Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

suspected rootkit infection


  • This topic is locked This topic is locked
38 replies to this topic

#1 jrr91

jrr91

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:11:06 PM

Posted 06 November 2009 - 11:54 PM

Referred to this forum by boopme. We started our discussion at http://www.bleepingcomputer.com/forums/t/269670/windows-explorer-is-unavailable/
After looking at my Win32kDiag.exe log file boopme suggested there may be a rootkit variant and recommended I post the log file here and see what happens.
Thanks for looking, I'm keeping my fingers crossed.


Contents of win32kDiag.txt are as follows:

Running from: C:\Documents and Settings\User\Desktop\Win32kDiag.exe

Log file at : C:\Documents and Settings\User\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'...



Found mount point : C:\WINDOWS\$hf_mig$\KB912812\KB912812

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB916281\KB916281

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB918899\KB918899

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB920213\KB920213

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB922760\KB922760

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB924496\KB924496

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB925454\KB925454

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB928090\KB928090

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB931768\KB931768

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB932168\KB932168

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB933566\KB933566

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB937143\KB937143

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB939653\KB939653

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB943460\KB943460

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ADDINS\ADDINS

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP121.tmp\ZAP121.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP13F.tmp\ZAP13F.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP1AA.tmp\ZAP1AA.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP380.tmp\ZAP380.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP385.tmp\ZAP385.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ASSEMBLY\TEMP\TEMP

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ASSEMBLY\TMP\TMP

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Cache\Cache

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Config\Config

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Connection Wizard\Connection Wizard

Mount point destination : \Device\__max++>\^

Cannot access: C:\WINDOWS\explorer.exe

[1] 2007-06-13 05:26:03 1033216 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe (Microsoft Corporation)

[1] 2007-06-13 04:23:07 1033216 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe (Microsoft Corporation)

[1] 2004-08-03 16:56:50 1032192 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe (Microsoft Corporation)

[1] 2008-04-13 18:12:19 1033728 C:\WINDOWS\explorer.exe ()

[1] 2008-04-13 18:12:19 1033728 C:\WINDOWS\ServicePackFiles\i386\explorer.exe (Microsoft Corporation)

[1] 2004-08-03 16:56:50 1032192 C:\i386\explorer.exe (Microsoft Corporation)



Found mount point : C:\WINDOWS\Help\SBSI\Training\WXPPer\Cbz\Cbz

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Help\SBSI\Training\WXPPer\Lib\Lib

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Help\SBSI\Training\WXPPer\Wave\Wave

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\IME\CHSIME\APPLETS\APPLETS

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\IME\CHTIME\Applets\Applets

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\IME\IMEJP\APPLETS\APPLETS

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\IME\IMEJP98\IMEJP98

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\IME\IMJP8_1\APPLETS\APPLETS

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\IME\IMKR6_1\APPLETS\APPLETS

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\IME\IMKR6_1\DICTS\DICTS

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\IME\SHARED\RES\RES

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}\{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\JAVA\CLASSES\CLASSES

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\JAVA\TRUSTLIB\TRUSTLIB

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\MSAPPS\MSINFO\MSINFO

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\PCHEALTH\ERRORREP\QHEADLES\QHEADLES

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\PCHEALTH\ERRORREP\QSIGNOFF\QSIGNOFF

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\PCHEALTH\HELPCTR\BATCH\BATCH

Mount point destination : \Device\__max++>\^

Cannot access: C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\helpsvc.exe

[1] 2004-08-04 05:00:00 743936 C:\WINDOWS\$NtServicePackUninstall$\helpsvc.exe (Microsoft Corporation)

[1] 2008-04-13 18:12:21 744448 C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\helpsvc.exe ()

[1] 2008-04-13 18:12:21 744448 C:\WINDOWS\ServicePackFiles\i386\helpsvc.exe (Microsoft Corporation)

[1] 2004-08-04 05:00:00 743936 C:\i386\helpsvc.exe (Microsoft Corporation)



Found mount point : C:\WINDOWS\PCHEALTH\HELPCTR\Config\CheckPoint\CheckPoint

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\PCHEALTH\HELPCTR\HelpFiles\HelpFiles

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\PCHEALTH\HELPCTR\InstalledSKUs\InstalledSKUs

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\DFS

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\PCHEALTH\HELPCTR\Temp\Temp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\PIF\PIF

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Registration\CRMLog\CRMLog

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\setup.pss\setupupd\temp\temp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\88a28ec3847c01e056ff4268caaa255d\backup\backup

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\e9fe9a7f9083b5302f779977df11c395\backup\backup

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

Mount point destination : \Device\__max++>\^

Cannot access: C:\WINDOWS\SYSTEM32\eventlog.dll

[1] 2004-08-03 16:56:44 55808 C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll (Microsoft Corporation)

[1] 2008-04-13 18:11:53 56320 C:\WINDOWS\ServicePackFiles\i386\eventlog.dll (Microsoft Corporation)

[1] 2008-04-13 18:11:53 61952 C:\WINDOWS\SYSTEM32\eventlog.dll ()

[2] 2008-04-13 18:11:53 56320 C:\WINDOWS\SYSTEM32\logevent.dll (Microsoft Corporation)

[1] 2004-08-03 16:56:44 55808 C:\i386\eventlog.dll (Microsoft Corporation)



Found mount point : C:\WINDOWS\Temp\Google Toolbar\Google Toolbar

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\History\Results\Results

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00000\MCE00000

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00001\MCE00001

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00002\MCE00002

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00003\MCE00003

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00004\MCE00004

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00005\MCE00005

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00006\MCE00006

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00007\MCE00007

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00008\MCE00008

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00009\MCE00009

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0000a\MCE0000a

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0000b\MCE0000b

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0000c\MCE0000c

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0000d\MCE0000d

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0000e\MCE0000e

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0000f\MCE0000f

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00010\MCE00010

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00011\MCE00011

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00012\MCE00012

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00013\MCE00013

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00014\MCE00014

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00015\MCE00015

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00016\MCE00016

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00017\MCE00017

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00018\MCE00018

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00019\MCE00019

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0001a\MCE0001a

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0001b\MCE0001b

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0001c\MCE0001c

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0001d\MCE0001d

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0001e\MCE0001e

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0001f\MCE0001f

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00020\MCE00020

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00021\MCE00021

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00022\MCE00022

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00023\MCE00023

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00024\MCE00024

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00025\MCE00025

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00026\MCE00026

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00027\MCE00027

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00028\MCE00028

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00029\MCE00029

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0002a\MCE0002a

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0002b\MCE0002b

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0002c\MCE0002c

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0002d\MCE0002d

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0002e\MCE0002e

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0002f\MCE0002f

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00030\MCE00030

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00031\MCE00031

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00032\MCE00032

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00033\MCE00033

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00034\MCE00034

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00035\MCE00035

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00036\MCE00036

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00037\MCE00037

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00038\MCE00038

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00039\MCE00039

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0003a\MCE0003a

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0003b\MCE0003b

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0003c\MCE0003c

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0003d\MCE0003d

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0003e\MCE0003e

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0003f\MCE0003f

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00040\MCE00040

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00041\MCE00041

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00042\MCE00042

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00043\MCE00043

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00044\MCE00044

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00045\MCE00045

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00046\MCE00046

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00047\MCE00047

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00048\MCE00048

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00049\MCE00049

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0004a\MCE0004a

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0004b\MCE0004b

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0004c\MCE0004c

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0004d\MCE0004d

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0004e\MCE0004e

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0004f\MCE0004f

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00050\MCE00050

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00051\MCE00051

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00052\MCE00052

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00053\MCE00053

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00054\MCE00054

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00055\MCE00055

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00056\MCE00056

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00057\MCE00057

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00058\MCE00058

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00059\MCE00059

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0005a\MCE0005a

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0005b\MCE0005b

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0005c\MCE0005c

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0005d\MCE0005d

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0005e\MCE0005e

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0005f\MCE0005f

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00060\MCE00060

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00061\MCE00061

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00062\MCE00062

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00063\MCE00063

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00064\MCE00064

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00065\MCE00065

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00066\MCE00066

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00067\MCE00067

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00068\MCE00068

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00069\MCE00069

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0006a\MCE0006a

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0006b\MCE0006b

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0006c\MCE0006c

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0006d\MCE0006d

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0006e\MCE0006e

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0006f\MCE0006f

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00070\MCE00070

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00071\MCE00071

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00072\MCE00072

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00073\MCE00073

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00074\MCE00074

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00075\MCE00075

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00076\MCE00076

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00077\MCE00077

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00078\MCE00078

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00079\MCE00079

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0007a\MCE0007a

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0007b\MCE0007b

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0007c\MCE0007c

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0007d\MCE0007d

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0007e\MCE0007e

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0007f\MCE0007f

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00080\MCE00080

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00081\MCE00081

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00082\MCE00082

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00083\MCE00083

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00084\MCE00084

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00085\MCE00085

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00086\MCE00086

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00087\MCE00087

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00088\MCE00088

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00089\MCE00089

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0008a\MCE0008a

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0008b\MCE0008b

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0008c\MCE0008c

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0008d\MCE0008d

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0008e\MCE0008e

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0008f\MCE0008f

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00090\MCE00090

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00091\MCE00091

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00092\MCE00092

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00093\MCE00093

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00094\MCE00094

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00095\MCE00095

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00096\MCE00096

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00097\MCE00097

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00098\MCE00098

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE00099\MCE00099

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0009a\MCE0009a

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0009b\MCE0009b

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0009c\MCE0009c

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0009d\MCE0009d

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0009e\MCE0009e

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE0009f\MCE0009f

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000a0\MCE000a0

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000a1\MCE000a1

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000a2\MCE000a2

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000a3\MCE000a3

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000a4\MCE000a4

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000a5\MCE000a5

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000a6\MCE000a6

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000a7\MCE000a7

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000a8\MCE000a8

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000a9\MCE000a9

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000aa\MCE000aa

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000ab\MCE000ab

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000ac\MCE000ac

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000ad\MCE000ad

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000ae\MCE000ae

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000af\MCE000af

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000b0\MCE000b0

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000b1\MCE000b1

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000b2\MCE000b2

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000b3\MCE000b3

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000b4\MCE000b4

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000b5\MCE000b5

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000b6\MCE000b6

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000b7\MCE000b7

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000b8\MCE000b8

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000b9\MCE000b9

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000ba\MCE000ba

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000bb\MCE000bb

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000bc\MCE000bc

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000bd\MCE000bd

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000be\MCE000be

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000bf\MCE000bf

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000c0\MCE000c0

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000c1\MCE000c1

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000c2\MCE000c2

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000c3\MCE000c3

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000c4\MCE000c4

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000c5\MCE000c5

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000c6\MCE000c6

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000c7\MCE000c7

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000c8\MCE000c8

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000c9\MCE000c9

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000ca\MCE000ca

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000cb\MCE000cb

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000cc\MCE000cc

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000cd\MCE000cd

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000ce\MCE000ce

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000cf\MCE000cf

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000d0\MCE000d0

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000d1\MCE000d1

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000d2\MCE000d2

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000d3\MCE000d3

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000d4\MCE000d4

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000d5\MCE000d5

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000d6\MCE000d6

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000d7\MCE000d7

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000d8\MCE000d8

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000d9\MCE000d9

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000da\MCE000da

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000db\MCE000db

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000dc\MCE000dc

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000dd\MCE000dd

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000de\MCE000de

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000df\MCE000df

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000e0\MCE000e0

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000e1\MCE000e1

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000e2\MCE000e2

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000e3\MCE000e3

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000e4\MCE000e4

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000e5\MCE000e5

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000e6\MCE000e6

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000e7\MCE000e7

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000e8\MCE000e8

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000e9\MCE000e9

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000ea\MCE000ea

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000eb\MCE000eb

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000ec\MCE000ec

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000ed\MCE000ed

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000ee\MCE000ee

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000ef\MCE000ef

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000f0\MCE000f0

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000f1\MCE000f1

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000f2\MCE000f2

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\MCE000f3\MCE000f3

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu100.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu101.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu10B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu112.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu113.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu11B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu126.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu145.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu14D.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu14F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu150.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu151.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu158.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu15A.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu167.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu168.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu16B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu170.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu175.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu180.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu186.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu18A.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu18D.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu18F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu193.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu19B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu19C.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1A.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1A2.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1AB.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1AC.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1AD.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1B4.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1B8.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1BB.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1BF.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1C.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1C8.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1D.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1E.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1E4.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1ED.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1F1.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1FA.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu1FC.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu20.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu21.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu215.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu22.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu226.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu23.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu238.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu23F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu24.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu244.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu248.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu24C.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu24E.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu25.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu258.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu26.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu27.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu28.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu29.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu2A.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu2B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu2B2.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu2B4.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu2C.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu2D.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu2DF.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu2E.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu2F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu30.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu30F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu31.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu313.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu32.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu33.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu333.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu334.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu34B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu39.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu391.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu3F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu4.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu44.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu45.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu46.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu48.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu4A.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu4B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu4C.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu4C5.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu4E.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu50.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu51.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu52C.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu55.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu56.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu57.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu5F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu69.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu6F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu70.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu72.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu77.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu791.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu7D.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu806.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu82.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu842.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu86.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu90.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu91.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu96.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu97.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcu9E.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcuA0.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcuAB.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcuAC.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcuB1.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcuBF.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcuC5.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcuC8.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcuCE.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcuD9.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcuDF.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcuEF.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\mcuFF.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\RtSigs\Data\Data

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\SansaUpdater\SansaUpdater

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\_ISTMP0.DIR\_ISTMP0.DIR

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\{4511E6C2-C2AD-4387-A111-70F2DB8F48C6}\Disk1\Disk1

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\{53620028-DD98-41A8-BDD7-DA6B10C49C92}\{53620028-DD98-41A8-BDD7-DA6B10C49C92}

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\{7A900EAB-DA37-4554-AF19-9C337476D05D}\{7A900EAB-DA37-4554-AF19-9C337476D05D}

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\{971C5099-088D-456A-84E6-4C143D40D2D1}\Disk1\Disk1

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\{9E2514D9-DC24-4634-B348-61F3EF0F1628}\{9E2514D9-DC24-4634-B348-61F3EF0F1628}

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\{B673B7FC-FADA-4C41-A5CD-C069F9D39879}\{E2D7E05E-C8C7-45F4-8D89-D6696075E0B7}\{E2D7E05E-C8C7-45F4-8D89-D6696075E0B7}

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\{E2D27B84-6365-11D6-9BAF-0090271AF8A4}\{E2D27B84-6365-11D6-9BAF-0090271AF8A4}

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Temp\{EE6699B3-E5AD-4E59-8F2B-207DF630670C}\{EE6699B3-E5AD-4E59-8F2B-207DF630670C}

Mount point destination : \Device\__max++>\^



Finished!

Edited by Orange Blossom, 07 November 2009 - 07:34 PM.
Fixed link. ~ OB


BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:06 PM

Posted 10 November 2009 - 02:02 PM

Hello jrr91,

Please save this file to your desktop.
Click on Start->Run, and copy-paste the following command (the bolded text)

"%userprofile%\desktop\win32kdiag.exe" -f -r

into the "Open" box, and click OK.
When it's finished, there will be a log called Win32kDiag.txt on your desktop.
Please open it with notepad and post the contents here.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 jrr91

jrr91
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:11:06 PM

Posted 10 November 2009 - 05:11 PM

I'm so glad my number finally came up!
Thank you in advance SifuMike, for taking your time to help me out.

win32kdiag.txt file as requested:


Running from: C:\Documents and Settings\User\desktop\win32kdiag.exe

Log file at : C:\Documents and Settings\User\Desktop\Win32kDiag.txt

Removing all found mount points.

Attempting to reset file permissions.

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'...



Found mount point : C:\WINDOWS\$hf_mig$\KB912812\KB912812

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB912812\KB912812

Found mount point : C:\WINDOWS\$hf_mig$\KB916281\KB916281

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB916281\KB916281

Found mount point : C:\WINDOWS\$hf_mig$\KB918899\KB918899

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB918899\KB918899

Found mount point : C:\WINDOWS\$hf_mig$\KB920213\KB920213

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB920213\KB920213

Found mount point : C:\WINDOWS\$hf_mig$\KB922760\KB922760

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB922760\KB922760

Found mount point : C:\WINDOWS\$hf_mig$\KB924496\KB924496

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB924496\KB924496

Found mount point : C:\WINDOWS\$hf_mig$\KB925454\KB925454

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB925454\KB925454

Found mount point : C:\WINDOWS\$hf_mig$\KB928090\KB928090

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB928090\KB928090

Found mount point : C:\WINDOWS\$hf_mig$\KB931768\KB931768

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB931768\KB931768

Found mount point : C:\WINDOWS\$hf_mig$\KB932168\KB932168

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB932168\KB932168

Found mount point : C:\WINDOWS\$hf_mig$\KB933566\KB933566

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB933566\KB933566

Found mount point : C:\WINDOWS\$hf_mig$\KB937143\KB937143

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB937143\KB937143

Found mount point : C:\WINDOWS\$hf_mig$\KB939653\KB939653

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB939653\KB939653

Found mount point : C:\WINDOWS\$hf_mig$\KB943460\KB943460

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB943460\KB943460

Found mount point : C:\WINDOWS\ADDINS\ADDINS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ADDINS\ADDINS

Found mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP121.tmp\ZAP121.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP121.tmp\ZAP121.tmp

Found mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP13F.tmp\ZAP13F.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP13F.tmp\ZAP13F.tmp

Found mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP1AA.tmp\ZAP1AA.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP1AA.tmp\ZAP1AA.tmp

Found mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP380.tmp\ZAP380.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP380.tmp\ZAP380.tmp

Found mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP385.tmp\ZAP385.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ASSEMBLY\NativeImages_v2.0.50727_32\Temp\ZAP385.tmp\ZAP385.tmp

Found mount point : C:\WINDOWS\ASSEMBLY\TEMP\TEMP

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ASSEMBLY\TEMP\TEMP

Found mount point : C:\WINDOWS\ASSEMBLY\TMP\TMP

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ASSEMBLY\TMP\TMP

Found mount point : C:\WINDOWS\Cache\Cache

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Cache\Cache

Found mount point : C:\WINDOWS\Config\Config

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Config\Config

Found mount point : C:\WINDOWS\Connection Wizard\Connection Wizard

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Connection Wizard\Connection Wizard

Cannot access: C:\WINDOWS\explorer.exe

Attempting to restore permissions of : C:\WINDOWS\explorer.exe

Found mount point : C:\WINDOWS\Help\SBSI\Training\WXPPer\Cbz\Cbz

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Help\SBSI\Training\WXPPer\Cbz\Cbz

Found mount point : C:\WINDOWS\Help\SBSI\Training\WXPPer\Lib\Lib

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Help\SBSI\Training\WXPPer\Lib\Lib

Found mount point : C:\WINDOWS\Help\SBSI\Training\WXPPer\Wave\Wave

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Help\SBSI\Training\WXPPer\Wave\Wave

Found mount point : C:\WINDOWS\IME\CHSIME\APPLETS\APPLETS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\IME\CHSIME\APPLETS\APPLETS

Found mount point : C:\WINDOWS\IME\CHTIME\Applets\Applets

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\IME\CHTIME\Applets\Applets

Found mount point : C:\WINDOWS\IME\IMEJP\APPLETS\APPLETS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\IME\IMEJP\APPLETS\APPLETS

Found mount point : C:\WINDOWS\IME\IMEJP98\IMEJP98

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\IME\IMEJP98\IMEJP98

Found mount point : C:\WINDOWS\IME\IMJP8_1\APPLETS\APPLETS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\IME\IMJP8_1\APPLETS\APPLETS

Found mount point : C:\WINDOWS\IME\IMKR6_1\APPLETS\APPLETS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\IME\IMKR6_1\APPLETS\APPLETS

Found mount point : C:\WINDOWS\IME\IMKR6_1\DICTS\DICTS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\IME\IMKR6_1\DICTS\DICTS

Found mount point : C:\WINDOWS\IME\SHARED\RES\RES

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\IME\SHARED\RES\RES

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729

Found mount point : C:\WINDOWS\Installer\{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}\{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}\{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}

Found mount point : C:\WINDOWS\JAVA\CLASSES\CLASSES

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\JAVA\CLASSES\CLASSES

Found mount point : C:\WINDOWS\JAVA\TRUSTLIB\TRUSTLIB

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\JAVA\TRUSTLIB\TRUSTLIB

Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs

Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files

Found mount point : C:\WINDOWS\MSAPPS\MSINFO\MSINFO

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\MSAPPS\MSINFO\MSINFO

Found mount point : C:\WINDOWS\PCHEALTH\ERRORREP\QHEADLES\QHEADLES

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHEALTH\ERRORREP\QHEADLES\QHEADLES

Found mount point : C:\WINDOWS\PCHEALTH\ERRORREP\QSIGNOFF\QSIGNOFF

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHEALTH\ERRORREP\QSIGNOFF\QSIGNOFF

Found mount point : C:\WINDOWS\PCHEALTH\HELPCTR\BATCH\BATCH

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHEALTH\HELPCTR\BATCH\BATCH

Cannot access: C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\helpsvc.exe

Attempting to restore permissions of : C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\helpsvc.exe

Found mount point : C:\WINDOWS\PCHEALTH\HELPCTR\Config\CheckPoint\CheckPoint

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHEALTH\HELPCTR\Config\CheckPoint\CheckPoint

Found mount point : C:\WINDOWS\PCHEALTH\HELPCTR\HelpFiles\HelpFiles

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHEALTH\HELPCTR\HelpFiles\HelpFiles

Found mount point : C:\WINDOWS\PCHEALTH\HELPCTR\InstalledSKUs\InstalledSKUs

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHEALTH\HELPCTR\InstalledSKUs\InstalledSKUs

Found mount point : C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\DFS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\DFS

Found mount point : C:\WINDOWS\PCHEALTH\HELPCTR\Temp\Temp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHEALTH\HELPCTR\Temp\Temp

Found mount point : C:\WINDOWS\PIF\PIF

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PIF\PIF

Found mount point : C:\WINDOWS\Registration\CRMLog\CRMLog

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Registration\CRMLog\CRMLog

Found mount point : C:\WINDOWS\REPAIR\Backup\BootableSystemState\BootableSystemState

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\REPAIR\Backup\BootableSystemState\BootableSystemState

Found mount point : C:\WINDOWS\REPAIR\Backup\ServiceState\ServiceState

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\REPAIR\Backup\ServiceState\ServiceState

Found mount point : C:\WINDOWS\setup.pss\setupupd\temp\temp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\setup.pss\setupupd\temp\temp

Found mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\88a28ec3847c01e056ff4268caaa255d\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\88a28ec3847c01e056ff4268caaa255d\backup\backup

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\e9fe9a7f9083b5302f779977df11c395\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\e9fe9a7f9083b5302f779977df11c395\backup\backup

Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

Cannot access: C:\WINDOWS\SYSTEM32\eventlog.dll

Attempting to restore permissions of : C:\WINDOWS\SYSTEM32\eventlog.dll

[1] 2004-08-03 16:56:44 55808 C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll (Microsoft Corporation)

[1] 2008-04-13 18:11:53 56320 C:\WINDOWS\ServicePackFiles\i386\eventlog.dll (Microsoft Corporation)

[1] 2008-04-13 18:11:53 61952 C:\WINDOWS\SYSTEM32\eventlog.dll ()

[2] 2008-04-13 18:11:53 56320 C:\WINDOWS\SYSTEM32\logevent.dll (Microsoft Corporation)

[1] 2004-08-03 16:56:44 55808 C:\i386\eventlog.dll (Microsoft Corporation)



Found mount point : C:\WINDOWS\Temp\Google Toolbar\Google Toolbar

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\Google Toolbar\Google Toolbar

Found mount point : C:\WINDOWS\Temp\History\Results\Results

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\History\Results\Results

Found mount point : C:\WINDOWS\Temp\MCE00000\MCE00000

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00000\MCE00000

Found mount point : C:\WINDOWS\Temp\MCE00001\MCE00001

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00001\MCE00001

Found mount point : C:\WINDOWS\Temp\MCE00002\MCE00002

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00002\MCE00002

Found mount point : C:\WINDOWS\Temp\MCE00003\MCE00003

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00003\MCE00003

Found mount point : C:\WINDOWS\Temp\MCE00004\MCE00004

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00004\MCE00004

Found mount point : C:\WINDOWS\Temp\MCE00005\MCE00005

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00005\MCE00005

Found mount point : C:\WINDOWS\Temp\MCE00006\MCE00006

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00006\MCE00006

Found mount point : C:\WINDOWS\Temp\MCE00007\MCE00007

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00007\MCE00007

Found mount point : C:\WINDOWS\Temp\MCE00008\MCE00008

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00008\MCE00008

Found mount point : C:\WINDOWS\Temp\MCE00009\MCE00009

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00009\MCE00009

Found mount point : C:\WINDOWS\Temp\MCE0000a\MCE0000a

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0000a\MCE0000a

Found mount point : C:\WINDOWS\Temp\MCE0000b\MCE0000b

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0000b\MCE0000b

Found mount point : C:\WINDOWS\Temp\MCE0000c\MCE0000c

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0000c\MCE0000c

Found mount point : C:\WINDOWS\Temp\MCE0000d\MCE0000d

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0000d\MCE0000d

Found mount point : C:\WINDOWS\Temp\MCE0000e\MCE0000e

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0000e\MCE0000e

Found mount point : C:\WINDOWS\Temp\MCE0000f\MCE0000f

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0000f\MCE0000f

Found mount point : C:\WINDOWS\Temp\MCE00010\MCE00010

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00010\MCE00010

Found mount point : C:\WINDOWS\Temp\MCE00011\MCE00011

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00011\MCE00011

Found mount point : C:\WINDOWS\Temp\MCE00012\MCE00012

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00012\MCE00012

Found mount point : C:\WINDOWS\Temp\MCE00013\MCE00013

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00013\MCE00013

Found mount point : C:\WINDOWS\Temp\MCE00014\MCE00014

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00014\MCE00014

Found mount point : C:\WINDOWS\Temp\MCE00015\MCE00015

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00015\MCE00015

Found mount point : C:\WINDOWS\Temp\MCE00016\MCE00016

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00016\MCE00016

Found mount point : C:\WINDOWS\Temp\MCE00017\MCE00017

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00017\MCE00017

Found mount point : C:\WINDOWS\Temp\MCE00018\MCE00018

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00018\MCE00018

Found mount point : C:\WINDOWS\Temp\MCE00019\MCE00019

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00019\MCE00019

Found mount point : C:\WINDOWS\Temp\MCE0001a\MCE0001a

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0001a\MCE0001a

Found mount point : C:\WINDOWS\Temp\MCE0001b\MCE0001b

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0001b\MCE0001b

Found mount point : C:\WINDOWS\Temp\MCE0001c\MCE0001c

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0001c\MCE0001c

Found mount point : C:\WINDOWS\Temp\MCE0001d\MCE0001d

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0001d\MCE0001d

Found mount point : C:\WINDOWS\Temp\MCE0001e\MCE0001e

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0001e\MCE0001e

Found mount point : C:\WINDOWS\Temp\MCE0001f\MCE0001f

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0001f\MCE0001f

Found mount point : C:\WINDOWS\Temp\MCE00020\MCE00020

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00020\MCE00020

Found mount point : C:\WINDOWS\Temp\MCE00021\MCE00021

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00021\MCE00021

Found mount point : C:\WINDOWS\Temp\MCE00022\MCE00022

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00022\MCE00022

Found mount point : C:\WINDOWS\Temp\MCE00023\MCE00023

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00023\MCE00023

Found mount point : C:\WINDOWS\Temp\MCE00024\MCE00024

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00024\MCE00024

Found mount point : C:\WINDOWS\Temp\MCE00025\MCE00025

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00025\MCE00025

Found mount point : C:\WINDOWS\Temp\MCE00026\MCE00026

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00026\MCE00026

Found mount point : C:\WINDOWS\Temp\MCE00027\MCE00027

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00027\MCE00027

Found mount point : C:\WINDOWS\Temp\MCE00028\MCE00028

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00028\MCE00028

Found mount point : C:\WINDOWS\Temp\MCE00029\MCE00029

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00029\MCE00029

Found mount point : C:\WINDOWS\Temp\MCE0002a\MCE0002a

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0002a\MCE0002a

Found mount point : C:\WINDOWS\Temp\MCE0002b\MCE0002b

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0002b\MCE0002b

Found mount point : C:\WINDOWS\Temp\MCE0002c\MCE0002c

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0002c\MCE0002c

Found mount point : C:\WINDOWS\Temp\MCE0002d\MCE0002d

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0002d\MCE0002d

Found mount point : C:\WINDOWS\Temp\MCE0002e\MCE0002e

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0002e\MCE0002e

Found mount point : C:\WINDOWS\Temp\MCE0002f\MCE0002f

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0002f\MCE0002f

Found mount point : C:\WINDOWS\Temp\MCE00030\MCE00030

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00030\MCE00030

Found mount point : C:\WINDOWS\Temp\MCE00031\MCE00031

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00031\MCE00031

Found mount point : C:\WINDOWS\Temp\MCE00032\MCE00032

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00032\MCE00032

Found mount point : C:\WINDOWS\Temp\MCE00033\MCE00033

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00033\MCE00033

Found mount point : C:\WINDOWS\Temp\MCE00034\MCE00034

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00034\MCE00034

Found mount point : C:\WINDOWS\Temp\MCE00035\MCE00035

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00035\MCE00035

Found mount point : C:\WINDOWS\Temp\MCE00036\MCE00036

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00036\MCE00036

Found mount point : C:\WINDOWS\Temp\MCE00037\MCE00037

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00037\MCE00037

Found mount point : C:\WINDOWS\Temp\MCE00038\MCE00038

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00038\MCE00038

Found mount point : C:\WINDOWS\Temp\MCE00039\MCE00039

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00039\MCE00039

Found mount point : C:\WINDOWS\Temp\MCE0003a\MCE0003a

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0003a\MCE0003a

Found mount point : C:\WINDOWS\Temp\MCE0003b\MCE0003b

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0003b\MCE0003b

Found mount point : C:\WINDOWS\Temp\MCE0003c\MCE0003c

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0003c\MCE0003c

Found mount point : C:\WINDOWS\Temp\MCE0003d\MCE0003d

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0003d\MCE0003d

Found mount point : C:\WINDOWS\Temp\MCE0003e\MCE0003e

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0003e\MCE0003e

Found mount point : C:\WINDOWS\Temp\MCE0003f\MCE0003f

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0003f\MCE0003f

Found mount point : C:\WINDOWS\Temp\MCE00040\MCE00040

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00040\MCE00040

Found mount point : C:\WINDOWS\Temp\MCE00041\MCE00041

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00041\MCE00041

Found mount point : C:\WINDOWS\Temp\MCE00042\MCE00042

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00042\MCE00042

Found mount point : C:\WINDOWS\Temp\MCE00043\MCE00043

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00043\MCE00043

Found mount point : C:\WINDOWS\Temp\MCE00044\MCE00044

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00044\MCE00044

Found mount point : C:\WINDOWS\Temp\MCE00045\MCE00045

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00045\MCE00045

Found mount point : C:\WINDOWS\Temp\MCE00046\MCE00046

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00046\MCE00046

Found mount point : C:\WINDOWS\Temp\MCE00047\MCE00047

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00047\MCE00047

Found mount point : C:\WINDOWS\Temp\MCE00048\MCE00048

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00048\MCE00048

Found mount point : C:\WINDOWS\Temp\MCE00049\MCE00049

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00049\MCE00049

Found mount point : C:\WINDOWS\Temp\MCE0004a\MCE0004a

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0004a\MCE0004a

Found mount point : C:\WINDOWS\Temp\MCE0004b\MCE0004b

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0004b\MCE0004b

Found mount point : C:\WINDOWS\Temp\MCE0004c\MCE0004c

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0004c\MCE0004c

Found mount point : C:\WINDOWS\Temp\MCE0004d\MCE0004d

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0004d\MCE0004d

Found mount point : C:\WINDOWS\Temp\MCE0004e\MCE0004e

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0004e\MCE0004e

Found mount point : C:\WINDOWS\Temp\MCE0004f\MCE0004f

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0004f\MCE0004f

Found mount point : C:\WINDOWS\Temp\MCE00050\MCE00050

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00050\MCE00050

Found mount point : C:\WINDOWS\Temp\MCE00051\MCE00051

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00051\MCE00051

Found mount point : C:\WINDOWS\Temp\MCE00052\MCE00052

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00052\MCE00052

Found mount point : C:\WINDOWS\Temp\MCE00053\MCE00053

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00053\MCE00053

Found mount point : C:\WINDOWS\Temp\MCE00054\MCE00054

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00054\MCE00054

Found mount point : C:\WINDOWS\Temp\MCE00055\MCE00055

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00055\MCE00055

Found mount point : C:\WINDOWS\Temp\MCE00056\MCE00056

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00056\MCE00056

Found mount point : C:\WINDOWS\Temp\MCE00057\MCE00057

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00057\MCE00057

Found mount point : C:\WINDOWS\Temp\MCE00058\MCE00058

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00058\MCE00058

Found mount point : C:\WINDOWS\Temp\MCE00059\MCE00059

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00059\MCE00059

Found mount point : C:\WINDOWS\Temp\MCE0005a\MCE0005a

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0005a\MCE0005a

Found mount point : C:\WINDOWS\Temp\MCE0005b\MCE0005b

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0005b\MCE0005b

Found mount point : C:\WINDOWS\Temp\MCE0005c\MCE0005c

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0005c\MCE0005c

Found mount point : C:\WINDOWS\Temp\MCE0005d\MCE0005d

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0005d\MCE0005d

Found mount point : C:\WINDOWS\Temp\MCE0005e\MCE0005e

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0005e\MCE0005e

Found mount point : C:\WINDOWS\Temp\MCE0005f\MCE0005f

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0005f\MCE0005f

Found mount point : C:\WINDOWS\Temp\MCE00060\MCE00060

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00060\MCE00060

Found mount point : C:\WINDOWS\Temp\MCE00061\MCE00061

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00061\MCE00061

Found mount point : C:\WINDOWS\Temp\MCE00062\MCE00062

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00062\MCE00062

Found mount point : C:\WINDOWS\Temp\MCE00063\MCE00063

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00063\MCE00063

Found mount point : C:\WINDOWS\Temp\MCE00064\MCE00064

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00064\MCE00064

Found mount point : C:\WINDOWS\Temp\MCE00065\MCE00065

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00065\MCE00065

Found mount point : C:\WINDOWS\Temp\MCE00066\MCE00066

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00066\MCE00066

Found mount point : C:\WINDOWS\Temp\MCE00067\MCE00067

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00067\MCE00067

Found mount point : C:\WINDOWS\Temp\MCE00068\MCE00068

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00068\MCE00068

Found mount point : C:\WINDOWS\Temp\MCE00069\MCE00069

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00069\MCE00069

Found mount point : C:\WINDOWS\Temp\MCE0006a\MCE0006a

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0006a\MCE0006a

Found mount point : C:\WINDOWS\Temp\MCE0006b\MCE0006b

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0006b\MCE0006b

Found mount point : C:\WINDOWS\Temp\MCE0006c\MCE0006c

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0006c\MCE0006c

Found mount point : C:\WINDOWS\Temp\MCE0006d\MCE0006d

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0006d\MCE0006d

Found mount point : C:\WINDOWS\Temp\MCE0006e\MCE0006e

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0006e\MCE0006e

Found mount point : C:\WINDOWS\Temp\MCE0006f\MCE0006f

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0006f\MCE0006f

Found mount point : C:\WINDOWS\Temp\MCE00070\MCE00070

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00070\MCE00070

Found mount point : C:\WINDOWS\Temp\MCE00071\MCE00071

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00071\MCE00071

Found mount point : C:\WINDOWS\Temp\MCE00072\MCE00072

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00072\MCE00072

Found mount point : C:\WINDOWS\Temp\MCE00073\MCE00073

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00073\MCE00073

Found mount point : C:\WINDOWS\Temp\MCE00074\MCE00074

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00074\MCE00074

Found mount point : C:\WINDOWS\Temp\MCE00075\MCE00075

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00075\MCE00075

Found mount point : C:\WINDOWS\Temp\MCE00076\MCE00076

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00076\MCE00076

Found mount point : C:\WINDOWS\Temp\MCE00077\MCE00077

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00077\MCE00077

Found mount point : C:\WINDOWS\Temp\MCE00078\MCE00078

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00078\MCE00078

Found mount point : C:\WINDOWS\Temp\MCE00079\MCE00079

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00079\MCE00079

Found mount point : C:\WINDOWS\Temp\MCE0007a\MCE0007a

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0007a\MCE0007a

Found mount point : C:\WINDOWS\Temp\MCE0007b\MCE0007b

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0007b\MCE0007b

Found mount point : C:\WINDOWS\Temp\MCE0007c\MCE0007c

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0007c\MCE0007c

Found mount point : C:\WINDOWS\Temp\MCE0007d\MCE0007d

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0007d\MCE0007d

Found mount point : C:\WINDOWS\Temp\MCE0007e\MCE0007e

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0007e\MCE0007e

Found mount point : C:\WINDOWS\Temp\MCE0007f\MCE0007f

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0007f\MCE0007f

Found mount point : C:\WINDOWS\Temp\MCE00080\MCE00080

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00080\MCE00080

Found mount point : C:\WINDOWS\Temp\MCE00081\MCE00081

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00081\MCE00081

Found mount point : C:\WINDOWS\Temp\MCE00082\MCE00082

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00082\MCE00082

Found mount point : C:\WINDOWS\Temp\MCE00083\MCE00083

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00083\MCE00083

Found mount point : C:\WINDOWS\Temp\MCE00084\MCE00084

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00084\MCE00084

Found mount point : C:\WINDOWS\Temp\MCE00085\MCE00085

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00085\MCE00085

Found mount point : C:\WINDOWS\Temp\MCE00086\MCE00086

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00086\MCE00086

Found mount point : C:\WINDOWS\Temp\MCE00087\MCE00087

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00087\MCE00087

Found mount point : C:\WINDOWS\Temp\MCE00088\MCE00088

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00088\MCE00088

Found mount point : C:\WINDOWS\Temp\MCE00089\MCE00089

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00089\MCE00089

Found mount point : C:\WINDOWS\Temp\MCE0008a\MCE0008a

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0008a\MCE0008a

Found mount point : C:\WINDOWS\Temp\MCE0008b\MCE0008b

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0008b\MCE0008b

Found mount point : C:\WINDOWS\Temp\MCE0008c\MCE0008c

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0008c\MCE0008c

Found mount point : C:\WINDOWS\Temp\MCE0008d\MCE0008d

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0008d\MCE0008d

Found mount point : C:\WINDOWS\Temp\MCE0008e\MCE0008e

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0008e\MCE0008e

Found mount point : C:\WINDOWS\Temp\MCE0008f\MCE0008f

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0008f\MCE0008f

Found mount point : C:\WINDOWS\Temp\MCE00090\MCE00090

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00090\MCE00090

Found mount point : C:\WINDOWS\Temp\MCE00091\MCE00091

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00091\MCE00091

Found mount point : C:\WINDOWS\Temp\MCE00092\MCE00092

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00092\MCE00092

Found mount point : C:\WINDOWS\Temp\MCE00093\MCE00093

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00093\MCE00093

Found mount point : C:\WINDOWS\Temp\MCE00094\MCE00094

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00094\MCE00094

Found mount point : C:\WINDOWS\Temp\MCE00095\MCE00095

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00095\MCE00095

Found mount point : C:\WINDOWS\Temp\MCE00096\MCE00096

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00096\MCE00096

Found mount point : C:\WINDOWS\Temp\MCE00097\MCE00097

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00097\MCE00097

Found mount point : C:\WINDOWS\Temp\MCE00098\MCE00098

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00098\MCE00098

Found mount point : C:\WINDOWS\Temp\MCE00099\MCE00099

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE00099\MCE00099

Found mount point : C:\WINDOWS\Temp\MCE0009a\MCE0009a

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0009a\MCE0009a

Found mount point : C:\WINDOWS\Temp\MCE0009b\MCE0009b

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0009b\MCE0009b

Found mount point : C:\WINDOWS\Temp\MCE0009c\MCE0009c

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0009c\MCE0009c

Found mount point : C:\WINDOWS\Temp\MCE0009d\MCE0009d

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0009d\MCE0009d

Found mount point : C:\WINDOWS\Temp\MCE0009e\MCE0009e

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0009e\MCE0009e

Found mount point : C:\WINDOWS\Temp\MCE0009f\MCE0009f

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE0009f\MCE0009f

Found mount point : C:\WINDOWS\Temp\MCE000a0\MCE000a0

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000a0\MCE000a0

Found mount point : C:\WINDOWS\Temp\MCE000a1\MCE000a1

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000a1\MCE000a1

Found mount point : C:\WINDOWS\Temp\MCE000a2\MCE000a2

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000a2\MCE000a2

Found mount point : C:\WINDOWS\Temp\MCE000a3\MCE000a3

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000a3\MCE000a3

Found mount point : C:\WINDOWS\Temp\MCE000a4\MCE000a4

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000a4\MCE000a4

Found mount point : C:\WINDOWS\Temp\MCE000a5\MCE000a5

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000a5\MCE000a5

Found mount point : C:\WINDOWS\Temp\MCE000a6\MCE000a6

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000a6\MCE000a6

Found mount point : C:\WINDOWS\Temp\MCE000a7\MCE000a7

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000a7\MCE000a7

Found mount point : C:\WINDOWS\Temp\MCE000a8\MCE000a8

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000a8\MCE000a8

Found mount point : C:\WINDOWS\Temp\MCE000a9\MCE000a9

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000a9\MCE000a9

Found mount point : C:\WINDOWS\Temp\MCE000aa\MCE000aa

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000aa\MCE000aa

Found mount point : C:\WINDOWS\Temp\MCE000ab\MCE000ab

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000ab\MCE000ab

Found mount point : C:\WINDOWS\Temp\MCE000ac\MCE000ac

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000ac\MCE000ac

Found mount point : C:\WINDOWS\Temp\MCE000ad\MCE000ad

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000ad\MCE000ad

Found mount point : C:\WINDOWS\Temp\MCE000ae\MCE000ae

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000ae\MCE000ae

Found mount point : C:\WINDOWS\Temp\MCE000af\MCE000af

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000af\MCE000af

Found mount point : C:\WINDOWS\Temp\MCE000b0\MCE000b0

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000b0\MCE000b0

Found mount point : C:\WINDOWS\Temp\MCE000b1\MCE000b1

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000b1\MCE000b1

Found mount point : C:\WINDOWS\Temp\MCE000b2\MCE000b2

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000b2\MCE000b2

Found mount point : C:\WINDOWS\Temp\MCE000b3\MCE000b3

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000b3\MCE000b3

Found mount point : C:\WINDOWS\Temp\MCE000b4\MCE000b4

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000b4\MCE000b4

Found mount point : C:\WINDOWS\Temp\MCE000b5\MCE000b5

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000b5\MCE000b5

Found mount point : C:\WINDOWS\Temp\MCE000b6\MCE000b6

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000b6\MCE000b6

Found mount point : C:\WINDOWS\Temp\MCE000b7\MCE000b7

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000b7\MCE000b7

Found mount point : C:\WINDOWS\Temp\MCE000b8\MCE000b8

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000b8\MCE000b8

Found mount point : C:\WINDOWS\Temp\MCE000b9\MCE000b9

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000b9\MCE000b9

Found mount point : C:\WINDOWS\Temp\MCE000ba\MCE000ba

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000ba\MCE000ba

Found mount point : C:\WINDOWS\Temp\MCE000bb\MCE000bb

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000bb\MCE000bb

Found mount point : C:\WINDOWS\Temp\MCE000bc\MCE000bc

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000bc\MCE000bc

Found mount point : C:\WINDOWS\Temp\MCE000bd\MCE000bd

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000bd\MCE000bd

Found mount point : C:\WINDOWS\Temp\MCE000be\MCE000be

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000be\MCE000be

Found mount point : C:\WINDOWS\Temp\MCE000bf\MCE000bf

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000bf\MCE000bf

Found mount point : C:\WINDOWS\Temp\MCE000c0\MCE000c0

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000c0\MCE000c0

Found mount point : C:\WINDOWS\Temp\MCE000c1\MCE000c1

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000c1\MCE000c1

Found mount point : C:\WINDOWS\Temp\MCE000c2\MCE000c2

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000c2\MCE000c2

Found mount point : C:\WINDOWS\Temp\MCE000c3\MCE000c3

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000c3\MCE000c3

Found mount point : C:\WINDOWS\Temp\MCE000c4\MCE000c4

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000c4\MCE000c4

Found mount point : C:\WINDOWS\Temp\MCE000c5\MCE000c5

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000c5\MCE000c5

Found mount point : C:\WINDOWS\Temp\MCE000c6\MCE000c6

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000c6\MCE000c6

Found mount point : C:\WINDOWS\Temp\MCE000c7\MCE000c7

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000c7\MCE000c7

Found mount point : C:\WINDOWS\Temp\MCE000c8\MCE000c8

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000c8\MCE000c8

Found mount point : C:\WINDOWS\Temp\MCE000c9\MCE000c9

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000c9\MCE000c9

Found mount point : C:\WINDOWS\Temp\MCE000ca\MCE000ca

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000ca\MCE000ca

Found mount point : C:\WINDOWS\Temp\MCE000cb\MCE000cb

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000cb\MCE000cb

Found mount point : C:\WINDOWS\Temp\MCE000cc\MCE000cc

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000cc\MCE000cc

Found mount point : C:\WINDOWS\Temp\MCE000cd\MCE000cd

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000cd\MCE000cd

Found mount point : C:\WINDOWS\Temp\MCE000ce\MCE000ce

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000ce\MCE000ce

Found mount point : C:\WINDOWS\Temp\MCE000cf\MCE000cf

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000cf\MCE000cf

Found mount point : C:\WINDOWS\Temp\MCE000d0\MCE000d0

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000d0\MCE000d0

Found mount point : C:\WINDOWS\Temp\MCE000d1\MCE000d1

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000d1\MCE000d1

Found mount point : C:\WINDOWS\Temp\MCE000d2\MCE000d2

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000d2\MCE000d2

Found mount point : C:\WINDOWS\Temp\MCE000d3\MCE000d3

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000d3\MCE000d3

Found mount point : C:\WINDOWS\Temp\MCE000d4\MCE000d4

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000d4\MCE000d4

Found mount point : C:\WINDOWS\Temp\MCE000d5\MCE000d5

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000d5\MCE000d5

Found mount point : C:\WINDOWS\Temp\MCE000d6\MCE000d6

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000d6\MCE000d6

Found mount point : C:\WINDOWS\Temp\MCE000d7\MCE000d7

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000d7\MCE000d7

Found mount point : C:\WINDOWS\Temp\MCE000d8\MCE000d8

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000d8\MCE000d8

Found mount point : C:\WINDOWS\Temp\MCE000d9\MCE000d9

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000d9\MCE000d9

Found mount point : C:\WINDOWS\Temp\MCE000da\MCE000da

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000da\MCE000da

Found mount point : C:\WINDOWS\Temp\MCE000db\MCE000db

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000db\MCE000db

Found mount point : C:\WINDOWS\Temp\MCE000dc\MCE000dc

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000dc\MCE000dc

Found mount point : C:\WINDOWS\Temp\MCE000dd\MCE000dd

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000dd\MCE000dd

Found mount point : C:\WINDOWS\Temp\MCE000de\MCE000de

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000de\MCE000de

Found mount point : C:\WINDOWS\Temp\MCE000df\MCE000df

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000df\MCE000df

Found mount point : C:\WINDOWS\Temp\MCE000e0\MCE000e0

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000e0\MCE000e0

Found mount point : C:\WINDOWS\Temp\MCE000e1\MCE000e1

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000e1\MCE000e1

Found mount point : C:\WINDOWS\Temp\MCE000e2\MCE000e2

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000e2\MCE000e2

Found mount point : C:\WINDOWS\Temp\MCE000e3\MCE000e3

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000e3\MCE000e3

Found mount point : C:\WINDOWS\Temp\MCE000e4\MCE000e4

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000e4\MCE000e4

Found mount point : C:\WINDOWS\Temp\MCE000e5\MCE000e5

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000e5\MCE000e5

Found mount point : C:\WINDOWS\Temp\MCE000e6\MCE000e6

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000e6\MCE000e6

Found mount point : C:\WINDOWS\Temp\MCE000e7\MCE000e7

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000e7\MCE000e7

Found mount point : C:\WINDOWS\Temp\MCE000e8\MCE000e8

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000e8\MCE000e8

Found mount point : C:\WINDOWS\Temp\MCE000e9\MCE000e9

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000e9\MCE000e9

Found mount point : C:\WINDOWS\Temp\MCE000ea\MCE000ea

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000ea\MCE000ea

Found mount point : C:\WINDOWS\Temp\MCE000eb\MCE000eb

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000eb\MCE000eb

Found mount point : C:\WINDOWS\Temp\MCE000ec\MCE000ec

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000ec\MCE000ec

Found mount point : C:\WINDOWS\Temp\MCE000ed\MCE000ed

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000ed\MCE000ed

Found mount point : C:\WINDOWS\Temp\MCE000ee\MCE000ee

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000ee\MCE000ee

Found mount point : C:\WINDOWS\Temp\MCE000ef\MCE000ef

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000ef\MCE000ef

Found mount point : C:\WINDOWS\Temp\MCE000f0\MCE000f0

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000f0\MCE000f0

Found mount point : C:\WINDOWS\Temp\MCE000f1\MCE000f1

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000f1\MCE000f1

Found mount point : C:\WINDOWS\Temp\MCE000f2\MCE000f2

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000f2\MCE000f2

Found mount point : C:\WINDOWS\Temp\MCE000f3\MCE000f3

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000f3\MCE000f3

Found mount point : C:\WINDOWS\Temp\MCE000f4\MCE000f4

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000f4\MCE000f4

Found mount point : C:\WINDOWS\Temp\MCE000f5\MCE000f5

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000f5\MCE000f5

Found mount point : C:\WINDOWS\Temp\MCE000f6\MCE000f6

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\MCE000f6\MCE000f6

Found mount point : C:\WINDOWS\Temp\mcu100.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu100.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu101.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu101.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu10B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu10B.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu112.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu112.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu113.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu113.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu11B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu11B.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu126.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu126.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu145.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu145.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu14D.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu14D.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu14F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu14F.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu150.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu150.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu151.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu151.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu158.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu158.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu15A.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu15A.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu167.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu167.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu168.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu168.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu16B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu16B.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu170.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu170.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu175.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu175.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu180.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu180.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu186.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu186.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu18A.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu18A.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu18D.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu18D.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu18F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu18F.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu193.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu193.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu19B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu19B.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu19C.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu19C.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1A.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1A.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1A2.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1A2.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1AB.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1AB.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1AC.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1AC.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1AD.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1AD.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1B.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1B4.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1B4.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1B8.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1B8.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1BB.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1BB.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1BF.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1BF.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1C.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1C.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1C8.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1C8.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1D.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1D.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1E.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1E.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1E4.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1E4.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1ED.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1ED.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1F.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1F1.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1F1.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1FA.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1FA.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu1FC.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu1FC.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu20.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu20.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu21.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu21.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu215.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu215.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu22.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu22.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu226.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu226.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu23.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu23.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu238.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu238.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu23F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu23F.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu24.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu24.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu244.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu244.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu248.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu248.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu24C.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu24C.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu24E.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu24E.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu25.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu25.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu258.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu258.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu26.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu26.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu27.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu27.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu28.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu28.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu29.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu29.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu2A.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu2A.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu2B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu2B.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu2B2.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu2B2.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu2B4.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu2B4.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu2C.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu2C.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu2D.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu2D.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu2DF.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu2DF.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu2E.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu2E.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu2F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu2F.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu30.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu30.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu30F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu30F.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu31.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu31.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu313.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu313.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu32.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu32.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu33.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu33.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu333.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu333.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu334.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu334.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu34B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu34B.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu39.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu39.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu391.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu391.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu3F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu3F.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu4.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu4.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu44.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu44.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu45.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu45.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu46.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu46.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu48.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu48.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu4A.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu4A.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu4B.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu4B.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu4C.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu4C.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu4C5.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu4C5.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu4E.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu4E.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu50.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu50.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu51.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu51.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu52C.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu52C.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu55.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu55.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu56.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu56.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu57.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu57.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu5F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu5F.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu69.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu69.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu6F.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu6F.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu70.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu70.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu72.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu72.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu77.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu77.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu791.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu791.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu7D.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu7D.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu806.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu806.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu82.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu82.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu842.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu842.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu86.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu86.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu90.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu90.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu91.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu91.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu96.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu96.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu97.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu97.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcu9E.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcu9E.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcuA0.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcuA0.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcuAB.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcuAB.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcuAC.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcuAC.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcuB1.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcuB1.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcuBF.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcuBF.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcuC5.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcuC5.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcuC8.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcuC8.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcuCE.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcuCE.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcuD9.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcuD9.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcuDF.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcuDF.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcuEF.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcuEF.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\mcuFF.tmp\vso\vso

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\mcuFF.tmp\vso\vso

Found mount point : C:\WINDOWS\Temp\RtSigs\Data\Data

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\RtSigs\Data\Data

Found mount point : C:\WINDOWS\Temp\SansaUpdater\SansaUpdater

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\SansaUpdater\SansaUpdater

Found mount point : C:\WINDOWS\Temp\_ISTMP0.DIR\_ISTMP0.DIR

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\_ISTMP0.DIR\_ISTMP0.DIR

Found mount point : C:\WINDOWS\Temp\{4511E6C2-C2AD-4387-A111-70F2DB8F48C6}\Disk1\Disk1

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\{4511E6C2-C2AD-4387-A111-70F2DB8F48C6}\Disk1\Disk1

Found mount point : C:\WINDOWS\Temp\{53620028-DD98-41A8-BDD7-DA6B10C49C92}\{53620028-DD98-41A8-BDD7-DA6B10C49C92}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\{53620028-DD98-41A8-BDD7-DA6B10C49C92}\{53620028-DD98-41A8-BDD7-DA6B10C49C92}

Found mount point : C:\WINDOWS\Temp\{7A900EAB-DA37-4554-AF19-9C337476D05D}\{7A900EAB-DA37-4554-AF19-9C337476D05D}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\{7A900EAB-DA37-4554-AF19-9C337476D05D}\{7A900EAB-DA37-4554-AF19-9C337476D05D}

Found mount point : C:\WINDOWS\Temp\{971C5099-088D-456A-84E6-4C143D40D2D1}\Disk1\Disk1

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\{971C5099-088D-456A-84E6-4C143D40D2D1}\Disk1\Disk1

Found mount point : C:\WINDOWS\Temp\{9E2514D9-DC24-4634-B348-61F3EF0F1628}\{9E2514D9-DC24-4634-B348-61F3EF0F1628}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\{9E2514D9-DC24-4634-B348-61F3EF0F1628}\{9E2514D9-DC24-4634-B348-61F3EF0F1628}

Found mount point : C:\WINDOWS\Temp\{B673B7FC-FADA-4C41-A5CD-C069F9D39879}\{E2D7E05E-C8C7-45F4-8D89-D6696075E0B7}\{E2D7E05E-C8C7-45F4-8D89-D6696075E0B7}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\{B673B7FC-FADA-4C41-A5CD-C069F9D39879}\{E2D7E05E-C8C7-45F4-8D89-D6696075E0B7}\{E2D7E05E-C8C7-45F4-8D89-D6696075E0B7}

Found mount point : C:\WINDOWS\Temp\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}

Found mount point : C:\WINDOWS\Temp\{E2D27B84-6365-11D6-9BAF-0090271AF8A4}\{E2D27B84-6365-11D6-9BAF-0090271AF8A4}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\{E2D27B84-6365-11D6-9BAF-0090271AF8A4}\{E2D27B84-6365-11D6-9BAF-0090271AF8A4}

Found mount point : C:\WINDOWS\Temp\{EE6699B3-E5AD-4E59-8F2B-207DF630670C}\{EE6699B3-E5AD-4E59-8F2B-207DF630670C}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\{EE6699B3-E5AD-4E59-8F2B-207DF630670C}\{EE6699B3-E5AD-4E59-8F2B-207DF630670C}



Finished!

#4 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:06 PM

Posted 10 November 2009 - 05:56 PM

Hi jrr91,

Your very welcome. :)

Please do this:
  • Click on the Start button, then click on Run...
  • In the empty "Open:" box provided, type cmd and press Enter
    • This will launch a Command Prompt window (looks like DOS).
  • Copy the entire blue text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).
    copy C:\WINDOWS\ServicePackFiles\i386\eventlog.dll C:\ /y
  • In the Command Prompt window, paste the copied text by right-clicking and selecting Paste.
  • Press Enter.When successfully, you should get this message within the Command Prompt: "1 file(s) copied"
    NOTE: If you didn't get this message, stop and tell me first. Executing The Avenger script (next step) won't work if the file copy was not successful.
  • Exit the Command Prompt window.
==========


:( Warning to others reading this thread!: The Avenger is a VERY POWERFUL program, and can easily be misused.
Certain misuses of this program can prevent your system from ever starting again.
For this reason, it is strongly recommended to use The Avenger only as directed and under qualified supervision.
We can accept no responsibility for damage caused by misuse of the program.
:(
  • Download The Avenger by Swandog46 from here.
  • Unzip/extract it to a folder on your desktop.
  • Double click on avenger.exe to run The Avenger.
  • Click OK.
  • Make sure that the box next to Scan for rootkits has a tick in it and that the box next to Automatically disable any rootkits found does not have a tick in it.
  • Copy all of the text in the below code box to the clipboard by highlighting it and then pressing Ctrl+C.
    Files to move:C:\eventlog.dll | C:\WINDOWS\system32\eventlog.dll
  • In the avenger window, click the Paste Script from Clipboard, Posted Image button.
  • Click the Execute button.
  • You will be asked Are you sure you want to execute the current script?.
  • Click Yes.
  • You will now be asked First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?.
  • Click Yes.
  • Your PC will now be rebooted.
  • Note: If the above script contains Drivers to delete: or Drivers to disable:, then The Avenger will require two reboots to complete its operation.
  • After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%\avenger.txt (typically C:\avenger.txt).
  • Please post this log in your next reply.

Edited by SifuMike, 10 November 2009 - 05:57 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 jrr91

jrr91
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:11:06 PM

Posted 10 November 2009 - 06:29 PM

The first directive for the command prompt was executed successfully. It returned 1 file(s) copied.

As I was opening Avenger, the desktop went black and then returned with all icons, programs and taskbar visible.

I copied and pasted the code as directed and Avenger returned an error message:

Error: Invalid Script.
A valid script must begin with a command directive.
Aborting Execution!

#6 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:06 PM

Posted 10 November 2009 - 06:39 PM

It returned 1 file(s) copied.


That sounds like copy worked, but avenger had a problem.


Error: Invalid Script.
A valid script must begin with a command directive.
Aborting Execution!


This means Avenger did not find a valid command directive. It is expecting Files to Move:, but did not find it. :( Or you typed it Files to Move: C:\eventlog.dll | C:\WINDOWS\system32\eventlog.dll You cant have it all on one line.

Did you accidently include the word CODE?

Make sure you have

Files to move: on the first line and

C:\eventlog.dll | C:\WINDOWS\system32\eventlog.dll on the second line

Try Avenger again and report back.

Edited by SifuMike, 10 November 2009 - 06:43 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 jrr91

jrr91
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:11:06 PM

Posted 10 November 2009 - 07:01 PM

The copy/paste actually put it all in one line.
Much better result when it was divided up.

contents of avenger.txt:


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 3)
Tue Nov 10 17:14:28 2009

17:14:27: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 3)
Tue Nov 10 17:18:26 2009

17:18:26: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File move operation "C:\eventlog.dll|C:\WINDOWS\system32\eventlog.dll" completed successfully.

Completed script processing.

*******************

Finished! Terminate.

#8 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:06 PM

Posted 10 November 2009 - 09:44 PM

Looks good. :(
  • We need to scan the system with this special tool.
  • Please download Junction.zip and save it.
  • First unzip. If it is extracted/unzipped to a folder open the folder and put junction.exe inside it on the desktop. Make sure the file itself is on the desktop. It should look like this: Posted Image
  • Run Command Prompt as administrator:
  • Click on Start button.
  • Type Cmd in the Start Search text box.
  • Press Ctrl-Shift-Enter keyboard shortcut to run Command Prompt as Administrator.
Copy and paste the following command (the bold text) into the open command window, and press Enter:

"%userprofile%\desktop\junction.exe" -s c:\ >log.txt&log.txt

Wait until a log file opens. Copy and paste or attach the content of it.
[/list]
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 jrr91

jrr91
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:11:06 PM

Posted 10 November 2009 - 10:12 PM

contents of log.txt:


Junction v1.05 - Windows junction creator and reparse point viewer
Copyright © 2000-2007 Mark Russinovich
Systems Internals - http://www.sysinternals.com


Failed to open \\?\c:\\pagefile.sys: The process cannot access the file because it is being used by another process.


...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...
Failed to open \\?\c:\\Program Files\McAfee\VirusScan\mcods.exe: Access is denied.




...

...

...

...

...

...

...

...

.
Failed to open \\?\c:\\Program Files\Spybot - Search & Destroy\SpybotSD.exe: Access is denied.


..

.
Failed to open \\?\c:\\System Volume Information\MountPointManagerRemoteDatabase: Access is denied.


..

...

...

...

...

...\\?\c:\\WINDOWS\ASSEMBLY\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a: JUNCTION
Print Name : C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790
Substitute Name: C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790



\\?\c:\\WINDOWS\ASSEMBLY\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a: JUNCTION
Print Name : C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e
Substitute Name: C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e

...

...

...

...

...

...

...

...

...

...

...

#10 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:06 PM

Posted 10 November 2009 - 10:23 PM

Hi jrr91,
  • Download this tool and save it to the desktop: http://download.bleepingcomputer.com/sUBs/...xes/Inherit.exe
  • Go to Start => Run => Copy and paste the first line of the following lines in the run box and click OK:

    "%userprofile%\desktop\inherit" "c:\\Program Files\McAfee\VirusScan\mcods.exe"

    "%userprofile%\desktop\inherit" "c:\\Program Files\Spybot - Search & Destroy\SpybotSD.exe"

  • If you get a security warning select Run.
  • You will get a "Finish" popup. Click OK.
  • Do the same for the rest of the lines until you have run all the above commands one by one.
Note: If you already have Malwarebytes installed on your computer, then update, run it and post the log.

Please download Malwarebytes' Anti-Malware from one of these places:
http://download.cnet.com/Malwarebytes-Anti...&tag=button
http://www.majorgeeks.com/Malwarebytes_Ant...ware_d5756.html
http://www.besttechie.net/mbam/mbam-setup.exe

Double Click mbam-setup.exe to install the application.

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform Quick Scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy&Paste the entire MBAM report (even if it does not find anything) in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

Edited by SifuMike, 10 November 2009 - 10:24 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#11 jrr91

jrr91
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:11:06 PM

Posted 10 November 2009 - 11:10 PM

I'm encouraged by number of times it says "deleted successfully"!
contents of malwarebytes log:


Malwarebytes' Anti-Malware 1.41
Database version: 3143
Windows 5.1.2600 Service Pack 3

11/10/2009 9:57:24 PM
mbam-log-2009-11-10 (21-57-24).txt

Scan type: Quick Scan
Objects scanned: 123753
Time elapsed: 10 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 14
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 5
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ed403e8-470a-4a8a-85a4-d7688cfe39a3} (Adware.Gamevance) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d714a94f-123a-45cc-8f03-040bcaf82ad6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d} (Rogue.AntiVirus2008) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7545d8c8-f53c-4e2f-8fa0-d248ef4a6e61} (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\bfgtoolbar (Adware.OneToolBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\WinBudget (Adware.Admedia) -> Quarantined and deleted successfully.
C:\Program Files\WinBudget\bin (Adware.Admedia) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\win32k.sys (Trojan.Dropper) -> Quarantined and deleted successfully.

#12 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:06 PM

Posted 10 November 2009 - 11:17 PM

Hi jrr91,

I think your still infected, so we need to run some more tools.

Please tell me the antivirus you are running.
Is it McAfee Security Center?
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#13 jrr91

jrr91
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:11:06 PM

Posted 10 November 2009 - 11:35 PM

I knew this was going along too well.

Yes, mcafee security center.

#14 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:06 PM

Posted 10 November 2009 - 11:50 PM

Hi jrr91,


We have removed part of the rootkit, but he brought his malware friends to the party. :(
We will run ComboFix.

You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert.
It is intended by its creator to be used under the guidance and supervision of an Malware Removal Expert, not for private use.

Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.
Please read Combofix's Disclaimer.
Further, ComboFix logs are not permitted outside the HijackThis forums and then only when requested by a HJT Team member.

You need to disable your McAfee Security Center and Spybot Teatimer before running ComboFix, as they will prevent it from running.

To Disable McAfee Security Center
Posted Image


While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent some things from being fixed.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your log is clean.

* Open Spybot Search & Destroy.
* In the Mode menu click "Advanced mode" if not already selected.
* Choose "Yes" at the Warning prompt.
* Expand the "Tools" menu.
* Click "Resident".
* Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
* In the File menu click "Exit" to exit Spybot Search & Destroy.



Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

Please visit this webpage for instructions for downloading and running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

To work properly, you must install ComboFix on the Desktop..

A caution -
Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.
Do not run Combofix more than once.
Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

Post the ComboFix log..
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#15 jrr91

jrr91
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:11:06 PM

Posted 11 November 2009 - 02:09 AM

Thought I fell into some strange time loop, but finally combofix produced a .log file:



ComboFix 09-11-09.02 - User 11/10/2009 23:58.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.149 [GMT -6:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system\oeminfo.ini
f:\my documents\ZbThumbnail.info

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}


((((((((((((((((((((((((( Files Created from 2009-10-11 to 2009-11-11 )))))))))))))))))))))))))))))))
.

2009-11-11 03:44 . 2009-09-10 20:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-11 03:44 . 2009-09-10 20:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-06 02:38 . 2009-11-06 02:38 -------- d-----w- c:\windows\McAfee.com
2009-11-06 01:24 . 2009-11-06 01:24 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Threat Expert
2009-11-06 00:12 . 2009-11-06 00:12 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-11-06 00:03 . 2009-11-06 00:03 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-11-05 23:54 . 2009-11-05 23:54 -------- d-----w- c:\documents and settings\User\Application Data\Malwarebytes
2009-11-05 23:53 . 2009-11-05 23:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-21 21:34 . 2009-09-30 17:11 288096 ----a-r- c:\documents and settings\User\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll
2009-10-21 21:31 . 2009-10-21 21:31 -------- d-----w- c:\documents and settings\User\Application Data\McAfee

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-11 05:27 . 2007-03-14 21:34 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-11 05:12 . 2005-04-03 23:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-11 02:11 . 2007-01-18 13:09 -------- d-----w- c:\program files\McAfee
2009-11-06 17:05 . 2005-07-25 19:00 4864 ----a-w- c:\documents and settings\User\Application Data\wklnhst.dat
2009-11-06 14:06 . 2005-04-03 23:59 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-06 00:08 . 2009-01-07 02:59 -------- d-----w- c:\program files\PopCap Games
2009-10-29 15:55 . 2009-09-17 03:51 -------- d-----w- c:\documents and settings\User\Application Data\U3
2009-10-27 02:52 . 2009-09-04 23:39 63 ----a-w- c:\documents and settings\User\jagex_runescape_preferences2.dat
2009-10-27 02:51 . 2008-07-07 18:55 38 ----a-w- c:\documents and settings\User\jagex_runescape_preferences.dat
2009-10-21 21:29 . 2007-01-18 13:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-16 20:36 . 2009-02-04 13:08 -------- d-----w- c:\program files\Sony Ericsson
2009-10-16 20:35 . 2005-01-12 05:57 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-16 20:32 . 2009-03-15 01:00 -------- d-----w- c:\documents and settings\User\Application Data\Sony
2009-10-14 21:05 . 2005-04-04 00:10 -------- d-----w- c:\program files\Common Files\Adobe
2009-09-28 23:42 . 2009-09-25 04:44 -------- d-----w- c:\program files\Oberon Media
2009-09-16 15:22 . 2007-01-18 13:10 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 15:22 . 2007-01-18 13:10 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 15:22 . 2007-01-18 13:10 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 15:22 . 2007-01-18 13:10 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 15:22 . 2007-01-18 13:10 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-11 14:18 . 2004-08-03 22:56 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 11:22 . 2009-01-13 17:02 548792 ----a-w- c:\documents and settings\User\Application Data\SanDisk\Sansa Updater\SansaUpdater.exe
2009-09-04 21:03 . 2004-08-03 22:56 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-03 22:56 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-03 22:56 247326 ----a-w- c:\windows\system32\strmdll.dll
2006-12-13 13:04 . 2006-12-13 13:04 774144 -c--a-w- c:\program files\RngInterstitial.dll
2005-08-01 02:37 . 2005-08-01 02:37 563416 -c--a-w- c:\program files\flashplayer7_winax.exe
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2005-06-07 05:46 . 2005-06-07 05:46 57344 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe

2007-04-27 21:17 . 2007-04-27 21:17 50736 c:\program files\AIM6\bak\aim6.exe
2009-05-19 05:23 . 2009-05-19 05:23 49968 c:\program files\AIM6\aim6.exe

2007-04-18 06:49 . 2007-04-18 06:49 50736 c:\program files\AOL 9.0\bak\AOL.EXE

2007-10-23 09:38 . 2008-09-29 22:54 24 c:\program files\AOL 9.0\bak\shellmon.ph
2007-09-20 12:44 . 2007-10-01 22:10 24 c:\program files\AOL 9.0\shellmon.ph

2005-01-12 05:57 . 2005-03-30 02:05 339968 c:\program files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe

2006-09-26 00:52 . 2006-09-26 00:52 50736 c:\program files\Common Files\AOL\1170480497\ee\bak\AOLSoftware.exe

2002-07-10 02:45 . 2002-07-10 02:45 28672 c:\program files\Common Files\Microsoft Shared\Works Shared\bak\WkUFind.exe

2005-11-11 22:32 . 2007-02-11 18:56 185896 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe

2003-08-19 06:01 . 2003-08-19 06:01 110592 c:\program files\Common Files\Sonic\Update Manager\bak\sgtray.exe

2005-01-12 05:58 . 2004-10-12 21:54 57344 c:\program files\CyberLink\PowerDVD\bak\DVDLauncher.exe

2007-02-28 22:37 . 2006-12-15 09:23 75520 c:\program files\Java\jre1.5.0_11\bin\bak\jusched.exe

2003-07-28 22:50 . 2003-07-28 22:50 106496 c:\program files\Lexmark 3100 Series\bak\lxbrbmgr.exe

2005-07-24 18:41 . 2003-06-13 20:57 294912 c:\program files\Lexmark 3100 Series\bak\LXBRKsk.exe

2004-08-04 07:06 . 2004-10-13 16:24 1694208 c:\program files\Messenger\bak\msmsgs.exe
2008-09-03 11:05 . 2008-04-14 00:12 1695232 c:\program files\Messenger\msmsgs.exe

2007-02-13 03:22 . 2007-02-13 03:22 155648 c:\program files\QuickTime\bak\qttask.exe
2009-05-26 22:18 . 2009-05-26 22:18 413696 c:\program files\QuickTime\QTTask.exe

2004-05-12 06:03 . 2004-05-12 06:03 1038336 c:\program files\Spybot - Search & Destroy\bak\TeaTimer.exe
2008-03-09 21:03 . 2009-03-05 21:07 2260480 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

2002-08-14 20:21 . 2002-08-14 20:21 94208 c:\program files\Symantec\Norton Ghost 2003\bak\GhostStartTrayApp.exe

2006-10-19 01:05 . 2006-10-19 01:05 204288 c:\program files\Windows Media Player\bak\WMPNSCFG.exe

2004-08-03 22:56 . 2004-08-03 22:56 15360 c:\windows\SYSTEM32\bak\ctfmon.exe
2004-08-03 22:56 . 2008-04-14 00:12 15360 c:\windows\SYSTEM32\ctfmon.exe

2004-05-06 21:48 . 2005-01-23 15:31 126976 c:\windows\SYSTEM32\bak\hkcmd.exe

2004-05-06 21:52 . 2005-01-23 15:36 155648 c:\windows\SYSTEM32\bak\igfxtray.exe

2005-04-04 00:27 . 2004-03-15 06:04 122933 c:\windows\SYSTEM32\dla\bak\tfswctrl.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Walgreens PhotoShow Media Manager"="c:\progra~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" [N/A]
"SansaDispatch"="c:\documents and settings\User\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-03-27 79872]
"Upromise Update"="c:\program files\Upromise\dca-ua.exe" [2009-07-01 81920]
"Upromise Tray"="c:\program files\Upromise\UpromiseTray.exe" [2009-07-01 167936]
"MediaSolaris"="c:\windows\msa.exe" [N/A]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [N/A]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Aim6"="" [N/A]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150596.exe" [2009-04-29 468408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [N/A]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [N/A]
"GhostStartTrayApp"="c:\program files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe" [N/A]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [N/A]
"Lexmark 3100 Series"="c:\program files\Lexmark 3100 Series\lxbrbmgr.exe" [N/A]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [N/A]
"LXBRKsk"="c:\progra~1\LEXMAR~1\LXBRKsk.exe" [N/A]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [N/A]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [N/A]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-21 177472]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Malwarebytes Anti-Malware (reboot)"="c:\documents and settings\User\Desktop\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= c:\documents and settings\User\My Documents\YUCKLES - Polka Pigs in Space_ Animated dancing page.htm
FriendlyName=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1170480497\\ee\\AOLOpenRide.exe"=
"c:\\Program Files\\Common Files\\AOL\\1170480497\\ee\\aim6.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R1 GhPciScan;GhostPciScanner;c:\program files\Symantec\Norton Ghost 2003\GhPciScan.sys [8/14/2002 2:11 PM 5632]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/5/2009 1:55 PM 24652]
S2 gupdate1c97f3a9aabfa44;Google Update Service (gupdate1c97f3a9aabfa44);c:\program files\Google\Update\GoogleUpdate.exe [1/25/2009 4:16 PM 133104]
S2 PDSched;PDScheduler;c:\program files\Raxco\PerfectDisk\PDSched.exe [1/4/2005 2:59 PM 237635]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\SYSTEM32\DRIVERS\ggflt.sys [2/4/2009 7:14 AM 13224]
S3 KBCAM;JamC@m USB service;c:\windows\system32\Drivers\KBCAM.sys --> c:\windows\system32\Drivers\KBCAM.sys [?]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder

2009-11-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-11-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-01-25 00:34]

2009-11-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-01-25 00:34]

2009-10-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-01-18 17:22]

2009-11-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-01-18 17:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\User\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: internet
Trusted Zone: mcafee.com
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{472734EA-242A-422B-ADF8-83D1E48CC825} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-11 00:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(380)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\INK\PENUSA.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTSvcCDA.EXE
c:\progra~1\Symantec\NORTON~1\GHOSTS~2.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MPFSrv.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\wanmpsvc.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-11-11 0:58 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-11 06:56

Pre-Run: 16,662,290,432 bytes free
Post-Run: 16,699,588,608 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - F4D21D539A432174FA87F802B8F03663




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users