2009/10/22 11:19:13 | 00,000,000 | ---D | C] -- C:\Users\Mr j bloggs\AppData\Local\temp
[2009/10/15 19:45:39 | 00,000,000 | ---D | C] -- C:\Users\Mr j bloggs\AppData\Local\Threat Expert
[2009/10/15 19:23:33 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2009/10/09 15:17:17 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2009/10/19 17:41:34 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/16 12:22:14 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/10/15 19:23:33 | 00,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2009/10/16 17:39:49 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2009/10/19 17:15:43 | 00,000,000 | ---D | C] -- C:\Program Files\Super-AS2
[2009/10/19 16:44:00 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Installer Clean Up
[2009/10/09 14:23:14 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live Safety Center
[2009/10/22 11:30:10 | 00,521,216 | ---- | C] (OldTimer Tools) -- C:\Users\Mr j bloggs\Desktop\OTL.exe
[2009/10/22 11:08:52 | 00,000,000 | ---D | C] -- C:\thcbytes
[2009/10/21 22:48:21 | 00,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2009/10/21 22:48:21 | 00,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2009/10/21 22:48:21 | 00,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2009/10/21 22:48:21 | 00,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2009/10/21 22:48:14 | 00,000,000 | ---D | C] -- C:\Windows\ERDNT
[2009/10/21 21:58:44 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/10/21 21:54:28 | 00,000,000 | ---D | C] -- C:\Avenger
[2009/10/21 21:28:25 | 00,000,000 | ---D | C] -- C:\Users\Mr j bloggs\Desktop\tools
[2009/10/19 17:41:36 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/10/19 17:41:34 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/10/19 16:42:22 | 00,000,000 | ---D | C] -- C:\WINSSLog
[2009/10/19 10:21:11 | 04,045,528 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Mr j bloggs\Desktop\zttoy.exe
[2009/10/16 16:33:37 | 00,000,000 | ---D | C] -- C:\Users\Mr j bloggs\Desktop\spyware tools
[2009/10/16 12:04:42 | 00,000,000 | ---D | C] -- C:\Windows\Downloaded Installations
[2009/10/15 19:23:55 | 00,229,304 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2009/10/15 19:23:55 | 00,097,208 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2009/10/15 19:23:51 | 00,207,280 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2009/10/15 19:23:50 | 00,087,784 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2009/10/15 19:23:44 | 00,070,408 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2009/10/15 19:21:58 | 34,102,304 | ---- | C] (PC Tools ) -- C:\Users\Mr j bloggs\Desktop\sdasetup_aff.exe
[2009/10/15 15:23:16 | 00,000,000 | ---D | C] -- C:\Windows\pss
[2009/10/14 14:13:31 | 00,834,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
[2009/10/14 14:13:30 | 03,599,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2009/10/14 14:13:30 | 01,176,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
[2009/10/14 14:13:28 | 06,079,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
[2009/10/14 14:13:27 | 00,180,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2009/10/14 14:13:26 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll
[2009/10/14 14:13:24 | 00,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2009/10/14 14:13:04 | 00,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msasn1.dll
[2009/10/14 14:12:59 | 03,548,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2009/10/14 14:12:58 | 03,600,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2009/10/14 14:12:52 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msv1_0.dll
[2009/10/14 14:12:43 | 00,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\srv2.sys
[2009/10/14 14:09:24 | 00,604,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMSPDMOD.DLL
[2009/10/08 13:46:57 | 00,000,000 | ---D | C] -- C:\Users\Mr j bloggs\Desktop\walking
[2008/01/25 12:47:00 | 00,217,088 | ---- | C] ( ) -- C:\Users\Mr j bloggs\AppData\Local\Interop.Microsoft.Office.Core.dll
[2007/08/09 16:50:38 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\Users\Mr j bloggs\AppData\Local\stdole.dll

========== Files - Modified Within 30 Days ==========

[2009/10/22 16:19:26 | 00,003,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/10/22 16:19:26 | 00,003,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/10/22 15:56:58 | 00,013,507 | ---- | M] () -- C:\Windows\System32\Config.MPF
[2009/10/22 15:56:26 | 00,033,354 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2009/10/22 15:56:26 | 00,033,354 | ---- | M] () -- C:\ProgramData\nvModes.001
[2009/10/22 15:56:23 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/10/22 15:56:18 | 00,000,256 | ---- | M] () -- C:\Windows\tasks\Check Updates for Windows Live Toolbar.job
[2009/10/22 14:26:55 | 00,716,194 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/10/22 14:26:55 | 00,622,516 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/10/22 14:26:55 | 00,107,948 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/10/22 14:22:10 | 00,095,616 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Windows\junction.exe
[2009/10/22 14:21:02 | 00,046,375 | ---- | M] () -- C:\Users\Mr j bloggs\Desktop\junction.zip
[2009/10/22 14:19:27 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/10/22 11:48:35 | 02,680,437 | -H-- | M] () -- C:\Users\Mr j bloggs\AppData\Local\IconCache.db
[2009/10/22 11:30:13 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Users\Mr j bloggs\Desktop\OTL.exe
[2009/10/22 11:17:47 | 00,000,215 | ---- | M] () -- C:\Windows\system.ini
[2009/10/21 22:59:18 | 00,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2009/10/21 21:43:48 | 00,724,954 | ---- | M] () -- C:\Users\Mr j bloggs\Desktop\screwyou.zip
[2009/10/21 15:31:00 | 03,351,153 | R--- | M] () -- C:\Users\Mr j bloggs\Desktop\thcbytes.exe
[2009/10/21 15:29:06 | 00,047,104 | ---- | M] () -- C:\Users\Mr j bloggs\Desktop\Win32kDiag.exe
[2009/10/20 20:25:18 | 00,002,509 | ---- | M] () -- C:\Users\Mr j bloggs\Desktop\Memeo AutoBackup.lnk
[2009/10/20 11:37:12 | 00,125,440 | ---- | M] () -- C:\Users\Mr j bloggs\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/19 17:15:45 | 00,000,853 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/10/19 10:21:25 | 04,045,528 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Mr j bloggs\Desktop\zttoy.exe
[2009/10/16 16:03:12 | 00,201,030 | ---- | M] () -- C:\Users\Mr j bloggs\Desktop\lspfix.zip
[2009/10/15 19:23:48 | 00,001,759 | ---- | M] () -- C:\Users\Public\Desktop\Spyware Doctor.lnk
[2009/10/15 19:23:12 | 34,102,304 | ---- | M] (PC Tools ) -- C:\Users\Mr j bloggs\Desktop\sdasetup_aff.exe
[2009/10/11 08:10:09 | 00,236,544 | ---- | M] () -- C:\Windows\PEV.exe
[2009/10/06 16:31:30 | 00,087,784 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2009/09/24 08:55:46 | 00,229,304 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2009/09/24 08:55:46 | 00,097,208 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2009/09/23 16:10:06 | 00,207,280 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys

========== Files - No Company Name ==========
[2009/10/22 14:21:02 | 00,046,375 | ---- | C] () -- C:\Users\Mr j bloggs\Desktop\junction.zip
[2009/10/21 22:48:21 | 00,236,544 | ---- | C] () -- C:\Windows\PEV.exe
[2009/10/21 22:48:21 | 00,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2009/10/21 22:48:21 | 00,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2009/10/21 22:48:21 | 00,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2009/10/21 21:57:07 | 03,351,153 | R--- | C] () -- C:\Users\Mr j bloggs\Desktop\thcbytes.exe
[2009/10/21 21:41:46 | 00,724,954 | ---- | C] () -- C:\Users\Mr j bloggs\Desktop\screwyou.zip
[2009/10/19 21:15:25 | 00,047,104 | ---- | C] () -- C:\Users\Mr j bloggs\Desktop\Win32kDiag.exe
[2009/10/19 18:01:50 | 02,680,437 | -H-- | C] () -- C:\Users\Mr j bloggs\AppData\Local\IconCache.db
[2009/10/19 17:15:45 | 00,000,853 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/10/16 16:03:10 | 00,201,030 | ---- | C] () -- C:\Users\Mr j bloggs\Desktop\lspfix.zip
[2009/10/15 19:23:55 | 00,007,387 | ---- | C] () -- C:\Windows\System32\drivers\pctgntdi.cat
[2009/10/15 19:23:51 | 00,007,412 | ---- | C] () -- C:\Windows\System32\drivers\PCTAppEvent.cat
[2009/10/15 19:23:51 | 00,007,383 | ---- | C] () -- C:\Windows\System32\drivers\pctcore.cat
[2009/10/15 19:23:48 | 00,001,759 | ---- | C] () -- C:\Users\Public\Desktop\Spyware Doctor.lnk
[2009/10/15 19:23:44 | 00,007,383 | ---- | C] () -- C:\Windows\System32\drivers\pctplsg.cat
[2009/08/07 19:51:34 | 00,178,430 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2009/07/26 19:34:40 | 00,033,354 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/07/26 19:34:37 | 00,033,354 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/06/19 14:43:39 | 00,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/05/25 22:27:54 | 00,000,052 | ---- | C] () -- C:\Users\Mr j bloggs\AppData\Local\mm-device-08.ini
[2009/03/05 06:54:58 | 00,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2009/02/19 14:14:46 | 00,015,872 | ---- | C] () -- C:\Windows\System32\drivers\bfturboh.sys
[2008/11/07 15:57:08 | 00,015,872 | ---- | C] () -- C:\Windows\System32\drivers\vburner.sys
[2008/10/10 18:32:50 | 00,006,416 | ---- | C] () -- C:\Windows\UN080325.INI
[2008/10/10 18:32:38 | 00,008,068 | ---- | C] () -- C:\Windows\UN020914.INI
[2008/10/07 09:13:30 | 00,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008/04/04 14:58:32 | 00,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2008/02/28 15:30:08 | 00,008,784 | ---- | C] () -- C:\Windows\System32\ractrlkeyhook.dll
[2008/02/03 16:46:20 | 00,000,319 | ---- | C] () -- C:\Windows\game.ini
[2007/11/30 16:38:48 | 00,022,328 | ---- | C] () -- C:\Users\Mr j bloggs\AppData\Roaming\PnkBstrK.sys
[2007/04/11 14:26:40 | 00,053,912 | ---- | C] () -- C:\Users\Mr j bloggs\AppData\Roaming\GDIPFONTCACHEV1.DAT
[2007/03/18 22:31:00 | 00,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2007/03/17 20:50:52 | 00,125,440 | ---- | C] () -- C:\Users\Mr j bloggs\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/03/15 16:24:01 | 00,053,912 | ---- | C] () -- C:\Users\Mr j bloggs\AppData\Local\GDIPFONTCACHEV1.DAT
[2007/03/15 16:23:45 | 00,001,356 | ---- | C] () -- C:\Users\Mr j bloggs\AppData\Local\d3d9caps.dat
[2006/11/02 13:50:50 | 00,000,174 | -HS- | C] () -- C:\Program Files\desktop.ini
[2006/11/02 13:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:23:31 | 00,000,215 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 11:23:31 | 00,000,144 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 08:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/04/19 15:14:32 | 00,015,498 | ---- | C] () -- C:\Windows\VX1000.ini
[1999/01/27 13:39:06 | 00,065,024 | ---- | C] () -- C:\Windows\System32\indounin.dll
[1998/08/16 06:00:00 | 00,004,096 | ---- | C] () -- C:\Windows\System32\sysres.dll
[1997/06/13 07:56:08 | 00,056,832 | ---- | C] () -- C:\Windows\System32\Iyvu9_32.dll

========== LOP Check ==========

[2007/11/20 17:49:30 | 00,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming
[2006/11/02 13:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Media Center Programs
[2007/11/20 17:49:30 | 00,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming
[2006/11/02 13:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Media Center Programs
[2009/10/20 12:05:13 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming
[2009/10/20 12:05:13 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\.clamwin
[2009/01/21 15:20:54 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\Ahead
[2009/10/16 16:26:23 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\Azureus
[2009/10/01 17:16:21 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\Bioshock
[2009/08/10 18:00:50 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\Command & Conquer 3 Tiberium Wars Demo
[2009/01/24 13:34:25 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\GARMIN
[2007/06/13 22:50:01 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\Juniper Networks
[2006/11/02 13:37:34 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\Media Center Programs
[2008/10/23 14:54:59 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\Motive
[2008/11/07 14:41:08 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\NCH Software
[2008/11/07 14:46:23 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\NCH Swift Sound
[2007/05/28 21:52:38 | 00,000,000 | RH-D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\SecuROM
[2008/04/05 19:28:31 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\TomTom
[2008/09/26 18:05:59 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\Ubisoft
[2009/10/15 15:34:12 | 00,000,000 | ---D | M] -- C:\Users\Mr j bloggs\AppData\Roaming\Uniblue
[2009/10/22 15:56:18 | 00,000,256 | ---- | M] () -- C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job
[2009/09/17 15:13:19 | 00,000,350 | ---- | M] () -- C:\Windows\Tasks\McDefragTask.job
[2009/04/03 14:30:40 | 00,000,342 | ---- | M] () -- C:\Windows\Tasks\McQcTask.job
[2009/10/22 14:19:27 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
[2009/10/22 11:48:38 | 00,032,622 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 195 bytes -> C:\ProgramData\temp:DFC5A2B2
@Alternate Data Stream - 114 bytes -> C:\ProgramData\temp:A8ADE5D8
< End of report >
Proud member - Unified Network of Instructors and Trained Eliminators
Posted Image

I do not accept personal donations for assistance provided. I would ask that you instead consider donating the greatest gift - Organ Donation. Your organs are of no use to you when your gone. You will save a life that would otherwise be lost!

http://donatelife.net/register-now/

#15 SDC0603

SDC0603
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:10:16 PM

Posted 22 October 2009 - 12:01 PM

Thankyou. I will leave you to it for now then :(

Can you tell what this particular rootkit was designed to do, i.e. keylogger, sniffer, backdoor, or was it just intended to be a pain in the ars@? Would any of my data have been compromised and sent to some distant server farm??

I would also be interested in a paraphrased explanation of all the steps we have been through (not super tech and not noob either) so I can understand what all of the custom programs did. I am genuinely interested.

I also need guidance cleaning up after my somewhat frantic steps taken (prior to contacting BC) by neatly uninstalling mbam, SAS, spybot, onecare, etc, as all these still seem to be referred in the registry/logs even though I uninstalled them, and some have/had protected exe files due to rootkit exploits.

Essentially I am aiming for a clean system (no s/w conflicts) and then be able to run my McAfee security centre and a specialist spyware/malware app (spyware blaster/guard) to protect my system.

Thanks for your continued support, and I look forward to the all clear.......




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users