Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Win7 Only partial boot


  • This topic is locked This topic is locked
14 replies to this topic

#1 jandmM2

jandmM2

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:03:21 PM

Posted 28 November 2011 - 04:43 PM

I have had this problem for about 1 week. that is I receive the BSOD with STOP: c0000135 missing %hs. Pls reinstall. This occurs after windows starts but before the desktop appears.
I had been able to use repair system and the restore option to get back to booting successfully. The last time however I corrected 4 of 5 errors in Norton 360 v5.1.0.29 which was in trial mode as an update to v 3 of the same which my registration had expired. As I shut down after making a restore point windows did 4 updates- 3 of which were for .net 3,5 sp1 which i do not have on the system. I have .net 4 client. After that I go the error.
I was able to scan using a live disk with bitDefender and remove 4 viruses.However the error remins and I have only 1 restore point and it is the manually made one down before the updates but after the the fixes done to Norton 360. here is my Farbar Recovery Scan Tool log file
Scan result of Farbars's Recovery Tool (FRST written by farbar) Version 2.3.0
Ran by SYSTEM at 2011-11-28 21:11:41
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM-x32\...\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [LTCM Client] C:\Program Files (x86)\LTCM Client\ltcmClient.exe /startup [1583808 2009-03-02] (Leader Technologies Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2011-09-07] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-29] (Adobe Systems Incorporated)
HKU\User\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized [25623336 2009-10-09] (Skype Technologies S.A.)
HKU\User\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3872080 2010-04-16] (Microsoft Corporation)
HKU\User\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-03-04] (Google Inc.)
HKLM\...\RunOnce: [*Restore] C:\windows\system32\rstrui.exe /RUNONCE [296960 2009-07-13] (Microsoft Corporation)
HKLM-x32\...\Winlogon: [Userinit] c:\windows\syswow64\userinit.exe,
Tcpip\Parameters: [DhcpNameServer] 205.150.58.13 205.150.58.80
SubSystems: [Windows] ==> ZeroAccess

==================== Services (Whitelisted) ======

2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
2 N360; "C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\diMaster.dll" /prefetch:1 [262584 2011-03-31] (Symantec Corporation)

========================== Drivers (Whitelisted) =============

1 BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20111114.002_5b3\BHDrvx64.sys [1156216 2011-11-14] (Symantec Corporation)
1 eeCtrl; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [482936 2011-11-26] (Symantec Corporation)
3 EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138360 2011-11-26] (Symantec Corporation)
1 IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20111124.030_61f\IDSvia64.sys [488568 2011-11-24] (Symantec Corporation)
3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20111126.007\ENG64.SYS [117880 2011-11-26] (Symantec Corporation)
3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20111126.007\EX64.SYS [2048632 2011-11-26] (Symantec Corporation)
1 SRTSP; C:\Windows\System32\Drivers\N360x64\0501000.01D\SRTSP64.SYS [744568 2011-03-30] (Symantec Corporation)
1 SRTSPX; C:\Windows\System32\drivers\N360x64\0501000.01D\SRTSPX64.SYS [40568 2011-03-30] (Symantec Corporation)
0 SymDS; C:\Windows\System32\drivers\N360x64\0501000.01D\SYMDS64.SYS [450680 2011-01-26] (Symantec Corporation)
0 SymEFA; C:\Windows\System32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [912504 2011-03-14] (Symantec Corporation)
3 SymEvent; \??\C:\windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2011-11-22] (Symantec Corporation)
1 SymIRON; C:\Windows\System32\drivers\N360x64\0501000.01D\Ironx64.SYS [171128 2011-01-26] (Symantec Corporation)
1 SymNetS; C:\Windows\System32\drivers\N360x64\0501000.01D\SYMNETS.SYS [382584 2011-03-21] (Symantec Corporation)
3 RtsUIR; C:\Windows\System32\DRIVERS\Rts516xIR.sys [x]
3 SYMFW; C:\Windows\System32\Drivers\N360x64\0308000.029\SYMFW.SYS [x]
3 SYMNDISV; C:\Windows\System32\Drivers\N360x64\0308000.029\SYMNDISV.SYS [x]
3 USBCCID; C:\Windows\System32\DRIVERS\RtsUCcid.sys [x]

========================== NetSvcs (Whitelisted) ===========

============ One Month Created Files and Folders ==============

2011-11-26 22:04 - 2011-11-26 22:04 - 0000000 ____D C:\Program Files\Windows Portable Devices
2011-11-26 12:31 - 2011-11-26 22:46 - 0000000 ____D C:\Program Files (x86)\Tweaking.com
2011-11-26 12:31 - 2011-11-26 12:31 - 0002242 ____A C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
2011-11-26 12:01 - 2011-11-26 12:01 - 0000000 ____D C:\Users\User\AppData\Roaming\Tific
2011-11-26 11:39 - 2011-11-26 23:33 - 0000000 ____D C:\Users\All Users\symbols
2011-11-26 11:39 - 2011-11-26 23:33 - 0000000 ____D C:\ProgramData\symbols
2011-11-26 11:39 - 2011-11-26 22:50 - 0000000 ____D C:\Windows\Standalone System Sweeper
2011-11-25 18:26 - 2011-11-26 12:36 - 0000000 ____D C:\Users\User\AppData\Local\CrashDumps
2011-11-22 12:01 - 2010-11-20 05:33 - 0273792 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\msiscsi.sys
2011-11-22 12:00 - 2010-11-20 02:44 - 0229888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\1394ohci.sys
2011-11-22 11:59 - 2010-11-20 05:34 - 0071552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\volmgr.sys
2011-11-22 11:59 - 2010-11-20 05:33 - 0140672 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\msdsm.sys
2011-11-22 11:59 - 2010-11-20 05:33 - 0103808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\sbp2port.sys
2011-11-22 11:59 - 2010-11-20 05:33 - 0063360 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\termdd.sys
2011-11-22 11:59 - 2010-11-20 05:32 - 0334208 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\acpi.sys
2011-11-22 11:58 - 2010-11-20 05:33 - 0155008 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mpio.sys
2011-11-22 11:57 - 2010-11-20 02:44 - 0350208 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\HdAudio.sys
2011-11-22 11:57 - 2010-11-20 01:30 - 0012800 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\acpipmi.sys
2011-11-22 11:33 - 2011-11-22 11:34 - 0001985 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2011-11-22 11:15 - 2010-08-20 19:59 - 0034152 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2011-11-22 10:57 - 2011-11-26 22:47 - 0000000 ____D C:\Users\Public\Downloads\Norton
2011-11-22 10:57 - 2011-11-22 10:57 - 0000000 ____D C:\Users\User\Downloads\Norton
2011-11-22 10:54 - 2011-11-22 10:54 - 0000338 ____A C:\Windows\PFRO.log
2011-11-22 10:30 - 2011-11-22 10:30 - 0000248 ____A C:\Windows\System32\Drivers\kgpcpy.cfg
2011-11-22 10:08 - 2004-06-11 15:33 - 0290304 ____A (Microsoft Corporation) C:\subinacl.exe
2011-11-22 08:58 - 2011-11-26 17:37 - 0459575 ____A C:\Windows\WindowsUpdate.log
2011-11-22 08:55 - 2011-11-26 22:07 - 0001298 ____A C:\Windows\setupact.log
2011-11-22 08:55 - 2011-11-22 08:55 - 0000000 ____A C:\Windows\setuperr.log
2011-11-22 08:45 - 2011-11-27 19:53 - 0179206 ____A C:\Windows\ntbtlog.txt
2011-11-21 19:49 - 2011-11-22 09:57 - 0000000 ____D C:\Users\User\AppData\Roaming\360F1
2011-11-21 19:49 - 2011-11-21 19:49 - 0001213 ____A C:\Users\User\AppData\Roaming\ahst.lni
2011-11-21 19:49 - 2011-11-21 19:49 - 0000000 ____D C:\Program Files (x86)\LP
2011-11-21 19:43 - 2011-11-21 19:43 - 0065536 __ASH C:\Windows\System32\config\COMPONENTS{7525c032-14b1-11e1-84d0-002622f1b193}.TxR.blf
2011-11-21 18:26 - 2011-11-21 18:26 - 0010168 ____N C:\bootsqm.dat
2011-11-21 18:19 - 2011-11-22 10:24 - 0181064 ____A (Sysinternals) C:\Windows\PSEXESVC.EXE
2011-11-21 17:58 - 2011-11-27 20:08 - 0000000 ____D C:\Program Files\CCleaner
2011-11-21 17:58 - 2011-11-21 17:58 - 0000833 ____A C:\Users\Public\Desktop\CCleaner.lnk
2011-11-21 17:56 - 2011-11-26 23:00 - 0000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-11-21 17:56 - 2011-08-31 14:00 - 0025416 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2011-11-21 17:51 - 2011-11-22 08:53 - 0000000 ____D C:\Program Files\Java
2011-11-21 17:51 - 2011-11-21 17:51 - 0525544 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2011-11-21 17:51 - 2011-11-21 17:51 - 0190752 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2011-11-21 17:51 - 2011-11-21 17:51 - 0171808 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2011-11-21 17:51 - 2011-11-21 17:51 - 0171808 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2011-11-21 17:49 - 2011-11-26 23:00 - 0000000 ____D C:\Users\User\Downloads\Tweaking com Sftwr
2011-11-21 17:48 - 2011-11-26 23:00 - 0000000 ____D C:\Users\User\Downloads\Java Sftwr
2011-11-21 16:45 - 2011-11-28 12:15 - 0000000 ____D C:\bd_logs
2011-11-21 15:47 - 2011-11-21 15:47 - 9852544 ____A (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-1.51.2.1300.exe
2011-11-21 15:47 - 2011-11-21 15:47 - 0000000 ____D C:\Windows\Sun
2011-11-21 15:46 - 2011-11-21 15:46 - 3511776 ____A (Piriform Ltd) C:\Users\User\Downloads\ccsetup312.exe
2011-11-21 15:45 - 2011-11-22 14:23 - 0000000 ____D C:\Users\User\AppData\Roaming\Mozilla
2011-11-21 15:44 - 2011-11-26 23:00 - 0000000 ____D C:\Users\User\Downloads\Javaextra runtime ver delete
2011-11-21 15:44 - 2011-11-26 23:00 - 0000000 ____D C:\Users\User\Downloads\FirefoxPortable
2011-11-14 10:24 - 2011-11-14 10:24 - 0066658 ____A C:\Users\Public\Documents\14 NOV 2011.docx
2011-11-14 09:05 - 2011-11-14 09:05 - 0000714 ____A C:\Users\Public\Documents\Libraries - Shortcut.lnk
2011-11-10 05:27 - 2011-11-10 05:27 - 0000215 ____A C:\Windows\System32\MRT.INI
2011-11-09 08:01 - 2011-09-29 08:24 - 1897328 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2011-11-09 08:00 - 2011-09-28 20:09 - 3141120 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys


============ 3 Months Modified Files and Folders =============

2011-11-28 21:11 - 2011-11-28 21:10 - 0000000 ____D C:\FRST
2011-11-28 12:15 - 2011-11-21 16:45 - 0000000 ____D C:\bd_logs
2011-11-27 20:08 - 2011-11-21 17:58 - 0000000 ____D C:\Program Files\CCleaner
2011-11-27 20:08 - 2011-03-04 13:58 - 0000000 ____D C:\Users\User\AppData\Roaming\ArcSoft
2011-11-27 20:08 - 2009-12-29 09:36 - 0000000 ____D C:\Users\All Users\Pure Networks
2011-11-27 20:08 - 2009-12-29 09:36 - 0000000 ____D C:\ProgramData\Pure Networks
2011-11-27 20:08 - 2009-12-27 11:23 - 0000000 ____D C:\users\User
2011-11-27 20:08 - 2009-12-16 19:03 - 0000000 ____D C:\Users\All Users\Norton
2011-11-27 20:08 - 2009-12-16 19:03 - 0000000 ____D C:\ProgramData\Norton
2011-11-27 20:06 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\registration
2011-11-27 19:53 - 2011-11-22 08:45 - 0179206 ____A C:\Windows\ntbtlog.txt
2011-11-27 19:53 - 2009-12-16 18:02 - 2213302272 __ASH C:\hiberfil.sys
2011-11-27 17:09 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\config\TxR
2011-11-26 23:33 - 2011-11-26 11:39 - 0000000 ____D C:\Users\All Users\symbols
2011-11-26 23:33 - 2011-11-26 11:39 - 0000000 ____D C:\ProgramData\symbols
2011-11-26 23:04 - 2009-07-13 23:45 - 0000000 ____D C:\Program Files\Windows Journal
2011-11-26 23:04 - 2009-07-13 21:37 - 0000000 ____D C:\Windows\SysWOW64\sysprep
2011-11-26 23:04 - 2009-07-13 21:32 - 0000000 ____D C:\Windows\addins
2011-11-26 23:04 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\Windows Sidebar
2011-11-26 23:04 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\Windows Defender
2011-11-26 23:04 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\DVD Maker
2011-11-26 23:04 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files (x86)\Windows Sidebar
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ___AD C:\Windows\System32\sysprep
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\TAPI
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\zh-TW
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\uk-UA
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\tr-TR
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\th-TH
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\sv-SE
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\sr-Latn-CS
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\sppui
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\sk-SK
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\Setup
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\ru-RU
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\ro-RO
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\Recovery
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\ras
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\pt-PT
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\pl-PL
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\oobe
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\nl-NL
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\migwiz
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\manifeststore
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\InstallShield
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\Dism
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\com
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\sppui
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\Setup
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\Recovery
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\ras
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\oobe
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\Msdtc
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\migwiz
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\manifeststore
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\ias
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\Dism
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\com
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\AdvancedInstallers
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\servicing
2011-11-26 23:04 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Common Files\Services
2011-11-26 23:03 - 2009-07-13 21:32 - 0000000 ____D C:\Windows\System32\WinBioPlugIns
2011-11-26 23:03 - 2009-07-13 21:32 - 0000000 ____D C:\Windows\Downloaded Program Files
2011-11-26 23:03 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\Windows Photo Viewer
2011-11-26 23:03 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 __RSD C:\Windows\Media
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\lv-LV
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\lt-LT
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\ja-JP
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\it-IT
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\hu-HU
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\hr-HR
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\fr-FR
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\fi-FI
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\et-EE
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\es-ES
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\el-GR
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\de-DE
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\da-DK
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\cs-CZ
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\bg-BG
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\zh-TW
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\uk-UA
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\tr-TR
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\th-TH
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\sv-SE
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\sr-Latn-CS
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\sl-SI
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\sk-SK
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\ro-RO
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\pt-PT
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\pl-PL
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\nl-NL
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\nb-NO
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\lv-LV
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\lt-LT
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\ko-KR
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\ja-JP
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\it-IT
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\hu-HU
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\hr-HR
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\he-IL
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\fr-FR
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\fi-FI
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\et-EE
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\es-ES
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\el-GR
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\de-DE
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\da-DK
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\cs-CZ
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\bg-BG
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\PolicyDefinitions
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\Cursors
2011-11-26 23:03 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Common Files\System
2011-11-26 23:01 - 2009-12-16 18:38 - 0000000 ____D C:\Windows\SysWOW64\Macromed
2011-11-26 23:01 - 2009-12-16 18:20 - 0000000 ____D C:\Windows\SysWOW64\TSFM
2011-11-26 23:01 - 2009-12-16 18:16 - 0000000 ____D C:\Windows\SysWOW64\RTCOM
2011-11-26 23:01 - 2009-12-16 18:06 - 0000000 ____D C:\Windows\SysWOW64\Microsoft.VC80.MFC
2011-11-26 23:01 - 2009-07-13 21:37 - 0000000 ____D C:\Windows\SysWOW64\winrm
2011-11-26 23:01 - 2009-07-13 21:37 - 0000000 ____D C:\Windows\SysWOW64\WCN
2011-11-26 23:01 - 2009-07-13 21:37 - 0000000 ____D C:\Windows\SysWOW64\slmgr
2011-11-26 23:01 - 2009-07-13 21:37 - 0000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2011-11-26 23:01 - 2009-07-13 21:37 - 0000000 ____D C:\Windows\System32\winrm
2011-11-26 23:01 - 2009-07-13 21:37 - 0000000 ____D C:\Windows\System32\WCN
2011-11-26 23:01 - 2009-07-13 21:37 - 0000000 ____D C:\Windows\System32\slmgr
2011-11-26 23:01 - 2009-07-13 21:37 - 0000000 ____D C:\Windows\System32\Printing_Admin_Scripts
2011-11-26 23:01 - 2009-07-13 21:32 - 0000000 ____D C:\Windows\System32\restore
2011-11-26 23:01 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\Speech
2011-11-26 23:01 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\NetworkList
2011-11-26 23:01 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\MUI
2011-11-26 23:01 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\Msdtc
2011-11-26 23:01 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\IME
2011-11-26 23:01 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\spp
2011-11-26 23:01 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\spool
2011-11-26 23:01 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\Speech
2011-11-26 23:01 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\SMI
2011-11-26 23:01 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\MUI
2011-11-26 23:01 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\IME
2011-11-26 23:00 - 2011-11-21 17:56 - 0000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-11-26 23:00 - 2011-11-21 17:49 - 0000000 ____D C:\Users\User\Downloads\Tweaking com Sftwr
2011-11-26 23:00 - 2011-11-21 17:48 - 0000000 ____D C:\Users\User\Downloads\Java Sftwr
2011-11-26 23:00 - 2011-11-21 15:44 - 0000000 ____D C:\Users\User\Downloads\Javaextra runtime ver delete
2011-11-26 23:00 - 2011-11-21 15:44 - 0000000 ____D C:\Users\User\Downloads\FirefoxPortable
2011-11-26 23:00 - 2011-10-20 18:31 - 0000000 ____D C:\Program Files (x86)\ARO 2011
2011-11-26 23:00 - 2011-10-15 10:05 - 0000000 __SHD C:\Windows\System32\%APPDATA%
2011-11-26 23:00 - 2011-09-08 18:19 - 0000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2011-11-26 23:00 - 2011-05-05 18:19 - 0000000 ___RD C:\Users\User\Documents\Scanned Documents
2011-11-26 23:00 - 2011-03-01 17:35 - 0000000 ____D C:\Program Files (x86)\TurboTax 2010
2011-11-26 23:00 - 2010-02-01 13:09 - 0000000 ___SD C:\Users\User\Documents\My Data Sources
2011-11-26 23:00 - 2010-01-16 12:54 - 0000000 ___RD C:\Program Files (x86)\Skype
2011-11-26 23:00 - 2009-12-31 07:47 - 0000000 ____D C:\Users\All Users\Hewlett-Packard
2011-11-26 23:00 - 2009-12-31 07:47 - 0000000 ____D C:\ProgramData\Hewlett-Packard
2011-11-26 23:00 - 2009-12-28 08:09 - 0000000 ____D C:\Users\User\AppData\Local\Downloaded Installations
2011-11-26 23:00 - 2009-12-28 08:09 - 0000000 ____D C:\Program Files (x86)\Norton 360
2011-11-26 23:00 - 2009-12-27 11:56 - 0000000 ____D C:\Users\User\AppData\Local\TOSHIBA_Corporation
2011-11-26 23:00 - 2009-12-16 18:53 - 0000000 ____D C:\Users\All Users\Microsoft Help
2011-11-26 23:00 - 2009-12-16 18:53 - 0000000 ____D C:\ProgramData\Microsoft Help
2011-11-26 23:00 - 2009-12-16 18:51 - 0000000 ____D C:\Program Files (x86)\Microsoft Works
2011-11-26 23:00 - 2009-12-16 18:28 - 0000000 ____D C:\Windows\Downloaded Installations
2011-11-26 23:00 - 2009-08-21 00:21 - 0000000 ____D C:\Program Files (x86)\Java
2011-11-26 23:00 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\security
2011-11-26 23:00 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\schemas
2011-11-26 23:00 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\Branding
2011-11-26 23:00 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\AppCompat
2011-11-26 23:00 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Windows NT
2011-11-26 23:00 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Common Files\Microsoft Shared
2011-11-26 22:53 - 2009-07-13 21:32 - 0000000 ____D C:\Windows\System32\WindowsPowerShell
2011-11-26 22:50 - 2011-11-26 11:39 - 0000000 ____D C:\Windows\Standalone System Sweeper
2011-11-26 22:47 - 2011-11-22 10:57 - 0000000 ____D C:\Users\Public\Downloads\Norton
2011-11-26 22:47 - 2009-12-27 11:23 - 0000000 ____D C:\Users\User\AppData\LocalLow
2011-11-26 22:46 - 2011-11-26 12:31 - 0000000 ____D C:\Program Files (x86)\Tweaking.com
2011-11-26 22:46 - 2009-12-16 18:52 - 0000000 ____D C:\Program Files (x86)\Microsoft Office
2011-11-26 22:46 - 2009-12-16 18:12 - 0000000 ____D C:\Program Files (x86)\ATI Technologies
2011-11-26 22:46 - 2009-08-21 00:22 - 0000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2011-11-26 22:45 - 2009-12-28 07:53 - 0000000 ___RD C:\MSOCache
2011-11-26 22:12 - 2009-07-13 23:44 - 0000000 ___RD C:\Users\Public\Recorded TV
2011-11-26 22:08 - 2010-03-09 07:02 - 0000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2011-11-26 22:08 - 2010-01-16 15:39 - 0000000 ____D C:\Users\User\Tracing
2011-11-26 22:08 - 2010-01-16 12:55 - 0000000 ____D C:\Users\User\AppData\Roaming\Skype
2011-11-26 22:07 - 2011-11-22 08:55 - 0001298 ____A C:\Windows\setupact.log
2011-11-26 22:07 - 2009-07-13 21:08 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2011-11-26 22:04 - 2011-11-26 22:04 - 0000000 ____D C:\Program Files\Windows Portable Devices
2011-11-26 22:04 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files (x86)\Windows Portable Devices
2011-11-26 21:43 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\NDF
2011-11-26 20:14 - 2009-07-13 21:08 - 0032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2011-11-26 17:37 - 2011-11-22 08:58 - 0459575 ____A C:\Windows\WindowsUpdate.log
2011-11-26 17:33 - 2009-07-13 21:13 - 0726316 ____A C:\Windows\System32\PerfStringBackup.INI
2011-11-26 17:13 - 2009-07-13 20:45 - 0016304 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2011-11-26 17:13 - 2009-07-13 20:45 - 0016304 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2011-11-26 12:36 - 2011-11-25 18:26 - 0000000 ____D C:\Users\User\AppData\Local\CrashDumps
2011-11-26 12:31 - 2011-11-26 12:31 - 0002242 ____A C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
2011-11-26 12:21 - 2009-07-13 21:38 - 0067584 ___AS C:\Windows\bootstat(5842).dat
2011-11-26 12:01 - 2011-11-26 12:01 - 0000000 ____D C:\Users\User\AppData\Roaming\Tific
2011-11-25 11:36 - 2011-02-08 16:59 - 0000000 ____D C:\process
2011-11-25 11:32 - 2009-12-27 11:26 - 0091608 ____A C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2011-11-22 14:23 - 2011-11-21 15:45 - 0000000 ____D C:\Users\User\AppData\Roaming\Mozilla
2011-11-22 14:00 - 2009-08-21 16:57 - 0000000 ____D C:\Windows\Panther
2011-11-22 12:23 - 2009-07-13 18:36 - 0152576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2011-11-22 11:55 - 2010-03-09 07:02 - 0000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2011-11-22 11:34 - 2011-11-22 11:33 - 0001985 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2011-11-22 11:33 - 2009-08-21 00:24 - 0000000 ____D C:\Users\All Users\Adobe
2011-11-22 11:33 - 2009-08-21 00:24 - 0000000 ____D C:\ProgramData\Adobe
2011-11-22 11:32 - 2010-01-05 09:03 - 0000000 ____D C:\Users\User\AppData\Local\Adobe
2011-11-22 11:23 - 2009-07-13 18:36 - 0628460 ____A C:\Windows\System32\perfh009(5990).dat
2011-11-22 11:18 - 2009-12-28 08:09 - 0000000 ____D C:\Windows\System32\Drivers\N360x64
2011-11-22 11:17 - 2009-12-28 08:09 - 0002359 ____A C:\Users\Public\Desktop\Norton 360.lnk
2011-11-22 11:14 - 2009-12-28 08:09 - 0174200 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS
2011-11-22 11:14 - 2009-12-28 08:09 - 0007488 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT
2011-11-22 11:14 - 2009-12-28 08:09 - 0000855 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.INF
2011-11-22 10:57 - 2011-11-22 10:57 - 0000000 ____D C:\Users\User\Downloads\Norton
2011-11-22 10:54 - 2011-11-22 10:54 - 0000338 ____A C:\Windows\PFRO.log
2011-11-22 10:54 - 2009-07-13 20:45 - 0373160 ____A C:\Windows\System32\FNTCACHE.DAT
2011-11-22 10:30 - 2011-11-22 10:30 - 0000248 ____A C:\Windows\System32\Drivers\kgpcpy.cfg
2011-11-22 10:24 - 2011-11-21 18:19 - 0181064 ____A (Sysinternals) C:\Windows\PSEXESVC.EXE
2011-11-22 10:22 - 2009-07-13 18:34 - 0000855 ____A C:\Windows\System32\Drivers\etc\hosts
2011-11-22 10:14 - 2009-08-21 00:21 - 0000000 ____D C:\Program Files\PlayReady
2011-11-22 10:10 - 2009-07-13 21:32 - 0000000 ____D C:\Windows\Offline Web Pages
2011-11-22 10:10 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files (x86)\Windows Defender
2011-11-22 10:10 - 2009-07-13 19:20 - 0000000 ___RD C:\users\Public
2011-11-22 10:10 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\zh-HK
2011-11-22 10:10 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\zh-CN
2011-11-22 10:10 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\sl-SI
2011-11-22 10:10 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\pt-BR
2011-11-22 10:10 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\nb-NO
2011-11-22 10:10 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\ko-KR
2011-11-22 10:10 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\icsxml
2011-11-22 10:10 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\he-IL
2011-11-22 10:10 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\icsxml
2011-11-22 10:09 - 2009-07-13 23:45 - 0000000 ____D C:\Windows\ShellNew
2011-11-22 10:09 - 2009-07-13 19:20 - 0000000 ___RD C:\Users\Public\Libraries
2011-11-22 10:09 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\ar-SA
2011-11-22 10:09 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\zh-HK
2011-11-22 10:09 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\zh-CN
2011-11-22 10:09 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\ru-RU
2011-11-22 10:09 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\pt-BR
2011-11-22 10:09 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\ar-SA
2011-11-22 10:09 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\rescache
2011-11-22 10:09 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\L2Schemas
2011-11-22 10:09 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\IME
2011-11-22 10:02 - 2009-07-13 21:32 - 0000000 ____D C:\Windows\SysWOW64\WindowsPowerShell
2011-11-22 10:02 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\spp
2011-11-22 10:01 - 2009-07-13 20:45 - 0000000 ___AD C:\Windows\Setup
2011-11-22 10:01 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\Speech
2011-11-22 10:00 - 2009-07-13 21:32 - 0000000 ____D C:\Windows\Performance
2011-11-22 10:00 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\Resources
2011-11-22 10:00 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\PLA
2011-11-22 10:00 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\Help
2011-11-22 10:00 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\Globalization
2011-11-22 09:59 - 2011-03-04 14:00 - 0000000 ____D C:\Program Files (x86)\LTCM Client
2011-11-22 09:59 - 2010-09-21 17:22 - 0000000 ____D C:\Users\User\AppData\Local\PokerStars.NET
2011-11-22 09:59 - 2010-09-21 17:22 - 0000000 ____D C:\Program Files (x86)\PokerStars.NET
2011-11-22 09:59 - 2010-01-16 15:37 - 0000000 ____D C:\Program Files (x86)\Windows Live SkyDrive
2011-11-22 09:59 - 2010-01-16 15:37 - 0000000 ____D C:\Program Files (x86)\Windows Live
2011-11-22 09:59 - 2010-01-16 12:54 - 0000000 ____D C:\Users\All Users\Skype
2011-11-22 09:59 - 2010-01-16 12:54 - 0000000 ____D C:\ProgramData\Skype
2011-11-22 09:59 - 2009-12-28 08:10 - 0000000 ____D C:\Users\All Users\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2011-11-22 09:59 - 2009-12-28 08:10 - 0000000 ____D C:\ProgramData\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2011-11-22 09:59 - 2009-12-28 07:56 - 0000000 ____D C:\Users\User\AppData\Local\Microsoft Help
2011-11-22 09:59 - 2009-12-27 11:40 - 0000000 ____D C:\Users\All Users\EPSON
2011-11-22 09:59 - 2009-12-27 11:40 - 0000000 ____D C:\ProgramData\EPSON
2011-11-22 09:59 - 2009-12-27 11:40 - 0000000 ____D C:\Program Files (x86)\epson
2011-11-22 09:59 - 2009-12-16 19:00 - 0000000 ____D C:\Users\All Users\WildTangent
2011-11-22 09:59 - 2009-12-16 19:00 - 0000000 ____D C:\ProgramData\WildTangent
2011-11-22 09:59 - 2009-12-16 19:00 - 0000000 ____D C:\Program Files (x86)\TOSHIBA Games
2011-11-22 09:59 - 2009-12-16 18:46 - 0000000 ____D C:\Program Files\Google
2011-11-22 09:59 - 2009-12-16 18:46 - 0000000 ____D C:\Program Files (x86)\Google
2011-11-22 09:59 - 2009-12-16 18:36 - 0000000 ____D C:\Users\All Users\Ulead Systems
2011-11-22 09:59 - 2009-12-16 18:36 - 0000000 ____D C:\ProgramData\Ulead Systems
2011-11-22 09:59 - 2009-12-16 18:23 - 0000000 ____D C:\Program Files (x86)\Realtek WLAN Driver
2011-11-22 09:59 - 2009-12-16 18:16 - 0000000 ____D C:\Program Files\Realtek
2011-11-22 09:59 - 2009-12-16 18:06 - 0000000 ____D C:\Users\All Users\XP
2011-11-22 09:59 - 2009-12-16 18:06 - 0000000 ____D C:\Users\All Users\win7_64
2011-11-22 09:59 - 2009-12-16 18:06 - 0000000 ____D C:\Users\All Users\win7_32
2011-11-22 09:59 - 2009-12-16 18:06 - 0000000 ____D C:\Users\All Users\Vista64
2011-11-22 09:59 - 2009-12-16 18:06 - 0000000 ____D C:\Users\All Users\Vista32
2011-11-22 09:59 - 2009-12-16 18:06 - 0000000 ____D C:\ProgramData\XP
2011-11-22 09:59 - 2009-12-16 18:06 - 0000000 ____D C:\ProgramData\win7_64
2011-11-22 09:59 - 2009-12-16 18:06 - 0000000 ____D C:\ProgramData\win7_32
2011-11-22 09:59 - 2009-12-16 18:06 - 0000000 ____D C:\ProgramData\Vista64
2011-11-22 09:59 - 2009-12-16 18:06 - 0000000 ____D C:\ProgramData\Vista32
2011-11-22 09:59 - 2009-12-16 18:06 - 0000000 ____D C:\Program Files (x86)\TOSHIBA
2011-11-22 09:59 - 2009-08-21 00:22 - 0000000 ____D C:\Program Files\TOSHIBA
2011-11-22 09:59 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\Reference Assemblies
2011-11-22 09:59 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\MSBuild
2011-11-22 09:59 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\Microsoft Games
2011-11-22 09:59 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files (x86)\MSBuild
2011-11-22 09:59 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files (x86)\Windows NT
2011-11-22 09:57 - 2011-11-21 19:49 - 0000000 ____D C:\Users\User\AppData\Roaming\360F1
2011-11-22 09:19 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\Web
2011-11-22 09:19 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\Vss
2011-11-22 09:06 - 2009-07-13 20:45 - 0000000 ____D C:\Windows\ServiceProfiles
2011-11-22 08:57 - 2011-05-05 18:19 - 0000000 ____D C:\Users\User\Documents\Fax
2011-11-22 08:57 - 2011-03-04 14:46 - 0000000 ____D C:\Users\User\AppData\Roaming\Epson
2011-11-22 08:57 - 2011-03-01 17:36 - 0000000 ____D C:\Users\User\AppData\Roaming\Intuit Canada
2011-11-22 08:57 - 2009-12-27 11:27 - 0000000 ____D C:\Users\User\AppData\Roaming\Adobe
2011-11-22 08:56 - 2011-03-04 14:00 - 0000000 ____D C:\Users\All Users\ArcSoft
2011-11-22 08:56 - 2011-03-04 14:00 - 0000000 ____D C:\ProgramData\ArcSoft
2011-11-22 08:56 - 2011-03-01 17:34 - 0000000 ____D C:\Users\All Users\Intuit Canada
2011-11-22 08:56 - 2011-03-01 17:34 - 0000000 ____D C:\ProgramData\Intuit Canada
2011-11-22 08:56 - 2011-01-16 14:49 - 0000000 ____D C:\Users\User\AppData\Local\Roblox
2011-11-22 08:56 - 2009-12-16 18:46 - 0000000 ____D C:\Users\All Users\Google
2011-11-22 08:56 - 2009-12-16 18:46 - 0000000 ____D C:\ProgramData\Google
2011-11-22 08:56 - 2009-12-16 18:23 - 0000000 ____D C:\Users\All Users\Toshiba
2011-11-22 08:56 - 2009-12-16 18:23 - 0000000 ____D C:\ProgramData\Toshiba
2011-11-22 08:56 - 2009-07-13 19:20 - 0000000 ___RD C:\users\Default
2011-11-22 08:55 - 2011-11-22 08:55 - 0000000 ____A C:\Windows\setuperr.log
2011-11-22 08:53 - 2011-11-21 17:51 - 0000000 ____D C:\Program Files\Java
2011-11-22 08:53 - 2009-12-28 07:57 - 0000000 ____D C:\Program Files\Microsoft Office
2011-11-22 08:53 - 2009-12-27 11:42 - 0000000 ____D C:\Program Files\EpsonNet
2011-11-22 08:53 - 2009-12-16 18:19 - 0000000 ____D C:\Program Files\Synaptics
2011-11-22 08:53 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Common Files\SpeechEngines
2011-11-22 08:52 - 2009-12-16 18:12 - 0000000 ____D C:\Program Files\ATI
2011-11-22 08:51 - 2009-12-16 18:16 - 0000000 ____D C:\Program Files (x86)\Realtek
2011-11-22 08:51 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files (x86)\Reference Assemblies
2011-11-22 08:50 - 2009-12-27 11:42 - 0000000 ____D C:\Program Files (x86)\EpsonNet
2011-11-22 08:50 - 2009-12-27 11:40 - 0000000 ____D C:\Program Files (x86)\Epson Software
2011-11-22 08:49 - 2009-12-16 18:35 - 0000000 ____D C:\Program Files (x86)\Corel
2011-11-22 08:47 - 2011-03-04 13:59 - 0000000 ____D C:\Program Files (x86)\ArcSoft
2011-11-22 08:47 - 2009-08-21 00:24 - 0000000 ____D C:\Program Files (x86)\Adobe
2011-11-21 19:49 - 2011-11-21 19:49 - 0001213 ____A C:\Users\User\AppData\Roaming\ahst.lni
2011-11-21 19:49 - 2011-11-21 19:49 - 0000000 ____D C:\Program Files (x86)\LP
2011-11-21 19:43 - 2011-11-21 19:43 - 0065536 __ASH C:\Windows\System32\config\COMPONENTS{7525c032-14b1-11e1-84d0-002622f1b193}.TxR.blf
2011-11-21 18:26 - 2011-11-21 18:26 - 0010168 ____N C:\bootsqm.dat
2011-11-21 17:58 - 2011-11-21 17:58 - 0000833 ____A C:\Users\Public\Desktop\CCleaner.lnk
2011-11-21 17:51 - 2011-11-21 17:51 - 0525544 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
2011-11-21 17:51 - 2011-11-21 17:51 - 0190752 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
2011-11-21 17:51 - 2011-11-21 17:51 - 0171808 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
2011-11-21 17:51 - 2011-11-21 17:51 - 0171808 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
2011-11-21 15:47 - 2011-11-21 15:47 - 9852544 ____A (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-1.51.2.1300.exe
2011-11-21 15:47 - 2011-11-21 15:47 - 0000000 ____D C:\Windows\Sun
2011-11-21 15:46 - 2011-11-21 15:46 - 3511776 ____A (Piriform Ltd) C:\Users\User\Downloads\ccsetup312.exe
2011-11-21 15:38 - 2009-07-13 18:34 - 0000808 ____A C:\Windows\System32\Drivers\etc\hosts_bak_261
2011-11-14 11:01 - 2009-12-31 08:36 - 0008492 ____A C:\Users\User\AppData\Roaming\wklnhst.dat
2011-11-14 11:01 - 2009-07-13 21:32 - 0000000 ____D C:\Windows\System32\FxsTmp
2011-11-14 10:24 - 2011-11-14 10:24 - 0066658 ____A C:\Users\Public\Documents\14 NOV 2011.docx
2011-11-14 09:05 - 2011-11-14 09:05 - 0000714 ____A C:\Users\Public\Documents\Libraries - Shortcut.lnk
2011-11-14 07:57 - 2009-12-27 11:27 - 0000000 ____D C:\Users\User\AppData\Local\Google
2011-11-10 05:27 - 2011-11-10 05:27 - 0000215 ____A C:\Windows\System32\MRT.INI
2011-11-10 05:23 - 2009-12-27 11:32 - 52174280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2011-10-27 09:03 - 2011-10-19 20:32 - 0000016 ____A C:\Windows\System32\config\software.szfi
2011-10-20 18:31 - 2011-10-20 18:31 - 0000000 ____D C:\Users\User\AppData\Roaming\Sammsoft
2011-10-19 19:50 - 2011-10-14 13:22 - 0000000 ____D C:\Windows\Minidump
2011-10-17 07:25 - 2011-10-17 07:20 - 5356304 ____A (PC Cleaners) C:\Windows\uninst.exe
2011-10-17 07:20 - 2011-10-17 07:20 - 0000000 ____D C:\Users\User\AppData\Roaming\PC Cleaners
2011-10-17 07:20 - 2011-10-17 07:20 - 0000000 ____D C:\Users\All Users\PC1Data
2011-10-17 07:20 - 2011-10-17 07:20 - 0000000 ____D C:\ProgramData\PC1Data
2011-10-14 04:29 - 2011-10-14 04:29 - 0065536 __ASH C:\Windows\System32\config\COMPONENTS{42b3bcf8-ef4d-11df-825b-002622f1b193}.TxR.blf
2011-10-11 09:19 - 2011-08-02 11:45 - 0066590 ____A C:\Users\Public\Documents\01 AUGUST 2011.docx
2011-10-11 09:12 - 2011-09-13 06:33 - 0012099 ____A C:\Users\Public\Documents\SEPTEMBER 2011 ACTUALS.docx
2011-10-08 16:23 - 2011-10-08 16:23 - 0000000 ____D C:\Windows\system64
2011-09-30 21:24 - 2011-10-12 08:00 - 9326080 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2011-09-30 20:42 - 2011-10-12 08:00 - 5990912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2011-09-30 19:21 - 2011-10-12 08:00 - 1638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2011-09-30 18:59 - 2011-10-12 08:00 - 1638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2011-09-29 08:24 - 2011-11-09 08:01 - 1897328 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2011-09-28 20:09 - 2011-11-09 08:00 - 3141120 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2011-09-12 09:36 - 2011-08-02 11:42 - 0012403 ____A C:\Users\Public\Documents\AUGUST 2011 ACTUALS.docx
2011-08-31 14:00 - 2011-11-21 17:56 - 0025416 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys

========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

========================= Memory info ======================

Percentage of memory in use: 17%
Total physical RAM: 2814.36 MB
Available physical RAM: 2314.11 MB
Total Pagefile: 2812.51 MB
Available Pagefile: 2303.34 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB

======================= Partitions =========================

1 Drive c: (S3A7844D003) (Fixed) (Total:268.16 GB) (Free:229.15 GB) NTFS ==>[System with boot components]
2 Drive d: (System) (Fixed) (Total:1.46 GB) (Free:1.27 GB) NTFS ==>[System with boot components]
4 Drive f: (MALCOLM16GB) (Removable) (Total:15.73 GB) (Free:11.27 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 1024 KB
Disk 1 Online 15 GB 0 B

Partitions of Disk 0:

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 1500 MB 1024 KB
Partition 2 Primary 268 GB 1501 MB
Partition 0 Extended 17 GB 269 GB
Partition 4 Logical 17 GB 269 GB
Partition 3 Primary 10 GB 287 GB

Disk: 0
Partition 1
Hidden: Yes
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D System NTFS Partition 1500 MB Healthy Hidden

==========================================================

Last Boot: 2011-08-23 15:52

======================= End Of Log ==========================

Thanks for your help
JMM

Edited by Orange Blossom, 29 November 2011 - 04:28 PM.
Moved to log forum. ~ OB


BC AdBot (Login to Remove)

 


#2 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,696 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:10:21 PM

Posted 01 December 2011 - 10:36 AM

Hello jandmM2,

Welcome to Bleeping Computer.

Please update me about the current condition of your computer if the issue is not resolved.

#3 jandmM2

jandmM2
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:03:21 PM

Posted 01 December 2011 - 10:50 AM

Thank you for replying and inquiring as to the state of my problem.

The situation has not changed. The error is still ocuring and thus the laptop is not usable.

JMM

#4 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,696 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:10:21 PM

Posted 01 December 2011 - 11:02 AM

Hi again JMM,

Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste). Save it on the flashdrive as fixlist.txt

start
HKLM\...\RunOnce: [*Restore] C:\windows\system32\rstrui.exe /RUNONCE [296960 2009-07-13] (Microsoft Corporation)
HKLM-x32\...\Winlogon: [Userinit] c:\windows\syswow64\userinit.exe,
SubSystems: [Windows] ==> ZeroAccess
end

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Now please enter System Recovery Options.

Run FRST and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Also restart the computer, let it boot normally and tell me how it went.

#5 jandmM2

jandmM2
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:03:21 PM

Posted 01 December 2011 - 08:41 PM

Farbar

Applied the Fixit.txt with frst64.exe and then rebooted the computer. Computer booted completely. I made a restore point. Norton 360 found Trojan.gen.2 in consrv.dll and quarantined it. Updated Virus definitions.

Here is the results from frst64 Fixlog.txt.

Fix result of Farbars's Recovery Tool (FRST written by farbar Version 2.3.0)
Ran by SYSTEM at 2011-12-01 08:20:54 R:1
Running from F:\

==============================================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\*Restore Value deleted successfully.
HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit Value was restored.
HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Session Manager\SubSystems\\Windows Value was restored.

==== End of Fixlog =

#6 jandmM2

jandmM2
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:03:21 PM

Posted 01 December 2011 - 08:43 PM

FarBar

Is there anything else that I should do Like run malwarebytes etc.

I forgot in previous post to than you Which I do now,

Thank you

JMM

#7 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,696 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:10:21 PM

Posted 02 December 2011 - 05:16 AM

Great. :thumbup2:

  • Run Command Prompt as administrator:
    • Click on Start button.
    • Type Cmd in the Start Search text box.
    • Press Ctrl-Shift-Enter keyboard shortcut to run Command Prompt as Administrator.
    • Type in the following line and press Enter: netsh winsock reset
    • Close the Command Prompt.
  • Open your Malwarebytes' Anti-Malware.
    • First update it, to do that under the Update tab press "Check for Updates".
    • Under Scanner tab select "Perform Quick Scan", then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the MBAM log.
    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.


#8 jandmM2

jandmM2
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:03:21 PM

Posted 02 December 2011 - 10:41 AM

FarBar

Applied both tasks. The Mbam log file is below and the infected file found was quarantined and deleted. Any other tasks to do? All seems to working well. Thanks again. What would you say was the original cause of the issue?

JMM

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8290

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

03/12/2011 10:27:47 AM
mbam-log-2011-12-03 (10-27-47).txt

Scan type: Full scan (C:\|)
Objects scanned: 347709
Time elapsed: 1 hour(s), 44 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\User\AppData\Roaming\ahst.lni (Malware.Trace) -> Quarantined and deleted successfully.

#9 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,696 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:10:21 PM

Posted 02 December 2011 - 02:09 PM

The system was infected with ZeroAccess rootkit. We removed it with the first fix and Norton and Malwarebytes found the leftovers.

Which version of Java do you have. You can check it on the list of Programs And Features from control panel.

#10 jandmM2

jandmM2
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:03:21 PM

Posted 02 December 2011 - 02:19 PM

FarBar

Version of Java Is 6 update 29. Don't know if I should update to ver 7?

Thanks for the explanation.

J M M

#11 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,696 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:10:21 PM

Posted 02 December 2011 - 02:39 PM

Yes, please update to version 7. Make sure any older version is uninstalled.

We run ESET to make sure nothing is left behind. It takes some time but it is better to be safe than sorry.:)

  • To Clear the Java Runtime Environment (JRE) cache, do this:
    • Click Start > Settings > Control Panel.
    • Double-click the Java icon.
      -The Java Control Panel appears.
    • Click "Settings" under Temporary Internet Files.
      -The Temporary Files Settings dialog box appears.
    • Click "Delete Files".
      -The Delete Temporary Files dialog box appears.
      -There are three options on this window to clear the cache.
    • Make sure all the options are checked.
    • Click "OK" on Delete Temporary Files window.
      -Note: This deletes all the Downloaded Applications and Applets from the cache.
    • Click "OK" on Temporary Files Settings window.
    • Close the Java Control Panel.
    You can also view these instructions along with screenshots here.
  • ESET Online Scanner:

    Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

    Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

    • Please go here then click on: Posted Image

      Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
      All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

    • Select the option YES, I accept the Terms of Use then click on: Posted Image
    • When prompted allow the Add-On/Active X to install.
    • Make sure that the option Remove found threats and the option Scan archives are checked.
    • Now click on Advanced Settings and select the following:
    • Enable Anti-Stealth Technology
    • Now click on: Posted Image
    • The virus signature database... will begin to download. Be patient this may take some time depending on the speed of your Internet Connection.
    • When completed the Online Scan will begin automatically.
    • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
    • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
    • Now click on: Posted Image
    • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
    • Copy and paste that log as a reply to this topic.
    Note: Do not forget to re-enable your Anti-Virus application after running the above scan!


#12 jandmM2

jandmM2
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:03:21 PM

Posted 02 December 2011 - 08:05 PM

FarBar

Updated to Java v 7.0.1 and deleted all other versions successfully including the cache.

Successfully ran ESET online scanner with the log posted below. Nothing was found


ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK

JMM

#13 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,696 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:10:21 PM

Posted 02 December 2011 - 08:36 PM

That looks good. :thumbup2:

  • Please delete FRST tool as we don't need it any more. Also go to C:\FRST and delete the entire FRST folder.
  • Remove the old restore points and create a new restore point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Setting a new restore point AFTER cleaning your system will enable your computer to "roll-back" to a clean working state if needed. :
  • Go to Start => Right-click "Computer" and select "Properties".
  • In the left pane select "System Protection".
  • Press "Configure".
  • Select "Delete". Then press "Continue" close and "OK".
  • Select your drive (drive C) and press "Create".
    Fill in a name for the restore point and press "Create".
    After finished press "Close".
Recommendations:
  • I recommend using Site Advisor for safe surfing. It is a free extension both for Internet Explorer and Firefox. When you search a site it gives you an indication of how safe a site is.
  • I recommend installing this small application for safe surfing: Javacoolsİ SpywareBlaster
    SpywareBlaster will add a large list of programs and sites into your Internet Explorer and Firefox settings and that will protect you from running and downloading known malicious programs.
  • Download and install it.
  • Update it manually by clicking on Updates in the left pane and then Check for Updates.
  • Then enable all the protections by clicking on Protection Status on the left pane. Then click on Enable All Protection.
  • The free version doesn't have an automatic update. Update it once in two or three weeks and enable all protection again.
Happy Surfing JMM.:)

#14 jandmM2

jandmM2
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:03:21 PM

Posted 03 December 2011 - 12:56 PM

FarBar

All steps completed successfully and an additional full backup made to external drive. All is working well. Guess this topic can be closed.

Thanks again for all the assistance.

JMM

#15 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,696 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:10:21 PM

Posted 03 December 2011 - 06:45 PM

You are most welcome JMM. :)

This thread will now be closed since the issue seems to be resolved.

If you need this topic reopened, please send me a Private Message and I will reopen it for you. If you should have a new issue, please start a new topic.

Every one else should start a new topic.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users