Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Unknown Nasty In Win7


  • Please log in to reply
36 replies to this topic

#1 Carryon

Carryon

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:05:53 PM

Posted 19 June 2013 - 04:41 PM

Greetings --
I believe that something has invaded my Win7 PC & possibly my WinXP PC.
Description: Three PCs - 2 WinXP SP3 (1 desktop, 1 laptop) & 1 Win7 SP1 all on the same network. Laptop via wireless, 2 desktops connected via switch to each other & the Internet (Comcast). Both have 2GB RAM (could use more). WinXP drives (laptop & desktop) are shared and mapped to Win7.
Symptoms: Win7 - Over a period of a few weeks started running slow on Internet. Creeping slowness until it would stall when installing updates, e.g. Malwarebytes (1-2% then stalls), etc. I use Logmein (free) to access this computer everyday from work as I use it for my primary email (Outlook 2007). Everything good for several months. Then I would get kicked off after a few minutes, then not able to connect at all. Won't copy files from from mapped XP drives. Extremely slow loading websites and downloading email (Outlook 2007).
Installed anti-virus (a few years ago): Avast Free - Full System Scan every night
Other: WinPatrol 2012 Free, Windows firewall enabled, Windows updates automatic,
Default browser: Firefox (I hate IE). Each time I close Firefox it essentially "sterilizes" itself insofar as it is capable (clears cache, history, cookies, etc). Checked Firefox & IE for unwanted toolbars & addons. Both appear to be clean.
What I've done so far: 1) Pre-boot scan w/Avast - found nothing. 2) AVG bootable CD - 2012-08-23 version: 120823, found nothing 3) AVG bootable CD - 2013-05-15 version: 130515, would not boot on Win7 but ran on WinXP. 4) Ran TDSKiller - found nothing. 5) Ran Spybot - Found nothing. 6) HijackThis - log attached. 5) Installed different NIC but too old- no driver anywhere. 6) Ran Ccleaner a few times. Deleted files & cleaned registry as best it can. 7) Ran JRT. Did not delete anything - just saved report. 8) Ran DDS. Saved reports. 9) Ran AdwCleaner. Did not delete anything. Saved report 10) Ran SecurityCheck (downloaded using XP desktop. Canceled Win7 download after 15min).
If there is something there, my WinXP may be similarily infected.

Thanks in advance for your help.

Attached Files



BC AdBot (Login to Remove)

 


#2 Carryon

Carryon
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:05:53 PM

Posted 21 June 2013 - 12:07 PM

Subsequent to my original post:

  • I swapped computers, removing my HDDs from the original Win7 PC and installed in an identical PC. No change in performance. Still being blocked and nearly impossible to download anti-virus updates and virtually anything else while my XP PC functions normally on the same network.
  • I downloaded and ran OTL. OTL.txt is too large to upload.

 

 



#3 The Dark Knight

The Dark Knight

    The Magician


  • Security Colleague
  • 661 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Krypton
  • Local time:10:53 AM

Posted 22 June 2013 - 05:57 PM

Hello and welcome to BleepingComputer. I am The Dark Knight and will be assisting you. Please ask questions if anything is unclear. :welcome:

 

Please paste the contents of the OTL logs. You may need to use multiple posts. :)


If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!


If I have helped you please consider donating to the Neuroscience Research Institute.


Posted Image
Posted Image


#4 Carryon

Carryon
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:05:53 PM

Posted 23 June 2013 - 01:17 PM

Thanks very much for your help (One of my favorite movies!).

 

There are 40 otl files. Here's the first.

 

Please disregard this post. I misunderstood - how embarassing.

Attached Files


Edited by Carryon, 23 June 2013 - 01:34 PM.


#5 Carryon

Carryon
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:05:53 PM

Posted 23 June 2013 - 01:22 PM

This post is blank. Sorry for the inconvenience.


Edited by Carryon, 23 June 2013 - 01:35 PM.


#6 Carryon

Carryon
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:05:53 PM

Posted 23 June 2013 - 01:29 PM

Sorry - I misunderstood. Here is the first part of the OTL file:

 

OTL logfile created on: 6/21/2013 9:50:31 AM - Run 1
OTL by OldTimer - Version 3.2.36.3     Folder = C:\Users\Dave\Downloads
 Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
999.31 Mb Total Physical Memory | 457.30 Mb Available Physical Memory | 45.76% Memory free
1.98 Gb Paging File | 0.93 Gb Available in Paging File | 47.22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 82.57 Gb Free Space | 55.40% Space Free | Partition Type: NTFS
Drive D: | 186.31 Gb Total Space | 129.31 Gb Free Space | 69.41% Space Free | Partition Type: NTFS
 
Computer Name: DOUGLASFIR | User Name: David | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013/06/15 11:19:12 | 000,202,576 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\ramaint.exe
PRC - [2013/06/15 11:18:30 | 000,375,120 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
PRC - [2013/05/11 04:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/05/09 02:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/05/09 02:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013/04/01 09:09:59 | 001,964,408 | ---- | M] (LogMeIn, Inc.) -- C:\Users\Dave\AppData\Local\LogMeIn Rescue Unattended\LMIR0002.tmp\unattended_srv.exe
PRC - [2013/04/01 09:09:59 | 001,964,408 | ---- | M] (LogMeIn, Inc.) -- C:\Users\Dave\AppData\Local\LogMeIn Rescue Unattended\LMIR0002.tmp\unattended.exe
PRC - [2013/03/25 13:45:52 | 000,694,584 | ---- | M] (Motorola Mobility LLC) -- C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
PRC - [2013/03/25 13:45:52 | 000,121,144 | ---- | M] (Motorola Mobility LLC) -- C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
PRC - [2013/03/24 16:25:56 | 000,613,888 | ---- | M] (SanDisk Corporation) -- C:\Users\Dave\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2012/11/22 20:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012/03/25 12:13:18 | 000,329,312 | ---- | M] (BillP Studios) -- C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2012/03/12 11:28:18 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\Dave\Downloads\OTL.exe
PRC - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) -- C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe
PRC - [2011/03/25 23:26:58 | 000,064,112 | ---- | M] (VMware, Inc.) -- C:\Program Files\VMware\VMware Player\hqtray.exe
PRC - [2011/03/25 23:26:16 | 000,113,264 | ---- | M] (VMware, Inc.) -- C:\Program Files\VMware\VMware Player\vmware-authd.exe
PRC - [2011/03/25 22:27:40 | 000,539,248 | ---- | M] (VMware, Inc.) -- C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2011/02/24 23:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/01/26 11:08:44 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
PRC - [2010/11/08 13:04:20 | 000,390,528 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2010/09/17 16:40:06 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2010/05/04 12:07:22 | 000,503,080 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Update\NASvc.exe
PRC - [2009/06/17 12:18:42 | 006,582,912 | ---- | M] () -- D:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/12/10 02:10:14 | 000,024,636 | ---- | M] (Apache Software Foundation) -- D:\wamp\bin\apache\Apache2.2.11\bin\httpd.exe
PRC - [2008/10/14 22:38:56 | 000,623,992 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011/04/14 19:01:33 | 000,548,854 | ---- | M] () -- C:\Program Files\BillP Studios\WinPatrol\sqlite3.dll
MOD - [2011/03/25 23:26:48 | 000,970,352 | ---- | M] () -- C:\Program Files\VMware\VMware Player\libxml2.dll
MOD - [2011/03/25 23:26:18 | 000,068,720 | ---- | M] () -- C:\Program Files\VMware\VMware Player\zlib1.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2013/06/15 18:00:00 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/06/15 11:19:12 | 000,202,576 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\RaMaint.exe -- (LMIMaint)
SRV - [2013/06/15 11:18:30 | 000,375,120 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2013/05/11 04:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/05/09 02:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2013/04/01 09:09:59 | 001,964,408 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Users\Dave\AppData\Local\LogMeIn Rescue Unattended\LMIR0002.tmp\unattended_srv.exe -- (LMIRescueUA_1763321) LogMeIn Rescue (1763321)
SRV - [2013/03/25 13:45:52 | 000,121,144 | ---- | M] (Motorola Mobility LLC) [Auto | Running] -- C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe -- (Motorola Device Manager)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) [Auto | Running] -- C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe -- (PST Service)
SRV - [2011/03/25 23:26:46 | 000,334,448 | ---- | M] (VMware, Inc.) [Auto | Stopped] -- C:\Windows\System32\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2011/03/25 23:26:28 | 000,404,080 | ---- | M] (VMware, Inc.) [Auto | Stopped] -- C:\Windows\System32\vmnat.exe -- (VMware NAT Service)
SRV - [2011/03/25 23:26:16 | 000,113,264 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files\VMware\VMware Player\vmware-authd.exe -- (VMAuthdService)
SRV - [2011/03/25 22:27:40 | 000,539,248 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe -- (VMUSBArbService)
SRV - [2011/01/26 11:08:44 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Running] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/12/08 11:41:42 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/11/08 13:04:20 | 000,390,528 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
SRV - [2010/08/19 13:57:14 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files\VMware\VMware Player\vmware-ufad.exe -- (ufad-ws60)
SRV - [2010/05/04 12:07:22 | 000,503,080 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2009/07/13 19:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/13 19:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 19:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 19:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/06/17 12:18:42 | 006,582,912 | ---- | M] () [Auto | Running] -- D:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe -- (wampmysqld)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008/12/10 02:10:14 | 000,024,636 | ---- | M] (Apache Software Foundation) [Auto | Running] -- D:\wamp\bin\apache\apache2.2.11\bin\httpd.exe -- (wampapache)
SRV - [2007/03/20 17:41:24 | 000,153,792 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe -- (Adobe Version Cue CS3)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (Motousbnet)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (MotoSwitchService)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (motmodem)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (motccgpfl)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (motccgp)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (motandroidusb)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (LVUVC) Logitech QuickCam Fusion(UVC)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (lvpopflt)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (BTCFilterService)
DRV - [2013/06/15 11:19:08 | 000,013,624 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo)
DRV - [2013/06/15 11:18:33 | 000,086,888 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2013/05/09 02:59:10 | 000,765,736 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2013/05/09 02:59:10 | 000,368,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2013/05/09 02:59:10 | 000,174,664 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2013/05/09 02:59:10 | 000,061,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\Drivers\aswrdr2.sys -- (aswRdr)
DRV - [2013/05/09 02:59:10 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2013/05/09 02:59:10 | 000,049,376 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2013/05/09 02:59:09 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2013/05/09 02:59:08 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/03/25 23:27:18 | 000,854,256 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmx86.sys -- (vmx86)
DRV - [2011/03/25 23:27:16 | 000,070,768 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmci.sys -- (vmci)
DRV - [2011/03/25 23:25:46 | 000,024,688 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VMkbd.sys -- (vmkbd)
DRV - [2011/03/25 23:24:56 | 000,026,352 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV - [2011/03/25 22:27:32 | 000,032,368 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hcmon.sys -- (hcmon)
DRV - [2011/03/25 20:05:00 | 000,036,400 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV - [2011/03/25 20:05:00 | 000,016,560 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV - [2010/11/20 06:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 06:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 06:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 04:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 03:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 03:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 03:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/11/09 15:35:30 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\cpuz135_x32.sys -- (cpuz135)
DRV - [2010/09/17 16:40:06 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\System32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2010/09/17 16:39:58 | 000,013,408 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\radpms.sys -- (radpms)
DRV - [2010/08/19 13:56:38 | 000,022,448 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files\VMware\VMware Player\vstor2-ws60.sys -- (vstor2-ws60)
DRV - [2009/09/21 15:20:26 | 000,028,632 | ---- | M] (Intel Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\iqvw32.sys -- (NAL)
DRV - [2009/07/13 17:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | System | Running] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
DRV - [2009/07/13 16:02:50 | 000,211,456 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel®
DRV - [2007/05/11 18:31:22 | 000,041,888 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2006/09/12 12:02:10 | 000,046,309 | ---- | M] (Sonix) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\UALFDrv2.sys -- (UALFDrv2)
DRV - [2004/04/13 17:03:46 | 000,016,509 | ---- | M] (Palm, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PalmUSBD.sys -- (PalmUSBD)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://localhost/index.html
IE - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\..\SearchScopes,DefaultScope = {D00F8D47-DE11-492E-AA1D-DEF9C3B11192}
IE - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\..\SearchScopes\{D00F8D47-DE11-492E-AA1D-DEF9C3B11192}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
IE - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/06/17 10:58:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/06/15 18:00:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/06/15 17:59:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey 2.15.1\extensions\\Components: C:\Program Files\SeaMonkey\components [2013/01/26 10:47:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey 2.15.1\extensions\\Plugins: C:\Program Files\SeaMonkey\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/06/15 18:00:02 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/06/15 17:59:53 | 000,000,000 | ---D | M]
 
[2011/01/26 18:47:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\mozilla\Extensions
[2011/01/26 18:47:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013/06/19 12:17:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\uuralmwk.default\extensions
[2010/12/28 15:08:44 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\uuralmwk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013/05/16 08:47:36 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\uuralmwk.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2012/08/28 14:26:31 | 000,000,000 | ---D | M] (LogMeIn, Inc. Rescue Technician Console) -- C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\uuralmwk.default\extensions\TechnicianConsole@logmeinrescue.com
[2013/01/26 10:47:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\mozilla\SeaMonkey\Profiles\39ibsdp2.default\extensions
[2013/06/15 17:59:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/06/15 17:59:50 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2013/06/15 17:59:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2013/06/15 18:00:02 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/06/17 10:58:13 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
() (No name found) -- C:\USERS\DAVE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UURALMWK.DEFAULT\EXTENSIONS\{1A2D0EC4-75F5-4C91-89C4-3656F6E44B68}.XPI
() (No name found) -- C:\USERS\DAVE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UURALMWK.DEFAULT\EXTENSIONS\{A7C6CF7F-112C-4500-A7EA-39801A327E5F}.XPI
() (No name found) -- C:\USERS\DAVE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UURALMWK.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI
 
O1 HOSTS File: ([2012/06/10 19:10:03 | 000,442,806 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1             localhost
O1 - Hosts: 127.0.0.1    www.007guard.com
O1 - Hosts: 127.0.0.1    007guard.com
O1 - Hosts: 127.0.0.1    008i.com
O1 - Hosts: 127.0.0.1    www.008k.com
O1 - Hosts: 127.0.0.1    008k.com
O1 - Hosts: 127.0.0.1    www.00hq.com
O1 - Hosts: 127.0.0.1    00hq.com
O1 - Hosts: 127.0.0.1    010402.com
O1 - Hosts: 127.0.0.1    www.032439.com
O1 - Hosts: 127.0.0.1    032439.com
O1 - Hosts: 127.0.0.1    www.0scan.com
O1 - Hosts: 127.0.0.1    0scan.com
O1 - Hosts: 127.0.0.1    1000gratisproben.com
O1 - Hosts: 127.0.0.1    www.1000gratisproben.com
O1 - Hosts: 127.0.0.1    1001namen.com
O1 - Hosts: 127.0.0.1    www.1001namen.com
O1 - Hosts: 127.0.0.1    www.100888290cs.com
O1 - Hosts: 127.0.0.1    100888290cs.com
O1 - Hosts: 127.0.0.1    100sexlinks.com
O1 - Hosts: 127.0.0.1    www.100sexlinks.com
O1 - Hosts: 127.0.0.1    www.10sek.com
O1 - Hosts: 127.0.0.1    10sek.com
O1 - Hosts: 127.0.0.1    1-2005-search.com
O1 - Hosts: 15217 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe_ID0EYTHM] C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [VMware hqtray] C:\Program Files\VMware\VMware Player\hqtray.exe (VMware, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKU\S-1-5-21-1454471165-789336058-1801674531-1003..\Run: [SansaDispatch] C:\Users\Dave\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKU\S-1-5-21-1454471165-789336058-1801674531-1003..\Run: [Uploader] C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O15 - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\..Trusted Domains: wspbx.com ([]* in Trusted sites)
O16 - DPF: {3D19135C-6D38-44AD-80F0-D9318F48726D} http://myphone3.onvoip.net/commpilot/customcontrols/BwOutlook.CAB (BwOutlook.OutlookIntegrator)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.0.cab (DLM Control)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab (GMNRev Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B1FA02F9-6A7A-4D82-B931-EAE4B092F39A}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 15:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2012/05/02 15:03:21 | 000,000,000 | ---D | M] - C:\autoruns -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013/06/20 21:14:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/06/20 21:14:53 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013/06/20 21:14:53 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013/06/19 14:15:16 | 000,000,000 | ---D | C] -- C:\Users\Dave\Desktop\RK_Quarantine
[2013/06/19 13:17:23 | 000,688,992 | R--- | C] (Swearware) -- C:\Users\Dave\Desktop\dds.com
[2013/06/19 12:15:02 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/06/19 12:14:17 | 000,000,000 | ---D | C] -- C:\jrt
[2013/06/16 12:22:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013/06/16 12:21:59 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2013/06/16 12:21:38 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013/06/16 12:21:38 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013/06/16 12:21:38 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013/06/16 12:13:44 | 000,000,000 | ---D | C] -- C:\ProgramData\SecTaskMan
[2013/06/16 12:13:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Task Manager
[2013/06/16 12:13:38 | 000,000,000 | ---D | C] -- C:\Program Files\Security Task Manager
[2013/06/16 03:04:14 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013/06/16 03:04:09 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013/06/16 03:04:08 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013/06/16 03:04:07 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013/06/16 03:04:06 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/06/16 03:04:02 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013/06/16 03:04:01 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013/06/16 03:03:55 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013/06/15 17:59:48 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013/06/15 12:50:34 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/06/15 12:23:11 | 001,505,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
[2013/06/15 12:12:44 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\temp
[2013/06/15 11:54:27 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/06/15 11:54:27 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/06/15 11:54:27 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/06/15 11:54:15 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/06/15 11:53:49 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/06/15 11:36:57 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cryptdlg.dll
[2013/06/15 11:36:34 | 000,903,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certutil.exe
[2013/06/15 11:36:32 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certenc.dll
[2013/06/15 11:29:59 | 003,968,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2013/06/15 11:29:59 | 003,913,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2013/06/15 11:07:33 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\LavasoftStatistics
[2013/06/15 10:53:03 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\Ad-Aware Antivirus
[2013/06/14 05:57:46 | 000,000,000 | ---D | C] -- C:\Config.Msi
 
========== Files - Modified Within 30 Days ==========
 
[2013/06/21 09:54:34 | 000,013,088 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/21 09:54:34 | 000,013,088 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/21 09:10:33 | 000,626,846 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/06/21 09:10:33 | 000,107,748 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/06/21 09:05:50 | 000,016,384 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2013/06/21 09:05:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/06/21 09:05:38 | 785,887,232 | -HS- | M] () -- C:\hiberfil.sys
[2013/06/20 21:14:55 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/06/19 13:26:17 | 000,000,642 | ---- | M] () -- C:\Users\Dave\Documents\registry-export_06-19-13.reg
[2013/06/19 12:12:39 | 000,001,149 | ---- | M] () -- C:\Users\Dave\Desktop\Continue WinSock XP Fix Installation.lnk
[2013/06/18 18:10:04 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\Dave\Desktop\dds.com
[2013/06/17 10:58:14 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2013/06/17 06:51:16 | 001,699,176 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/06/16 12:21:32 | 000,094,112 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013/06/16 12:21:31 | 000,263,584 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2013/06/16 12:21:31 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013/06/16 12:21:30 | 000,866,720 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll
[2013/06/16 12:21:30 | 000,788,896 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2013/06/16 12:21:30 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013/06/16 12:19:13 | 000,014,462 | ---- | M] () -- C:\Users\Dave\Documents\cc_20130616_121909.reg
[2013/06/15 18:03:08 | 000,001,990 | ---- | M] () -- C:\Users\Dave\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/06/15 16:04:45 | 000,001,169 | ---- | M] () -- C:\Users\Dave\Desktop\Continue Media Crawler Installation.lnk
[2013/06/15 12:20:31 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts-06-19-2013
[2013/06/15 11:32:16 | 000,018,814 | ---- | M] () -- C:\Users\Dave\Documents\cc_20130615_113209.reg
[2013/06/15 11:21:10 | 000,002,003 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/06/15 11:18:33 | 000,086,888 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\System32\LMIRfsClientNP.dll
[2013/06/15 11:18:31 | 000,092,488 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\System32\LMIinit.dll
[2013/06/15 11:18:31 | 000,031,560 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\System32\LMIport.dll
[2013/05/28 09:28:10 | 000,000,600 | ---- | M] () -- C:\Users\Dave\AppData\Local\PUTTY.RND
 
========== Files Created - No Company Name ==========
 
[2013/06/20 21:14:55 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/06/19 13:26:17 | 000,000,642 | ---- | C] () -- C:\Users\Dave\Documents\registry-export_06-19-13.reg
[2013/06/19 12:12:39 | 000,001,149 | ---- | C] () -- C:\Users\Dave\Desktop\Continue WinSock XP Fix Installation.lnk
[2013/06/17 06:51:00 | 001,699,176 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/06/16 12:19:11 | 000,014,462 | ---- | C] () -- C:\Users\Dave\Documents\cc_20130616_121909.reg
[2013/06/15 16:03:40 | 000,001,169 | ---- | C] () -- C:\Users\Dave\Desktop\Continue Media Crawler Installation.lnk
[2013/06/15 11:54:27 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/06/15 11:54:27 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/06/15 11:54:27 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/06/15 11:54:27 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/06/15 11:54:27 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/06/15 11:32:13 | 000,018,814 | ---- | C] () -- C:\Users\Dave\Documents\cc_20130615_113209.reg
[2013/06/15 11:21:10 | 000,002,003 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/05/27 12:38:39 | 000,000,600 | ---- | C] () -- C:\Users\Dave\AppData\Local\PUTTY.RND
[2013/03/07 12:51:25 | 000,174,664 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2013/03/07 12:51:23 | 000,049,376 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2012/10/07 12:55:34 | 000,000,082 | ---- | C] () -- C:\Windows\operws.ini
[2012/10/07 12:54:14 | 000,024,576 | ---- | C] () -- C:\Windows\System32\GetDllList.dll
[2012/06/30 14:15:24 | 000,038,410 | ---- | C] () -- C:\Users\Dave\AppData\Roaming\Comma Separated Values (DOS).ADR
[2012/06/30 07:12:31 | 000,038,434 | ---- | C] () -- C:\Users\Dave\AppData\Roaming\Comma Separated Values (Windows).ADR
[2012/01/08 12:55:41 | 000,000,553 | ---- | C] () -- C:\Users\Dave\AppData\Local\Perfmon.PerfmonCfg
[2012/01/05 15:07:45 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2011/08/02 13:43:40 | 000,004,040 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/06/23 09:36:22 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
 
========== LOP Check ==========
 
[2012/10/07 09:52:15 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Motorola Mobility
[2011/06/23 16:11:00 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Notepad++
[2012/09/19 01:08:15 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\.purple
[2013/06/15 10:53:03 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Ad-Aware Antivirus
[2013/01/09 16:57:32 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2013/04/28 12:18:46 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1
[2013/05/19 10:18:04 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\DVDVideoSoft
[2012/08/26 15:31:27 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\EPSON
[2011/01/27 14:51:29 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Leadertech
[2012/06/04 17:43:03 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Motorola
[2012/06/04 17:45:48 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Motorola Mobility
[2013/06/19 13:50:27 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Notepad++
[2011/01/06 09:17:04 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\OpenOffice.org
[2010/12/28 10:24:00 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Panda Security
[2011/01/27 13:10:39 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Philips
[2013/02/10 11:00:57 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\PTGui
[2013/03/24 16:20:47 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\SanDisk
[2013/06/16 12:29:27 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Seagate
[2011/08/03 11:27:09 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Simple Star
[2011/07/08 15:21:23 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\SystemRequirementsLab
[2012/01/08 14:06:40 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Thunderbird
[2012/03/28 23:41:12 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\WinPatrol
[2013/06/20 21:23:28 | 000,000,000 | ---D | M] -- C:\Users\NewGuy\AppData\Roaming\Motorola Mobility
[2013/06/20 21:25:17 | 000,000,000 | ---D | M] -- C:\Users\NewGuy\AppData\Roaming\WinPatrol
[2009/07/13 22:53:46 | 000,000,364 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< BASESERVICES >
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: EXPLORER.EXE  >
[2011/02/25 23:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 19:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/25 23:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/30 23:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/25 23:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 06:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/24 23:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\erdnt\cache\explorer.exe
[2011/02/24 23:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\explorer.exe
[2011/02/24 23:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/02 23:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/02 23:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 00:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
[2013/06/19 14:15:10 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\0af06f0b-ccb5-4c02-aa58-c7761fa9032d\explorer.exe
 
< MD5 for: SERVICES  >
[2006/09/18 15:41:30 | 000,017,244 | ---- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 -- C:\$INPLACE.~TR\Machine\DATA\Windows\System32\drivers\etc\services
[2009/06/10 15:39:37 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\System32\drivers\etc\services
[2009/06/10 15:39:37 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
 
< MD5 for: SERVICES.CFG  >
[2012/09/23 21:43:36 | 000,603,848 | R--- | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 04:37:26 | 000,558,990 | ---- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 -- C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg
 
< MD5 for: SERVICES.DAT  >
[2013/04/21 21:04:55 | 000,001,720 | ---- | M] () MD5=43C1700D78D89F0B1F6FA88FD132BE1A -- C:\jrt\services.dat
 
< MD5 for: SERVICES.EXE  >
[2009/07/13 19:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\erdnt\cache\services.exe
[2009/07/13 19:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\System32\services.exe
[2009/07/13 19:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2013/06/19 14:15:05 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\cf7e109a-201a-4d08-a718-412048839c3d\services.exe
 
< MD5 for: SERVICES.EXE.MUI  >
[2009/07/13 20:03:06 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 -- C:\Windows\System32\en-US\services.exe.mui
[2009/07/13 20:03:06 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 -- C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui
 
< MD5 for: SERVICES.HTML  >
[2008/04/16 10:29:04 | 000,004,166 | ---- | M] () MD5=DB0CABD236311DDEB186C9B8A13F39A6 -- C:\Program Files\BillP Studios\WinPatrol\services.html
 
< MD5 for: SERVICES.LNK  >
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Start Menu\Programs\Administrative Tools\services.lnk
File not found Unable to obtain MD5 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
File not found Unable to obtain MD5 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
 
< MD5 for: SERVICES.MOF  >
[2009/06/10 15:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\System32\wbem\services.mof
[2009/06/10 15:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof
 
< MD5 for: SERVICES.MSC  >
[2009/07/13 20:08:50 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\en-US\services.msc
[2009/06/10 15:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\services.msc
[2009/07/13 20:08:50 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 15:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
 
< MD5 for: SERVICES.PTXML  >
[2009/07/13 14:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 14:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml
 
< MD5 for: SERVICES.SBS  >
[2011/03/01 09:58:46 | 000,034,818 | ---- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B -- C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
 
< MD5 for: SVCHOST.EXE  >
[2009/07/13 19:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\erdnt\cache\svchost.exe
[2009/07/13 19:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009/07/13 19:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2013/04/04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2013/06/19 14:15:08 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\19e25798-a1bb-43db-96ac-a376000eaf7b\svchost.exe
[2013/06/19 14:15:05 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\227e6f5e-6608-448e-a24e-36d6b7246892\svchost.exe
[2013/06/19 14:15:06 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\26d2e6da-9d00-4347-8a8a-9ec995def4b4\svchost.exe
[2013/06/19 14:15:05 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\3b8bfed3-4215-4a02-b953-d849d8bea8ec\svchost.exe
[2013/06/19 14:15:05 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\4ff39b84-ceaa-4845-a73d-1305f4868542\svchost.exe
[2013/06/19 14:15:06 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\5fd271e2-5697-4a50-8ad9-bd32cb7fc368\svchost.exe
[2013/06/19 14:15:06 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\6e10de19-46ca-47e9-95e4-0f3ac6bef76e\svchost.exe
[2013/06/19 14:15:08 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\90512ee1-d9c7-4b9b-b58c-ebade2e27951\svchost.exe
[2013/06/19 14:15:05 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\aad1de66-979d-4025-a32c-b2be279d294a\svchost.exe
[2013/06/19 14:15:05 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\ac839ad6-ea3e-40fc-b42e-da2bfe625349\svchost.exe
[2013/06/19 14:15:07 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\b4035cee-4af7-4975-885a-5e6eee16fe4a\svchost.exe
[2013/06/19 14:15:07 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\c787fe51-e267-4d48-a77c-51961893f6bc\svchost.exe
[2013/06/19 14:15:09 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\d12708ba-05e9-4e74-ade7-754fa95ff029\svchost.exe
[2013/06/19 14:15:05 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\f0ccffd2-82a6-40c3-afd8-b3d7bca819f7\svchost.exe
 
< MD5 for: USERINIT.EXE  >
[2010/11/20 06:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\erdnt\cache\userinit.exe
[2010/11/20 06:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010/11/20 06:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 19:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009/10/28 00:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/27 23:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 06:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\erdnt\cache\winlogon.exe
[2010/11/20 06:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010/11/20 06:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/13 19:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2013/06/19 14:15:05 | 000,051,928 | ---- | M] () MD5=E887F98CD5B28446E6D51A88336F68C8 -- C:\Windows\Temp\f08eb5a9-e2e6-4e5f-b173-efc0a11003d1\winlogon.exe
 
< dir "%systemdrive%\*" /S /A:L /C >
 Volume in drive C has no label.
 Volume Serial Number is C449-627E
 Directory of C:\
07/13/2009  10:53 PM    <JUNCTION>     Documents and Settings [C:\Users]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings
07/13/2009  10:53 PM    <SYMLINKD>     All Users [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Default User [C:\Users\Default]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Roaming]
06/21/2011  03:50 PM    <JUNCTION>     Cookies [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies]
06/21/2011  03:50 PM    <JUNCTION>     Local Settings [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     My Documents [C:\Users\Administrator\Documents]
06/21/2011  03:50 PM    <JUNCTION>     NetHood [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/21/2011  03:50 PM    <JUNCTION>     PrintHood [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/21/2011  03:50 PM    <JUNCTION>     Recent [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent]
06/21/2011  03:50 PM    <JUNCTION>     SendTo [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo]
06/21/2011  03:50 PM    <JUNCTION>     Start Menu [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu]
06/21/2011  03:50 PM    <JUNCTION>     Templates [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\AppData\Local
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes



#7 Carryon

Carryon
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:05:53 PM

Posted 23 June 2013 - 01:31 PM

Here is the second part of the OTL file:

 

 Directory of C:\Documents and Settings\Administrator\AppData\Local\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\AppData\Local\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\AppData\Local\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [.]
06/21/2011  03:50 PM    <JUNCTION>     History [.]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Documents
06/21/2011  03:50 PM    <JUNCTION>     My Music [C:\Users\Administrator\Music]
06/21/2011  03:50 PM    <JUNCTION>     My Pictures [C:\Users\Administrator\Pictures]
06/21/2011  03:50 PM    <JUNCTION>     My Videos [C:\Users\Administrator\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Local Settings
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Administrator\My Documents
06/21/2011  03:50 PM    <JUNCTION>     My Music [C:\Users\Administrator\Music]
06/21/2011  03:50 PM    <JUNCTION>     My Pictures [C:\Users\Administrator\Pictures]
06/21/2011  03:50 PM    <JUNCTION>     My Videos [C:\Users\Administrator\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [.]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [.]
07/13/2009  10:53 PM    <JUNCTION>     Documents [.]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [.]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [.]
07/13/2009  10:53 PM    <JUNCTION>     Templates [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [.]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\All Users\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Roaming]
12/08/2010  11:03 AM    <JUNCTION>     Cookies [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies]
12/08/2010  11:03 AM    <JUNCTION>     Local Settings [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     My Documents [C:\Users\Dave\Documents]
12/08/2010  11:03 AM    <JUNCTION>     NetHood [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
12/08/2010  11:03 AM    <JUNCTION>     PrintHood [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
12/08/2010  11:03 AM    <JUNCTION>     Recent [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Recent]
12/08/2010  11:03 AM    <JUNCTION>     SendTo [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\SendTo]
12/08/2010  11:03 AM    <JUNCTION>     Start Menu [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu]
12/08/2010  11:03 AM    <JUNCTION>     Templates [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [.]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Documents
12/08/2010  11:03 AM    <JUNCTION>     My Music [C:\Users\Dave\Music]
12/08/2010  11:03 AM    <JUNCTION>     My Pictures [C:\Users\Dave\Pictures]
12/08/2010  11:03 AM    <JUNCTION>     My Videos [C:\Users\Dave\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [.]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Dave\My Documents
12/08/2010  11:03 AM    <JUNCTION>     My Music [C:\Users\Dave\Music]
12/08/2010  11:03 AM    <JUNCTION>     My Pictures [C:\Users\Dave\Pictures]
12/08/2010  11:03 AM    <JUNCTION>     My Videos [C:\Users\Dave\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Roaming]
07/13/2009  10:53 PM    <JUNCTION>     Local Settings [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     My Documents [C:\Users\Default\Documents]
07/13/2009  10:53 PM    <JUNCTION>     NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/13/2009  10:53 PM    <JUNCTION>     PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/13/2009  10:53 PM    <JUNCTION>     Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/13/2009  10:53 PM    <JUNCTION>     SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [.]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Default\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [.]
07/13/2009  10:53 PM    <JUNCTION>     History [.]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default\My Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Default\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Roaming]
07/13/2009  10:53 PM    <JUNCTION>     Local Settings [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     My Documents [C:\Users\Default\Documents]
07/13/2009  10:53 PM    <JUNCTION>     NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/13/2009  10:53 PM    <JUNCTION>     PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/13/2009  10:53 PM    <JUNCTION>     Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/13/2009  10:53 PM    <JUNCTION>     SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [.]
07/13/2009  10:53 PM    <JUNCTION>     History [.]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Default\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [.]
07/13/2009  10:53 PM    <JUNCTION>     History [.]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Default User\My Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Default\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Roaming]
01/06/2011  03:09 PM    <JUNCTION>     Cookies [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Cookies]
01/06/2011  03:09 PM    <JUNCTION>     Local Settings [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     My Documents [C:\Users\LogMeInRemoteUser\Documents]
01/06/2011  03:09 PM    <JUNCTION>     NetHood [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/06/2011  03:09 PM    <JUNCTION>     PrintHood [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/06/2011  03:09 PM    <JUNCTION>     Recent [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Recent]
01/06/2011  03:09 PM    <JUNCTION>     SendTo [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\SendTo]
01/06/2011  03:09 PM    <JUNCTION>     Start Menu [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Start Menu]
01/06/2011  03:09 PM    <JUNCTION>     Templates [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\AppData\Local
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\AppData\Local\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\AppData\Local\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [.]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Documents
01/06/2011  03:09 PM    <JUNCTION>     My Music [C:\Users\LogMeInRemoteUser\Music]
01/06/2011  03:09 PM    <JUNCTION>     My Pictures [C:\Users\LogMeInRemoteUser\Pictures]
01/06/2011  03:09 PM    <JUNCTION>     My Videos [C:\Users\LogMeInRemoteUser\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Local Settings
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Local Settings\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Local Settings\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [.]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\LogMeInRemoteUser\My Documents
01/06/2011  03:09 PM    <JUNCTION>     My Music [C:\Users\LogMeInRemoteUser\Music]
01/06/2011  03:09 PM    <JUNCTION>     My Pictures [C:\Users\LogMeInRemoteUser\Pictures]
01/06/2011  03:09 PM    <JUNCTION>     My Videos [C:\Users\LogMeInRemoteUser\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\NewGuy
06/20/2013  09:23 PM    <JUNCTION>     Application Data [C:\Users\NewGuy\AppData\Roaming]
06/20/2013  09:23 PM    <JUNCTION>     Cookies [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\Cookies]
06/20/2013  09:23 PM    <JUNCTION>     Local Settings [C:\Users\NewGuy\AppData\Local]
06/20/2013  09:23 PM    <JUNCTION>     My Documents [C:\Users\NewGuy\Documents]
06/20/2013  09:23 PM    <JUNCTION>     NetHood [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/20/2013  09:23 PM    <JUNCTION>     PrintHood [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/20/2013  09:23 PM    <JUNCTION>     Recent [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\Recent]
06/20/2013  09:23 PM    <JUNCTION>     SendTo [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\SendTo]
06/20/2013  09:23 PM    <JUNCTION>     Start Menu [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\Start Menu]
06/20/2013  09:23 PM    <JUNCTION>     Templates [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\NewGuy\AppData\Local
06/20/2013  09:23 PM    <JUNCTION>     Application Data [C:\Users\NewGuy\AppData\Local]
06/20/2013  09:23 PM    <JUNCTION>     History [C:\Users\NewGuy\AppData\Local\Microsoft\Windows\History]
06/20/2013  09:23 PM    <JUNCTION>     Temporary Internet Files [C:\Users\NewGuy\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\NewGuy\Documents
06/20/2013  09:23 PM    <JUNCTION>     My Music [C:\Users\NewGuy\Music]
06/20/2013  09:23 PM    <JUNCTION>     My Pictures [C:\Users\NewGuy\Pictures]
06/20/2013  09:23 PM    <JUNCTION>     My Videos [C:\Users\NewGuy\Videos]
               0 File(s)              0 bytes
 Directory of C:\Documents and Settings\Public\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 


Here is the third part of the OTL file:

 

 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [.]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [.]
07/13/2009  10:53 PM    <JUNCTION>     Documents [.]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [.]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [.]
07/13/2009  10:53 PM    <JUNCTION>     Templates [.]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users
07/13/2009  10:53 PM    <SYMLINKD>     All Users [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Default User [C:\Users\Default]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Roaming]
06/21/2011  03:50 PM    <JUNCTION>     Cookies [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies]
06/21/2011  03:50 PM    <JUNCTION>     Local Settings [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     My Documents [C:\Users\Administrator\Documents]
06/21/2011  03:50 PM    <JUNCTION>     NetHood [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/21/2011  03:50 PM    <JUNCTION>     PrintHood [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/21/2011  03:50 PM    <JUNCTION>     Recent [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent]
06/21/2011  03:50 PM    <JUNCTION>     SendTo [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo]
06/21/2011  03:50 PM    <JUNCTION>     Start Menu [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu]
06/21/2011  03:50 PM    <JUNCTION>     Templates [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [.]
06/21/2011  03:50 PM    <JUNCTION>     History [.]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Documents
06/21/2011  03:50 PM    <JUNCTION>     My Music [C:\Users\Administrator\Music]
06/21/2011  03:50 PM    <JUNCTION>     My Pictures [C:\Users\Administrator\Pictures]
06/21/2011  03:50 PM    <JUNCTION>     My Videos [C:\Users\Administrator\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
06/21/2011  03:50 PM    <JUNCTION>     Application Data [C:\Users\Administrator\AppData\Local]
06/21/2011  03:50 PM    <JUNCTION>     History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
06/21/2011  03:50 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\Administrator\My Documents
06/21/2011  03:50 PM    <JUNCTION>     My Music [C:\Users\Administrator\Music]
06/21/2011  03:50 PM    <JUNCTION>     My Pictures [C:\Users\Administrator\Pictures]
06/21/2011  03:50 PM    <JUNCTION>     My Videos [C:\Users\Administrator\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/13/2009  10:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [.]
07/13/2009  10:53 PM    <JUNCTION>     Desktop [.]
07/13/2009  10:53 PM    <JUNCTION>     Documents [.]
07/13/2009  10:53 PM    <JUNCTION>     Favorites [.]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [.]
07/13/2009  10:53 PM    <JUNCTION>     Templates [.]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [.]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Application Data\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Roaming]
12/08/2010  11:03 AM    <JUNCTION>     Cookies [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies]
12/08/2010  11:03 AM    <JUNCTION>     Local Settings [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     My Documents [C:\Users\Dave\Documents]
12/08/2010  11:03 AM    <JUNCTION>     NetHood [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
12/08/2010  11:03 AM    <JUNCTION>     PrintHood [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
12/08/2010  11:03 AM    <JUNCTION>     Recent [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Recent]
12/08/2010  11:03 AM    <JUNCTION>     SendTo [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\SendTo]
12/08/2010  11:03 AM    <JUNCTION>     Start Menu [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu]
12/08/2010  11:03 AM    <JUNCTION>     Templates [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [.]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Documents
12/08/2010  11:03 AM    <JUNCTION>     My Music [C:\Users\Dave\Music]
12/08/2010  11:03 AM    <JUNCTION>     My Pictures [C:\Users\Dave\Pictures]
12/08/2010  11:03 AM    <JUNCTION>     My Videos [C:\Users\Dave\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [C:\Users\Dave\AppData\Local]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
12/08/2010  11:03 AM    <JUNCTION>     Application Data [.]
12/08/2010  11:03 AM    <JUNCTION>     History [C:\Users\Dave\AppData\Local\Microsoft\Windows\History]
12/08/2010  11:03 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\Dave\My Documents
12/08/2010  11:03 AM    <JUNCTION>     My Music [C:\Users\Dave\Music]
12/08/2010  11:03 AM    <JUNCTION>     My Pictures [C:\Users\Dave\Pictures]
12/08/2010  11:03 AM    <JUNCTION>     My Videos [C:\Users\Dave\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Default
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Roaming]
07/13/2009  10:53 PM    <JUNCTION>     Local Settings [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     My Documents [C:\Users\Default\Documents]
07/13/2009  10:53 PM    <JUNCTION>     NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/13/2009  10:53 PM    <JUNCTION>     PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/13/2009  10:53 PM    <JUNCTION>     Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/13/2009  10:53 PM    <JUNCTION>     SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [.]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Default\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [.]
07/13/2009  10:53 PM    <JUNCTION>     History [.]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\My Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Default\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Roaming]
07/13/2009  10:53 PM    <JUNCTION>     Local Settings [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     My Documents [C:\Users\Default\Documents]
07/13/2009  10:53 PM    <JUNCTION>     NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/13/2009  10:53 PM    <JUNCTION>     PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/13/2009  10:53 PM    <JUNCTION>     Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/13/2009  10:53 PM    <JUNCTION>     SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/13/2009  10:53 PM    <JUNCTION>     Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/13/2009  10:53 PM    <JUNCTION>     Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [.]
07/13/2009  10:53 PM    <JUNCTION>     History [.]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Default\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/13/2009  10:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/13/2009  10:53 PM    <JUNCTION>     Application Data [.]
07/13/2009  10:53 PM    <JUNCTION>     History [.]
07/13/2009  10:53 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\Default User\My Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Default\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Roaming]
01/06/2011  03:09 PM    <JUNCTION>     Cookies [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Cookies]
01/06/2011  03:09 PM    <JUNCTION>     Local Settings [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     My Documents [C:\Users\LogMeInRemoteUser\Documents]
01/06/2011  03:09 PM    <JUNCTION>     NetHood [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/06/2011  03:09 PM    <JUNCTION>     PrintHood [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/06/2011  03:09 PM    <JUNCTION>     Recent [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Recent]
01/06/2011  03:09 PM    <JUNCTION>     SendTo [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\SendTo]
01/06/2011  03:09 PM    <JUNCTION>     Start Menu [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Start Menu]
01/06/2011  03:09 PM    <JUNCTION>     Templates [C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [.]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Documents
01/06/2011  03:09 PM    <JUNCTION>     My Music [C:\Users\LogMeInRemoteUser\Music]
01/06/2011  03:09 PM    <JUNCTION>     My Pictures [C:\Users\LogMeInRemoteUser\Pictures]
01/06/2011  03:09 PM    <JUNCTION>     My Videos [C:\Users\LogMeInRemoteUser\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [C:\Users\LogMeInRemoteUser\AppData\Local]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
01/06/2011  03:09 PM    <JUNCTION>     Application Data [.]
01/06/2011  03:09 PM    <JUNCTION>     History [C:\Users\LogMeInRemoteUser\AppData\Local\Microsoft\Windows\History]
01/06/2011  03:09 PM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Users\LogMeInRemoteUser\My Documents
01/06/2011  03:09 PM    <JUNCTION>     My Music [C:\Users\LogMeInRemoteUser\Music]
01/06/2011  03:09 PM    <JUNCTION>     My Pictures [C:\Users\LogMeInRemoteUser\Pictures]
01/06/2011  03:09 PM    <JUNCTION>     My Videos [C:\Users\LogMeInRemoteUser\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\NewGuy
06/20/2013  09:23 PM    <JUNCTION>     Application Data [C:\Users\NewGuy\AppData\Roaming]
06/20/2013  09:23 PM    <JUNCTION>     Cookies [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\Cookies]
06/20/2013  09:23 PM    <JUNCTION>     Local Settings [C:\Users\NewGuy\AppData\Local]
06/20/2013  09:23 PM    <JUNCTION>     My Documents [C:\Users\NewGuy\Documents]
06/20/2013  09:23 PM    <JUNCTION>     NetHood [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/20/2013  09:23 PM    <JUNCTION>     PrintHood [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/20/2013  09:23 PM    <JUNCTION>     Recent [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\Recent]
06/20/2013  09:23 PM    <JUNCTION>     SendTo [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\SendTo]
06/20/2013  09:23 PM    <JUNCTION>     Start Menu [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\Start Menu]
06/20/2013  09:23 PM    <JUNCTION>     Templates [C:\Users\NewGuy\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\NewGuy\AppData\Local
06/20/2013  09:23 PM    <JUNCTION>     Application Data [C:\Users\NewGuy\AppData\Local]
06/20/2013  09:23 PM    <JUNCTION>     History [C:\Users\NewGuy\AppData\Local\Microsoft\Windows\History]
06/20/2013  09:23 PM    <JUNCTION>     Temporary Internet Files [C:\Users\NewGuy\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\NewGuy\Documents
06/20/2013  09:23 PM    <JUNCTION>     My Music [C:\Users\NewGuy\Music]
06/20/2013  09:23 PM    <JUNCTION>     My Pictures [C:\Users\NewGuy\Pictures]
06/20/2013  09:23 PM    <JUNCTION>     My Videos [C:\Users\NewGuy\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Public\Documents
07/13/2009  10:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/13/2009  10:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/13/2009  10:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
     Total Files Listed:
               0 File(s)              0 bytes
            1378 Dir(s)  91,167,961,088 bytes free
 
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2013/06/15 17:59:59 | 000,865,968 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2013/06/15 17:59:59 | 000,865,968 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2013/06/15 17:59:59 | 000,865,968 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2013/06/15 18:00:01 | 000,920,472 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2013/06/15 18:00:01 | 000,920,472 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2013/06/15 18:00:01 | 000,920,472 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2012/08/27 10:13:34 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2012/08/27 10:13:34 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2012/08/27 10:13:34 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2013/05/16 17:34:33 | 000,757,400 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" [2013/05/16 17:34:33 | 000,757,400 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\SEAMONKEY.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\SeaMonkey\uninstall\helper.exe" /HideShortcuts [2013/01/18 23:21:08 | 000,824,728 | ---- | M] (mozilla.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\SEAMONKEY.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\SeaMonkey\uninstall\helper.exe" /ShowShortcuts [2013/01/18 23:21:08 | 000,824,728 | ---- | M] (mozilla.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\SEAMONKEY.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\SeaMonkey\uninstall\helper.exe" /SetAsDefaultAppGlobal [2013/01/18 23:21:08 | 000,824,728 | ---- | M] (mozilla.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\SEAMONKEY.EXE\shell\open\command\\: "C:\Program Files\SeaMonkey\seamonkey.exe" [2013/01/18 23:21:08 | 000,068,096 | ---- | M] (mozilla.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\SEAMONKEY.EXE\shell\properties\command\\: "C:\Program Files\SeaMonkey\seamonkey.exe" -preferences [2013/01/18 23:21:08 | 000,068,096 | ---- | M] (mozilla.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\SEAMONKEY.EXE\shell\safemode\command\\: "C:\Program Files\SeaMonkey\seamonkey.exe" -safe-mode [2013/01/18 23:21:08 | 000,068,096 | ---- | M] (mozilla.org)
 
< hklm\software\clients\startmenuinternet|command /64 /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2013/06/15 17:59:59 | 000,865,968 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2013/06/15 17:59:59 | 000,865,968 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2013/06/15 17:59:59 | 000,865,968 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2013/06/15 18:00:01 | 000,920,472 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2013/06/15 18:00:01 | 000,920,472 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2013/06/15 18:00:01 | 000,920,472 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2012/08/27 10:13:34 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2012/08/27 10:13:34 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2012/08/27 10:13:34 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2013/05/16 17:34:33 | 000,757,400 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" [2013/05/16 17:34:33 | 000,757,400 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\SEAMONKEY.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\SeaMonkey\uninstall\helper.exe" /HideShortcuts [2013/01/18 23:21:08 | 000,824,728 | ---- | M] (mozilla.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\SEAMONKEY.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\SeaMonkey\uninstall\helper.exe" /ShowShortcuts [2013/01/18 23:21:08 | 000,824,728 | ---- | M] (mozilla.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\SEAMONKEY.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\SeaMonkey\uninstall\helper.exe" /SetAsDefaultAppGlobal [2013/01/18 23:21:08 | 000,824,728 | ---- | M] (mozilla.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\SEAMONKEY.EXE\shell\open\command\\: "C:\Program Files\SeaMonkey\seamonkey.exe" [2013/01/18 23:21:08 | 000,068,096 | ---- | M] (mozilla.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\SEAMONKEY.EXE\shell\properties\command\\: "C:\Program Files\SeaMonkey\seamonkey.exe" -preferences [2013/01/18 23:21:08 | 000,068,096 | ---- | M] (mozilla.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\SEAMONKEY.EXE\shell\safemode\command\\: "C:\Program Files\SeaMonkey\seamonkey.exe" -safe-mode [2013/01/18 23:21:08 | 000,068,096 | ---- | M] (mozilla.org)

< End of report >



#8 The Dark Knight

The Dark Knight

    The Magician


  • Security Colleague
  • 661 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Krypton
  • Local time:10:53 AM

Posted 24 June 2013 - 06:38 AM

Good evening Carryon,

 

Please run OTL.exe.

  • Copy the commands with file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :OTL

     

    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O7 - HKU\S-1-5-21-1454471165-789336058-1801674531-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    :Commands
    [EmptyTemp]

  • Return to OTL.exe, right click in the "Custom Scans/Fixes" window (under the light green bar) and choose Paste.
  • Click the red Run Fix button.
  • A fix log in Notepad will appear. Copy the contents of the fix log to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTL.exe

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

 

=====

 

Then, please download to the Desktop RogueKiller (by tigzy).

  • Please quit all programs.
  • Start RogueKiller.exe.
  • Wait until Prescan has finished.
  • Click on Scan.
  • Click on Report and copy/paste the contents of the report in your next reply.

 

=====

 

In your reply please provide the contents of the logs from OTL (fix log) and RogueKiller.

 

 

 


If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!


If I have helped you please consider donating to the Neuroscience Research Institute.


Posted Image
Posted Image


#9 Carryon

Carryon
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:05:53 PM

Posted 24 June 2013 - 08:23 AM

Hi Dark Knight --

 

Thanks very much for your help. Below are the logs you requested.

 

--------------------------------------------------------------------------------------------------------------------------------

 

OTL Fix Log:

 

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-1454471165-789336058-1801674531-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 433843 bytes
->Temporary Internet Files folder emptied: 38418 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 118483236 bytes
->Flash cache emptied: 42326 bytes
 
User: All Users
 
User: Dave
->Temp folder emptied: 24112655 bytes
->Temporary Internet Files folder emptied: 662567 bytes
->Java cache emptied: 853579 bytes
->FireFox cache emptied: 70415682 bytes
->Flash cache emptied: 3141329 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 57472 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: LogMeInRemoteUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: NewGuy
->Temp folder emptied: 454296 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 13785388 bytes
->Flash cache emptied: 57472 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 114286288 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 89733 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 741 bytes
RecycleBin emptied: 850805426 bytes
 
Total Files Cleaned = 1,142.00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 06242013_070123

Files\Folders moved on Reboot...
C:\Windows\temp\_avast_\unp137689122.tmp moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
C:\Windows\temp\vmware-SYSTEM\vmware-usbarb-SYSTEM-2600.log moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
 

--------------------------------------------------------------------------------------------------------------------------------

 

RogueKiller:

 

RogueKiller V8.6.1 [Jun 19 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : David [Admin rights]
Mode : Scan -- Date : 06/24/2013 07:11:10
| ARK || FAK || MBR |

¤¤¤ Bad processes : 2 ¤¤¤
[SUSP PATH] unattended_srv.exe -- C:\Users\Dave\AppData\Local\LogMeIn Rescue Unattended\LMIR0002.tmp\unattended_srv.exe [7] -> KILLED [TermProc]
[SUSP PATH] unattended.exe -- C:\Users\Dave\AppData\Local\LogMeIn Rescue Unattended\LMIR0002.tmp\unattended.exe [7] -> KILLED [TermProc]

¤¤¤ Registry Entries : 7 ¤¤¤
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyPics (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyMusic (0) -> FOUND
[HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ DESK] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : Mal.Hosts ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts

127.0.0.1    download-winmx-free.com --> Potentially malicious!
127.0.0.1    www.download-winmx-free.com --> Potentially malicious!
127.0.0.1    www.facebook.com.img335.tk --> Potentially malicious!
127.0.0.1    free-winmx-downloads.com --> Potentially malicious!
127.0.0.1    www.free-winmx-downloads.com --> Potentially malicious!
127.0.0.1    www.google.dospop.com --> Potentially malicious!
127.0.0.1    mp3winmx.com --> Potentially malicious!
127.0.0.1    www.mp3winmx.com --> Potentially malicious!
127.0.0.1    winmx.click-new-download.com --> Potentially malicious!
127.0.0.1    www.winmx.click-new-download.com --> Potentially malicious!
127.0.0.1    winmx-d0wnload.com --> Potentially malicious!
127.0.0.1    www.winmx-d0wnload.com --> Potentially malicious!
127.0.0.1    www.winmxfrance.com --> Potentially malicious!
127.0.0.1    winmxfrance.com --> Potentially malicious!
127.0.0.1    winmx-freebie.com --> Potentially malicious!
127.0.0.1    www.winmx-freebie.com --> Potentially malicious!
127.0.0.1    winmx-music-download.com --> Potentially malicious!
127.0.0.1    www.winmx-music-download.com --> Potentially malicious!
127.0.0.1    winmx-usa.com --> Potentially malicious!
127.0.0.1    www.winmx-usa.com --> Potentially malicious!

127.0.0.1       localhost
::1             localhost
127.0.0.1    www.007guard.com
127.0.0.1    007guard.com
127.0.0.1    008i.com
127.0.0.1    www.008k.com
127.0.0.1    008k.com
127.0.0.1    www.00hq.com
127.0.0.1    00hq.com
127.0.0.1    010402.com
127.0.0.1    www.032439.com
127.0.0.1    032439.com
127.0.0.1    www.0scan.com
127.0.0.1    0scan.com
127.0.0.1    1000gratisproben.com
127.0.0.1    www.1000gratisproben.com
127.0.0.1    1001namen.com
127.0.0.1    www.1001namen.com
127.0.0.1    www.100888290cs.com
127.0.0.1    100888290cs.com
[...]


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD1600AAJS-00B4A0 ATA Device +++++
--- User ---
[MBR] 073034c37be3bf707bc4b225433cfcf5
[BSP] 742f621ff06ce32ee1e1fd5230e305a2 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152617 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: WDC WD1600AAJS-00B4A0 ATA Device +++++
--- User ---
[MBR] 845c23bc61a42effeee7bb7c858658a8
[BSP] 020007aca84afcd336a08586c9a14e37 : Legit.A MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 190780 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive2: WDC WD1600AAJS-00B4A0 ATA Device +++++
--- User ---
[MBR] 09f1580e0e705f4d9330806f0b520171
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 32 | Size: 61050 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Finished : << RKreport[0]_S_06242013_071110.txt >>
RKreport[0]_S_06192013_141955.txt
 



#10 The Dark Knight

The Dark Knight

    The Magician


  • Security Colleague
  • 661 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Krypton
  • Local time:10:53 AM

Posted 25 June 2013 - 04:35 PM

Hello Carryon,

  • Please re-run RogueKiller.
  • Click on the Delete button.
  • The report has been created on the Desktop. Please post it in your reply.

 

How is your computer running now?


If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!


If I have helped you please consider donating to the Neuroscience Research Institute.


Posted Image
Posted Image


#11 Carryon

Carryon
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:05:53 PM

Posted 25 June 2013 - 05:20 PM

Hello Dark Knight --

 

Here's the the RogueKiller report after hitting the Delete button. I noticed in that it marked several entries in the hosts file as "Potentially malicious!".  I opened the hosts file in notepad++ and found that it has 15,262 lines in it. Here are the last 2 lines:

     # This list is Copyright 2000-2008 Safer Networking Limited
     # End of entries inserted by Spybot - Search & Destroy

 

Should I be concerned about this?

 

RogueKiller Report -----------------------------------------------------------------------------------------------------------------------------------------------

 

RogueKiller V8.6.1 [Jun 19 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : David [Admin rights]
Mode : Remove -- Date : 06/25/2013 16:03:39
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 0 ¤¤¤

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : Mal.Hosts ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts

127.0.0.1    download-winmx-free.com --> Potentially malicious!
127.0.0.1    www.download-winmx-free.com --> Potentially malicious!
127.0.0.1    www.facebook.com.img335.tk --> Potentially malicious!
127.0.0.1    free-winmx-downloads.com --> Potentially malicious!
127.0.0.1    www.free-winmx-downloads.com --> Potentially malicious!
127.0.0.1    www.google.dospop.com --> Potentially malicious!
127.0.0.1    mp3winmx.com --> Potentially malicious!
127.0.0.1    www.mp3winmx.com --> Potentially malicious!
127.0.0.1    winmx.click-new-download.com --> Potentially malicious!
127.0.0.1    www.winmx.click-new-download.com --> Potentially malicious!
127.0.0.1    winmx-d0wnload.com --> Potentially malicious!
127.0.0.1    www.winmx-d0wnload.com --> Potentially malicious!
127.0.0.1    www.winmxfrance.com --> Potentially malicious!
127.0.0.1    winmxfrance.com --> Potentially malicious!
127.0.0.1    winmx-freebie.com --> Potentially malicious!
127.0.0.1    www.winmx-freebie.com --> Potentially malicious!
127.0.0.1    winmx-music-download.com --> Potentially malicious!
127.0.0.1    www.winmx-music-download.com --> Potentially malicious!
127.0.0.1    winmx-usa.com --> Potentially malicious!
127.0.0.1    www.winmx-usa.com --> Potentially malicious!

127.0.0.1       localhost
::1             localhost
127.0.0.1    www.007guard.com
127.0.0.1    007guard.com
127.0.0.1    008i.com
127.0.0.1    www.008k.com
127.0.0.1    008k.com
127.0.0.1    www.00hq.com
127.0.0.1    00hq.com
127.0.0.1    010402.com
127.0.0.1    www.032439.com
127.0.0.1    032439.com
127.0.0.1    www.0scan.com
127.0.0.1    0scan.com
127.0.0.1    1000gratisproben.com
127.0.0.1    www.1000gratisproben.com
127.0.0.1    1001namen.com
127.0.0.1    www.1001namen.com
127.0.0.1    www.100888290cs.com
127.0.0.1    100888290cs.com
[...]


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD1600AAJS-00B4A0 ATA Device +++++
--- User ---
[MBR] 073034c37be3bf707bc4b225433cfcf5
[BSP] 742f621ff06ce32ee1e1fd5230e305a2 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152617 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: WDC WD1600AAJS-00B4A0 ATA Device +++++
--- User ---
[MBR] 845c23bc61a42effeee7bb7c858658a8
[BSP] 020007aca84afcd336a08586c9a14e37 : Legit.A MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 190780 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_D_06252013_160339.txt >>
RKreport[001]_D_06252013_155614.txt;RKreport[0]_D_06252013_155614.txt;RKreport[0]_S_06192013_141955.txt
RKreport[0]_S_06242013_071110.txt;RKreport[0]_S_06252013_160147.txt


 



#12 Carryon

Carryon
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:05:53 PM

Posted 25 June 2013 - 07:04 PM

To answer your last question: "How is your computer running now?"

 

It took several minutes to load oracle.com. Downloading the Java installer (as we speak) from Oracle is estimated at 1 hour 38 minutes and climbing. The same download of the Java installer on my XP PC took 15 seconds!

 

I would say that many local functions (non-Internet) seem to be reasonably normal.



#13 The Dark Knight

The Dark Knight

    The Magician


  • Security Colleague
  • 661 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Krypton
  • Local time:10:53 AM

Posted 26 June 2013 - 04:34 PM

Hello Carryon,

 

Should I be concerned about this?

Please re-run RogueKiller and tick all of those potentially malicious entries. Then click Delete.

 

Post new log in your reply.


If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!


If I have helped you please consider donating to the Neuroscience Research Institute.


Posted Image
Posted Image


#14 Carryon

Carryon
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:05:53 PM

Posted 26 June 2013 - 08:55 PM

Hi Dark Knight --

 

When RogueKiller finished its scan it displayed this message: "Please look at the different tabs and delete items with the buttons"

None of the tabs had any buttons:
     Processes Tab: 2 Processes killed. These were for Logmein Rescue which I use in my work.
     Registry Tab: Blank. No entries.
     Hosts Tab: Showed only text.
     Proxy Tab: Blank. No entries.
     DNS Tab: Blank. No entries.
     Driver Tab: Listed 11 drivers
     Files Tab: Blank. No entries.
     MBR Tab: Showed only text.
     Shortcuts Tab: Showed only text.

 

I think that the only way to remove the "Potentially malicious!" entries in the hosts file is to edit it manually. I won't do so unless instructed by you.
 

To further refine my observations, funtions that are non-network related appear to be fine. It's only the network functions (internal between my Win7 & XP PCs and expecially Internet) that hardly work or not at all. To eliminate hardware failure I swapped disks with another identical PC that I have. It functions exactly the same as when the disks were in the first PC. I also changed the Ethernet cables and the ports on my switch to no avail. I eliminated the switch by connecting my Win7 PC directly into the cable modem. My Win7 PC chokes and still my XP PC hums along.

 

Sorry that the symptoms remain but nothing positive has reared it's ugly head so far.

 

-------------------------------------------------------------------------------------------------------------------------

 

RogueKiller Report (after Delete):

 

RogueKiller V8.6.1 [Jun 19 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : David [Admin rights]
Mode : Remove -- Date : 06/26/2013 19:36:01
| ARK || FAK || MBR |

¤¤¤ Bad processes : 2 ¤¤¤
[SUSP PATH] unattended_srv.exe -- C:\Users\Dave\AppData\Local\LogMeIn Rescue Unattended\LMIR0002.tmp\unattended_srv.exe [7] -> KILLED [TermProc]
[SUSP PATH] unattended.exe -- C:\Users\Dave\AppData\Local\LogMeIn Rescue Unattended\LMIR0002.tmp\unattended.exe [7] -> KILLED [TermThr]

¤¤¤ Registry Entries : 0 ¤¤¤

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : Mal.Hosts ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts

127.0.0.1    download-winmx-free.com --> Potentially malicious!
127.0.0.1    www.download-winmx-free.com --> Potentially malicious!
127.0.0.1    www.facebook.com.img335.tk --> Potentially malicious!
127.0.0.1    free-winmx-downloads.com --> Potentially malicious!
127.0.0.1    www.free-winmx-downloads.com --> Potentially malicious!
127.0.0.1    www.google.dospop.com --> Potentially malicious!
127.0.0.1    mp3winmx.com --> Potentially malicious!
127.0.0.1    www.mp3winmx.com --> Potentially malicious!
127.0.0.1    winmx.click-new-download.com --> Potentially malicious!
127.0.0.1    www.winmx.click-new-download.com --> Potentially malicious!
127.0.0.1    winmx-d0wnload.com --> Potentially malicious!
127.0.0.1    www.winmx-d0wnload.com --> Potentially malicious!
127.0.0.1    www.winmxfrance.com --> Potentially malicious!
127.0.0.1    winmxfrance.com --> Potentially malicious!
127.0.0.1    winmx-freebie.com --> Potentially malicious!
127.0.0.1    www.winmx-freebie.com --> Potentially malicious!
127.0.0.1    winmx-music-download.com --> Potentially malicious!
127.0.0.1    www.winmx-music-download.com --> Potentially malicious!
127.0.0.1    winmx-usa.com --> Potentially malicious!
127.0.0.1    www.winmx-usa.com --> Potentially malicious!

127.0.0.1       localhost
::1             localhost
127.0.0.1    www.007guard.com
127.0.0.1    007guard.com
127.0.0.1    008i.com
127.0.0.1    www.008k.com
127.0.0.1    008k.com
127.0.0.1    www.00hq.com
127.0.0.1    00hq.com
127.0.0.1    010402.com
127.0.0.1    www.032439.com
127.0.0.1    032439.com
127.0.0.1    www.0scan.com
127.0.0.1    0scan.com
127.0.0.1    1000gratisproben.com
127.0.0.1    www.1000gratisproben.com
127.0.0.1    1001namen.com
127.0.0.1    www.1001namen.com
127.0.0.1    www.100888290cs.com
127.0.0.1    100888290cs.com
[...]


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD1600AAJS-00B4A0 ATA Device +++++
--- User ---
[MBR] 073034c37be3bf707bc4b225433cfcf5
[BSP] 742f621ff06ce32ee1e1fd5230e305a2 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152617 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: WDC WD1600AAJS-00B4A0 ATA Device +++++
--- User ---
[MBR] 845c23bc61a42effeee7bb7c858658a8
[BSP] 020007aca84afcd336a08586c9a14e37 : Legit.A MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 190780 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_D_06262013_193601.txt >>
RKreport[0]_S_06192013_141955.txt;RKreport[0]_S_06262013_192506.txt


 



#15 The Dark Knight

The Dark Knight

    The Magician


  • Security Colleague
  • 661 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Krypton
  • Local time:10:53 AM

Posted 27 June 2013 - 04:32 PM

Hey Carryon,

 

Please set Windows to show hidden/system files and folders so that you can find them:

  • Please click Start and open My Computer.
  • On the Organize tab, click on Folder and search options.
  • On the View tab, uncheck Hide file extensions for known file types.
  • Also uncheck Hide protected operating system files (Recommended) and click Yes on the warning message.
  • Under Hidden files and folders, check Show hidden files, folders, or drives.
  • Click Apply.
  • Click OK and close My Computer.

I will give you instructions for hiding them again after it looks like your computer is clean.

 

Please go to C:\Windows\system32\drivers\etc and find this file: hosts.

 

Search for the following entries, and delete all of them.

 

127.0.0.1    download-winmx-free.com
127.0.0.1    www.download-winmx-free.com
127.0.0.1    www.facebook.com.img335.tk
127.0.0.1    free-winmx-downloads.com
127.0.0.1    www.free-winmx-downloads.com
127.0.0.1    www.google.dospop.com
127.0.0.1    mp3winmx.com
127.0.0.1    www.mp3winmx.com
127.0.0.1    winmx.click-new-download.com
127.0.0.1    www.winmx.click-new-download.com
127.0.0.1    winmx-d0wnload.com
127.0.0.1    www.winmx-d0wnload.com
127.0.0.1    www.winmxfrance.com
127.0.0.1    winmxfrance.com
127.0.0.1    www.winmx-freebie.com
127.0.0.1    winmx-music-download.com
127.0.0.1    www.winmx-music-download.com
127.0.0.1    winmx-usa.com

 

The please re-run RogueKiller and post the new log.


If you make yourself more than just a man, if you devote yourself to an ideal...you become something else entirely. A legend, Mr. Wayne, a legend!


If I have helped you please consider donating to the Neuroscience Research Institute.


Posted Image
Posted Image





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users