This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help removing Heur.dropper trojan

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Running Vista, AVG 2011 continuously gives me win 32 heur.dropper notice and says it can't fix it. I am new to this forum (and fixing my PC) so I will post information to the best of my ability.

Here is the text from my OTL scan:

OTL logfile created on: 6/29/2011 8:43:59 AM - Run 1
OTL by OldTimer - Version 3.2.24.2 Folder = C:\Users\Julie\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.87 Gb Total Physical Memory | 2.05 Gb Available Physical Memory | 52.88% Memory free
7.95 Gb Paging File | 4.38 Gb Available in Paging File | 55.17% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453.57 Gb Total Space | 206.65 Gb Free Space | 45.56% Space Free | Partition Type: NTFS
Drive D: | 12.18 Gb Total Space | 0.33 Gb Free Space | 2.71% Space Free | Partition Type: NTFS
Drive J: | 295.02 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive K: | 465.26 Gb Total Space | 421.13 Gb Free Space | 90.52% Space Free | Partition Type: FAT32

Computer Name: OWNER-PC | User Name: Julie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Julie\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe (IObit)
PRC - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
PRC - C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe (LeapFrog Enterprises, Inc.)
PRC - C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Hitachi\Hitachi Backup\HitachiBackupService.exe (Hitachi GST)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)


========== Modules (SafeList) ==========

MOD - C:\Users\Julie\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (MatSvc) – C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)
SRV:64bit: - (NisSrv) – C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\DRIVERS\xaudio64.exe (Conexant Systems, Inc.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AVG Security Toolbar Service) – C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (UMVPFSrv) – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (LeapFrog Connect Device Service) – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe (LeapFrog Enterprises, Inc.)
SRV - (HitachiBackupService) – C:\Program Files (x86)\Hitachi\Hitachi Backup\HitachiBackupService.exe (Hitachi GST)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\DRIVERS\AVGIDSDriver.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\DRIVERS\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (LVUVC64) Logitech HD Webcam C510(UVC) – C:\Windows\SysNative\DRIVERS\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\DRIVERS\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (CompFilter64) – C:\Windows\SysNative\DRIVERS\lvbflt64.sys (Logitech Inc.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\DRIVERS\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\DRIVERS\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (SmartDefragDriver) – C:\Windows\SysNative\Drivers\SmartDefragDriver.sys ()
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\DRIVERS\AVGIDSFilter.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\DRIVERS\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\DRIVERS\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\DRIVERS\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (LVPr2Mon) – C:\Windows\SysNative\DRIVERS\LVPr2M64.sys ()
DRV:64bit: - (LVPr2M64) – C:\Windows\SysNative\DRIVERS\LVPr2M64.sys ()
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (netr7364) – C:\Windows\SysNative\DRIVERS\netr7364.sys (Ralink Technology, Corp.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (FlyUsb) – C:\Windows\SysNative\DRIVERS\FlyUsb.sys (LeapFrog)
DRV:64bit: - (CAXHWBS3) – C:\Windows\SysNative\DRIVERS\CAXHWBS3.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DP) – C:\Windows\SysNative\DRIVERS\CAX_DP.sys (Conexant Systems, Inc.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\DRIVERS\xaudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\Wbem\ntfs.mof ()
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys (Conexant)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/?ref=hp"
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.1.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.10.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: [removed]:1.4
FF - prefs.js..extensions.enabledItems: [removed]:4.4.5.184
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p="


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/30 07:07:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Meeting Center\Modules\Firefox [2011/02/17 14:44:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2011/03/28 07:57:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG10\Firefox4\ [2011/06/27 19:16:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared [2011/06/27 19:16:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/21 15:34:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/06/18 08:55:46 | 000,000,000 | —D | M]

[2010/04/25 08:30:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Julie\AppData\Roaming\Mozilla\Extensions
[2011/06/22 11:59:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Julie\AppData\Roaming\Mozilla\Firefox\Profiles\18zq0u9j.default\extensions
[2010/06/07 07:21:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Julie\AppData\Roaming\Mozilla\Firefox\Profiles\18zq0u9j.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/17 18:58:23 | 000,000,000 | —D | M] (AddThis) – C:\Users\Julie\AppData\Roaming\Mozilla\Firefox\Profiles\18zq0u9j.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2011/06/16 13:49:35 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Julie\AppData\Roaming\Mozilla\Firefox\Profiles\18zq0u9j.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/05/15 07:53:34 | 000,000,000 | —D | M] (Swag Bucks Community Toolbar) – C:\Users\Julie\AppData\Roaming\Mozilla\Firefox\Profiles\18zq0u9j.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
[2011/05/15 07:53:33 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\Julie\AppData\Roaming\Mozilla\Firefox\Profiles\18zq0u9j.default\extensions\[removed]
[2011/06/23 12:01:29 | 000,000,000 | —D | M] (No name found) – C:\Users\Julie\AppData\Roaming\Mozilla\Firefox\Profiles\18zq0u9j.default\extensions\staged
[2010/10/23 11:25:48 | 000,000,923 | —- | M] () – C:\Users\Julie\AppData\Roaming\Mozilla\Firefox\Profiles\18zq0u9j.default\searchplugins\conduit.xml
[2011/06/19 11:55:33 | 000,001,524 | —- | M] () – C:\Users\Julie\AppData\Roaming\Mozilla\Firefox\Profiles\18zq0u9j.default\searchplugins\swagbuckscom.xml
[2011/03/27 16:59:23 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/01/16 22:06:18 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/06/23 07:02:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/23 07:30:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/27 18:54:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/23 09:36:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
File not found (No name found) –
[2011/02/17 14:44:02 | 000,000,000 | —D | M] (Genesys Meeting Center) – C:\PROGRAM FILES (X86)\MEETING CENTER\MODULES\FIREFOX
() (No name found) – C:\USERS\JULIE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\18ZQ0U9J.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\USERS\JULIE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\18ZQ0U9J.DEFAULT\EXTENSIONS\[removed]
[2011/06/21 15:34:33 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/02/07 12:23:55 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\NPcol400.dll
[2011/02/07 12:23:56 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\NPcol500.dll
[2011/03/18 14:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 14:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/02/19 12:31:15 | 000,430,057 | R— | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 14806 more lines…
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (eBay Toolbar Helper) - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTb.dll (eBay Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files (x86)\PicLensIE\cooliris.dll (Cooliris Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (eBay Toolbar) - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTb.dll (eBay Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [WPCUMI] C:\Windows\SysNative\WpcUmi.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KbdStub.EXE ()
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [Monitor] C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKCU..\Run: [ccleaner] C:\Program Files (x86)\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [WMPNSCFG] File not found
O4 - Startup: C:\Users\Julie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hitachi LifeStudio Tray.lnk = C:\Users\Julie\AppData\Roaming\Microsoft\Installer\{B15B502F-FEC3-4AB5-9967-B3B7FFC99043}\MyKey.ico ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Customize Menu - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8:64bit: - Extra context menu item: eBay Search - C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTb.dll (eBay Inc.)
O8:64bit: - Extra context menu item: Fill Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O8:64bit: - Extra context menu item: RoboForm Toolbar - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8:64bit: - Extra context menu item: Save Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Customize Menu - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: eBay Search - C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTb.dll (eBay Inc.)
O8 - Extra context menu item: Fill Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files (x86)\PicLensIE\cooliris.dll (Cooliris Inc.)
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/24 11:26:00 | 000,000,740 | R— | M] () - J:\autorun.inf – [ UDF ]
O32 - AutoRun File - [2010/06/03 10:45:28 | 000,000,060 | —- | M] () - K:\autorun.inf – [ FAT32 ]
O33 - MountPoints2\{5949414e-3e79-11e0-943a-001fe2567a25}\Shell - "" = AutoRun
O33 - MountPoints2\{5949414e-3e79-11e0-943a-001fe2567a25}\Shell\AutoRun\command - "" = J:\MI.exe
O33 - MountPoints2\{c3d865d4-9b5f-11e0-8b60-001fe2567a25}\Shell\AutoRun\command - "" = J:\fscommand\LS_Start_Launch.exe – [2010/05/10 14:00:11 | 000,151,040 | R— | M] ()
O33 - MountPoints2\{c3d865d4-9b5f-11e0-8b60-001fe2567a25}\Shell\Launcher\command - "" = J:\Get_Started_with_LifeStudio.exe – [2010/05/10 14:00:13 | 003,478,888 | R— | M] (Adobe Systems, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\LVCodec2.dll (Logitech Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/06/27 20:28:51 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/06/27 19:52:50 | 000,000,000 | —D | C] – C:\Windows\pss
[2011/06/27 19:38:44 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Roaming\AVG10
[2011/06/27 19:17:05 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2011/06/27 19:16:47 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar
[2011/06/27 19:16:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2011
[2011/06/27 19:13:53 | 000,000,000 | —D | C] – C:\ProgramData\AVG10
[2011/06/27 19:13:53 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\AVG
[2011/06/27 19:11:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2011/06/27 19:04:01 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/06/27 18:40:00 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Local\{F91DA3A9-B148-49D8-BBBA-BA8089B413F8}
[2011/06/27 18:38:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Hitachi
[2011/06/24 22:10:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2011/06/24 22:10:24 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/06/21 07:46:47 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Window Registry Repair
[2011/06/21 07:46:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Window Registry Repair
[2011/06/21 07:46:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free Window Registry Repair
[2011/06/21 07:36:27 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Local\{8C9F4CC5-F889-4609-9599-090A730816DF}
[2011/06/20 21:02:43 | 000,000,000 | —D | C] – C:\Hitachi Backup
[2011/06/20 21:01:59 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Roaming\HitachiGST
[2011/06/20 20:47:36 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Local\Cooliris
[2011/06/20 18:57:25 | 000,000,000 | -H-D | C] – C:\.hitachi-lifestudio
[2011/06/20 18:57:18 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Local\LifeStudio
[2011/06/20 18:56:52 | 000,000,000 | —D | C] – C:\ProgramData\Hitachi GST
[2011/06/20 18:56:43 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hitachi
[2011/06/20 18:56:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\PicLensIE
[2011/06/20 07:52:57 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Local\{97B11FF0-A058-409F-BD48-21ACD53B4AE4}
[2011/06/16 13:40:05 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Local\{6A73B350-CCFE-441B-838E-A6FAAC3F3251}
[2011/06/16 09:31:25 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/16 09:31:25 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/16 09:31:24 | 002,303,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/06/16 09:31:24 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript9.dll
[2011/06/16 09:31:24 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/06/16 09:31:24 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/06/16 09:31:24 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/16 09:31:24 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/15 22:25:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/06/15 22:24:25 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/06/15 22:24:24 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/06/15 22:24:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/06/15 07:34:06 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/12 09:51:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Calendar Sync
[2011/06/05 08:40:04 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Local\{B2495D63-43E7-45A1-B78B-4F21E40B8496}
[2011/06/01 11:22:27 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Local\Reasonable_Software_House
[2011/06/01 11:22:05 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Roaming\Reasonable Software House Ltd
[2011/06/01 11:21:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Connect
[2011/05/31 08:09:48 | 000,000,000 | —D | C] – C:\Users\Julie\AppData\Local\{9595D64B-324A-44EF-B91E-41F501C6C4F1}
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/29 08:45:00 | 000,000,432 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{E01CDC1E-762F-4FC6-9281-034F7630D388}.job
[2011/06/29 08:13:55 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/29 08:13:51 | 000,002,027 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/06/29 08:06:20 | 000,002,575 | —- | M] () – C:\Users\Julie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hitachi LifeStudio Tray.lnk
[2011/06/29 08:06:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/29 08:05:48 | 000,000,326 | —- | M] () – C:\Windows\tasks\GlaryInitialize.job
[2011/06/29 08:05:47 | 000,000,406 | —- | M] () – C:\Windows\tasks\AutoSmartDefrag.job
[2011/06/29 08:05:28 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/29 08:05:27 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/29 08:05:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/28 14:37:27 | 000,000,000 | —- | M] () – C:\Users\Julie\AppData\Local\{72F6EE2D-C776-4A34-99AE-DBE1A5C1BC4F}
[2011/06/28 07:02:25 | 000,000,844 | —- | M] () – C:\Users\Public\Desktop\Microsoft Fix it Center.lnk
[2011/06/27 19:39:31 | 120,201,870 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/06/27 19:16:32 | 000,000,862 | —- | M] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2011/06/27 19:16:30 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\avg\incavi.avm
[2011/06/27 19:16:30 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\avg\iavichjw.avm
[2011/06/27 18:38:55 | 000,003,033 | —- | M] () – C:\Users\Julie\Desktop\Hitachi Backup.lnk
[2011/06/27 18:38:55 | 000,003,007 | —- | M] () – C:\Users\Julie\Desktop\Hitachi LifeStudio.lnk
[2011/06/26 22:14:53 | 000,012,668 | -HS- | M] () – C:\ProgramData\x34ld0wa75056ge55t2tgw3a1m25050
[2011/06/24 22:11:17 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2011/06/24 22:11:00 | 000,725,364 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/06/24 22:11:00 | 000,609,268 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/24 22:11:00 | 000,105,808 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/21 07:46:47 | 000,000,872 | —- | M] () – C:\Users\Julie\Desktop\Free Window Registry Repair.lnk
[2011/06/20 18:55:56 | 000,707,456 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/20 07:52:25 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/06/16 14:13:46 | 000,001,924 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/06/16 13:32:08 | 000,427,112 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/15 22:25:07 | 000,001,696 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/06/14 18:27:48 | 001,170,406 | —- | M] () – C:\Users\Julie\Documents\ChaddsLakeBylaws ORIGINAL.pdf
[2011/06/14 18:27:30 | 001,720,393 | —- | M] () – C:\Users\Julie\Documents\ChaddsLakeCovenants ORIGINAL.pdf
[2011/06/14 13:03:02 | 000,000,334 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJulie.job
[2011/06/12 09:51:14 | 000,002,047 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Google Calendar Sync.lnk
[2011/06/12 09:51:14 | 000,001,208 | —- | M] () – C:\Users\Public\Desktop\Google Calendar.lnk
[2011/06/06 22:55:04 | 000,000,338 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForRoss_G.job
[2011/06/05 08:31:05 | 000,000,950 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/01 11:20:28 | 000,001,952 | —- | M] () – C:\Users\Public\Desktop\Media Impression for Kodak.lnk
[2011/06/01 11:05:52 | 000,030,208 | —- | M] () – C:\Users\Julie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/31 09:56:37 | 000,001,517 | —- | M] () – C:\Users\Public\Desktop\Logitech Webcam Software .lnk
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/28 14:37:27 | 000,000,000 | —- | C] () – C:\Users\Julie\AppData\Local\{72F6EE2D-C776-4A34-99AE-DBE1A5C1BC4F}
[2011/06/27 19:39:31 | 120,201,870 | —- | C] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/06/27 19:16:32 | 000,000,862 | —- | C] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2011/06/26 22:12:47 | 000,012,668 | -HS- | C] () – C:\ProgramData\x34ld0wa75056ge55t2tgw3a1m25050
[2011/06/24 22:10:35 | 000,001,810 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/06/21 07:46:47 | 000,000,872 | —- | C] () – C:\Users\Julie\Desktop\Free Window Registry Repair.lnk
[2011/06/20 18:56:43 | 000,003,033 | —- | C] () – C:\Users\Julie\Desktop\Hitachi Backup.lnk
[2011/06/20 18:56:43 | 000,003,007 | —- | C] () – C:\Users\Julie\Desktop\Hitachi LifeStudio.lnk
[2011/06/20 18:56:43 | 000,002,575 | —- | C] () – C:\Users\Julie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hitachi LifeStudio Tray.lnk
[2011/06/16 14:13:46 | 000,001,924 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/06/16 14:13:46 | 000,001,804 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/06/15 22:25:07 | 000,001,696 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/06/14 18:27:48 | 001,170,406 | —- | C] () – C:\Users\Julie\Documents\ChaddsLakeBylaws ORIGINAL.pdf
[2011/06/14 18:27:30 | 001,720,393 | —- | C] () – C:\Users\Julie\Documents\ChaddsLakeCovenants ORIGINAL.pdf
[2011/06/12 09:51:14 | 000,002,047 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Google Calendar Sync.lnk
[2011/06/12 09:51:14 | 000,001,208 | —- | C] () – C:\Users\Public\Desktop\Google Calendar.lnk
[2011/04/01 01:07:02 | 010,877,272 | —- | C] () – C:\Windows\SysWow64\LogiDPP.dll
[2011/04/01 01:07:02 | 000,102,744 | —- | C] () – C:\Windows\SysWow64\LogiDPPApp.exe
[2011/04/01 01:06:56 | 000,331,608 | —- | C] () – C:\Windows\SysWow64\DevManagerCore.dll
[2011/01/17 12:27:54 | 000,040,960 | —- | C] () – C:\Windows\SysWow64\IPPCPUID.DLL
[2011/01/17 12:27:54 | 000,000,105 | —- | C] () – C:\Windows\UMXADDIN.INI
[2011/01/17 12:27:45 | 000,011,776 | —- | C] () – C:\Windows\SysWow64\pmsbfn32.dll
[2011/01/17 12:27:03 | 000,000,074 | —- | C] () – C:\Windows\PMINI.ini
[2011/01/16 22:07:23 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2011/01/01 10:04:24 | 000,187,248 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2010/09/03 07:43:41 | 000,038,605 | —- | C] () – C:\Users\Julie\AppData\Roaming\Microsoft Access 97-2003.ADR
[2010/09/03 07:38:33 | 000,038,436 | —- | C] () – C:\Users\Julie\AppData\Roaming\Tab Separated Values (Windows).ADR
[2010/09/03 07:33:58 | 000,038,442 | —- | C] () – C:\Users\Julie\AppData\Roaming\Comma Separated Values (Windows).ADR
[2010/09/03 07:32:21 | 000,000,104 | —- | C] () – C:\Users\Julie\AppData\Roaming\wklnhst.dat
[2010/09/03 07:30:06 | 000,038,429 | —- | C] () – C:\Users\Julie\AppData\Roaming\Microsoft Excel 97-2003.ADR
[2010/06/07 08:16:27 | 000,012,967 | —- | C] () – C:\Users\Julie\AppData\Roaming\Comma Separated Values (DOS).CAL
[2010/06/06 07:01:41 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/05/15 12:45:51 | 000,077,408 | —- | C] () – C:\Windows\hpqins05.dat
[2010/04/25 08:30:17 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/04/11 19:46:53 | 000,725,364 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/03/30 07:06:36 | 000,023,127 | —- | C] () – C:\Windows\hpqins15.dat
[2010/03/25 09:27:33 | 000,030,208 | —- | C] () – C:\Users\Julie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/24 07:56:09 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2010/03/24 07:55:43 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2010/03/24 07:55:21 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2008/10/20 17:02:49 | 000,000,957 | —- | C] () – C:\Windows\ODBCINST.INI
[2008/10/20 17:02:49 | 000,000,737 | —- | C] () – C:\Windows\ODBC.INI
[2008/10/20 16:23:14 | 000,157,556 | —- | C] () – C:\Windows\hpoins28.dat
[2008/10/17 12:10:58 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/08/02 10:41:51 | 000,265,392 | —- | C] () – C:\Windows\hpqins13.dat
[2008/08/02 10:19:55 | 000,327,680 | —- | C] () – C:\Windows\SysWow64\pythoncom25.dll
[2008/08/02 10:19:55 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\pywintypes25.dll
[2008/01/20 22:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/12/12 20:01:47 | 000,000,932 | —- | C] () – C:\Windows\hpomdl28.dat
[2006/11/02 11:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 08:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 08:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 05:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[1997/07/11 00:00:00 | 000,094,208 | —- | C] () – C:\Windows\SysWow64\MSENCODE.DLL
[1997/07/11 00:00:00 | 000,022,016 | —- | C] () – C:\Windows\SysWow64\DOCOBJ.DLL
[1997/07/11 00:00:00 | 000,012,288 | —- | C] () – C:\Windows\SysWow64\HLINKPRX.DLL

========== LOP Check ==========

[2011/06/27 19:38:44 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\AVG10
[2011/02/07 12:23:56 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\Catalina Marketing Corp
[2010/10/09 20:37:33 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\com.picaboo.Picaboo.A382D4714709B456C4E0088DFC1F7243AF9EBF75.1
[2010/06/21 18:43:05 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\E-centives
[2010/04/03 14:00:44 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\eBay
[2010/06/15 07:20:28 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\Facebook
[2010/04/11 11:06:21 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\GlarySoft
[2011/06/20 21:01:59 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\HitachiGST
[2011/03/24 06:06:55 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\IObit
[2011/01/17 07:49:27 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\Leadertech
[2011/02/17 14:44:16 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\Meeting Center
[2011/06/01 11:22:05 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\Reasonable Software House Ltd
[2011/03/28 07:58:28 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\RoboForm
[2010/09/03 07:32:22 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\Template
[2011/04/20 08:15:46 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\Unity
[2010/04/04 11:11:56 | 000,000,000 | —D | M] – C:\Users\Julie\AppData\Roaming\WinBatch
[2011/06/29 08:05:47 | 000,000,406 | —- | M] () – C:\Windows\Tasks\AutoSmartDefrag.job
[2011/06/29 08:05:48 | 000,000,326 | —- | M] () – C:\Windows\Tasks\GlaryInitialize.job
[2011/06/28 14:29:50 | 000,032,574 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/04/26 00:00:00 | 000,000,408 | —- | M] () – C:\Windows\Tasks\SmartDefrag.job
[2011/06/29 08:50:00 | 000,000,432 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{E01CDC1E-762F-4FC6-9281-034F7630D388}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/12/07 22:11:58 | 006,590,735 | —- | M] () – C:\AdobeDebug.txt
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/08/02 11:01:36 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2010/03/23 12:16:49 | 000,329,674 | —- | M] () – C:\coreuninstall.log
[2010/04/22 23:46:44 | 000,032,707 | —- | M] () – C:\CybDefInstallInfo.log
[2011/06/01 11:18:49 | 000,000,045 | —- | M] () – C:\error.log
[2010/05/15 11:53:41 | 000,000,250 | —- | M] () – C:\FINIS_IT.TXT
[2008/10/17 13:20:10 | 000,000,164 | —- | M] () – C:\install.dat
[2010/04/25 10:35:35 | 000,000,400 | —- | M] () – C:\InstallHelper.log
[2011/06/29 08:04:56 | 176,435,199 | -HS- | M] () – C:\pagefile.sys
[2010/03/23 12:17:03 | 000,000,000 | -H– | M] () – C:\ProgramData.LOG1
[2010/03/23 12:17:03 | 000,000,000 | -H– | M] () – C:\ProgramData.LOG2

< %systemroot%\Fonts\*.com >
[2006/11/02 11:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 11:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 11:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/03/28 07:31:41 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 17:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 23:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/05 07:45:22 | 000,000,574 | -HS- | M] () – C:\Users\Julie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< >

< End of report >

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, Julie

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

—————————————————————————————————

Can you post AVG log for me?

—————————————————————————————————
Thank you for helping. I am including the scan from today and the one from the day I posted. I have done nothing to the computer (cleaning it) so I am not sure why it is clean today. ALso, ever since I got this virus I get tons of errors. I will list a couple below (before the AVG scan reports). Please tell me where to post these types of errors if they are not part of the virus and/or if this is not the right thread.

  • ffmpeg.exe has stopped working
  • Extension clsid verifcation host has stopped wokring
  • microsoft search protocol has stopped working
  • avg scan executer has stopped working
  • microsoft security essentials has stopped working

AVG Reoprt from today:

Scan "Whole computer scan" completed.
No infection was found during this scan
Folders selected for scanning:;"Whole computer scan"
Scan started:;"Friday, July 01, 2011, 8:01:16 AM"
Scan finished:;"Friday, July 01, 2011, 9:12:34 AM (1 hour(s) 11 minute(s) 17 second(s))"
Total object scanned:;"3448318"
User who launched the scan:;"Julie"


AVG Report from June 27:

AVG 2011 Anti-Virus command line scanner
Copyright © 1992 - 2011 AVG Technologies
Program version 10.0.1388, engine 10.0.1516
Virus Database: Version 1516/3730 2011-06-27

C:\Boot\BCD Locked file. Not tested.
C:\Boot\BCD.LOG Locked file. Not tested.
C:\Documents and Settings\ Locked file. Not tested.
C:\pagefile.sys Locked file. Not tested.
C:\Program Files (x86)\HP Games\Bejeweled 2 Deluxe\WinBej2-WT.exe:\WinBej2-WT.exe Virus found Win32/Heur
C:\Program Files (x86)\HP Games\Bejeweled 2 Deluxe\WinBej2-WT.exe Virus found Win32/Heur.dropper
C:\Program Files (x86)\HP Games\Boggle\BoggleSA-WT.exe:\BoggleSA-WT.exe Virus found Win32/Heur Object was moved to Virus Vault.
C:\Program Files (x86)\HP Games\Boggle\BoggleSA-WT.exe Virus found Win32/Heur.dropper Object was moved to Virus Vault.
C:\Program Files (x86)\HP Games\Chuzzle Deluxe\Chuzzle-WT.exe:\Chuzzle-WT.exe Virus found Win32/Heur
C:\Program Files (x86)\HP Games\Chuzzle Deluxe\Chuzzle-WT.exe Virus found Win32/Heur.dropper
C:\Program Files (x86)\HP Games\Diner Dash\Diner Dash-WT.exe:\Diner Dash-WT.exe:\Diner Dash-WT.exe Virus found Win32/Heur Object was moved to Virus Vault.
C:\Program Files (x86)\HP Games\Diner Dash\Diner Dash-WT.exe:\Diner Dash-WT.exe Virus found Win32/Heur.dropper Object was moved to Virus Vault.
C:\Program Files (x86)\HP Games\Diner Dash\Diner Dash-WT.exe Virus found Win32/Heur.dropper Object was moved to Virus Vault.
C:\ProgramData\Desktop\ Locked file. Not tested.
C:\ProgramData\Documents\ Locked file. Not tested.
C:\ProgramData\Favorites\ Locked file. Not tested.
C:\ProgramData\Hewlett-Packard\HP Print Settings\HP8921a2.cfg Locked file. Not tested.
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\250c0a0d750fbbd2f5558c10c8f8c559_97ba11b6-a867-4493-b61e-1488207666e8 Locked file. Not tested.
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\476a210fd1fc31e66ec0553f504ea0f4_97ba11b6-a867-4493-b61e-1488207666e8 Locked file. Not tested.
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f16d5852954c1ab5ce93d10e05b451a1_97ba11b6-a867-4493-b61e-1488207666e8 Locked file. Not tested.
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_97ba11b6-a867-4493-b61e-1488207666e8 Locked file. Not tested.
C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\CacheManager\MpScanCache-1.bin Locked file. Not tested.
C:\ProgramData\Templates\ Locked file. Not tested.
C:\System Volume Information\ Locked file. Not tested.
C:\Users\Default\AppData\Local\History\ Locked file. Not tested.
C:\Users\Default\Documents\My Music\ Locked file. Not tested.
C:\Users\Default\Documents\My Pictures\ Locked file. Not tested.
C:\Users\Default\Documents\My Videos\ Locked file. Not tested.
C:\Users\Default\NetHood\ Locked file. Not tested.
C:\Users\Default\PrintHood\ Locked file. Not tested.
C:\Users\Default\Recent\ Locked file. Not tested.
C:\Users\Default\Templates\ Locked file. Not tested.
C:\Users\Gavin\AppData\Local\History\ Locked file. Not tested.
C:\Users\Gavin\Documents\My Music\ Locked file. Not tested.
C:\Users\Gavin\Documents\My Pictures\ Locked file. Not tested.
C:\Users\Gavin\Documents\My Videos\ Locked file. Not tested.
C:\Users\Gavin\NetHood\ Locked file. Not tested.
C:\Users\Gavin\PrintHood\ Locked file. Not tested.
C:\Users\Gavin\Templates\ Locked file. Not tested.
C:\Users\Julie\AppData\Local\History\ Locked file. Not tested.
C:\Users\Julie\AppData\Local\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
C:\Users\Julie\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Locked file. Not tested.
C:\Users\Julie\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Locked file. Not tested.
C:\Users\Julie\Documents\My Music\ Locked file. Not tested.
C:\Users\Julie\Documents\My Pictures\ Locked file. Not tested.
C:\Users\Julie\Documents\My Videos\ Locked file. Not tested.
C:\Users\Julie\ntuser.dat Locked file. Not tested.
C:\Users\Julie\ntuser.dat.LOG1 Locked file. Not tested.
C:\Users\Julie\ntuser.dat.LOG2 Locked file. Not tested.
C:\Users\Kyra\AppData\Local\History\ Locked file. Not tested.
C:\Users\Kyra\Documents\My Music\ Locked file. Not tested.
C:\Users\Kyra\Documents\My Pictures\ Locked file. Not tested.
C:\Users\Kyra\Documents\My Videos\ Locked file. Not tested.
C:\Users\Kyra\NetHood\ Locked file. Not tested.
C:\Users\Kyra\PrintHood\ Locked file. Not tested.
C:\Users\Kyra\Templates\ Locked file. Not tested.
C:\Users\Owner\AppData\Local\History\ Locked file. Not tested.
C:\Users\Owner\Documents\My Music\ Locked file. Not tested.
C:\Users\Owner\Documents\My Pictures\ Locked file. Not tested.
C:\Users\Owner\Documents\My Videos\ Locked file. Not tested.
C:\Users\Public\Documents\My Music\ Locked file. Not tested.
C:\Users\Public\Documents\My Pictures\ Locked file. Not tested.
C:\Users\Public\Documents\My Videos\ Locked file. Not tested.
C:\Users\Ross\AppData\Local\History\ Locked file. Not tested.
C:\Users\Ross\Documents\My Music\ Locked file. Not tested.
C:\Users\Ross\Documents\My Pictures\ Locked file. Not tested.
C:\Users\Ross\Documents\My Videos\ Locked file. Not tested.
C:\Users\Ross\NetHood\ Locked file. Not tested.
C:\Users\Ross\PrintHood\ Locked file. Not tested.
C:\Users\ROSS G\AppData\Local\History\ Locked file. Not tested.
C:\Users\ROSS G\Documents\My Music\ Locked file. Not tested.
C:\Users\ROSS G\Documents\My Pictures\ Locked file. Not tested.
C:\Users\ROSS G\Documents\My Videos\ Locked file. Not tested.
C:\Users\ROSS G\NetHood\ Locked file. Not tested.
C:\Users\ROSS G\PrintHood\ Locked file. Not tested.
C:\Users\ROSS G\Templates\ Locked file. Not tested.
C:\Users\Ross New\AppData\Local\History\ Locked file. Not tested.
C:\Users\Ross New\AppData\Local\Temp\~DF8CDE.tmp Locked file. Not tested.
C:\Users\Ross New\Documents\My Music\ Locked file. Not tested.
C:\Users\Ross New\Documents\My Pictures\ Locked file. Not tested.
C:\Users\Ross New\Documents\My Videos\ Locked file. Not tested.
C:\Users\Ross New\NetHood\ Locked file. Not tested.
C:\Users\Ross New\PrintHood\ Locked file. Not tested.
C:\Users\Ross New\Templates\ Locked file. Not tested.
C:\Users\Ross.Owner-PC\AppData\Local\Temp\hsperfdata_Ross\4864 Locked file. Not tested.
C:\Users\Ross_G\AppData\Local\History\ Locked file. Not tested.
C:\Users\Ross_G\Documents\My Music\ Locked file. Not tested.
C:\Users\Ross_G\Documents\My Pictures\ Locked file. Not tested.
C:\Users\Ross_G\Documents\My Videos\ Locked file. Not tested.
C:\Users\Ross_G\NetHood\ Locked file. Not tested.
C:\Users\Ross_G\PrintHood\ Locked file. Not tested.
C:\Users\TEMP\AppData\Local\History\ Locked file. Not tested.
C:\Users\TEMP\Documents\My Music\ Locked file. Not tested.
C:\Users\TEMP\Documents\My Pictures\ Locked file. Not tested.
C:\Users\TEMP\Documents\My Videos\ Locked file. Not tested.
C:\Users\TEMP\NetHood\ Locked file. Not tested.
C:\Users\TEMP\PrintHood\ Locked file. Not tested.
C:\Users\TEMP\Templates\ Locked file. Not tested.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Locked file. Not tested.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Locked file. Not tested.
C:\Windows\ServiceProfiles\LocalService\ntuser.dat Locked file. Not tested.
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Locked file. Not tested.
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Locked file. Not tested.
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\csp84B3.tmp Locked file. Not tested.
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\cspF9E8.tmp Locked file. Not tested.
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat Locked file. Not tested.
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Locked file. Not tested.
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Locked file. Not tested.
C:\Windows\System32\catroot2\edb.log Locked file. Not tested.
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Locked file. Not tested.
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Locked file. Not tested.
C:\Windows\System32\config\components Locked file. Not tested.
C:\Windows\System32\config\COMPONENTS.LOG1 Locked file. Not tested.
C:\Windows\System32\config\COMPONENTS.LOG2 Locked file. Not tested.
C:\Windows\System32\config\default Locked file. Not tested.
C:\Windows\System32\config\DEFAULT.LOG1 Locked file. Not tested.
C:\Windows\System32\config\DEFAULT.LOG2 Locked file. Not tested.
C:\Windows\System32\config\RegBack\COMPONENTS Locked file. Not tested.
C:\Windows\System32\config\RegBack\DEFAULT Locked file. Not tested.
C:\Windows\System32\config\RegBack\SAM Locked file. Not tested.
C:\Windows\System32\config\RegBack\SECURITY Locked file. Not tested.
C:\Windows\System32\config\RegBack\SOFTWARE Locked file. Not tested.
C:\Windows\System32\config\RegBack\SYSTEM Locked file. Not tested.
C:\Windows\System32\config\sam Locked file. Not tested.
C:\Windows\System32\config\SAM.LOG1 Locked file. Not tested.
C:\Windows\System32\config\SAM.LOG2 Locked file. Not tested.
C:\Windows\System32\config\security Locked file. Not tested.
C:\Windows\System32\config\SECURITY.LOG1 Locked file. Not tested.
C:\Windows\System32\config\SECURITY.LOG2 Locked file. Not tested.
C:\Windows\System32\config\software Locked file. Not tested.
C:\Windows\System32\config\SOFTWARE.LOG1 Locked file. Not tested.
C:\Windows\System32\config\SOFTWARE.LOG2 Locked file. Not tested.
C:\Windows\System32\config\system Locked file. Not tested.
C:\Windows\System32\config\SYSTEM.LOG1 Locked file. Not tested.
C:\Windows\System32\config\SYSTEM.LOG2 Locked file. Not tested.
C:\Windows\System32\LogFiles\WMI\RtBackup\ Locked file. Not tested.
D:\System Volume Information\ Locked file. Not tested.

————————————————————
Objects scanned : 3567500
Found infections : 9
Found PUPs : 0
Healed infections : 5
Healed PUPs : 0
Warnings : 0
————————————————————


Again thank you. :notworthy:
I forgot that I ran the scan in safe mode on the 27th b/c I got the Blue Screen and that is what was suggested. Not sure if that makes a difference.
Hello,

You're welcome ;)

I believe what AVG found was false positive. - Your best bet for solving the errors(hopefully) is to run sfc.exe

http://support.microsoft.com/kb/929833

Use the System File Checker tool (SFC.exe) to determine which file is causing the issue, and then replace the file. To do this, follow these steps:

  • Open an elevated command prompt. To do this, click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator. If you are prompted for an administrator password or for a confirmation, type the password, or click Allow.
  • Type the following command, and then press ENTER:
sfc /scannow

The sfc /scannow command scans all protected system files and replaces incorrect versions with correct Microsoft versions.

THis is what the san said (attached log as well). Please let me know if we (I) should move this problem to another forum. Microsoft Windows [Version 6.0.6002] Copyright © 2006 Microsoft Corporation. All rights reserved. C:\Users\Julie>sfc/scannow Beginning system scan. This process will take some time. Beginning verification phase of system scan. Verification 100% complete. Windows Resource Protection found corrupt files but was unable to fix some of th em. Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log C:\Users\Julie> C:\Users\Julie> Each time I try to copy and paste the log from Notepad - IE feezes and shuts down. I tried to attach the document log (txt) but i keep getting "You did not slecet a file to upload" SO I have attached the part of the scan that has today's date: 2011-07-01 10:31:37, Info CBS Loaded Servicing Stack v6.0.6002.18005 with Core: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_676975d87cc9b6e6\cbscore.dll 2011-07-01 10:31:37, Info CSI 00000001@2011/7/1:14:31:37.856 WcpInitialize (wcp.dll version 0.0.0.5) called (stack @0x7fef0298c85 @0x7fef1d253ae @0x7fef1cf3ed1 @0xffa749a8 @0xffa730c9 @0xffa73578) 2011-07-01 10:31:37, Info CSI 00000002@2011/7/1:14:31:37.871 WcpInitialize (wcp.dll version 0.0.0.5) called (stack @0x7fef0298c85 @0x7fef1d686cf @0x7fef1d425d9 @0x7fef1cf3feb @0xffa749a8 @0xffa730c9) 2011-07-01 10:31:37, Info CSI 00000003@2011/7/1:14:31:37.873 WcpInitialize (wcp.dll version 0.0.0.5) called (stack @0x7fef0298c85 @0x7fef356838d @0x7fef35684ba @0xffa74207 @0xffa73125 @0xffa73578) 2011-07-01 10:31:37, Info CBS NonStart: Checking to ensure startup processing was not required. 2011-07-01 10:31:37, Info CSI 00000004 IAdvancedInstallerAwareStore_ResolvePendingTransactions (call 1) (flags = 00000004, progress = NULL, phase = 0, pdwDisposition = @0x19bf750 2011-07-01 10:31:37, Info CBS NonStart: Success, startup processing not required as expected. 2011-07-01 10:31:37, Info CSI 00000005 CSI Store 3402848 (0x000000000033ec60) initialized 2011-07-01 10:31:42, Info CSI 00000006 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:31:42, Info CSI 00000007 [SR] Beginning Verify and Repair transaction 2011-07-01 10:31:44, Info CSI 00000008 Repair results created: POQ 0 starts: POQ 0 ends. 2011-07-01 10:31:44, Info CSI 00000009 [SR] Verify complete 2011-07-01 10:31:45, Info CSI 0000000a [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:31:45, Info CSI 0000000b [SR] Beginning Verify and Repair transaction 2011-07-01 10:31:47, Info CSI 0000000c Repair results created: POQ 1 starts: POQ 1 ends. 2011-07-01 10:31:47, Info CSI 0000000d [SR] Verify complete 2011-07-01 10:31:48, Info CSI 0000000e [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:31:48, Info CSI 0000000f [SR] Beginning Verify and Repair transaction 2011-07-01 10:31:50, Info CSI 00000010 Repair results created: POQ 2 starts: POQ 2 ends. 2011-07-01 10:31:50, Info CSI 00000011 [SR] Verify complete 2011-07-01 10:31:50, Info CSI 00000012 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:31:50, Info CSI 00000013 [SR] Beginning Verify and Repair transaction 2011-07-01 10:31:53, Info CSI 00000014 Repair results created: POQ 3 starts: POQ 3 ends. 2011-07-01 10:31:53, Info CSI 00000015 [SR] Verify complete 2011-07-01 10:31:55, Info CSI 00000016 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:31:55, Info CSI 00000017 [SR] Beginning Verify and Repair transaction 2011-07-01 10:31:58, Info CSI 00000018 Repair results created: POQ 4 starts: POQ 4 ends. 2011-07-01 10:31:58, Info CSI 00000019 [SR] Verify complete 2011-07-01 10:31:59, Info CSI 0000001a [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:31:59, Info CSI 0000001b [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:02, Info CSI 0000001c Repair results created: POQ 5 starts: POQ 5 ends. 2011-07-01 10:32:02, Info CSI 0000001d [SR] Verify complete 2011-07-01 10:32:03, Info CSI 0000001e [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:03, Info CSI 0000001f [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:05, Info CSI 00000020 Repair results created: POQ 6 starts: POQ 6 ends. 2011-07-01 10:32:05, Info CSI 00000021 [SR] Verify complete 2011-07-01 10:32:06, Info CSI 00000022 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:06, Info CSI 00000023 [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:08, Info CSI 00000024 Repair results created: POQ 7 starts: POQ 7 ends. 2011-07-01 10:32:08, Info CSI 00000025 [SR] Verify complete 2011-07-01 10:32:09, Info CSI 00000026 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:09, Info CSI 00000027 [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:11, Info CSI 00000028 Repair results created: POQ 8 starts: POQ 8 ends. 2011-07-01 10:32:11, Info CSI 00000029 [SR] Verify complete 2011-07-01 10:32:12, Info CSI 0000002a [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:12, Info CSI 0000002b [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:14, Info CSI 0000002c Repair results created: POQ 9 starts: POQ 9 ends. 2011-07-01 10:32:14, Info CSI 0000002d [SR] Verify complete 2011-07-01 10:32:15, Info CSI 0000002e [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:15, Info CSI 0000002f [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:16, Info CSI 00000030 Repair results created: POQ 10 starts: POQ 10 ends. 2011-07-01 10:32:16, Info CSI 00000031 [SR] Verify complete 2011-07-01 10:32:17, Info CSI 00000032 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:17, Info CSI 00000033 [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:19, Info CSI 00000034 Repair results created: POQ 11 starts: POQ 11 ends. 2011-07-01 10:32:19, Info CSI 00000035 [SR] Verify complete 2011-07-01 10:32:20, Info CSI 00000036 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:20, Info CSI 00000037 [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:22, Info CSI 00000038 Repair results created: POQ 12 starts: POQ 12 ends. 2011-07-01 10:32:22, Info CSI 00000039 [SR] Verify complete 2011-07-01 10:32:23, Info CSI 0000003a [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:23, Info CSI 0000003b [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:25, Info CSI 0000003c Repair results created: POQ 13 starts: POQ 13 ends. 2011-07-01 10:32:25, Info CSI 0000003d [SR] Verify complete 2011-07-01 10:32:26, Info CSI 0000003e [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:26, Info CSI 0000003f [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:27, Info CSI 00000040 Repair results created: POQ 14 starts: POQ 14 ends. 2011-07-01 10:32:27, Info CSI 00000041 [SR] Verify complete 2011-07-01 10:32:28, Info CSI 00000042 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:28, Info CSI 00000043 [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:30, Info CSI 00000044 Repair results created: POQ 15 starts: POQ 15 ends. 2011-07-01 10:32:30, Info CSI 00000045 [SR] Verify complete 2011-07-01 10:32:31, Info CSI 00000046 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:31, Info CSI 00000047 [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:33, Info CSI 00000048 Repair results created: POQ 16 starts: POQ 16 ends. 2011-07-01 10:32:33, Info CSI 00000049 [SR] Verify complete 2011-07-01 10:32:33, Info CSI 0000004a [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:33, Info CSI 0000004b [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:35, Info CSI 0000004c Repair results created: POQ 17 starts: POQ 17 ends. 2011-07-01 10:32:35, Info CSI 0000004d [SR] Verify complete 2011-07-01 10:32:36, Info CSI 0000004e [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:36, Info CSI 0000004f [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:38, Info CSI 00000050 Repair results created: POQ 18 starts: POQ 18 ends. 2011-07-01 10:32:38, Info CSI 00000051 [SR] Verify complete 2011-07-01 10:32:39, Info CSI 00000052 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:39, Info CSI 00000053 [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:43, Info CSI 00000054 Repair results created: POQ 19 starts: POQ 19 ends. 2011-07-01 10:32:43, Info CSI 00000055 [SR] Verify complete 2011-07-01 10:32:44, Info CSI 00000056 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:44, Info CSI 00000057 [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:47, Info CSI 00000058 Repair results created: POQ 20 starts: POQ 20 ends. 2011-07-01 10:32:47, Info CSI 00000059 [SR] Verify complete 2011-07-01 10:32:47, Info CSI 0000005a [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:47, Info CSI 0000005b [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:50, Info CSI 0000005c Repair results created: POQ 21 starts: POQ 21 ends. 2011-07-01 10:32:50, Info CSI 0000005d [SR] Verify complete 2011-07-01 10:32:50, Info CSI 0000005e [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:50, Info CSI 0000005f [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:52, Info CSI 00000060 Repair results created: POQ 22 starts: POQ 22 ends. 2011-07-01 10:32:52, Info CSI 00000061 [SR] Verify complete 2011-07-01 10:32:53, Info CSI 00000062 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:53, Info CSI 00000063 [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:55, Info CSI 00000064 Repair results created: POQ 23 starts: POQ 23 ends. 2011-07-01 10:32:55, Info CSI 00000065 [SR] Verify complete 2011-07-01 10:32:55, Info CSI 00000066 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:55, Info CSI 00000067 [SR] Beginning Verify and Repair transaction 2011-07-01 10:32:58, Info CSI 00000068 Repair results created: POQ 24 starts: POQ 24 ends. 2011-07-01 10:32:58, Info CSI 00000069 [SR] Verify complete 2011-07-01 10:32:58, Info CSI 0000006a [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:32:58, Info CSI 0000006b [SR] Beginning Verify and Repair transaction 2011-07-01 10:33:01, Info CSI 0000006c Repair results created: POQ 25 starts: POQ 25 ends. 2011-07-01 10:33:01, Info CSI 0000006d [SR] Verify complete 2011-07-01 10:33:02, Info CSI 0000006e [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:33:02, Info CSI 0000006f [SR] Beginning Verify and Repair transaction 2011-07-01 10:33:04, Info CSI 00000070 Repair results created: POQ 26 starts: POQ 26 ends. 2011-07-01 10:33:04, Info CSI 00000071 [SR] Verify complete 2011-07-01 10:33:04, Info CSI 00000072 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:33:04, Info CSI 00000073 [SR] Beginning Verify and Repair transaction 2011-07-01 10:33:06, Info CSI 00000074 Repair results created: POQ 27 starts: POQ 27 ends. 2011-07-01 10:33:06, Info CSI 00000075 [SR] Verify complete 2011-07-01 10:33:06, Info CSI 00000076 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:33:06, Info CSI 00000077 [SR] Beginning Verify and Repair transaction 2011-07-01 10:33:08, Info CSI 00000078 Repair results created: POQ 28 starts: POQ 28 ends. 2011-07-01 10:33:08, Info CSI 00000079 [SR] Verify complete 2011-07-01 10:33:09, Info CSI 0000007a [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:33:09, Info CSI 0000007b [SR] Beginning Verify and Repair transaction 2011-07-01 10:33:15, Info CSI 0000007c Repair results created: POQ 29 starts: POQ 29 ends. 2011-07-01 10:33:15, Info CSI 0000007d [SR] Verify complete 2011-07-01 10:33:16, Info CSI 0000007e [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:33:16, Info CSI 0000007f [SR] Beginning Verify and Repair transaction 2011-07-01 10:33:21, Info CSI 00000080 Repair results created: POQ 30 starts: 0: Move File: Source = [l:192{96}]"\SystemRoot\WinSxS\Temp\PendingRenames\003d02d3fb37cc011d0c00007017d412._0000000000000000.cdf-ms", Destination = [l:104{52}]"\SystemRoot\WinSxS\FileMaps\_0000000000000000.cdf-ms" 1: Move File: Source = [l:162{81}]"\SystemRoot\WinSxS\Temp\PendingRenames\f0d90bd3fb37cc011e0c00007017d412.$$.cdf-ms", Destination = [l:74{37}]"\SystemRoot\WinSxS\FileMaps\$$.cdf-ms" 2: Move File: Source = [l:234{117}]"\SystemRoot\WinSxS\Temp\PendingRenames\00c515d3fb37cc011f0c00007017d412.$$_help_windows_en-us_b594929e73669c5e.cdf-ms", Destination = [l:146{73}]"\SystemRoot\WinSxS\FileMaps\$$_help_windows_en-us_b594929e73669c5e.cdf-ms" 3: Move File: Source = [l:228{114}]"\SystemRoot\WinSxS\Temp\PendingRenames\301c1bd3fb37cc01200c00007017d412.$$_help_help_en-us_91e6e7979a9bf9c6.cdf-ms", Destination = [l:140{70}]"\SystemRoot\WinSxS\FileMaps\$$_help_help_en-us_91e6e7979a9bf9c6.cdf-ms" 4: Move File: Source = [l:218{109}]"\SystemRoot\WinSxS\Temp\PendingRenames\c08b43d3fb37cc01210c00007017d412.program_files_ffd0cbfc813cc4f1.cdf-ms", Destination = [l:130{65}]"\SystemRoot\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms" 5: Create Directory: Directory = [l:48{24}]"\??\C:\Program Files\MSN", Attributes = 00000080 6: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\b02163d3fb37cc01220c00007017d412.$$_system32_21f9a9c4a2f8b514.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms" 7: Move File: Source = [l:242{121}]"\SystemRoot\WinSxS\Temp\PendingRenames\706767d3fb37cc01230c00007017d412.$$_system32_manifeststore_7d35b12f9be4c20e.cdf-ms", Destination = [l:154{77}]"\SystemRoot\WinSxS\FileMaps\$$_system32_manifeststore_7d35b12f9be4c20e.cdf-ms" 8: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\004f7cd3fb37cc01240c00007017d412.$$_apppatch_1143992cbbbebcab.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_apppatch_ 2011-07-01 10:33:21, Info CSI 1143992cbbbebcab.cdf-ms" 9: Move File: Source = [l:236{118}]"\SystemRoot\WinSxS\Temp\PendingRenames\90ae7dd3fb37cc01250c00007017d412.$$_apppatch_apppatch64_e39bab3b20714e20.cdf-ms", Destination = [l:148{74}]"\SystemRoot\WinSxS\FileMaps\$$_apppatch_apppatch64_e39bab3b20714e20.cdf-ms" POQ 30 ends. 2011-07-01 10:33:21, Info CSI 00000081 [SR] Verify complete 2011-07-01 10:33:21, Info CSI 00000082 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:33:21, Info CSI 00000083 [SR] Beginning Verify and Repair transaction 2011-07-01 10:33:28, Info CSI 00000084 Ignoring duplicate ownership for directory [l:64{32}]"\??\C:\Windows\Branding\Shellbrd" in component Microsoft-Windows-Branding-Shell-HomePremium, Version = 6.0.6000.16386, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:28, Info CSI 00000085 Ignoring duplicate ownership for directory [l:56{28}]"\??\C:\Windows\MSAgent\chars" in component Microsoft-Windows-Agent-Resource-Files, Version = 6.0.6000.16386, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:29, Info CSI 00000086 Ignoring duplicate ownership for directory [l:46{23}]"\??\C:\Windows\SchCache" in component Microsoft-Windows-Active-Directory-Services-Interface-LDAP-Provider, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:29, Info CSI 00000087 Repair results created: POQ 31 starts: 0: Move File: Source = [l:192{96}]"\SystemRoot\WinSxS\Temp\PendingRenames\90e6afd7fb37cc018a0c00007017d412._0000000000000000.cdf-ms", Destination = [l:104{52}]"\SystemRoot\WinSxS\FileMaps\_0000000000000000.cdf-ms" 1: Move File: Source = [l:162{81}]"\SystemRoot\WinSxS\Temp\PendingRenames\b034b0d7fb37cc018b0c00007017d412.$$.cdf-ms", Destination = [l:74{37}]"\SystemRoot\WinSxS\FileMaps\$$.cdf-ms" 2: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\20b7b3d7fb37cc018c0c00007017d412.$$_branding_1728f5d8b15e5263.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_branding_1728f5d8b15e5263.cdf-ms" 3: Move File: Source = [l:232{116}]"\SystemRoot\WinSxS\Temp\PendingRenames\205dc2d7fb37cc018d0c00007017d412.$$_branding_shellbrd_be1f632087fb0947.cdf-ms", Destination = [l:144{72}]"\SystemRoot\WinSxS\FileMaps\$$_branding_shellbrd_be1f632087fb0947.cdf-ms" 4: Move File: Source = [l:216{108}]"\SystemRoot\WinSxS\Temp\PendingRenames\b05be8d7fb37cc018e0c00007017d412.$$_msagent64_19017284d4b14d39.cdf-ms", Destination = [l:128{64}]"\SystemRoot\WinSxS\FileMaps\$$_msagent64_19017284d4b14d39.cdf-ms" 5: Move File: Source = [l:212{106}]"\SystemRoot\WinSxS\Temp\PendingRenames\20c0f0d7fb37cc018f0c00007017d412.$$_msagent_be90584645cb9b95.cdf-ms", Destination = [l:124{62}]"\SystemRoot\WinSxS\FileMaps\$$_msagent_be90584645cb9b95.cdf-ms" 6: Move File: Source = [l:224{112}]"\SystemRoot\WinSxS\Temp\PendingRenames\c0ce05d8fb37cc01900c00007017d412.$$_msagent_chars_9a5bcb5da392f588.cdf-ms", Destination = [l:136{68}]"\SystemRoot\WinSxS\FileMaps\$$_msagent_chars_9a5bcb5da392f588.cdf-ms" 7: Move File: Source = [l:216{108}]"\SystemRoot\WinSxS\Temp\PendingRenames\a09716d8fb37cc01910c00007017d412.$$_resources_fbee56ab048ab239.cdf-ms", Destination = [l:128{64}]"\SystemRoot\WinSxS\FileMaps\$$_resources_fbee56ab048ab239.cdf-ms" 8: Move File: Source = [l:230{115}]"\SystemRoot\WinSxS\Temp\PendingRenames\b02f19d8fb37cc01920c00007017d 2011-07-01 10:33:29, Info CSI 412.$$_resources_themes_4d0d4910e83c2273.cdf-ms", Destination = [l:142{71}]"\SystemRoot\WinSxS\FileMaps\$$_resources_themes_4d0d4910e83c2273.cdf-ms" 9: Move File: Source = [l:240{120}]"\SystemRoot\WinSxS\Temp\PendingRenames\60dd1ad8fb37cc01930c00007017d412.$$_resources_themes_aero_3fd78bf4cb5fa2c4.cdf-ms", Destination = [l:152{76}]"\SystemRoot\WinSxS\FileMaps\$$_resources_themes_aero_3fd78bf4cb5fa2c4.cdf-ms" 10: Move File: Source = [l:252{126}]"\SystemRoot\WinSxS\Temp\PendingRenames\50eb26d8fb37cc01940c00007017d412.$$_resources_themes_aero_shell_a91dfa5124b343c4.cdf-ms", Destination = [l:164{82}]"\SystemRoot\WinSxS\FileMaps\$$_resources_themes_aero_shell_a91dfa5124b343c4.cdf-ms" 11: Move File: Source = [l:276{138}]"\SystemRoot\WinSxS\Temp\PendingRenames\502033d8fb37cc01950c00007017d412.$$_resources_themes_aero_shell_normalcolor_10be8ec981b35fb6.cdf-ms", Destination = [l:188{94}]"\SystemRoot\WinSxS\FileMaps\$$_resources_themes_aero_shell_normalcolor_10be8ec981b35fb6.cdf-ms" 12: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\607c3fd8fb37cc01960c00007017d412.$$_schcache_f995a5d4decb8cc0.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_schcache_f995a5d4decb8cc0.cdf-ms" 13: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\30c45ed8fb37cc01970c00007017d412.$$_system32_21f9a9c4a2f8b514.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms" 14: Move File: Source = [l:224{112}]"\SystemRoot\WinSxS\Temp\PendingRenames\e07160d8fb37cc01980c00007017d412.$$_system32_boot_06654401df2fc50e.cdf-ms", Destination = [l:136{68}]"\SystemRoot\WinSxS\FileMaps\$$_system32_boot_06654401df2fc50e.cdf-ms" POQ 31 ends. 2011-07-01 10:33:29, Info CSI 00000088 [SR] Verify complete 2011-07-01 10:33:30, Info CSI 00000089 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:33:30, Info CSI 0000008a [SR] Beginning Verify and Repair transaction 2011-07-01 10:33:37, Info CSI 0000008b Repair results created: POQ 32 starts: 0: Move File: Source = [l:192{96}]"\SystemRoot\WinSxS\Temp\PendingRenames\4033b8dcfb37cc01fd0c00007017d412._0000000000000000.cdf-ms", Destination = [l:104{52}]"\SystemRoot\WinSxS\FileMaps\_0000000000000000.cdf-ms" 1: Move File: Source = [l:162{81}]"\SystemRoot\WinSxS\Temp\PendingRenames\50e2cbdcfb37cc01fe0c00007017d412.$$.cdf-ms", Destination = [l:74{37}]"\SystemRoot\WinSxS\FileMaps\$$.cdf-ms" 2: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\0054d7dcfb37cc01ff0c00007017d412.$$_system32_21f9a9c4a2f8b514.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms" 3: Move File: Source = [l:244{122}]"\SystemRoot\WinSxS\Temp\PendingRenames\10ecd9dcfb37cc01000d00007017d412.$$_system32_branding_en-us_86fc4588168f7f89.cdf-ms", Destination = [l:156{78}]"\SystemRoot\WinSxS\FileMaps\$$_system32_branding_en-us_86fc4588168f7f89.cdf-ms" 4: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\9052fddcfb37cc01010d00007017d412.$$_branding_1728f5d8b15e5263.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_branding_1728f5d8b15e5263.cdf-ms" 5: Move File: Source = [l:230{115}]"\SystemRoot\WinSxS\Temp\PendingRenames\00d500ddfb37cc01020d00007017d412.$$_branding_basebrd_9ee9a176c9fadab4.cdf-ms", Destination = [l:142{71}]"\SystemRoot\WinSxS\FileMaps\$$_branding_basebrd_9ee9a176c9fadab4.cdf-ms" 6: Move File: Source = [l:242{121}]"\SystemRoot\WinSxS\Temp\PendingRenames\209403ddfb37cc01030d00007017d412.$$_branding_basebrd_en-us_51c0631d4347f350.cdf-ms", Destination = [l:154{77}]"\SystemRoot\WinSxS\FileMaps\$$_branding_basebrd_en-us_51c0631d4347f350.cdf-ms" 7: Move File: Source = [l:232{116}]"\SystemRoot\WinSxS\Temp\PendingRenames\503e10ddfb37cc01040d00007017d412.$$_branding_shellbrd_be1f632087fb0947.cdf-ms", Destination = [l:144{72}]"\SystemRoot\WinSxS\FileMaps\$$_branding_shellbrd_be1f632087fb0947.cdf-ms" POQ 32 ends. 2011-07-01 10:33:37, Info CSI 0000008c [SR] Verify complete 2011-07-01 10:33:37, Info CSI 0000008d [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:33:37, Info CSI 0000008e [SR] Beginning Verify and Repair transaction 2011-07-01 10:33:43, Info CSI 0000008f Ignoring duplicate ownership for directory [ml:14{7},l:12{6}]"\??\C:" in component Microsoft-Windows-Client-Features-Default-Security, Version = 6.0.6000.16386, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:43, Info CSI 00000090 Ignoring duplicate ownership for directory [l:44{22}]"\??\C:\Windows\schemas" in component Microsoft-Windows-Client-Features-Default-Security, Version = 6.0.6000.16386, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:44, Info CSI 00000091 Repair results created: POQ 33 starts: 0: Move File: Source = [l:192{96}]"\SystemRoot\WinSxS\Temp\PendingRenames\e02de2e0fb37cc01690d00007017d412._0000000000000000.cdf-ms", Destination = [l:104{52}]"\SystemRoot\WinSxS\FileMaps\_0000000000000000.cdf-ms" 1: Move File: Source = [l:162{81}]"\SystemRoot\WinSxS\Temp\PendingRenames\f054e2e0fb37cc016a0d00007017d412.$$.cdf-ms", Destination = [l:74{37}]"\SystemRoot\WinSxS\FileMaps\$$.cdf-ms" 2: Move File: Source = [l:212{106}]"\SystemRoot\WinSxS\Temp\PendingRenames\b029e4e0fb37cc016b0d00007017d412.$$_schemas_9f2c881475a483d6.cdf-ms", Destination = [l:124{62}]"\SystemRoot\WinSxS\FileMaps\$$_schemas_9f2c881475a483d6.cdf-ms" 3: Move File: Source = [l:204{102}]"\SystemRoot\WinSxS\Temp\PendingRenames\6041fee0fb37cc016c0d00007017d412.$$_inf_3f581daba4c8c835.cdf-ms", Destination = [l:116{58}]"\SystemRoot\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms" 4: Move File: Source = [l:216{108}]"\SystemRoot\WinSxS\Temp\PendingRenames\c09c01e1fb37cc016d0d00007017d412.$$_inf_msdtc_0ef70686e1d9b30c.cdf-ms", Destination = [l:128{64}]"\SystemRoot\WinSxS\FileMaps\$$_inf_msdtc_0ef70686e1d9b30c.cdf-ms" 5: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\30ae02e1fb37cc016e0d00007017d412.$$_inf_msdtc_0000_5b1b81b54f36c82e.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_inf_msdtc_0000_5b1b81b54f36c82e.cdf-ms" 6: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\60152fe1fb37cc016f0d00007017d412.$$_system32_21f9a9c4a2f8b514.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms" 7: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\b02b37e1fb37cc01700d00007017d412.$$_system32_tasks_5f1dd67a5a1ae70e.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_tasks_5f1dd67a5a1ae70e.cdf-ms" 8: Move File: Source = [l:246{123}]"\SystemRoot\WinSxS\Temp\PendingRenames\50b238e1fb37cc01710d00007017d412.$$_system32_ 2011-07-01 10:33:44, Info CSI tasks_microsoft_b7abd682baafefc2.cdf-ms", Destination = [l:158{79}]"\SystemRoot\WinSxS\FileMaps\$$_system32_tasks_microsoft_b7abd682baafefc2.cdf-ms" 9: Move File: Source = [l:218{109}]"\SystemRoot\WinSxS\Temp\PendingRenames\60d938e1fb37cc01720d00007017d412.program_files_ffd0cbfc813cc4f1.cdf-ms", Destination = [l:130{65}]"\SystemRoot\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms" 10: Move File: Source = [l:252{126}]"\SystemRoot\WinSxS\Temp\PendingRenames\80983be1fb37cc01730d00007017d412.program_files_windows_calendar_49985597510 1431e.cdf-ms", Destination = [l:164{82}]"\SystemRoot\WinSxS\FileMaps\program_files_windows_calendar_499855975101431e.cdf-ms" 11: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\e0ce59e1fb37cc01740d00007017d412.$$_inf_msdtc_0409_5b1b92d34f36ae69.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_inf_msdtc_0409_5b1b92d34f36ae69.cdf-ms" 12: Move File: Source = [l:264{132}]"\SystemRoot\WinSxS\Temp\PendingRenames\109077e1fb37cc01750d00007017d412.program_files_windows_calendar_en-us_dd4914c795cbfad6.cdf-ms", Destination = [l:176{88}]"\SystemRoot\WinSxS\FileMaps\program_files_windows_calendar_en-us_dd4914c795cbfad6.cdf-ms" POQ 33 ends. 2011-07-01 10:33:44, Info CSI 00000092 [SR] Verify complete 2011-07-01 10:33:45, Info CSI 00000093 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:33:45, Info CSI 00000094 [SR] Beginning Verify and Repair transaction 2011-07-01 10:33:52, Info CSI 00000095 Repair results created: POQ 34 starts: 0: Move File: Source = [l:192{96}]"\SystemRoot\WinSxS\Temp\PendingRenames\a0357fe5fb37cc01da0d00007017d412._0000000000000000.cdf-ms", Destination = [l:104{52}]"\SystemRoot\WinSxS\FileMaps\_0000000000000000.cdf-ms" 1: Move File: Source = [l:162{81}]"\SystemRoot\WinSxS\Temp\PendingRenames\d0aa7fe5fb37cc01db0d00007017d412.$$.cdf-ms", Destination = [l:74{37}]"\SystemRoot\WinSxS\FileMaps\$$.cdf-ms" 2: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\308e96e5fb37cc01dc0d00007017d412.$$_system32_21f9a9c4a2f8b514.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms" 3: Move File: Source = [l:242{121}]"\SystemRoot\WinSxS\Temp\PendingRenames\00cfcbe5fb37cc01dd0d00007017d412.$$_system32_codeintegrity_e9af9308cfc26dc2.cdf-ms", Destination = [l:154{77}]"\SystemRoot\WinSxS\FileMaps\$$_system32_codeintegrity_e9af9308cfc26dc2.cdf-ms" 4: Move File: Source = [l:238{119}]"\SystemRoot\WinSxS\Temp\PendingRenames\204beee5fb37cc01de0d00007017d412.$$_system32_msdtc_trace_f33466dc5bf36670.cdf-ms", Destination = [l:150{75}]"\SystemRoot\WinSxS\FileMaps\$$_system32_msdtc_trace_f33466dc5bf36670.cdf-ms" 5: Move File: Source = [l:222{111}]"\SystemRoot\WinSxS\Temp\PendingRenames\804c00e6fb37cc01df0d00007017d412.$$_system32_com_066545e3d047e7c7.cdf-ms", Destination = [l:134{67}]"\SystemRoot\WinSxS\FileMaps\$$_system32_com_066545e3d047e7c7.cdf-ms" 6: Set Key Value: Key = [l:162{81}]"\Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Cleanup", Value = [l:76{38}]"{18606cb8-9e69-7571-16d3-ec814bdc5adc}", Type = REG_SZ (1), Data = {l:102 b:43003a005c00570069006e0064006f00770073005c00730079007300740065006d00330032005c 006d0073006400740063007000720078002e0064006c006c002c00530079007300500072006500700 044007400630043006c00650061006e00750070000000} 7: Set Key Value: Key = [l:168{84}]"\Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Generalize", Value = [ 2011-07-01 10:33:52, Info CSI l:76{38}]"{18606cb8-9e69-7571-1eb2-96b7091aa28f}", Type = REG_SZ (1), Data = {l:108 b:43003a005c00570069006e0064006f00770073005c00730079007300740065006d00330032005c 006d0073006400740063007000720078002e0064006c006c002c00530079007300500072006500700 0440074006300470065006e006500720061006c0069007a0065000000} 8: Set Key Value: Key = [l:168{84}]"\Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Specialize", Value = [l:76{38}]"{18606cb8-9e69-7571-35a2-cee9227ca977}", Type = REG_SZ (1), Data = {l:108 b:43003a005c00570069006e0064006f00770073005c00730079007300740065006d00330032005c 006d0073006400740063007000720078002e0064006c006c002c00530079007300500072006500700 04400740063005300700065006300690061006c0069007a0065000000} 9: Set Key Value: Key = [l:168{84}]"\Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Specialize", Value = [l:76{38}]"{8d0efec0-5a95-b5e9-594c-604cd9837b21}", Type = REG_SZ (1), Data = {l:96 b:43003a005c00570069006e0064006f00770073005c00730079007300740065006d00330032005c 00630061007400730072007600750074002e0064006c006c002c00530079007300700072006500700 043006f006d0070006c00750073000000} POQ 34 ends. 2011-07-01 10:33:52, Info CSI 00000096 [SR] Verify complete 2011-07-01 10:33:52, Info CSI 00000097 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:33:52, Info CSI 00000098 [SR] Beginning Verify and Repair transaction 2011-07-01 10:33:58, Info CSI 00000099 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\nl-NL" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"nl-NL", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:58, Info CSI 0000009a Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\sk-SK" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"sk-SK", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:58, Info CSI 0000009b Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\hu-HU" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"hu-HU", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:58, Info CSI 0000009c Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\pl-PL" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"pl-PL", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:58, Info CSI 0000009d Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\hr-HR" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"hr-HR", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:58, Info CSI 0000009e Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\es-ES" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"es-ES", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:59, Info CSI 0000009f Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\bg-BG" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"bg-BG", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:59, Info CSI 000000a0 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\ro-RO" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"ro-RO", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:59, Info CSI 000000a1 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\cs-CZ" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"cs-CZ", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:59, Info CSI 000000a2 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\sv-SE" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"sv-SE", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:59, Info CSI 000000a3 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\lv-LV" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"lv-LV", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:59, Info CSI 000000a4 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\lt-LT" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"lt-LT", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:33:59, Info CSI 000000a5 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\de-DE" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"de-DE", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:00, Info CSI 000000a6 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\th-TH" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"th-TH", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:00, Info CSI 000000a7 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\tr-TR" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"tr-TR", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:00, Info CSI 000000a8 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\it-IT" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"it-IT", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:00, Info CSI 000000a9 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\fr-FR" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"fr-FR", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:00, Info CSI 000000aa Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\fi-FI" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"fi-FI", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:00, Info CSI 000000ab Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\ja-JP" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"ja-JP", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:00, Info CSI 000000ac Ignoring duplicate ownership for directory [l:68{34}]"\??\C:\Windows\System32\sr-Latn-CS" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:20{10}]"sr-Latn-CS", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:01, Info CSI 000000ad Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\he-IL" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"he-IL", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:01, Info CSI 000000ae Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\uk-UA" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"uk-UA", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:02, Info CSI 000000af Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\sl-SI" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"sl-SI", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:02, Info CSI 000000b0 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\en-US" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-us", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:02, Info CSI 000000b1 Ignoring duplicate ownership for directory [l:102{51}]"\??\C:\ProgramData\Microsoft\Crypto\DSS\MachineKeys" in component Microsoft-Windows-Crypto-keys, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:02, Info CSI 000000b2 Ignoring duplicate ownership for directory [l:80{40}]"\??\C:\ProgramData\Microsoft\Crypto\Keys" in component Microsoft-Windows-Crypto-keys, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:02, Info CSI 000000b3 Ignoring duplicate ownership for directory [l:102{51}]"\??\C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys" in component Microsoft-Windows-Crypto-keys, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:02, Info CSI 000000b4 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\zh-CN" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"zh-CN", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:02, Info CSI 000000b5 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\zh-TW" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"zh-TW", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:03, Info CSI 000000b6 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\pt-BR" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"pt-BR", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:03, Info CSI 000000b7 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\ar-SA" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"ar-SA", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:03, Info CSI 000000b8 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\el-GR" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"el-GR", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:03, Info CSI 000000b9 Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\ko-KR" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"ko-KR", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:03, Info CSI 000000ba Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\da-DK" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"da-DK", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:03, Info CSI 000000bb Ignoring duplicate ownership for directory [l:58{29}]"\??\C:\Windows\System32\et-EE" in component Microsoft-Windows-comdlg32.Resources, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"et-EE", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral 2011-07-01 10:34:03, Info CSI 000000bc Repair results created: POQ 35 starts: 0: Move File: Source = [l:192{96}]"\SystemRoot\WinSxS\Temp\PendingRenames\c0f554e9fb37cc01440e00007017d412._0000000000000000.cdf-ms", Destination = [l:104{52}]"\SystemRoot\WinSxS\FileMaps\_0000000000000000.cdf-ms" 1: Move File: Source = [l:162{81}]"\SystemRoot\WinSxS\Temp\PendingRenames\f06a55e9fb37cc01450e00007017d412.$$.cdf-ms", Destination = [l:74{37}]"\SystemRoot\WinSxS\FileMaps\$$.cdf-ms" 2: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\a02f68e9fb37cc01460e00007017d412.$$_system32_21f9a9c4a2f8b514.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms" 3: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\40eb75e9fb37cc01470e00007017d412.$$_system32_nl-nl_53b6f9bc6b35343b.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_nl-nl_53b6f9bc6b35343b.cdf-ms" 4: Move File: Source = [l:206{103}]"\SystemRoot\WinSxS\Temp\PendingRenames\60fd7fe9fb37cc01480e00007017d412.$$_temp_401038c9a18c18c0.cdf-ms", Destination = [l:118{59}]"\SystemRoot\WinSxS\FileMaps\$$_temp_401038c9a18c18c0.cdf-ms" 5: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\e0f98ae9fb37cc01490e00007017d412.$$_syswow64_21ffbdd2a2dd92e0.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms" 6: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\b05fa5e9fb37cc014a0e00007017d412.$$_system32_sk-sk_5d374dfc5cf4b5c5.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_sk-sk_5d374dfc5cf4b5c5.cdf-ms" 7: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\b005b4e9fb37cc014b0e00007017d412.$$_system32_hu-hu_48503bf27c4f51d7.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_hu-hu_48503bf27c4f51d7.cdf-ms" 8: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\a066c7e9fb37cc014c0e00007017d41 2011-07-01 10:34:03, Info CSI 2.$$_system32_pt-pt_5783f7006581b92f.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_pt-pt_5783f7006581b92f.cdf-ms" 9: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\c0addde9fb37cc014d0e00007017d412.$$_system32_pl-pl_5783e8f06581cd6f.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_pl-pl_5783e8f06581cd6f.cdf-ms" 10: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\90c0f0e9fb37cc014e0e00007017d412.$$_system32_hr-hr_485036ac7c4f596f.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_hr-hr_485036ac7c4f596f.cdf-ms" 11: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\e0ed09eafb37cc014f0e00007017d412.$$_system32_es-es_429cd1a084dc7119.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_es-es_429cd1a084dc7119.cdf-ms" 12: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\60ae1eeafb37cc01500e00007017d412.$$_system32_ru-ru_5b50e7f65fce4fdb.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_ru-ru_5b50e7f65fce4fdb.cdf-ms" 13: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\d0652eeafb37cc01510e00007017d412.$$_system32_bg-bg_3ce955ba8d69a9ab.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_bg-bg_3ce955ba8d69a9ab.cdf-ms" 14: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\50d33beafb37cc01520e00007017d412.$$_system32_ro-ro_5b50dd6a5fce5f0b.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_ro-ro_5b50dd6a5fce5f0b.cdf-ms" 15: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\b0634beafb37cc01530e00007017d412.$$_system32_cs-cz_3ecfefb68a8fc3f6.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_cs-cz_3ecfefb68a8fc3f6.cdf-ms" 16: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\20fd5feafb37cc01540e00007017d412.$$_syst 2011-07-01 10:34:03, Info CSI em32_sv-se_5d37410c5cf4ca56.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_sv-se_5d37410c5cf4ca56.cdf-ms" 17: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\80e076eafb37cc01550e00007017d412.$$_system32_lv-lv_4fea1c1c70e881b7.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_lv-lv_4fea1c1c70e881b7.cdf-ms" 18: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\50d58eeafb37cc01560e00007017d412.$$_system32_lt-lt_4fea189870e886c7.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_lt-lt_4fea189870e886c7.cdf-ms" 19: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\e0da9eeafb37cc01570e00007017d412.$$_system32_de-de_40b6416a87b647ef.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_de-de_40b6416a87b647ef.cdf-ms" 20: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\80e9b3eafb37cc01580e00007017d412.$$_system32_th-th_5f1dc0505a1b09f7.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_th-th_5f1dc0505a1b09f7.cdf-ms" 21: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\301fc9eafb37cc01590e00007017d412.$$_system32_tr-tr_5f1dd1e45a1af0a7.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_tr-tr_5f1dd1e45a1af0a7.cdf-ms" 22: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\806addeafb37cc015a0e00007017d412.$$_system32_it-it_4a36b1ca7975a0f9.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_it-it_4a36b1ca7975a0f9.cdf-ms" 23: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\f074f4eafb37cc015b0e00007017d412.$$_system32_fr-fr_448347788202c03b.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_fr-fr_448347788202c03b.cdf-ms" 24: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\70c406ebfb37cc015c0e00007017d412.$$_system32_fi- 2011-07-01 10:34:03, Info CSI fi_448337a68202d703.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_fi-fi_448337a68202d703.cdf-ms" 25: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\30b019ebfb37cc015d0e00007017d412.$$_system32_ja-jp_4c1d2478769bf2f4.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_ja-jp_4c1d2478769bf2f4.cdf-ms" 26: Move File: Source = [l:236{118}]"\SystemRoot\WinSxS\Temp\PendingRenames\105b2febfb37cc015e0e00007017d412.$$_system32_sr-latn-cs_36d1c3d11e65ce00.cdf-ms", Destination = [l:148{74}]"\SystemRoot\WinSxS\FileMaps\$$_system32_sr-latn-cs_36d1c3d11e65ce00.cdf-ms" 27: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\107240ebfb37cc015f0e00007017d412.$$_system32_he-il_48502d1c7c4f6669.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_he-il_48502d1c7c4f6669.cdf-ms" 28: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\609f59ebfb37cc01600e00007017d412.$$_system32_uk-ua_61042a3457416b73.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_uk-ua_61042a3457416b73.cdf-ms" 29: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\00a9d7ebfb37cc01610e00007017d412.$$_system32_nb-no_53b700d66b352886.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_nb-no_53b700d66b352886.cdf-ms" 30: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\2061f0ebfb37cc01620e00007017d412.$$_system32_sl-si_5d374a0c5cf4bbc8.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_sl-si_5d374a0c5cf4bbc8.cdf-ms" 31: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\b0ee13ecfb37cc01630e00007017d412.$$_system32_en-us_429cd25484dc6f94.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_en-us_429cd25484dc6f94.cdf-ms" 32: Move File: Source = [l:280{140}]"\SystemRoot\WinSxS\Temp\PendingRenames\009419ecfb37cc01640e00007017d412.programdata_m 2011-07-01 10:34:03, Info CSI icrosoft_crypto_dss_machinekeys_43de8c451bf80cb4.cdf-ms", Destination = [l:192{96}]"\SystemRoot\WinSxS\FileMaps\programdata_microsoft_crypto_dss_machinekeys_43de8c451bf80cb4.cdf-ms" 33: Move File: Source = [l:258{129}]"\SystemRoot\WinSxS\Temp\PendingRenames\b0411becfb37cc01650e00007017d412.programdata_microsoft_crypto_keys_584b2843 68b25bef.cdf-ms", Destination = [l:170{85}]"\SystemRoot\WinSxS\FileMaps\programdata_microsoft_crypto_keys_584b284368b25bef.cdf-ms" 34: Move File: Source = [l:280{140}]"\SystemRoot\WinSxS\Temp\PendingRenames\90641decfb37cc01660e00007017d412.programdata_microsoft_crypto_rsa_machineke ys_aa739417efae0d58.cdf-ms", Destination = [l:192{96}]"\SystemRoot\WinSxS\FileMaps\programdata_microsoft_crypto_rsa_machinekeys_aa739417efae0d58.cdf-ms" 35: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\607730ecfb37cc01670e00007017d412.$$_system32_zh-cn_6a8499504900c466.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_zh-cn_6a8499504900c466.cdf-ms" 36: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\b0c244ecfb37cc01680e00007017d412.$$_system32_zh-hk_6a84939e4900ccf6.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_zh-hk_6a84939e4900ccf6.cdf-ms" 37: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\000e59ecfb37cc01690e00007017d412.$$_system32_zh-tw_6a84aa664900aad6.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_zh-tw_6a84aa664900aad6.cdf-ms" 38: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\305e74ecfb37cc016a0e00007017d412.$$_system32_pt-br_5783f3346581bed3.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_pt-br_5783f3346581bed3.cdf-ms" 39: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\000085ecfb37cc016b0e00007017d412.$$_system32_ar-sa_3b02d130904371b4.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_ar-sa_3b02d130904371b4.cdf 2011-07-01 10:34:03, Info CSI -ms" 40: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\10cd93ecfb37cc016c0e00007017d412.$$_system32_el-gr_429cd0b684dc71bd.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_el-gr_429cd0b684dc71bd.cdf-ms" 41: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\80f5a5ecfb37cc016d0e00007017d412.$$_system32_ko-kr_4e039de673c23e4a.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_ko-kr_4e039de673c23e4a.cdf-ms" 42: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\8041c3ecfb37cc016e0e00007017d412.$$_system32_da-dk_40b64d5e87b63595.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_da-dk_40b64d5e87b63595.cdf-ms" 43: Move File: Source = [l:226{113}]"\SystemRoot\WinSxS\Temp\PendingRenames\e060d0ecfb37cc016f0e00007017d412.$$_system32_et-ee_429cb6e884dc9948.cdf-ms", Destination = [l:138{69}]"\SystemRoot\WinSxS\FileMaps\$$_system32_et-ee_429cb6e884dc9948.cdf-ms" 44: Set Key Value: Key = [l:168{84}]"\Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Generalize", Value = [l:76{38}]"{787ca546-7183-45b1-c28d-ccc47a787790}", Type = REG_SZ (1), Data = {l:108 b:43003a005c00570069006e0064006f00770073005c00730079007300740065006d00330032005c 006300610070006900730070002e0064006c006c002c0043004100500049005300790073005000720 0650070005f00470065006e006500720061006c0069007a0065000000} 45: Set Key Value: Key = [l:168{84}]"\Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Specialize", Value = [l:76{38}]"{787ca546-7183-45b1-b30d-046ffeeb096e}", Type = REG_SZ (1), Data = {l:112 b:43003a005c00570069006e0064006f00770073005c00730079007300740065006d00330032005c 006300610070006900730070002e0064006c006c002c00430072007900700074006f0053007900730 050007200650070005f005300700065006300690061006c0069007a0065000000} 46: Set Key Value: Key = [l:162{81}]"\Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Cleanup", Value 2011-07-01 10:34:03, Info CSI = [l:76{38}]"{787ca546-7183-45b1-1dcd-fb0609f92d84}", Type = REG_SZ (1), Data = {l:102 b:43003a005c00570069006e0064006f00770073005c00730079007300740065006d00330032005c 006300610070006900730070002e0064006c006c002c00430072007900700074006f0053007900730 050007200650070005f0043006c00650061006e000000} POQ 35 ends. 2011-07-01 10:34:03, Info CSI 000000bd [SR] Verify complete 2011-07-01 10:34:04, Info CSI 000000be [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:34:04, Info CSI 000000bf [SR] Beginning Verify and Repair transaction 2011-07-01 10:34:12, Info CSI 000000c0 Repair results created: POQ 36 starts: 0: Move File: Source = [l:192{96}]"\SystemRoot\WinSxS\Temp\PendingRenames\10430ff1fb37cc01d40e00007017d412._0000000000000000.cdf-ms", Destination = [l:104{52}]"\SystemRoot\WinSxS\FileMaps\_0000000000000000.cdf-ms" 1: Move File: Source = [l:162{81}]"\SystemRoot\WinSxS\Temp\PendingRenames\600610f1fb37cc01d50e00007017d412.$$.cdf-ms", Destination = [l:74{37}]"\SystemRoot\WinSxS\FileMaps\$$.cdf-ms" 2: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\a0d71cf1fb37cc01d60e00007017d412.$$_system32_21f9a9c4a2f8b514.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms" 3: Move File: Source = [l:230{115}]"\SystemRoot\WinSxS\Temp\PendingRenames\f07c22f1fb37cc01d70e00007017d412.$$_system32_drivers_dc1b782427b5ee1b.cdf-ms", Destination = [l:142{71}]"\SystemRoot\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms" 4: Move File: Source = [l:240{120}]"\SystemRoot\WinSxS\Temp\PendingRenames\10cb22f1fb37cc01d80e00007017d412.$$_system32_drivers_umdf_a531b5dc588477d3.cdf-ms", Destination = [l:152{76}]"\SystemRoot\WinSxS\FileMaps\$$_system32_drivers_umdf_a531b5dc588477d3.cdf-ms" 5: Move File: Source = [l:242{121}]"\SystemRoot\WinSxS\Temp\PendingRenames\40b125f1fb37cc01d90e00007017d412.$$_system32_logfiles_wudf_082845cc19e06817.cdf-ms", Destination = [l:154{77}]"\SystemRoot\WinSxS\FileMaps\$$_system32_logfiles_wudf_082845cc19e06817.cdf-ms" 6: Move File: Source = [l:236{118}]"\SystemRoot\WinSxS\Temp\PendingRenames\808485f1fb37cc01da0e00007017d412.$$_system32_ime_shared_5a5b3a5824d8fee4.cdf-ms", Destination = [l:148{74}]"\SystemRoot\WinSxS\FileMaps\$$_system32_ime_shared_5a5b3a5824d8fee4.cdf-ms" 7: Move File: Source = [l:244{122}]"\SystemRoot\WinSxS\Temp\PendingRenames\10c68bf1fb37cc01db0e00007017d412.$$_system32_ime_shared_res_791e6438104a0cf8.cdf-ms", Destination = [l:156{78}]"\SystemRoot\WinSxS\FileMaps\$$_system32_ime_shared_res_791e6438104a0cf8.cdf-ms" POQ 36 ends. 2011-07-01 10:34:12, Info CSI 000000c1 [SR] Verify complete 2011-07-01 10:34:12, Info CSI 000000c2 [SR] Verifying 100 (0x0000000000000064) components 2011-07-01 10:34:12, Info CSI 000000c3 [SR] Beginning Verify and Repair transaction 2011-07-01 10:34:19, Info CSI 000000c4 Repair results created: POQ 37 starts: 0: Move File: Source = [l:192{96}]"\SystemRoot\WinSxS\Temp\PendingRenames\30ebe2f5fb37cc01400f00007017d412._0000000000000000.cdf-ms", Destination = [l:104{52}]"\SystemRoot\WinSxS\FileMaps\_0000000000000000.cdf-ms" 1: Move File: Source = [l:162{81}]"\SystemRoot\WinSxS\Temp\PendingRenames\7087e3f5fb37cc01410f00007017d412.$$.cdf-ms", Destination = [l:74{37}]"\SystemRoot\WinSxS\FileMaps\$$.cdf-ms" 2: Move File: Source = [l:204{102}]"\SystemRoot\WinSxS\Temp\PendingRenames\c0bbe6f5fb37cc01420f00007017d412.$$_ime_3f581be9a4c8cabd.cdf-ms", Destination = [l:116{58}]"\SystemRoot\WinSxS\FileMaps\$$_ime_3f581be9a4c8cabd.cdf-ms" 3: Move File: Source = [l:232{116}]"\SystemRoot\WinSxS\Temp\PendingRenames\00c9e9f5fb37cc01430f00007017d412.$$_ime_imejp10_dicts_281006c600450618.cdf-ms", Destination = [l:144{72}]"\SystemRoot\WinSxS\FileMaps\$$_ime_imejp10_dicts_281006c600450618.cdf-ms" 4: Move File: Source = [l:230{115}]"\SystemRoot\WinSxS\Temp\PendingRenames\30afecf5fb37cc01440f00007017d412.$$_ime_imejp10_help_280ffde19e779392.cdf-ms", Destination = [l:142{71}]"\SystemRoot\WinSxS\FileMaps\$$_ime_imejp10_help_280ffde19e779392.cdf-ms" 5: Move File: Source = [l:214{107}]"\SystemRoot\WinSxS\Temp\PendingRenames\6059f9f5fb37cc01450f00007017d412.$$_system32_21f9a9c4a2f8b514.cdf-ms", Destination = [l:126{63}]"\SystemRoot\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms" 6: Move File: Source = [l:236{118}]"\SystemRoot\WinSxS\Temp\PendingRenames\70f1fbf5fb37cc01460f00007017d412.$$_system32_ime_shared_5a5b3a5824d8fee4.cdf-ms", Destination = [l:148{74}]"\SystemRoot\WinSxS\FileMaps\$$_system32_ime_shared_5a5b3a5824d8fee4.cdf-ms" 7: Move File: Source = [l:238{119}]"\SystemRoot\WinSxS\Temp\PendingRenames\00c2fff5fb37cc01470f00007017d412.$$_system32_ime_imejp10_aead4918eed09977.cdf-ms", Destination = [l:150{75}]"\SystemRoot\WinSxS\FileMaps\$$_system32_ime_imejp10_aead4918eed09977.cdf-ms" 8: Move File: Source = [l:254{127}]"\SystemRoot\WinSxS\Temp\Pend 2011-07-01 10:34:19, Info CSI ingRenames\d0bd01f6fb37cc01480f00007017d412.$$_system32_ime_imejp10_applets_bad04da37647b46c.cdf-ms", Destination = [l:166{83}]"\SystemRoot\WinSxS\FileMaps\$$_system32_ime_imejp10_applets_bad04da37647b46c.cdf-ms" 9: Move File: Source = [l:224{112}]"\SystemRoot\WinSxS\Temp\PendingRenames\20b60ef6fb37cc01490f00007017d412.$$_digitallocker_c114c0cb179413b0.cdf-ms", Destination = [l:136{68}]"\SystemRoot\WinSxS\FileMaps\$$_digitallocker_c114c0cb179413b0.cdf-ms" 10: Set Key Value: Key = [l:168{84}]"\Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Generalize", Value = [l:76{38}]"{e40f0bfc-3e2f-3564-b1a6-321233838362}", Type = REG_SZ (1), Data = {l:110 b:43003a005c00570069006e0064006f00770073005c00530079007300740065006d00330032005c 00640068006300700063007300760063002e0064006c006c002c00440068006300700043006c00690 065006e0074005f00470065006e006500720061006c0069007a0065000000} POQ 37 ends. 2011-07-01 10:34:19, Info CSI 000000c5 [SR] Verify complete 2011-07-01 10:34:19, Info CSI 000000c6 [SR] Verifying 100 (0x0000000000000064) components Here is the log:
:( No I think it may be a Fake Anti-virus program - I keep getting .exe files that stop running and one of the biggest offenders is Microsoft Security Essentials. The errors I have gotten since last post: Microsfoft Security Essentials has stopped working ffpmg.exe has stopped working logitech updater has stopped working Failed to get trouble shooter catalog error mats get sap catalog failed Should I take this to another forum? SIde note when I get the error code for MSE it is : 0x80070424 Thanks Julie
Ok then, go to Microsoft Windows section and open a thread there telling them about this error. I will continue monitor the other one and find out what could be the cause. I will leave this open.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI