Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93084 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Computer Skips, Pauses and Shuts Down on Its Own - Part 1 [Solved]


  • This topic is locked This topic is locked
17 replies to this topic

#1 Temujin

Temujin

    Authentic Member

  • Authentic Member
  • PipPip
  • 30 posts

Posted 05 August 2014 - 09:35 PM

Hi there,
 
My computer has lately been skipping, pausing (with mouse not moving / freezing) for 5-10 seconds at a time, and frequently (1-2 times a day) shuts down on its own (oddly, it also turns on on its own sometimes, after I've shut it down for the night). It actually did this for a fairly long while, but lately these symptoms have increased in frequency and the PC is getting unusable.
 
Please find below my logs, as instructed. Thanks for your help!
 
Temujin
 
----------------------OTL.txt
 
OTL logfile created on: 8/5/2014 10:26:15 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = F:\Users\Temujin\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17207)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
5.98 Gb Total Physical Memory | 4.41 Gb Available Physical Memory | 73.66% Memory free
11.96 Gb Paging File | 10.52 Gb Available in Paging File | 87.95% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 59.53 Gb Total Space | 13.59 Gb Free Space | 22.82% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 350.19 Gb Free Space | 75.19% Space Free | Partition Type: NTFS
Drive G: | 931.51 Gb Total Space | 887.86 Gb Free Space | 95.31% Space Free | Partition Type: NTFS
Drive H: | 1.86 Gb Total Space | 1.16 Gb Free Space | 62.53% Space Free | Partition Type: FAT
Drive I: | 596.17 Gb Total Space | 303.84 Gb Free Space | 50.97% Space Free | Partition Type: NTFS
 
Computer Name: TEMUJIN-PC | User Name: Temujin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - F:\Users\Temujin\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - F:\Program Files\NYU VPN\cvpnd.exe (Cisco Systems, Inc.)
PRC - F:\Program Files\HP Webcam\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.)
 
 
========== Modules (No Company Name) ==========
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (ClickToRunSvc) -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe (Microsoft Corporation)
SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (NvStreamSvc) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (NvNetworkService) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SmcService) -- C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\Smc.exe (Symantec Corporation)
SRV - (SNAC) -- C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\snac64.exe (Symantec Corporation)
SRV - (SepMasterService) -- C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe (Symantec Corporation)
SRV - (ACDaemon) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (CVPND) -- F:\Program Files\NYU VPN\cvpnd.exe (Cisco Systems, Inc.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (uCamMonitor) -- F:\Program Files\HP Webcam\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.)
SRV - (NBService) -- F:\Program Files\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (nvvad_WaveExtensible) -- C:\Windows\SysNative\drivers\nvvad64v.sys (NVIDIA Corporation)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SysPlant) -- C:\Windows\SysNative\drivers\SysPlant.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\SEP\0C0107DF\07DF.105\x64\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\SEP\0C0107DF\07DF.105\x64\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) -- C:\Windows\SysNative\drivers\SEP\0C0107DF\07DF.105\x64\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (SYMNETS) -- C:\Windows\SysNative\drivers\SEP\0C0107DF\07DF.105\x64\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\SEP\0C0107DF\07DF.105\x64\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (ccSettings_{3771A34D-2132-48EA-A486-D62ECDF9D553}) -- C:\Windows\SysNative\drivers\SEP\0C0107DF\07DF.105\x64\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) -- C:\Windows\SysNative\drivers\SEP\0C0107DF\07DF.105\x64\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (Point64) -- C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) -- C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (nmwcdnsux64) -- C:\Windows\SysNative\drivers\nmwcdnsux64.sys (Nokia)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (BVRPMPR5a64) -- C:\Windows\SysNative\drivers\BVRPMPR5a64.SYS (Avanquest Software)
DRV:64bit: - (CVPNDRVA) -- C:\Windows\SysNative\drivers\CVPNDRVA.sys ()
DRV:64bit: - (CVirtA) -- C:\Windows\SysNative\drivers\CVirtA64.sys (Cisco Systems, Inc.)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (ArcSoftKsUFilter) -- C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys (ArcSoft, Inc.)
DRV:64bit: - (DNE) -- C:\Windows\SysNative\drivers\dne64x.sys (Deterministic Networks, Inc.)
DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVEX15) -- C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\VirusDefs\20140803.034\ex64.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\VirusDefs\20140803.034\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (IDSVia64) -- C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\IPSDefs\20140731.012\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) -- C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\BASHDefs\20140718.013\BHDrvx64.sys (Symantec Corporation)
DRV - (SyDvCtrl) -- C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\SyDvCtrl64.sys (Symantec Corporation)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (i8042prt) -- C:\Windows\SysWOW64\drivers\L8042PRT.SYS (Logitech)
DRV - (lsermous) -- C:\Windows\SysWOW64\drivers\LSERMOUS.SYS (Logitech)
DRV - (lmoufltr) -- C:\Windows\SysWOW64\drivers\LMOUFLTR.SYS (Logitech)
DRV - (lkbdfltr) -- C:\Windows\SysWOW64\drivers\LKBDFLTR.SYS (Logitech)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = F:\Users\Temujin\Downloads
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 37 91 1F 4E A2 23 CE 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = 
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "DuckDuckGo"
FF - prefs.js..browser.search.selectedEngine: "DuckDuckGo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "DuckDuckGo.com"
FF - prefs.js..extensions.enabledAddons: %7Bbee6eb20-01e0-ebd1-da83-080329fb9a3a%7D:1.59
FF - prefs.js..extensions.enabledAddons: %7B19503e42-ca3c-4c27-b1e2-9cdb2170ee34%7D:1.5.6.2
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.8.36
FF - prefs.js..extensions.enabledAddons: artur.dubovoy%40gmail.com:6.1.2
FF - prefs.js..extensions.enabledAddons: %7BBBDA0591-3099-440a-AA10-41764D9DB4DB%7D:12.3.0.3%20-%201
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:31.0
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.3.0: C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: F:\Program Files\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.65.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.65.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: F:\Program Files\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: F:\Users\Temujin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\IPSFF [2014/07/16 02:03:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 31.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/07/30 00:03:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 31.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 31.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/07/30 00:03:21 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 31.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2013/03/18 02:34:11 | 000,000,000 | ---D | M] (No name found) -- F:\Users\Temujin\AppData\Roaming\Mozilla\Extensions
[2014/08/01 02:26:29 | 000,000,000 | ---D | M] (No name found) -- F:\Users\Temujin\AppData\Roaming\Mozilla\Firefox\Profiles\i1fdowup.default\extensions
[2014/07/16 01:23:18 | 000,000,000 | ---D | M] (Flash and Video Download) -- F:\Users\Temujin\AppData\Roaming\Mozilla\Firefox\Profiles\i1fdowup.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
[2014/08/01 02:26:29 | 000,000,000 | ---D | M] ("Flash Video Downloader - YouTube Full HD Download") -- F:\Users\Temujin\AppData\Roaming\Mozilla\Firefox\Profiles\i1fdowup.default\extensions\artur.dubovoy@gmail.com
[2014/07/03 18:43:40 | 001,225,715 | ---- | M] () (No name found) -- F:\Users\Temujin\AppData\Roaming\Mozilla\Firefox\Profiles\i1fdowup.default\extensions\firefox@ghostery.com.xpi
[2014/07/21 18:53:15 | 000,389,516 | ---- | M] () (No name found) -- F:\Users\Temujin\AppData\Roaming\Mozilla\Firefox\Profiles\i1fdowup.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
[2014/07/30 22:16:49 | 000,538,675 | ---- | M] () (No name found) -- F:\Users\Temujin\AppData\Roaming\Mozilla\Firefox\Profiles\i1fdowup.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/06/10 22:48:04 | 000,010,316 | ---- | M] () -- F:\Users\Temujin\AppData\Roaming\Mozilla\Firefox\Profiles\i1fdowup.default\searchplugins\duckduckgo.xml
[2014/08/04 21:27:35 | 000,002,242 | ---- | M] () -- F:\Users\Temujin\AppData\Roaming\Mozilla\Firefox\Profiles\i1fdowup.default\searchplugins\here.xml
[2013/06/10 22:56:42 | 000,001,997 | ---- | M] () -- F:\Users\Temujin\AppData\Roaming\Mozilla\Firefox\Profiles\i1fdowup.default\searchplugins\wolframalpha.xml
[2014/07/30 00:03:21 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/07/30 00:03:27 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014/07/16 02:03:54 | 000,000,000 | ---D | M] (Symantec Vulnerability Protection) -- C:\PROGRAMDATA\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\12.1.2015.2015.105\DATA\IPSFF
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - homepage: 
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - Extension: Google Docs = F:\Users\Temujin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: Google Drive = F:\Users\Temujin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Voice Search Hotword (Beta) = F:\Users\Temujin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: YouTube = F:\Users\Temujin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = F:\Users\Temujin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Boomerang for Gmail = F:\Users\Temujin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdanidgdpmkimeiiojknlnekblgmpdll\1.2.4_0\
CHR - Extension: Save to Pocket = F:\Users\Temujin\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj\1.9.1_0\
CHR - Extension: Google Wallet = F:\Users\Temujin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = F:\Users\Temujin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\urlredir.dll (Microsoft Corporation)
O2:64bit: - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll (Microsoft Corporation)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (Symantec Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\urlredir.dll (Microsoft Corporation)
O2 - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\office15\grooveex.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: []  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Convert link target to Adobe PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to existing PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to Adobe PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to existing PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to Adobe PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to existing PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to existing PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Convert link target to Adobe PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnie.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnie.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation)
O9 - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\office15\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6DC67F99-3402-40E8-A064-D3004E3AF1EE}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\osf - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\msosb.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/08/02 15:09:16 | 002,620,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2014/08/02 15:09:16 | 000,058,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2014/08/02 15:09:16 | 000,044,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2014/08/02 15:09:14 | 000,700,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2014/08/02 15:09:14 | 000,581,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll
[2014/08/02 15:09:14 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2014/08/02 15:09:14 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll
[2014/08/02 15:09:14 | 000,038,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2014/08/02 15:09:14 | 000,036,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wups.dll
[2014/08/02 15:09:12 | 000,198,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2014/08/02 15:09:12 | 000,179,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll
[2014/08/02 15:09:12 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2014/08/02 15:09:12 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe
[2014/07/30 00:03:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014/07/20 21:15:02 | 000,000,000 | ---D | C] -- F:\Users\Temujin\AppData\Roaming\Oracle
[2014/07/20 21:14:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014/07/20 21:14:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014/07/17 02:19:12 | 000,000,000 | ---D | C] -- F:\Users\Temujin\AppData\Local\Adobe
[2014/07/09 21:46:31 | 000,519,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2014/07/09 21:46:30 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2014/07/09 21:46:27 | 000,692,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\osk.exe
[2014/07/09 21:46:27 | 000,646,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\osk.exe
[2014/07/09 21:46:26 | 000,624,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll
[2014/07/09 21:46:26 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll
[2014/07/09 21:46:25 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2014/07/09 21:46:23 | 000,592,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/07/09 21:46:23 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014/07/09 21:46:23 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/07/09 21:46:23 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/07/09 21:46:23 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014/07/09 21:46:23 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/07/09 21:46:23 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/07/09 21:46:23 | 000,032,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014/07/09 21:46:22 | 001,964,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/07/09 21:46:22 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/07/09 21:46:21 | 000,631,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/07/09 21:46:21 | 000,608,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/07/09 21:46:21 | 000,452,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014/07/09 21:46:21 | 000,442,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/07/09 21:46:21 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/07/09 21:46:21 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/07/09 21:46:21 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/07/09 21:46:20 | 002,040,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/07/09 21:46:20 | 001,068,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014/07/09 21:46:20 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/07/09 21:46:20 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/07/09 21:46:19 | 000,598,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/07/09 21:46:19 | 000,292,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014/07/09 21:46:19 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/07/09 21:46:19 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014/07/09 21:46:18 | 005,721,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/07/09 21:46:18 | 001,249,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014/07/09 21:46:18 | 000,846,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/07/09 21:46:18 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/07/09 21:46:18 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014/07/09 21:46:18 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/07/09 21:46:18 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014/07/09 21:46:17 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2014/07/09 21:46:17 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/07/09 21:46:17 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014/07/09 21:45:48 | 001,460,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2014/07/07 21:24:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2014/07/07 21:23:20 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\Windows\SysWow64\sqlite3.dll
[2014/07/07 20:47:24 | 000,122,584 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/07/07 20:47:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/07/07 20:47:13 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/07/07 20:47:13 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014/07/07 20:47:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
 
========== Files - Modified Within 30 Days ==========
 
[2014/08/05 22:20:30 | 000,020,496 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/08/05 22:20:30 | 000,020,496 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/08/05 22:17:58 | 000,782,470 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/08/05 22:17:58 | 000,662,384 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/08/05 22:17:58 | 000,122,252 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/08/05 22:13:30 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/08/05 22:13:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/08/05 22:13:16 | 522,338,303 | -HS- | M] () -- C:\hiberfil.sys
[2014/08/05 21:56:46 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/08/05 21:31:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/08/05 02:15:00 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2105342170-2719686501-3503371245-1000UA.job
[2014/08/04 23:15:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2105342170-2719686501-3503371245-1000Core.job
[2014/07/18 20:59:06 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/07/16 22:45:36 | 000,122,584 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/07/11 03:02:05 | 000,098,216 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2014/07/11 02:56:08 | 000,272,808 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2014/07/11 02:56:01 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2014/07/11 02:55:32 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2014/07/10 22:35:53 | 000,441,944 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/07/08 23:31:10 | 000,699,056 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014/07/08 23:31:10 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
 
========== Files Created - No Company Name ==========
 
[2013/11/08 00:29:37 | 001,527,650 | ---- | C] () -- C:\Windows\SysWow64\libfftw3f-3.dll
[2013/11/08 00:29:37 | 001,527,650 | ---- | C] () -- C:\Windows\SysWow64\fftw3.dll
[2013/11/08 00:29:37 | 000,140,288 | ---- | C] () -- C:\Windows\SysWow64\avsfilter.dll
[2013/11/08 00:29:37 | 000,004,608 | ---- | C] () -- C:\Windows\SysWow64\AvsRecursion.dll
[2013/10/08 00:57:07 | 000,774,592 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/06/04 20:50:03 | 000,004,510 | ---- | C] () -- F:\Users\Temujin\AppData\Roaming\CamStudio.cfg
[2013/06/04 20:50:03 | 000,000,408 | ---- | C] () -- F:\Users\Temujin\AppData\Roaming\CamShapes.ini
[2013/06/04 20:50:03 | 000,000,408 | ---- | C] () -- F:\Users\Temujin\AppData\Roaming\CamLayout.ini
[2013/06/04 20:50:03 | 000,000,038 | ---- | C] () -- F:\Users\Temujin\AppData\Roaming\Camdata.ini
[2013/06/04 20:46:52 | 000,004,608 | ---- | C] () -- F:\Users\Temujin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/04/04 01:12:48 | 000,104,448 | ---- | C] () -- C:\Windows\SysWow64\LGUICOM.DLL
[2013/04/04 01:12:48 | 000,000,438 | ---- | C] () -- C:\Windows\Cmousecc.ini
[2013/03/19 04:59:25 | 000,214,392 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013/03/19 04:59:25 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013/03/18 05:26:56 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
 
========== ZeroAccess Check ==========
 
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/03/24 22:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/24 22:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 23:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2014/08/03 13:39:20 | 000,000,000 | ---D | M] -- F:\Users\Temujin\AppData\Roaming\ActivePresenter
[2013/11/18 20:27:03 | 000,000,000 | ---D | M] -- F:\Users\Temujin\AppData\Roaming\Dropbox
[2013/06/04 20:50:08 | 000,000,000 | ---D | M] -- F:\Users\Temujin\AppData\Roaming\Fatshark
[2014/07/30 00:24:03 | 000,000,000 | ---D | M] -- F:\Users\Temujin\AppData\Roaming\HandBrake
[2014/03/11 22:08:47 | 000,000,000 | ---D | M] -- F:\Users\Temujin\AppData\Roaming\JOSM
[2014/07/11 01:06:55 | 000,000,000 | ---D | M] -- F:\Users\Temujin\AppData\Roaming\Mp3tag
[2014/07/20 21:15:02 | 000,000,000 | ---D | M] -- F:\Users\Temujin\AppData\Roaming\Oracle
[2013/10/07 21:18:52 | 000,000,000 | ---D | M] -- F:\Users\Temujin\AppData\Roaming\Origin
[2013/12/13 01:59:06 | 000,000,000 | ---D | M] -- F:\Users\Temujin\AppData\Roaming\SMRecorder
[2013/06/04 20:50:23 | 000,000,000 | ---D | M] -- F:\Users\Temujin\AppData\Roaming\The Creative Assembly
[2013/06/04 20:50:26 | 000,000,000 | ---D | M] -- F:\Users\Temujin\AppData\Roaming\TS3Client
[2013/10/11 01:23:10 | 000,000,000 | ---D | M] -- F:\Users\Temujin\AppData\Roaming\ViberPC
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %USERPROFILE%\..|smtmp;true;true;true /FP >
 
< %temp%\smtmp\*.* /s > >
 
< MD5 for: EXPLORER.ADML  >
[2011/04/11 22:15:49 | 000,003,695 | ---- | M] () MD5=7A4C7F3CB156543113596988479CAFCE -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml
[2011/04/12 04:17:31 | 000,003,695 | ---- | M] () MD5=7A4C7F3CB156543113596988479CAFCE -- C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
 
< MD5 for: EXPLORER.ADMX  >
[2009/06/10 17:34:46 | 000,003,836 | ---- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx
[2009/06/10 16:53:55 | 000,003,836 | ---- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 -- C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
 
< MD5 for: EXPLORER.EXE  >
[2011/02/26 01:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 17:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows.old\Windows\explorer.exe
[2010/11/20 17:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2010/11/20 23:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 23:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
 
< MD5 for: EXPLORER.EXE.MUI  >
[2011/04/12 04:17:19 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 -- C:\Windows\en-US\explorer.exe.mui
[2011/04/12 04:17:19 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2011/04/11 22:15:39 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 -- C:\Windows.old\Windows\en-US\explorer.exe.mui
[2011/04/11 22:15:39 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui
[2011/04/12 04:17:21 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 -- C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2011/04/12 04:17:21 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
 
< MD5 for: EXPLORER.EXE-A80E4F97.PF  >
[2013/03/18 01:44:33 | 000,041,746 | ---- | M] () MD5=EC3EAD341C9907FF0AFC3610304D8571 -- C:\Windows.old\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
 
< MD5 for: IEXPLORE.EXE  >
[2014/03/07 21:59:00 | 000,811,728 | ---- | M] (Microsoft Corporation) MD5=0667ED9F8E905E1F73DB60ACCEDCBCA7 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17041_none_858ffb5bf711c81f\iexplore.exe
[2013/11/26 02:13:07 | 000,804,560 | ---- | M] (Microsoft Corporation) MD5=0685765C0CBE095BA0C6C8790BAE21EF -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16428_none_7b0d6f67c2d3f97a\iexplore.exe
[2013/05/16 22:32:12 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_20d88bb252a3770f\iexplore.exe
[2014/05/12 07:24:30 | 000,750,392 | ---- | M] (MalwareBytes) MD5=09882E8EDD1144E6EF1AF6D1F98305EE -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\iexplore.exe
[2013/07/26 02:23:39 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=133CEF30905806A35606652D409EEEBA -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_16893df21e3dcd43\iexplore.exe
[2013/08/10 02:31:28 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=1F3B062444AD6F667B5336E78D5A02B7 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20794_none_ffb36d2837eafb72\iexplore.exe
[2014/06/20 16:14:31 | 000,810,160 | ---- | M] (Microsoft Corporation) MD5=24868C9D422EDB5B249C0C81B01A0C19 -- C:\Program Files\Internet Explorer\iexplore.exe
[2014/06/20 16:14:31 | 000,810,160 | ---- | M] (Microsoft Corporation) MD5=24868C9D422EDB5B249C0C81B01A0C19 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17207_none_7b212759c2c57270\iexplore.exe
[2013/03/18 08:32:46 | 000,770,560 | ---- | M] (Microsoft Corporation) MD5=2859EBC065D2E1CCC94161CE28BAC085 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16521_none_20e4a040529a2792\iexplore.exe
[2013/02/24 20:58:09 | 000,775,232 | ---- | M] (Microsoft Corporation) MD5=28F93BAFB3EB407E99A7ED3D9DBDE04C -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20644_none_ffb93ba237e760ce\iexplore.exe
[2013/06/12 00:41:27 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=2A5F565327BFD679EC5F790DC15BBF25 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_0a0343986c500b78\iexplore.exe
[2013/04/05 01:55:38 | 000,770,624 | ---- | M] (Microsoft Corporation) MD5=2DC6BD1047553611DAEF97C751131A5D -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_0a122b746c443b42\iexplore.exe
[2013/06/11 20:23:57 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_20da757e52a1c35e\iexplore.exe
[2013/08/10 02:10:22 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=351657C79B62B91E16A95AD23EA3710D -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_168ab5d61e3c99b7\iexplore.exe
[2013/08/10 00:18:11 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=37287D98A1BF5D56AA729CEB9B27C6B1 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_20df6028529d5bb2\iexplore.exe
[2013/05/16 21:57:28 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=3902E280F6117A468D5573343A7AA1F6 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_09ffa3426c5372da\iexplore.exe
[2013/10/12 17:42:28 | 000,775,344 | ---- | M] (Microsoft Corporation) MD5=39D0074C59F6D1A62731942C7FA8B60B -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16736_none_167ae4781e4936f5\iexplore.exe
[2014/03/01 18:02:17 | 000,808,152 | ---- | M] (Microsoft Corporation) MD5=3A3BEA53F039CE2E997A918E26E30B1D -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16521_none_8557e945f73c23ff\iexplore.exe
[2013/10/12 05:49:48 | 000,775,344 | ---- | M] (Microsoft Corporation) MD5=3C8C00380462B1023C9F8EA2A9A7A137 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20848_none_ffa340aa37f7ff34\iexplore.exe
[2014/02/06 18:24:01 | 000,808,152 | ---- | M] (Microsoft Corporation) MD5=4263F6C131E513CEA1AE82B5B81A4E1A -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16518_none_85564983f73dbe0f\iexplore.exe
[2013/08/10 01:13:42 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=48A1306191216997F717C451B8D15139 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20794_none_0a08177a6c4bbd6d\iexplore.exe
[2014/06/02 02:03:18 | 000,810,200 | ---- | M] (Microsoft Corporation) MD5=4F2AA3E7BD7257E4937E071E3700819E -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17126_none_7b2e0ea1c2bb6f8c\iexplore.exe
[2014/06/02 00:43:13 | 000,812,248 | ---- | M] (Microsoft Corporation) MD5=60F88F6CA6303E8273AF7AAA9AAFECAC -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17126_none_8582b8f3f71c3187\iexplore.exe
[2013/02/21 08:59:57 | 000,775,216 | ---- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_16920d4a1e377ea4\iexplore.exe
[2013/03/18 08:32:46 | 000,775,184 | ---- | M] (Microsoft Corporation) MD5=681B380492ACB571ED6CCC1F37F53343 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16521_none_168ff5ee1e396597\iexplore.exe
[2013/07/25 23:49:06 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_20dde844529e8f3e\iexplore.exe
[2014/03/01 18:33:45 | 000,806,104 | ---- | M] (Microsoft Corporation) MD5=84BCBFB752B96543307E6602E669A95A -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16521_none_7b033ef3c2db6204\iexplore.exe
[2010/11/20 23:24:43 | 000,695,056 | ---- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2013/07/26 01:47:06 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=8D805B4EEEE0ECF6B604BE284978F135 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20768_none_ffb0112a37ee15f1\iexplore.exe
[2013/05/16 23:02:08 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=8F00471CA24ADF8D2AFAACF856EB70A4 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_ffaaf8f037f2b0df\iexplore.exe
[2013/06/11 22:28:00 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_1685cb2c1e410163\iexplore.exe
[2013/10/12 03:16:06 | 000,770,736 | ---- | M] (Microsoft Corporation) MD5=9DFE1678738DD968D7BA5559B52706D1 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20848_none_09f7eafc6c58c12f\iexplore.exe
[2013/02/24 19:52:40 | 000,770,624 | ---- | M] (Microsoft Corporation) MD5=A11C5E3E288256C540B7ED8BE3A04B01 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20644_none_0a0de5f46c4822c9\iexplore.exe
[2013/03/18 08:25:28 | 000,763,424 | ---- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2013/04/05 02:02:26 | 000,770,608 | ---- | M] (Microsoft Corporation) MD5=AAD90795E84E710543C6C7C2F7048E30 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_20e92fca5296266a\iexplore.exe
[2010/11/20 17:29:33 | 000,673,040 | ---- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 -- C:\Windows.old\Program Files\Internet Explorer\iexplore.exe
[2010/11/20 17:29:33 | 000,673,040 | ---- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe
[2010/11/20 23:25:08 | 000,673,040 | ---- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2014/02/06 18:55:10 | 000,806,104 | ---- | M] (Microsoft Corporation) MD5=C6E1178294BDEAB1CACF50427688DF05 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16518_none_7b019f31c2dcfc14\iexplore.exe
[2013/11/26 02:13:07 | 000,806,096 | ---- | M] (Microsoft Corporation) MD5=C8A8321292A459B0A17FB39A782A5C74 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16428_none_856219b9f734bb75\iexplore.exe
[2013/06/12 03:51:43 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=CA88A25280B1D85ED0BC26B042ABBCCF -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_ffae994637ef497d\iexplore.exe
[2014/06/20 15:39:54 | 000,812,216 | ---- | M] (Microsoft Corporation) MD5=CD900EFB4F8946A2BB1950D9F45915C2 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2014/06/20 15:39:54 | 000,812,216 | ---- | M] (Microsoft Corporation) MD5=CD900EFB4F8946A2BB1950D9F45915C2 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17207_none_8575d1abf726346b\iexplore.exe
[2013/04/05 03:53:33 | 000,775,232 | ---- | M] (Microsoft Corporation) MD5=CEA304830B4770BDA3572B87D0841848 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_169485781e35646f\iexplore.exe
[2013/09/22 19:54:30 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=D6B7DDB68436F13C3CAE2B92524F1FEC -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16721_none_20cf006852aa5f74\iexplore.exe
[2013/10/12 03:44:13 | 000,770,736 | ---- | M] (Microsoft Corporation) MD5=D7D5768B8A697FCBAEE2CFE137070F02 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16736_none_20cf8eca52a9f8f0\iexplore.exe
[2013/09/22 20:01:39 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=DB352EBF77E8655E0C46B6923F3C9950 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20831_none_09f78a2a6c58f471\iexplore.exe
[2013/03/18 08:25:28 | 000,757,296 | ---- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013/04/05 03:23:03 | 000,775,216 | ---- | M] (Microsoft Corporation) MD5=DE751E18F8DBF7BCCE46989CBA4A9828 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_ffbd812237e37947\iexplore.exe
[2013/02/21 07:28:11 | 000,770,608 | ---- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_20e6b79c5298409f\iexplore.exe
[2013/07/26 01:09:39 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=E70D60B3A350BD09D86CDAD9CF55F36B -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20768_none_0a04bb7c6c4ed7ec\iexplore.exe
[2013/09/22 21:55:58 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=E9F843E7E412AE9A507FD5ABBBD06462 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20831_none_ffa2dfd837f83276\iexplore.exe
[2014/03/07 22:34:14 | 000,809,680 | ---- | M] (Microsoft Corporation) MD5=EA8386CA87165460D39A1D29FF11080B -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17041_none_7b3b5109c2b10624\iexplore.exe
[2013/05/16 23:30:45 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=EDC77CF787FA015205936C9A3228486E -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_1683e1601e42b514\iexplore.exe
[2013/09/22 21:25:59 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=F6A7D9C0BC326F695526069C1DA1E8B7 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16721_none_167a56161e499d79\iexplore.exe
 
< MD5 for: IEXPLORE.EXE.MUI  >
[2013/11/26 02:13:07 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=0B33787AB6EE3BB5FDB0C7C52E4E06A6 -- C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/11/26 02:13:07 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=0B33787AB6EE3BB5FDB0C7C52E4E06A6 -- C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/11/26 02:13:07 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=0B33787AB6EE3BB5FDB0C7C52E4E06A6 -- C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_11.2.9600.16428_en-us_74ba04defa813a61\iexplore.exe.mui
[2013/11/26 02:13:07 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=0B33787AB6EE3BB5FDB0C7C52E4E06A6 -- C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_11.2.9600.16428_en-us_7f0eaf312ee1fc5c\iexplore.exe.mui
[2013/03/18 08:25:28 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 -- C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2013/03/18 08:25:28 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F -- C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/03/18 08:32:46 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 -- C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/03/18 08:32:46 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 -- C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F -- C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 -- C:\Windows.old\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 -- C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
 
< MD5 for: IEXPLORE.EXE-908C99F8.PF  >
[2013/03/18 02:01:59 | 000,266,684 | ---- | M] () MD5=4132822B200C9ECF7D968F14EB99D564 -- C:\Windows.old\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf
 
< MD5 for: SERVICES  >
[2009/06/10 17:39:37 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows.old\Windows\System32\drivers\etc\services
[2009/06/10 17:39:37 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
[2009/06/10 17:00:26 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
 
< MD5 for: SERVICES.EXE  >
[2009/07/13 21:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009/07/13 21:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows.old\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
 
< MD5 for: SERVICES.EXE.MUI  >
[2011/04/11 22:15:38 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 -- C:\Windows.old\Windows\System32\en-US\services.exe.mui
[2011/04/11 22:15:38 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui
[2011/04/12 04:17:17 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 -- C:\Windows\SysNative\en-US\services.exe.mui
[2011/04/12 04:17:17 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 -- C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
 
< MD5 for: SERVICES.LNK  >
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\ProgramData\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Windows.old\Users\All Users\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
 
< MD5 for: SERVICES.MOF  >
[2009/06/10 17:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows.old\Windows\System32\wbem\services.mof
[2009/06/10 17:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof
[2009/06/10 16:44:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
 
< MD5 for: SERVICES.MSC  >
[2011/04/11 22:15:37 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows.old\Windows\System32\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows.old\Windows\System32\services.msc
[2011/04/11 22:15:37 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
[2011/04/12 04:17:16 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysNative\services.msc
[2011/04/12 04:17:18 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\services.msc
[2011/04/12 04:17:16 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2011/04/12 04:17:18 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
 
< MD5 for: SERVICES.PTXML  >
[2009/07/13 16:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows.old\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 16:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
 
< MD5 for: WINLOGON.ADML  >
[2011/04/11 22:15:49 | 000,008,013 | ---- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml
[2011/04/12 04:17:31 | 000,008,013 | ---- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
 
< MD5 for: WINLOGON.ADMX  >
[2009/06/10 17:43:18 | 000,005,237 | ---- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx
[2009/06/10 17:04:41 | 000,005,237 | ---- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
 
< MD5 for: WINLOGON.EXE  >
[2014/05/12 07:24:30 | 000,750,392 | ---- | M] (MalwareBytes) MD5=09882E8EDD1144E6EF1AF6D1F98305EE -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
[2010/11/20 23:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2014/03/04 07:08:14 | 000,455,680 | ---- | M] (Microsoft Corporation) MD5=6CE2AE073BD21C542FC2C707CAE944CC -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22616_none_ce748d1d04acf24f\winlogon.exe
[2010/11/20 17:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows.old\Windows\System32\winlogon.exe
[2010/11/20 17:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2014/03/04 05:43:50 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=88AB9B72B4BF3963A0DE0820B4B0B06C -- C:\Windows\SysNative\winlogon.exe
[2014/03/04 05:43:50 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=88AB9B72B4BF3963A0DE0820B4B0B06C -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18409_none_cdf8bf35eb848572\winlogon.exe
 
< MD5 for: WINLOGON.EXE.MUI  >
[2011/04/12 04:17:16 | 000,023,040 | ---- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F -- C:\Windows\SysNative\en-US\winlogon.exe.mui
[2011/04/12 04:17:16 | 000,023,040 | ---- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2011/04/11 22:15:37 | 000,023,040 | ---- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 -- C:\Windows.old\Windows\System32\en-US\winlogon.exe.mui
[2011/04/11 22:15:37 | 000,023,040 | ---- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui
 
< MD5 for: WINLOGON.MFL  >
[2011/04/11 22:15:38 | 000,001,080 | ---- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A -- C:\Windows.old\Windows\System32\wbem\en-US\winlogon.mfl
[2011/04/11 22:15:38 | 000,001,080 | ---- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl
[2011/04/12 04:17:17 | 000,001,080 | ---- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A -- C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2011/04/12 04:17:17 | 000,001,080 | ---- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
 
< MD5 for: WINLOGON.MOF  >
[2009/07/13 16:37:34 | 000,003,192 | ---- | M] () MD5=DF722B96F32A61783BC310FACF10240B -- C:\Windows.old\Windows\System32\wbem\winlogon.mof
[2009/07/13 16:37:34 | 000,003,192 | ---- | M] () MD5=DF722B96F32A61783BC310FACF10240B -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | ---- | M] () MD5=DF722B96F32A61783BC310FACF10240B -- C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | ---- | M] () MD5=DF722B96F32A61783BC310FACF10240B -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
 
< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2013/05/30 00:26:13 | 000,000,177 | ---- | M] () -- C:\BMSetup.log
[2009/06/10 17:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2013/06/04 23:20:20 | 000,112,232 | ---- | M] () -- C:\GDIPFONTCACHEV1.DAT
[2014/08/05 22:13:16 | 522,338,303 | -HS- | M] () -- C:\hiberfil.sys
[2013/04/02 23:05:59 | 000,558,760 | ---- | M] (Microsoft Corporation) -- C:\MS Office.exe
[2014/07/16 21:31:01 | 000,262,144 | ---- | M] () -- C:\ntuser.dat
[2014/07/16 21:32:32 | 000,005,120 | -HS- | M] () -- C:\ntuser.dat.LOG1
[2014/07/16 21:31:01 | 000,000,000 | -HS- | M] () -- C:\ntuser.dat.LOG2
[2014/07/16 21:32:32 | 000,065,536 | -HS- | M] () -- C:\ntuser.dat{318376ea-0d52-11e4-9fe3-e757a8bedef7}.TM.blf
[2014/07/16 21:32:32 | 000,524,288 | -HS- | M] () -- C:\ntuser.dat{318376ea-0d52-11e4-9fe3-e757a8bedef7}.TMContainer00000000000000000001.regtrans-ms
[2014/07/16 21:32:32 | 000,524,288 | -HS- | M] () -- C:\ntuser.dat{318376ea-0d52-11e4-9fe3-e757a8bedef7}.TMContainer00000000000000000002.regtrans-ms
[2014/07/16 21:31:01 | 000,065,536 | -HS- | M] () -- C:\ntuser.dat{35f600f8-0d4b-11e4-966c-f2f101a49df7}.TM.blf
[2014/07/16 21:31:01 | 000,524,288 | -HS- | M] () -- C:\ntuser.dat{35f600f8-0d4b-11e4-966c-f2f101a49df7}.TMContainer00000000000000000001.regtrans-ms
[2014/07/16 21:31:01 | 000,524,288 | -HS- | M] () -- C:\ntuser.dat{35f600f8-0d4b-11e4-966c-f2f101a49df7}.TMContainer00000000000000000002.regtrans-ms
[2014/08/05 22:13:17 | 2128,109,567 | -HS- | M] () -- C:\pagefile.sys
 
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
 
< %systemroot%\Fonts\*.dll >
 
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
 
< %systemroot%\Fonts\*.ini2 >
 
< %systemroot%\Fonts\*.exe >
 
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
 
< %systemroot%\REPAIR\*.bak1 >
 
< %systemroot%\REPAIR\*.ini >
 
< %systemroot%\system32\*.jpg >
 
< %systemroot%\*.jpg >
 
< %systemroot%\*.png >
 
< %systemroot%\*.scr >
 
< %systemroot%\*._sy >
 
< %APPDATA%\Adobe\Update\*.* >
 
< %ALLUSERSPROFILE%\Favorites\*.* >
 
< %APPDATA%\Microsoft\*.* >
[2014/01/01 22:55:49 | 000,001,702 | -HS- | M] () -- F:\Users\Temujin\AppData\Roaming\Microsoft\LastFlashConfig.wfc
 
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
 
< %APPDATA%\Update\*.* >
 
< %systemroot%\*. /mp /s >
 
< dir "%systemdrive%\*" /S /A:L /C >
 Volume in drive C has no label.
 Volume Serial Number is 82A8-7198
 Directory of C:\

    Advertisements

Register to Remove


#2 Temujin

Temujin

    Authentic Member

  • Authentic Member
  • PipPip
  • 30 posts

Posted 05 August 2014 - 09:37 PM

Part II

 

------------------------

07/14/2009  01:08 AM    <JUNCTION>     Documents and Settings [C:\Users]
               0 File(s)              0 bytes
 Directory of C:\ProgramData
07/14/2009  01:08 AM    <JUNCTION>     Application Data [C:\ProgramData]
07/14/2009  01:08 AM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/14/2009  01:08 AM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/14/2009  01:08 AM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/14/2009  01:08 AM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  01:08 AM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\ProgramData\Symantec\Symantec Endpoint Protection
03/18/2013  11:28 PM    <JUNCTION>     CurrentVersion [\??\C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105]
               0 File(s)              0 bytes
 Directory of C:\Users
07/14/2009  01:08 AM    <SYMLINKD>     All Users [C:\ProgramData]
07/14/2009  01:08 AM    <JUNCTION>     Default User [C:\Users\Default]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users
07/14/2009  01:08 AM    <JUNCTION>     Application Data [C:\ProgramData]
07/14/2009  01:08 AM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/14/2009  01:08 AM    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/14/2009  01:08 AM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/14/2009  01:08 AM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  01:08 AM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users\Symantec\Symantec Endpoint Protection
03/18/2013  11:28 PM    <JUNCTION>     CurrentVersion [\??\C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105]
               0 File(s)              0 bytes
 Directory of C:\Users\Default
07/14/2009  01:08 AM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009  01:08 AM    <JUNCTION>     Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009  01:08 AM    <JUNCTION>     Local Settings [C:\Users\Default\AppData\Local]
07/14/2009  01:08 AM    <JUNCTION>     My Documents [C:\Users\Default\Documents]
07/14/2009  01:08 AM    <JUNCTION>     NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009  01:08 AM    <JUNCTION>     PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009  01:08 AM    <JUNCTION>     Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009  01:08 AM    <JUNCTION>     SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009  01:08 AM    <JUNCTION>     Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009  01:08 AM    <JUNCTION>     Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local
07/14/2009  01:08 AM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/14/2009  01:08 AM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  01:08 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Documents
07/14/2009  01:08 AM    <JUNCTION>     My Music [C:\Users\Default\Music]
07/14/2009  01:08 AM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
07/14/2009  01:08 AM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Public\Documents
07/14/2009  01:08 AM    <JUNCTION>     My Music [C:\Users\Public\Music]
07/14/2009  01:08 AM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/14/2009  01:08 AM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old
07/14/2009  12:53 AM    <JUNCTION>     Documents and Settings [C:\Windows.old\Users]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings
07/14/2009  12:53 AM    <SYMLINKD>     All Users [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Default User [C:\Windows.old\Users\Default]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [.]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [.]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [.]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [.]
07/14/2009  12:53 AM    <JUNCTION>     Templates [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\All Users\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Roaming]
07/14/2009  12:53 AM    <JUNCTION>     Cookies [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009  12:53 AM    <JUNCTION>     Local Settings [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     My Documents [C:\Windows.old\Users\Default\Documents]
07/14/2009  12:53 AM    <JUNCTION>     NetHood [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009  12:53 AM    <JUNCTION>     PrintHood [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009  12:53 AM    <JUNCTION>     Recent [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009  12:53 AM    <JUNCTION>     SendTo [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\AppData\Local
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\AppData\Local\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\AppData\Local\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [.]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Default\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Default\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Local Settings
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Local Settings\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Local Settings\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [.]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default\My Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Default\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Default\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Roaming]
07/14/2009  12:53 AM    <JUNCTION>     Cookies [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009  12:53 AM    <JUNCTION>     Local Settings [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     My Documents [C:\Windows.old\Users\Default\Documents]
07/14/2009  12:53 AM    <JUNCTION>     NetHood [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009  12:53 AM    <JUNCTION>     PrintHood [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009  12:53 AM    <JUNCTION>     Recent [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009  12:53 AM    <JUNCTION>     SendTo [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\AppData\Local
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\AppData\Local\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\AppData\Local\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [.]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Default\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Default\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Local Settings
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Local Settings\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Local Settings\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [.]
07/14/2009  12:53 AM    <JUNCTION>     History [.]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Default User\My Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Default\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Default\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Public\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Roaming]
03/18/2013  01:44 AM    <JUNCTION>     Cookies [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\Cookies]
03/18/2013  01:44 AM    <JUNCTION>     Local Settings [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     My Documents [C:\Windows.old\Users\Temujin\Documents]
03/18/2013  01:44 AM    <JUNCTION>     NetHood [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
03/18/2013  01:44 AM    <JUNCTION>     PrintHood [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
03/18/2013  01:44 AM    <JUNCTION>     Recent [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\Recent]
03/18/2013  01:44 AM    <JUNCTION>     SendTo [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\SendTo]
03/18/2013  01:44 AM    <JUNCTION>     Start Menu [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\Start Menu]
03/18/2013  01:44 AM    <JUNCTION>     Templates [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\AppData\Local
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\AppData\Local\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\AppData\Local\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\AppData\Local\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [.]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Documents
03/18/2013  01:44 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Temujin\Music]
03/18/2013  01:44 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Temujin\Pictures]
03/18/2013  01:44 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Temujin\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Local Settings
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Local Settings\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Local Settings\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Local Settings\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [.]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Documents and Settings\Temujin\My Documents
03/18/2013  01:44 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Temujin\Music]
03/18/2013  01:44 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Temujin\Pictures]
03/18/2013  01:44 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Temujin\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [.]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\ProgramData\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users
07/14/2009  12:53 AM    <SYMLINKD>     All Users [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Default User [C:\Windows.old\Users\Default]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\ProgramData]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [C:\Windows.old\Users\Public\Documents]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [C:\Windows.old\Users\Public\Favorites]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [.]
07/14/2009  12:53 AM    <JUNCTION>     Desktop [C:\Windows.old\Users\Public\Desktop]
07/14/2009  12:53 AM    <JUNCTION>     Documents [.]
07/14/2009  12:53 AM    <JUNCTION>     Favorites [.]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [.]
07/14/2009  12:53 AM    <JUNCTION>     Templates [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Application Data\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\All Users\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Roaming]
07/14/2009  12:53 AM    <JUNCTION>     Cookies [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009  12:53 AM    <JUNCTION>     Local Settings [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     My Documents [C:\Windows.old\Users\Default\Documents]
07/14/2009  12:53 AM    <JUNCTION>     NetHood [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009  12:53 AM    <JUNCTION>     PrintHood [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009  12:53 AM    <JUNCTION>     Recent [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009  12:53 AM    <JUNCTION>     SendTo [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [.]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Default\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Default\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [.]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default\My Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Default\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Default\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Roaming]
07/14/2009  12:53 AM    <JUNCTION>     Cookies [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009  12:53 AM    <JUNCTION>     Local Settings [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     My Documents [C:\Windows.old\Users\Default\Documents]
07/14/2009  12:53 AM    <JUNCTION>     NetHood [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009  12:53 AM    <JUNCTION>     PrintHood [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009  12:53 AM    <JUNCTION>     Recent [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009  12:53 AM    <JUNCTION>     SendTo [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009  12:53 AM    <JUNCTION>     Start Menu [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009  12:53 AM    <JUNCTION>     Templates [C:\Windows.old\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [.]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Default\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Default\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Default\AppData\Local]
07/14/2009  12:53 AM    <JUNCTION>     History [C:\Windows.old\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/14/2009  12:53 AM    <JUNCTION>     Application Data [.]
07/14/2009  12:53 AM    <JUNCTION>     History [.]
07/14/2009  12:53 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Default User\My Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Default\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Default\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Public\Documents
07/14/2009  12:53 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Public\Music]
07/14/2009  12:53 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Public\Pictures]
07/14/2009  12:53 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Roaming]
03/18/2013  01:44 AM    <JUNCTION>     Cookies [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\Cookies]
03/18/2013  01:44 AM    <JUNCTION>     Local Settings [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     My Documents [C:\Windows.old\Users\Temujin\Documents]
03/18/2013  01:44 AM    <JUNCTION>     NetHood [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
03/18/2013  01:44 AM    <JUNCTION>     PrintHood [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
03/18/2013  01:44 AM    <JUNCTION>     Recent [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\Recent]
03/18/2013  01:44 AM    <JUNCTION>     SendTo [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\SendTo]
03/18/2013  01:44 AM    <JUNCTION>     Start Menu [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\Start Menu]
03/18/2013  01:44 AM    <JUNCTION>     Templates [C:\Windows.old\Users\Temujin\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [.]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Documents
03/18/2013  01:44 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Temujin\Music]
03/18/2013  01:44 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Temujin\Pictures]
03/18/2013  01:44 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Temujin\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [C:\Windows.old\Users\Temujin\AppData\Local]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
03/18/2013  01:44 AM    <JUNCTION>     Application Data [.]
03/18/2013  01:44 AM    <JUNCTION>     History [C:\Windows.old\Users\Temujin\AppData\Local\Microsoft\Windows\History]
03/18/2013  01:44 AM    <JUNCTION>     Temporary Internet Files [.]
               0 File(s)              0 bytes
 Directory of C:\Windows.old\Users\Temujin\My Documents
03/18/2013  01:44 AM    <JUNCTION>     My Music [C:\Windows.old\Users\Temujin\Music]
03/18/2013  01:44 AM    <JUNCTION>     My Pictures [C:\Windows.old\Users\Temujin\Pictures]
03/18/2013  01:44 AM    <JUNCTION>     My Videos [C:\Windows.old\Users\Temujin\Videos]
               0 File(s)              0 bytes
     Total Files Listed:
               0 File(s)              0 bytes
             953 Dir(s)  14,546,907,136 bytes free
 
< %systemroot%\System32\config\*.sav >
 
< %PROGRAMFILES%\bak. /s >
 
< %systemroot%\system32\bak. /s >
 
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
 
< %systemroot%\system32\config\systemprofile\*.dat /x >
 
< %systemroot%\*.config >
 
< %systemroot%\system32\*.db >
 
< %PROGRAMFILES%\Internet Explorer\*.dat >
 
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/03/18 02:32:01 | 000,000,221 | -HS- | M] () -- F:\Users\Temujin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
 
< %USERPROFILE%\Desktop\*.exe >
 
< %PROGRAMFILES%\Common Files\*.* >
 
< %systemroot%\*.src >
 
< %systemroot%\install\*.* >
 
< %systemroot%\system32\DLL\*.* >
 
< %systemroot%\system32\HelpFiles\*.* >
 
< %systemroot%\system32\rundll\*.* >
 
< %systemroot%\winn32\*.* >
 
< %systemroot%\Java\*.* >
 
< %systemroot%\system32\test\*.* >
 
< %systemroot%\system32\Rundll32\*.* >
 
< %systemroot%\AppPatch\Custom\*.* >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
 
< End of report >


#3 Temujin

Temujin

    Authentic Member

  • Authentic Member
  • PipPip
  • 30 posts

Posted 05 August 2014 - 09:38 PM

Part III

 

------------------------

 

-----------------Extras.txt
 
 
OTL Extras logfile created on: 8/5/2014 10:26:15 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = F:\Users\Temujin\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17207)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
5.98 Gb Total Physical Memory | 4.41 Gb Available Physical Memory | 73.66% Memory free
11.96 Gb Paging File | 10.52 Gb Available in Paging File | 87.95% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 59.53 Gb Total Space | 13.59 Gb Free Space | 22.82% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 350.19 Gb Free Space | 75.19% Space Free | Partition Type: NTFS
Drive G: | 931.51 Gb Total Space | 887.86 Gb Free Space | 95.31% Space Free | Partition Type: NTFS
Drive H: | 1.86 Gb Total Space | 1.16 Gb Free Space | 62.53% Space Free | Partition Type: FAT
Drive I: | 596.17 Gb Total Space | 303.84 Gb Free Space | 50.97% Space Free | Partition Type: NTFS
 
Computer Name: TEMUJIN-PC | User Name: Temujin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "F:\Program Files\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "F:\Program Files\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "F:\Program Files\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "F:\Program Files\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02116438-1025-44A3-BEFD-35B10A23521C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{02C4E448-A5DD-4D03-B2A8-ED8821856ADA}" = lport=445 | protocol=6 | dir=in | app=system | 
"{03693FCA-44A2-4890-AD31-FA9D92C9630F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{0A81A1D4-A9CB-47FC-B5DF-A189B573317E}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{0C27D97C-E012-46A4-AB06-2DC0C7B6FA67}" = rport=138 | protocol=17 | dir=out | app=system | 
"{0C6CB1C0-D2C5-416D-BBE5-6C5B4AD3E0AF}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{18748B0A-346B-4D62-8E2A-8B9CD1205A52}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\outlook.exe | 
"{311F1AB2-0566-4E66-9899-3912934E40EC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{3525498A-E0DE-4EF5-A8AD-6388B9129C80}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{3D63E9B3-3653-440D-8A36-C40883BC0B69}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{4FF04632-7D91-4E94-AC05-E12E1E268742}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{502B5494-F0C3-4B0F-97D9-E7A780EB103D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{57157127-ADF8-4037-A37B-FF06DC0FF432}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{632D165B-80EA-4DDE-B9F8-19E0B26A9359}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{69053DD5-FFF8-458B-B90C-0D419A9E9509}" = rport=445 | protocol=6 | dir=out | app=system | 
"{7ADC108C-D488-4D3E-9C74-95C31FDC7842}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{7EB48649-0C56-41EE-A3AE-FAC957DADBBA}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{829A3D09-AC50-4D04-9BA7-BE2649E94D4C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{8EB2F8D6-65DF-46BC-B2C3-C58C16FD9BA6}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{8FD09874-B338-4C8D-B45A-E5BD5DCB5DDF}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{9350FDF8-93C5-499F-911D-06836E96B588}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | 
"{A048EFA8-7156-4178-8AFB-98E74DADD123}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{B008A031-07EB-45F5-B3CC-B345435A09E4}" = lport=139 | protocol=6 | dir=in | app=system | 
"{B152A8E2-2F83-4DCA-B4C4-033394D8B3A0}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{B43B9D99-7EC3-4F9F-8C50-73B809BF5398}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{BE1BF71E-DCC3-4C6D-8C6D-3B68D9B9AE80}" = lport=138 | protocol=17 | dir=in | app=system | 
"{C5888865-7B4A-479F-8B99-D20877C0DDC9}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{C5F199EB-EAE6-49BB-BEB9-65B750712A84}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{CFDB41C2-F9ED-4BCE-BACE-DEA3DD49E74D}" = rport=137 | protocol=17 | dir=out | app=system | 
"{D030BA1A-84E3-47F4-B757-AB269F8F026A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{D1932524-0544-4834-A3BA-4326D0C1E49B}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | 
"{DFC68817-281C-48CD-BF1A-E9717C71D793}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{E71EC1B3-145A-4AFA-A02C-F3002A2B9747}" = lport=137 | protocol=17 | dir=in | app=system | 
"{ECB9631F-2EB8-4981-A876-798E23E3795B}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | 
"{ECC800D9-E5AA-4800-9E57-F831E5BFE94A}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{F444F39B-3953-47C7-AE83-5F9595A6CBEA}" = rport=139 | protocol=6 | dir=out | app=system | 
"{FFC5899C-A4A9-4D9F-8601-5FDC549428DF}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0201992D-1E73-44CC-A76B-D9CE86AF703E}" = protocol=6 | dir=in | app=i:\games\origin\downloads\battlefield 4 beta\bf4.exe | 
"{06374451-F273-4A3F-B925-B3CA58F4BFE6}" = dir=in | app=f:\program files\activepresenter\rlactivator.exe | 
"{0637F23F-8E35-40E1-9A10-5300E8CD975A}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{0F9C1201-B82E-4ECA-BD79-B3C4B2A8F1C6}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{120755EE-FBC1-4E12-BAF1-C1A5579E1D52}" = protocol=17 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\12.1.2015.2015.105\bin64\snac64.exe | 
"{18B2A5D9-8FEB-4C6A-A56E-59729E73AB2B}" = protocol=6 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\12.1.2015.2015.105\bin64\snac64.exe | 
"{19991194-FFE3-4831-911B-81EC777D1896}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{1B0A1A26-7137-483D-A0AE-B474BECAF01D}" = dir=in | app=f:\users\temujin\appdata\local\facebook\video\skype\facebookvideocalling.exe | 
"{1C3D9B8B-055F-41D3-A5F2-6C3F0AB976E2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{1D4AFFF3-68C6-4A64-81DF-D2B4A64ABE99}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{1FA0CF9A-CE8A-42D7-A758-A6B9D541D7D9}" = protocol=17 | dir=in | app=i:\games\steam\steam.exe | 
"{22F57997-B703-42FE-9C80-F73126FCE919}" = protocol=6 | dir=in | app=i:\games\steam\steamapps\common\war of the roses\run_game.exe | 
"{2822172F-20BB-4AC1-AEFB-F66AFC8B798B}" = protocol=6 | dir=in | app=c:\program files\microsoft office 15\root\office15\ucmapi.exe | 
"{291CDF3E-BFA8-4929-8A35-AD0F98F801E5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{2B96E887-6E41-4479-9E53-0055A95D421E}" = protocol=6 | dir=out | app=system | 
"{38C2289A-63BB-41F0-8FAB-AD829B5290A0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{3A3F2DEF-05BF-4D22-93D5-B76BFCD62DA3}" = dir=in | app=f:\program files\activepresenter\rlupdater.exe | 
"{3B248A93-63D0-4CCF-909A-6C4DB25FDCC3}" = protocol=6 | dir=in | app=i:\games\origin\downloads\battlefield 3\bf3.exe | 
"{3C6B83A8-22DB-4158-B85D-BDDCE8B55BFC}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 1000 j110 series\bin\usbsetup.exe | 
"{3D4F5577-0814-42C7-9A8B-9ECF344E3A8C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{3F41279F-759B-47C7-A964-9E31E16DED8F}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | 
"{40461D34-970D-4F36-84FC-27FAF38925FC}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 1000 j110 series\bin\usbsetup.exe | 
"{40780881-DD3F-45DE-B303-AB06D8E6EE1C}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{40BB58C5-4956-4167-98E9-586F48F138AA}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{41E8ACD5-E302-436F-9849-973905B661F6}" = dir=out | app=f:\program files\activepresenter\rlupdater.exe | 
"{4B2C70FB-7F93-4FFF-8AFF-A82496C19999}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | 
"{4F2C3FC5-BD18-42F5-8DEA-960D65EB0BA6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{573F8D60-D107-4510-98EF-734618CE2114}" = dir=out | app=f:\program files\activepresenter\rlupdater.exe | 
"{588E15F1-AAA5-4E11-8493-0A7AAE00382A}" = protocol=17 | dir=in | app=i:\games\origin\downloads\battlefield 3\bf3.exe | 
"{6169D414-CCAB-4926-B73C-FAAF7B4056D9}" = dir=out | app=f:\program files\activepresenter\rlactivator.exe | 
"{64607CAF-D28E-438E-B51A-FFD11E1DC18F}" = dir=out | app=f:\program files\activepresenter\activepresenter.exe | 
"{68C715F7-3C3D-4D39-BFCE-B053B136EE65}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{696F6F6D-24C7-4369-A6D0-F3176AE0B80D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{7345E404-07FB-485E-B6C2-B1EF39A641E3}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{75DE11B8-4A0A-4461-AC79-9E50B0B1427E}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | 
"{7AC0EEC1-6454-48A0-902B-4EA2E35763D0}" = dir=out | app=f:\program files\activepresenter\rlactivator.exe | 
"{7B8AD027-EC12-43DD-BC35-9B27D1D4E677}" = protocol=6 | dir=in | app=c:\program files\microsoft office 15\root\office15\lync.exe | 
"{7F1A0440-C715-482A-9DBE-DC588305718F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{80CC069F-AAEE-4F7C-96E7-90F5C045A5C3}" = protocol=17 | dir=in | app=i:\games\steam\steamapps\common\psychonauts\psychonauts.exe | 
"{84F61718-ABFA-47C0-BB26-9D6C4F318005}" = dir=in | app=f:\program files\activepresenter\activepresenter.exe | 
"{8913843D-20F0-4982-9427-47F2F457D3E5}" = dir=out | app=f:\program files\activepresenter\rlhtmlrenderer.exe | 
"{8E43F1DF-7D03-4984-9ECD-EE4DBCD127B4}" = dir=out | app=f:\program files\activepresenter\rlhtmlrenderer.exe | 
"{8F24711D-E203-4256-881C-BEC8AD9C8F62}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{96D89CB1-1DC5-485A-82CF-378097381745}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | 
"{9EDF4D89-259D-4119-83A0-17FD86EDC13F}" = protocol=17 | dir=in | app=f:\program files\messenger\yahoomessenger.exe | 
"{A0DF5C26-36B8-41A9-AD74-EDAFDF416E8E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{A3FFE9D7-C1AC-49B9-873F-2C62EAC51F52}" = dir=in | app=f:\program files\activepresenter\rlhtmlrenderer.exe | 
"{A8ED371C-1F3E-4387-AE8E-CF704D1BDEDA}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{AC6ECC14-76F4-446F-8D69-BDDDDE3A3FE4}" = protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\ucmapi.exe | 
"{AEBA5250-B1C7-4F47-A638-C6861A6828FB}" = protocol=17 | dir=in | app=i:\games\origin\downloads\battlefield 4 beta\bf4.exe | 
"{B0730C65-EE04-43F9-98CC-1C6DEFEB2175}" = dir=in | app=f:\program files\activepresenter\rlhtmlrenderer.exe | 
"{B15A8F50-81F7-4035-B24C-A7D21B364AF7}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | 
"{B5214EC3-2549-463D-ACD0-DCFE047D291B}" = protocol=6 | dir=in | app=i:\games\steam\steamapps\common\war of the roses\run_game.exe | 
"{B8033DF5-DB8C-4FB9-A800-9B173438F45B}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{B9CCA8E0-E7F8-47BD-8416-824277CF786A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{C20B44CA-403D-4791-898E-D58165BF5A99}" = dir=in | app=f:\users\temujin\appdata\local\viber\viber.exe | 
"{C4D3E5EF-CDE8-4DA5-AFBF-9689663770F9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{C4EA047C-9FF7-41D4-8E26-CF22776DB227}" = protocol=17 | dir=in | app=i:\games\steam\steamapps\common\war of the roses\run_game.exe | 
"{CC69F19D-38E4-410F-8861-3F75AAFD21BF}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{D395687F-2C45-47E2-8EA8-D6891837AD7E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{D50D499F-3883-4449-ACA0-6621FB8D1255}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{D6911FAE-DFE6-47E0-BB07-63D4E78BF6F1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{D74C924E-8C2D-4FA7-96BB-F801DD8A6E56}" = dir=in | app=f:\program files\activepresenter\rlactivator.exe | 
"{D7D20157-0CFC-46EE-AA17-4E186E7513AE}" = protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\lync.exe | 
"{D8178421-1DC0-4F43-A73C-72079F7E9942}" = protocol=6 | dir=in | app=f:\program files\messenger\yahoomessenger.exe | 
"{DCA4EE15-B251-4138-9F73-4BCA6E057F54}" = protocol=6 | dir=in | app=i:\games\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe | 
"{DFF59CA4-DD71-4B27-A5A7-87C05AB49C5C}" = protocol=6 | dir=in | app=f:\users\temujin\appdata\roaming\dropbox\bin\dropbox.exe | 
"{E16255B3-7E21-4FBA-A030-A100DB9E94D0}" = protocol=17 | dir=in | app=i:\games\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe | 
"{EC48F8D9-C9F7-4205-BB3A-20F7D17D6467}" = dir=in | app=f:\program files\activepresenter\rlupdater.exe | 
"{ECEC7C8C-FFDF-409E-A014-170B70CE889B}" = protocol=6 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\12.1.2015.2015.105\bin64\smc.exe | 
"{F09C6314-0B25-42AC-B825-2B8AACC61506}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{F4E7763B-2F73-4E0A-BC45-251693F41C08}" = protocol=6 | dir=in | app=i:\games\steam\steamapps\common\psychonauts\psychonauts.exe | 
"{F5AD94D1-8C10-4C5A-8B48-6896132EDEC7}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{F8294EC3-BEC2-4E63-A10A-5E8ABA71A64C}" = protocol=17 | dir=in | app=f:\users\temujin\appdata\roaming\dropbox\bin\dropbox.exe | 
"{F838F9A6-2700-4C16-995A-8FED5389FDA3}" = protocol=17 | dir=in | app=i:\games\steam\steamapps\common\war of the roses\run_game.exe | 
"{FA6DB520-BACE-4F89-A42B-AEFC91269691}" = dir=out | app=f:\program files\activepresenter\activepresenter.exe | 
"{FC6E6710-0CCA-4BE8-8C31-F3F3127A3F3C}" = protocol=6 | dir=in | app=i:\games\steam\steam.exe | 
"{FDA04370-AAE6-491C-A36B-4CF37C618158}" = protocol=17 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\12.1.2015.2015.105\bin64\smc.exe | 
"{FEBF5716-F62B-4860-8EC1-3FDCC112E64A}" = dir=in | app=f:\program files\activepresenter\activepresenter.exe | 
"TCP Query User{2C726077-2BFC-4558-BDA4-4D93D82DDE47}I:\games\origin\downloads\battlefield 3\bf3.exe" = protocol=6 | dir=in | app=i:\games\origin\downloads\battlefield 3\bf3.exe | 
"TCP Query User{C6E18502-4EC1-41A4-8AD7-37EAC8DC51DA}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe | 
"UDP Query User{9F63D167-0CA0-492F-9961-3F44DA8BC32D}I:\games\origin\downloads\battlefield 3\bf3.exe" = protocol=17 | dir=in | app=i:\games\origin\downloads\battlefield 3\bf3.exe | 
"UDP Query User{FBC2C303-5AE3-41D3-A85E-90B2AF98D646}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E5159B4-A519-41EF-80EF-AD58371515DF}" = Eraser 6.0.10.2620
"{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610
"{7AB6F8D7-7804-4662-BE8C-1AFCCD602D9F}" = Microsoft Mouse and Keyboard Center
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{883B114D-BD3E-498F-9DAD-5E4A8E1C43BA}" = HP Deskjet 1000 J110 series Basic Device Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90150000-008F-0000-1000-0000000FF1CE}" = Office 15 Click-to-Run Licensing Component
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{A9D20DF9-BF4C-40EE-BC98-1F861347E2CF}" = Cisco Systems VPN Client 5.0.07.0240
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 331.65
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 331.65
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 331.65
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.8.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 331.65
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.13.0725
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 10.11.15
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamC" = GeForce Experience NvStream Client Components
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.26.4
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 10.11.15
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.19
"{C2103AF2-E66C-446B-9791-9207840EC821}" = Symantec Endpoint Protection
"CCleaner" = CCleaner
"Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center
"ProPlusRetail - en-us" = Microsoft Office Professional Plus 2013 - en-us
"Speccy" = Speccy
"VLC media player" = VLC media player 2.0.6
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{2028646C-E143-4DB1-AE19-AA31CA90E103}" = HP Webcam User's Guide
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = MPC-HC 1.6.6.6957 (3975d54)
"{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 65
"{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1" = Samsung Magician
"{43FFE159-3199-4188-A1CD-629166AD1033}" = Nero 7 Ultra Edition
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}" = Google Earth
"{511CFE49-F318-4659-BC3F-73E9DBC3E2A8}" = ArcSoft Magic-i Visual Effects 2
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.16
"{7B5AA67E-FEA0-40BB-BAB5-CA56645A589C}" = NVIDIA PhysX
"{800B3855-2646-4707-B915-BDCC28F03D63}" = ArcSoft WebCam Companion 3
"{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}" = Facebook Video Calling 2.0.0.447
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90150000-008C-0000-0000-0000000FF1CE}" = Office 15 Click-to-Run Extensibility Component
"{90150000-008C-0409-0000-0000000FF1CE}" = Office 15 Click-to-Run Localization Component
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
"{A2A40277-D807-4754-95A3-2F294C2C51D3}_is1" = ActivePresenter
"{A50DE037-B5C0-4C8A-8049-B0C576B313D1}" = Google+ Auto Backup
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-F400-7760-100000000002}" = Adobe Acrobat 7.0 Professional - English, Français, Deutsch
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{CA634931-0CC3-4067-ABCC-7182E1DC23B7}" = HP Button Manager
"{CFAB3721-549D-4827-A4E8-7F90192114AB}" = Battlefield 4™ Beta
"{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}" = HP Deskjet 1000 J110 series Help
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Acrobat 7.0 Professional - English, Français, Deutsch - V" = Adobe Acrobat 7.1.0 Professional - English, Français, Deutsch
"Adobe Flash Player ActiveX" = Adobe Flash Player 14 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 14 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Battlelog Web Plugins" = Battlelog Web Plugins
"ESN Sonar-0.70.4" = ESN Sonar
"Google Chrome" = Google Chrome
"HandBrake" = HandBrake 0.9.9.1
"Logitech MouseWare" = Logitech MouseWare 9.10 
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.2.1012
"Mozilla Firefox 31.0 (x86 en-US)" = Mozilla Firefox 31.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Mp3tag" = Mp3tag v2.55a
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Origin" = Origin
"OSM" = JOSM 6891
"Picasa 3" = Picasa 3
"PunkBusterSvc" = PunkBuster Services
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"VLC media player" = VLC media player 2.0.6
"XviD4PSP5_is1" = XviD4PSP 5.10.330.0
"Yahoo! Messenger" = Yahoo! Messenger
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Screencast-O-Matic" = Screencast-O-Matic
"Viber" = Viber
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 3/13/2014 9:21:07 PM | Computer Name = Temujin-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 3/13/2014 11:57:47 PM | Computer Name = Temujin-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 3/14/2014 1:32:59 AM | Computer Name = Temujin-PC | Source = Application Error | ID = 1000
Description = Faulting application name: MP3GainGUI.exe, version: 1.2.0.5, time 
stamp: 0x41e04681  Faulting module name: MSCOMCTL.OCX, version: 6.0.88.62, time stamp:
 0x39247822  Exception code: 0xc0000005  Fault offset: 0x00084a28  Faulting process id:
 0x171c  Faulting application start time: 0x01cf3f46d69b544e  Faulting application path:
 F:\Program Files\MP3Gain\MP3GainGUI.exe  Faulting module path: C:\Windows\SysWow64\MSCOMCTL.OCX
Report
 Id: 1a07e145-ab3a-11e3-bc99-d306614665f0
 
Error - 3/15/2014 1:19:07 PM | Computer Name = Temujin-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 3/15/2014 11:39:26 PM | Computer Name = Temujin-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 3/16/2014 12:28:22 PM | Computer Name = Temujin-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 3/16/2014 12:58:20 PM | Computer Name = Temujin-PC | Source = VSS | ID = 8193
Description = 
 
Error - 3/17/2014 2:19:20 AM | Computer Name = Temujin-PC | Source = Application Error | ID = 1000
Description = Faulting application name: MP3GainGUI.exe, version: 1.2.0.5, time 
stamp: 0x41e04681  Faulting module name: MSCOMCTL.OCX, version: 6.0.88.62, time stamp:
 0x39247822  Exception code: 0xc0000005  Fault offset: 0x00084a28  Faulting process id:
 0x14a0  Faulting application start time: 0x01cf41a8d09dcfc7  Faulting application path:
 F:\Program Files\MP3Gain\MP3GainGUI.exe  Faulting module path: C:\Windows\SysWow64\MSCOMCTL.OCX
Report
 Id: 12b8f89d-ad9c-11e3-94dc-baff2c19c2f6
 
Error - 3/17/2014 7:15:24 PM | Computer Name = Temujin-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 3/18/2014 1:37:09 AM | Computer Name = Temujin-PC | Source = Application Error | ID = 1000
Description = Faulting application name: MP3GainGUI.exe, version: 1.2.0.5, time 
stamp: 0x41e04681  Faulting module name: MSCOMCTL.OCX, version: 6.0.88.62, time stamp:
 0x39247822  Exception code: 0xc0000005  Fault offset: 0x00084a28  Faulting process id:
 0x16b0  Faulting application start time: 0x01cf426c12da2201  Faulting application path:
 F:\Program Files\MP3Gain\MP3GainGUI.exe  Faulting module path: C:\Windows\SysWow64\MSCOMCTL.OCX
Report
 Id: 58ed47d8-ae5f-11e3-8d75-a7efc43c0cf7
 
[ Media Center Events ]
Error - 7/14/2014 8:40:31 PM | Computer Name = Temujin-PC | Source = MCUpdate | ID = 0
Description = 8:40:31 PM - Error connecting to the internet.  8:40:31 PM -     Unable
 to contact server..  
 
Error - 7/14/2014 8:40:39 PM | Computer Name = Temujin-PC | Source = MCUpdate | ID = 0
Description = 8:40:36 PM - Error connecting to the internet.  8:40:36 PM -     Unable
 to contact server..  
 
[ Symantec Endpoint Protection Client Events ]
Error - 4/2/2013 9:56:15 PM | Computer Name = Temujin-PC | Source = Symantec Endpoint Protection Client | ID = 16711731
Description =       Security Risk Found!Tracking Cookies in File: Cookie:temujin@rubiconproject.com/
 by: Manual scan.  Action: Delete succeeded.  Action Description: The file was deleted
 successfully.
 
Error - 8/8/2013 11:50:44 AM | Computer Name = Temujin-PC | Source = Symantec Endpoint Protection Client | ID = 16711731
Description =       Security Risk Found!Packed.Generic.432 in File: F:\Users\Temujin\AppData\Local\Temp\xNv26nb8.zip.part>>hd_gallery.exe
 by: Scheduled scan.  Action: Cleaned by Deletion.  Action Description: The file
 was deleted successfully.
 
Error - 8/8/2013 11:50:44 AM | Computer Name = Temujin-PC | Source = Symantec Endpoint Protection Client | ID = 16711731
Description =       Security Risk Found!Packed.Generic.432 in File: F:\Users\Temujin\AppData\Local\Temp\xNv26nb8.zip.part
 by: Scheduled scan.  Action: Compressed file processing succeeded.  Action Description:
 The file was deleted successfully.
 
Error - 6/21/2014 4:42:21 PM | Computer Name = Temujin-PC | Source = Symantec Endpoint Protection Client | ID = 16711731
Description =       Security Risk Found!Trojan Horse in File: f:\$recycle.bin\s-1-5-21-2105342170-2719686501-3503371245-1000\$rgj94jv.exe
 by: Scheduled scan.  Action: Quarantine succeeded.  Action Description: The file
 was quarantined successfully.
 
Error - 7/16/2014 11:12:14 PM | Computer Name = Temujin-PC | Source = Symantec Endpoint Protection Client | ID = 16711731
Description =       Security Risk Found!Tracking Cookies in File: Cookie:temujin@ads.bridgetrack.com/
 by: Manual scan.  Action: Delete succeeded.  Action Description: The file was deleted
 successfully.
 
[ System Events ]
Error - 8/5/2014 9:11:24 PM | Computer Name = Temujin-PC | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\lmoufltr.sys has been blocked from loading
 due to incompatibility with this system. Please contact your software vendor for
 a compatible version of the driver.
 
Error - 8/5/2014 9:11:31 PM | Computer Name = Temujin-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
   i8042prt  lkbdfltr  lmoufltr
 
Error - 8/5/2014 9:33:06 PM | Computer Name = Temujin-PC | Source = nvlddmkm | ID = 11141134
Description = 
 
Error - 8/5/2014 10:09:58 PM | Computer Name = Temujin-PC | Source = DCOM | ID = 10010
Description = 
 
Error - 8/5/2014 10:13:14 PM | Computer Name = Temujin-PC | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\l8042prt.sys has been blocked from loading
 due to incompatibility with this system. Please contact your software vendor for
 a compatible version of the driver.
 
Error - 8/5/2014 10:13:14 PM | Computer Name = Temujin-PC | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\lsermous.sys has been blocked from loading
 due to incompatibility with this system. Please contact your software vendor for
 a compatible version of the driver.
 
Error - 8/5/2014 10:13:14 PM | Computer Name = Temujin-PC | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\lkbdfltr.sys has been blocked from loading
 due to incompatibility with this system. Please contact your software vendor for
 a compatible version of the driver.
 
Error - 8/5/2014 10:13:14 PM | Computer Name = Temujin-PC | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\lmoufltr.sys has been blocked from loading
 due to incompatibility with this system. Please contact your software vendor for
 a compatible version of the driver.
 
Error - 8/5/2014 10:13:21 PM | Computer Name = Temujin-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
   i8042prt  lkbdfltr  lmoufltr
 
Error - 8/5/2014 10:15:28 PM | Computer Name = Temujin-PC | Source = nvlddmkm | ID = 11141134
Description = 
 
 
< End of report >
 
 
----------------HiJackThis Log
 
 
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:41:01 PM, on 8/5/2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17207)
Boot mode: Normal
 
Running processes:
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
F:\Users\Temujin\Downloads\OTL.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
F:\Users\Temujin\Downloads\HiJackThis.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft..../?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft..../?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\ActiveX\AcroIEHelper.dll
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: Symantec Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\bin\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - F:\Program Files\NYU VPN\cvpnd.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - F:\Program Files\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Symantec Endpoint Protection (SepMasterService) - Symantec Corporation - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\snac64.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - F:\Program Files\HP Webcam\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
 
--
End of file - 12269 bytes
 
 
-----------------DDS.txt
 
 
.
DDS (Ver_11-03-05.01) - NTFS_AMD64  
Run by Temujin at 22:42:36.00 on Tue 08/05/2014
Internet Explorer: 9.11.9600.17207 BrowserJavaVersion: 10.65.2
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.6126.4152 [GMT -4:00]
.
AV: Symantec Endpoint Protection *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Symantec Endpoint Protection *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
F:\Program Files\NYU VPN\cvpnd.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k imgsvc
F:\Program Files\HP Webcam\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\Smc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskhost.exe
F:\Users\Temujin\Downloads\OTL.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
F:\Users\Temujin\Downloads\HiJackThis.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
F:\Users\Temujin\Desktop\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit=userinit.exe,
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - F:\Program Files\Adobe\ActiveX\AcroIEHelper.dll
BHO: Lync Browser Helper: {31d09ba0-12f5-4cce-be8a-2923e76605da} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
BHO: Symantec Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\bin\IPS\IPSBHO.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
BHO: Microsoft SkyDrive Pro Browser Helper: {d0498e0a-45b7-42ae-a9aa-aba463dbd3bf} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll
mRun: [<NO NAME>] 
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: Convert link target to Adobe PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - F:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\msosb.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
BHO-X64: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll
BHO-X64:     Lync Click to Call BHO - No File
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL
BHO-X64:     URLRedirectionBHO - No File
BHO-X64: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
mRun-x64: [IntelliPoint] "c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe"
mRun-x64: [NvBackend] "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
mRun-x64: [ShadowPlay] C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
.
================= FIREFOX ===================
.
FF - ProfilePath - F:\Users\Temujin\AppData\Roaming\Mozilla\Firefox\Profiles\i1fdowup.default\
FF - prefs.js: browser.search.selectedEngine - DuckDuckGo
FF - prefs.js: browser.startup.homepage - DuckDuckGo.com
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
FF - plugin: C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll
FF - plugin: F:\Program Files\Adobe\Acrobat\browser\nppdf32.dll
FF - plugin: F:\Program Files\Picasa3\npPicasa3.dll
FF - plugin: F:\Program Files\QuickTime\Plugins\npqtplugin.dll
FF - plugin: F:\Program Files\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: F:\Program Files\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: F:\Program Files\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: F:\Program Files\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: F:\Program Files\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: F:\Program Files\QuickTime\Plugins\npqtplugin7.dll
FF - plugin: F:\Program Files\VLC\npvlc.dll
FF - plugin: F:\Users\Temujin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x64\SymDS64.sys [2012-11-3 493216]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x64\SymEFA64.sys [2012-11-3 1133216]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\BASHDefs\20140718.013\BHDrvx64.sys [2014-7-30 1530160]
R1 ccSettings_{3771A34D-2132-48EA-A486-D62ECDF9D553};Symantec Endpoint Protection 12.1.2015.2015.105 Settings Manager;C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x64\ccSetx64.sys [2012-11-3 168096]
R1 IDSVia64;IDSVia64;C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\IPSDefs\20140731.012\IDSviA64.sys [2014-8-1 525016]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x64\Ironx64.sys [2012-11-3 224416]
R1 SYMNETS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\SEP\0C0107DF\07DF.105\x64\symnets.sys [2012-11-3 432800]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-4-20 203776]
R2 ClickToRunSvc;Microsoft Office ClickToRun Service;C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe [2014-3-18 2356912]
R2 NvNetworkService;NVIDIA Network Service;C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-3-10 1494304]
R2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-10-8 15129376]
R2 SepMasterService;Symantec Endpoint Protection;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe [2012-11-3 143928]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-10-23 414496]
R2 uCamMonitor;CamMonitor;F:\Program Files\HP Webcam\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2013-6-4 104960]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;C:\Windows\System32\drivers\ArcSoftKsUFilter.sys [2013-5-30 19968]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2014-7-16 142128]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2013-10-8 196384]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\Windows\System32\drivers\nvvad64v.sys [2014-3-10 39200]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-3-18 116648]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-3-18 262320]
S3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2011-4-20 9319936]
S3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2011-4-20 306176]
S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;C:\Windows\System32\drivers\BVRPMPR5a64.SYS [2013-5-30 35840]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-3-18 116648]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-7-9 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-3-18 119408]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent;C:\Windows\System32\drivers\nmwcdnsux64.sys [2011-8-17 171008]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2013-2-21 5132888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-3-18 19456]
S3 SyDvCtrl;SyDvCtrl;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\SyDvCtrl64.sys [2012-11-3 34352]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-3-18 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-3-18 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-3-18 1255736]
.
=============== Created Last 30 ================
.
2014-07-30 04:03:21 93808 ----a-w- C:\Program Files (x86)\Mozilla Firefox\webapprt-stub.exe
2014-07-10 01:45:48 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2014-07-10 01:45:48 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2014-07-10 01:45:48 1460736 ----a-w- C:\Windows\System32\lsasrv.dll
2014-07-08 01:23:20 536576 ----a-w- C:\Windows\SysWow64\sqlite3.dll
2014-07-08 01:22:45 -------- d-----w- \AdwCleaner
2014-07-08 01:22:45 -------- d-----w- \AdwCleaner
2014-07-08 00:47:24 122584 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-07-08 00:47:13 91352 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-07-08 00:47:13 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-07-08 00:47:13 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
.
==================== Find3M  ====================
.
2014-07-11 07:02:05 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-07-09 03:31:10 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-07-09 03:31:10 699056 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-06-30 02:09:33 519168 ----a-w- C:\Windows\System32\aepdu.dll
2014-06-30 02:04:49 424448 ----a-w- C:\Windows\System32\aeinv.dll
2014-06-19 01:06:55 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-06-19 01:06:24 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-06-19 00:42:57 548352 ----a-w- C:\Windows\System32\vbscript.dll
2014-06-19 00:42:49 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-06-19 00:41:52 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-06-19 00:41:16 83968 ----a-w- C:\Windows\System32\MshtmlDac.dll
2014-06-19 00:24:30 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-06-19 00:24:12 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-06-19 00:23:53 752640 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-06-19 00:14:28 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-06-18 23:59:04 38400 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-06-18 23:56:37 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-06-18 23:51:38 5721088 ----a-w- C:\Windows\System32\jscript9.dll
2014-06-18 23:38:40 455168 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-06-18 23:37:23 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-06-18 23:36:35 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-06-18 23:35:55 62464 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2014-06-18 23:27:45 1249280 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2014-06-18 23:27:07 2040832 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-06-18 23:23:27 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-06-18 23:22:40 592896 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-06-18 23:06:10 32256 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-06-18 22:58:27 2266112 ----a-w- C:\Windows\System32\wininet.dll
2014-06-18 22:52:18 4254720 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-06-18 22:46:23 1068032 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2014-06-18 22:45:59 1964544 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-06-18 22:13:59 1791488 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-06-18 02:18:30 692736 ----a-w- C:\Windows\System32\osk.exe
2014-06-18 01:51:32 646144 ----a-w- C:\Windows\SysWow64\osk.exe
2014-06-18 01:10:36 3157504 ----a-w- C:\Windows\System32\win32k.sys
2014-06-06 10:10:34 624128 ----a-w- C:\Windows\System32\qedit.dll
2014-06-06 09:44:17 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2014-05-30 08:08:52 210944 ----a-w- C:\Windows\System32\wdigest.dll
2014-05-30 08:08:49 86528 ----a-w- C:\Windows\System32\TSpkg.dll
2014-05-30 08:08:47 340992 ----a-w- C:\Windows\System32\schannel.dll
2014-05-30 08:08:41 314880 ----a-w- C:\Windows\System32\msv1_0.dll
2014-05-30 08:08:41 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2014-05-30 08:08:36 728064 ----a-w- C:\Windows\System32\kerberos.dll
2014-05-30 08:08:31 22016 ----a-w- C:\Windows\System32\credssp.dll
2014-05-30 07:52:51 172032 ----a-w- C:\Windows\SysWow64\wdigest.dll
2014-05-30 07:52:49 65536 ----a-w- C:\Windows\SysWow64\TSpkg.dll
2014-05-30 07:52:45 247808 ----a-w- C:\Windows\SysWow64\schannel.dll
2014-05-30 07:52:41 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2014-05-30 07:52:40 259584 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2014-05-30 07:52:36 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll
2014-05-30 07:52:30 17408 ----a-w- C:\Windows\SysWow64\credssp.dll
2014-05-30 06:45:52 497152 ----a-w- C:\Windows\System32\drivers\afd.sys
2014-05-14 16:21:04 2620928 ----a-w- C:\Windows\System32\wucltux.dll
2014-05-14 16:20:45 97792 ----a-w- C:\Windows\System32\wudriver.dll
2014-05-14 16:17:10 92672 ----a-w- C:\Windows\SysWow64\wudriver.dll
2014-05-14 13:23:04 198600 ----a-w- C:\Windows\System32\wuwebv.dll
2014-05-14 13:23:04 179656 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2014-05-14 13:20:46 36864 ----a-w- C:\Windows\System32\wuapp.exe
2014-05-14 13:17:14 33792 ----a-w- C:\Windows\SysWow64\wuapp.exe
2014-05-12 11:25:56 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-05-08 09:32:11 3178496 ----a-w- C:\Windows\System32\rdpcorets.dll
2014-05-08 09:32:11 16384 ----a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll
.
============= FINISH: 22:42:58.83 ===============
 
 


#4 OCD

OCD

    SuperHelper

  • Malware Team
  • 5,574 posts

Posted 09 August 2014 - 08:27 PM

Hi Temujin,

Sorry for the delay in responding to your thread, but volunteers look for threads with zero replies. When you post additional replies it potentially delays the response time of the helper because the reply count goes up.

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

With that being said, your logs look pretty good. The symptoms you describe lead me to believe this might be more of a hardware issue. I have a few questions before we can proceed.

  • How old is the computer?
  • What is the make & model?
  • Is the computer a tower or a laptop?
  • Which drive is your primary drive? (where the operating system is located)

OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days








If you are satisfied with the help you have received, please consider making a donation.


#5 Temujin

Temujin

    Authentic Member

  • Authentic Member
  • PipPip
  • 30 posts

Posted 10 August 2014 - 01:27 AM

Hi OCD,
 
I'm very glad to get your help! I am happy to furnish the answers to your questions. Apologies also for the multiple reply thread, I thought the instructions said it was okay to do that if the logs I was asked to generate didn't fit into one post. In fact, crazily enough, trying to paste the logs into one post froze the forum for me, so I had to break the logs up into 3 posts to get it to work.
 
It's interesting you think it's hardware issue! Lately my PC has been freezing up and shutting down pretty much every time I use it (it did so in fact, when I was writing this reply). So I did wonder if it was overheating, or what.
 
Here are the answers to your questions:
 
How old is the computer?
 
I built this computer with parts bought in December 2012. Worked fine for the following years 'til these issues started cropping up about 4-5 months ago.
 
What is the make & model?
 
Since I built it, here are the main parts I used:
 
AMD FX-4100 Quad Core 3.60 ghz (I have a Cooler Master Hyper 212 Plus - CPU Cooler attached to this)
RAM: 6 GB
Graphics: NVIDIA GeForce GTX 460
Power Supply: OCZ ModXStream Pro 600W
OS: Windows 7
System type: 64 bit
Hard drive(s): Samsung SSD 830 series (60 GB) for the OS, and 3 other standard HDs for storage (total of 1992 GB).
 
Is the computer a tower or a laptop?
 
A tower.
 
Which drive is your primary drive? (where the operating system is located)
 
C: drive. It’s a Samsung SSD 830 series ATA device, 60 GB.
 
-------------------
 
Thanks for your help. Please let me know if you need any additional info!

Edited by Temujin, 10 August 2014 - 01:28 AM.


#6 OCD

OCD

    SuperHelper

  • Malware Team
  • 5,574 posts

Posted 10 August 2014 - 08:21 AM

Hi Temujin,

Thank you for the detailed answers. :thumbup:
 

So I did wonder if it was overheating, or what.

 

Based on your original post, overheating was my first thought also.

 

So I take it since you built the system yourself you have checked that the cooling fan is working properly.

That there are no obstructions around the tower that would limit the circulation of air.

=========================

Let's try the following to see if there are any issues with the hard drive.

bullseye_zpse9eaf36e.gif Chkdsk in Vista/7

You must run the command prompt as an administrator or in an "elevated mode".

  • Start menu, in the search bar type "cmd"
  • Right-click the cmd icon, select "run as administrator"
    • If you have user account control (UAC) set up it may prompt you to accept that action.
  • Then type in "chkdsk /r" (make note of the space between chkdsk and /)

=========================

bullseye_zpse9eaf36e.gif To view results log:

  • Open the Start Menu, and type eventvwr.msc in the search box and press enter.
  • If prompted by UAC, then click on Yes (Windows 7) or Continue (Vista).
  • In the left pane of Event Viewer, double click on Windows Logs to expand it, then right click on Application and click on Find.
  • Copy and paste Chkdsk into the line, and click on Find Next.
  • You will now see the system log for the scan results of Check Disk (chkdsk).
  • In the right had menu select copy, open notepad and paste the chkdsk results into notepad
  • Post in your next reply.

=========================

In your next post please provide the following:

  • chkdsk results

OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days








If you are satisfied with the help you have received, please consider making a donation.


#7 Temujin

Temujin

    Authentic Member

  • Authentic Member
  • PipPip
  • 30 posts

Posted 10 August 2014 - 11:48 AM

Hi OCD,

 

Thanks for the prompt reply!

 

Indeed, I have made sure there are no obstructions around the cooler attached to the processor, and that air is free-flowing. I have my mo-bo installed in a case with a bunch of vents and fans that keep it well-ventilated, however, it has been a while since I went in there and dusted everything. I think I will do that just in the course of our doing this.

 

Here are the chkdsk results as you requested:

 

Log Name:      Application
Source:        Microsoft-Windows-Wininit
Date:          8/10/2014 1:42:28 PM
Event ID:      1001
Task Category: None
Level:         Information
Keywords:      Classic
User:          N/A
Computer:      Temujin-PC
Description:
 
 
Checking file system on C:
The type of the file system is NTFS.
 
A disk check has been scheduled.
Windows will now check the disk.                         
 
CHKDSK is verifying files (stage 1 of 5)...
  170496 file records processed.                                         
 
File verification completed.
  528 large file records processed.                                   
 
  0 bad file records processed.                                     
 
  0 EA records processed.                                           
 
  73 reparse records processed.                                      
 
CHKDSK is verifying indexes (stage 2 of 5)...
  236042 index entries processed.                                        
 
Index verification completed.
  0 unindexed files scanned.                                        
 
  0 unindexed files recovered.                                      
 
CHKDSK is verifying security descriptors (stage 3 of 5)...
  170496 file SDs/SIDs processed.                                        
 
Cleaning up 3228 unused index entries from index $SII of file 0x9.
Cleaning up 3228 unused index entries from index $SDH of file 0x9.
Cleaning up 3228 unused security descriptors.
CHKDSK is compacting the security descriptor stream
  32774 data files processed.                                           
 
CHKDSK is verifying Usn Journal...
  37308656 USN bytes processed.                                            
 
Usn Journal verification completed.
CHKDSK is verifying file data (stage 4 of 5)...
  170480 files processed.                                                
 
File data verification completed.
CHKDSK is verifying free space (stage 5 of 5)...
  3464276 free clusters processed.                                        
 
Free space verification is complete.
CHKDSK discovered free space marked as allocated in the
master file table (MFT) bitmap.
Correcting errors in the Volume Bitmap.
Windows has made corrections to the file system.
 
  62417919 KB total disk space.
  48194804 KB in 132553 files.
     89880 KB in 32777 indexes.
         0 KB in bad sectors.
    276127 KB in use by the system.
     65536 KB occupied by the log file.
  13857108 KB available on disk.
 
      4096 bytes in each allocation unit.
  15604479 total allocation units on disk.
   3464277 allocation units available on disk.
 
Internal Info:
00 9a 02 00 dc 85 02 00 07 e1 04 00 00 00 00 00  ................
64 01 00 00 49 00 00 00 00 00 00 00 00 00 00 00  d...I...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
 
Windows has finished checking your disk.
Please wait while your computer restarts.
 
Event Xml:
  <System>
    <Provider Name="Microsoft-Windows-Wininit" Guid="{206f6dea-d3c5-4d10-bc72-989f03c8b84b}" EventSourceName="Wininit" />
    <EventID Qualifiers="16384">1001</EventID>
    <Version>0</Version>
    <Level>4</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-08-10T17:42:28.000000000Z" />
    <EventRecordID>60711</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>Temujin-PC</Computer>
    <Security />
  </System>
  <EventData>
    <Data>
 
Checking file system on C:
The type of the file system is NTFS.
 
A disk check has been scheduled.
Windows will now check the disk.                         
 
CHKDSK is verifying files (stage 1 of 5)...
  170496 file records processed.                                         
 
File verification completed.
  528 large file records processed.                                   
 
  0 bad file records processed.                                     
 
  0 EA records processed.                                           
 
  73 reparse records processed.                                      
 
CHKDSK is verifying indexes (stage 2 of 5)...
  236042 index entries processed.                                        
 
Index verification completed.
  0 unindexed files scanned.                                        
 
  0 unindexed files recovered.                                      
 
CHKDSK is verifying security descriptors (stage 3 of 5)...
  170496 file SDs/SIDs processed.                                        
 
Cleaning up 3228 unused index entries from index $SII of file 0x9.
Cleaning up 3228 unused index entries from index $SDH of file 0x9.
Cleaning up 3228 unused security descriptors.
CHKDSK is compacting the security descriptor stream
  32774 data files processed.                                           
 
CHKDSK is verifying Usn Journal...
  37308656 USN bytes processed.                                            
 
Usn Journal verification completed.
CHKDSK is verifying file data (stage 4 of 5)...
  170480 files processed.                                                
 
File data verification completed.
CHKDSK is verifying free space (stage 5 of 5)...
  3464276 free clusters processed.                                        
 
Free space verification is complete.
CHKDSK discovered free space marked as allocated in the
master file table (MFT) bitmap.
Correcting errors in the Volume Bitmap.
Windows has made corrections to the file system.
 
  62417919 KB total disk space.
  48194804 KB in 132553 files.
     89880 KB in 32777 indexes.
         0 KB in bad sectors.
    276127 KB in use by the system.
     65536 KB occupied by the log file.
  13857108 KB available on disk.
 
      4096 bytes in each allocation unit.
  15604479 total allocation units on disk.
   3464277 allocation units available on disk.
 
Internal Info:
00 9a 02 00 dc 85 02 00 07 e1 04 00 00 00 00 00  ................
64 01 00 00 49 00 00 00 00 00 00 00 00 00 00 00  d...I...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
 
Windows has finished checking your disk.
Please wait while your computer restarts.
</Data>
  </EventData>
</Event>


#8 OCD

OCD

    SuperHelper

  • Malware Team
  • 5,574 posts

Posted 10 August 2014 - 07:20 PM

Hi Temujin,

Everything in the chkdsk log looks in order. :thumbup:  Let's check the Windows System files to make sure they are in good order.

bullseye_zpse9eaf36e.gif System File Checker (SFC)

  • Click on the Start button and in the Search programs and files box type the following:
    • command
  • Don't press Enter, just let the search results populate above.
  • In the search results, locate the Programs section.
  • Locate the Command Prompt shortcut and right-click on it.
  • Select Run as administrator.
  • Click Yes on the User Account Control window that appears.
  • Important: If you see a User Account Control window but also a message that says To continue, type an administrator password, and then click Yes, then your user account must be a standard account, not an administrator account. Before you can click Yes and open an elevated command prompt, you'll need to type the password of another user on your Windows 7 computer that has administrator level privileges.
  • Note: You will not see this window at all if your User Account Control settings are turned all the way down. See How To Disable User Account Control in Windows 7 for more information.
  • An elevated Command Prompt window will appear.
    • Type: sfc /scannow (There's a space between sfc and /scannow.) , then hit Enter
  • Let the check run to completion. DO NOT reboot the PC or close the cmd window.
  • Copy & Paste the following command at the Command Prompt and press Enter:

    findstr /c:"[SR]" %windir%\logs\cbs\cbs.log >%userprofile%\Desktop\sfcdetails.txt
  • This will place a file on your desktop called sfcdetails.txt which contains the results of the scan.
  • Copy and Paste the contents of the file into your next post.
  • After the scan runs type exit to close the command prompt window

=========================

In your next post please provide the following:

  • sfcdetails.txt

OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days








If you are satisfied with the help you have received, please consider making a donation.


#9 Temujin

Temujin

    Authentic Member

  • Authentic Member
  • PipPip
  • 30 posts

Posted 10 August 2014 - 11:14 PM

Hi OCD,

 

Thanks for your help. :D  Following your instructions, I came up with the following:

 

2014-08-10 22:25:45, Info                  CSI    00000009 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:45, Info                  CSI    0000000a [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:45, Info                  CSI    0000000c [SR] Verify complete
2014-08-10 22:25:45, Info                  CSI    0000000d [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:45, Info                  CSI    0000000e [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:46, Info                  CSI    00000010 [SR] Verify complete
2014-08-10 22:25:46, Info                  CSI    00000011 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:46, Info                  CSI    00000012 [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:46, Info                  CSI    00000014 [SR] Verify complete
2014-08-10 22:25:46, Info                  CSI    00000015 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:46, Info                  CSI    00000016 [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:46, Info                  CSI    00000018 [SR] Verify complete
2014-08-10 22:25:46, Info                  CSI    00000019 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:46, Info                  CSI    0000001a [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:47, Info                  CSI    0000001c [SR] Verify complete
2014-08-10 22:25:47, Info                  CSI    0000001d [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:47, Info                  CSI    0000001e [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:47, Info                  CSI    00000020 [SR] Verify complete
2014-08-10 22:25:47, Info                  CSI    00000021 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:47, Info                  CSI    00000022 [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:47, Info                  CSI    00000024 [SR] Verify complete
2014-08-10 22:25:47, Info                  CSI    00000025 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:47, Info                  CSI    00000026 [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:48, Info                  CSI    00000028 [SR] Verify complete
2014-08-10 22:25:48, Info                  CSI    00000029 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:48, Info                  CSI    0000002a [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:49, Info                  CSI    0000002c [SR] Verify complete
2014-08-10 22:25:49, Info                  CSI    0000002d [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:49, Info                  CSI    0000002e [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:49, Info                  CSI    00000030 [SR] Verify complete
2014-08-10 22:25:50, Info                  CSI    00000031 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:50, Info                  CSI    00000032 [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:50, Info                  CSI    00000034 [SR] Verify complete
2014-08-10 22:25:50, Info                  CSI    00000035 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:50, Info                  CSI    00000036 [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:50, Info                  CSI    00000038 [SR] Verify complete
2014-08-10 22:25:50, Info                  CSI    00000039 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:50, Info                  CSI    0000003a [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:51, Info                  CSI    0000003c [SR] Verify complete
2014-08-10 22:25:51, Info                  CSI    0000003d [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:51, Info                  CSI    0000003e [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:52, Info                  CSI    00000040 [SR] Verify complete
2014-08-10 22:25:52, Info                  CSI    00000041 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:52, Info                  CSI    00000042 [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:52, Info                  CSI    00000044 [SR] Verify complete
2014-08-10 22:25:52, Info                  CSI    00000045 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:52, Info                  CSI    00000046 [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:54, Info                  CSI    00000049 [SR] Verify complete
2014-08-10 22:25:54, Info                  CSI    0000004a [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:54, Info                  CSI    0000004b [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:56, Info                  CSI    0000004f [SR] Verify complete
2014-08-10 22:25:56, Info                  CSI    00000050 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:56, Info                  CSI    00000051 [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:57, Info                  CSI    00000054 [SR] Verify complete
2014-08-10 22:25:57, Info                  CSI    00000055 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:57, Info                  CSI    00000056 [SR] Beginning Verify and Repair transaction
2014-08-10 22:25:59, Info                  CSI    00000059 [SR] Verify complete
2014-08-10 22:25:59, Info                  CSI    0000005a [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:25:59, Info                  CSI    0000005b [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:01, Info                  CSI    0000005d [SR] Verify complete
2014-08-10 22:26:01, Info                  CSI    0000005e [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:01, Info                  CSI    0000005f [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:04, Info                  CSI    00000084 [SR] Verify complete
2014-08-10 22:26:04, Info                  CSI    00000085 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:04, Info                  CSI    00000086 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:06, Info                  CSI    00000088 [SR] Verify complete
2014-08-10 22:26:06, Info                  CSI    00000089 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:06, Info                  CSI    0000008a [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:07, Info                  CSI    0000008c [SR] Verify complete
2014-08-10 22:26:08, Info                  CSI    0000008d [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:08, Info                  CSI    0000008e [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:09, Info                  CSI    00000090 [SR] Verify complete
2014-08-10 22:26:09, Info                  CSI    00000091 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:09, Info                  CSI    00000092 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:11, Info                  CSI    00000094 [SR] Verify complete
2014-08-10 22:26:11, Info                  CSI    00000095 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:11, Info                  CSI    00000096 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:12, Info                  CSI    00000098 [SR] Verify complete
2014-08-10 22:26:12, Info                  CSI    00000099 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:12, Info                  CSI    0000009a [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:15, Info                  CSI    0000009e [SR] Verify complete
2014-08-10 22:26:15, Info                  CSI    0000009f [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:15, Info                  CSI    000000a0 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:18, Info                  CSI    000000c1 [SR] Verify complete
2014-08-10 22:26:18, Info                  CSI    000000c2 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:18, Info                  CSI    000000c3 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:22, Info                  CSI    000000c5 [SR] Verify complete
2014-08-10 22:26:23, Info                  CSI    000000c6 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:23, Info                  CSI    000000c7 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:26, Info                  CSI    000000cb [SR] Verify complete
2014-08-10 22:26:26, Info                  CSI    000000cc [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:26, Info                  CSI    000000cd [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:27, Info                  CSI    000000cf [SR] Verify complete
2014-08-10 22:26:27, Info                  CSI    000000d0 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:27, Info                  CSI    000000d1 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:28, Info                  CSI    000000d3 [SR] Verify complete
2014-08-10 22:26:28, Info                  CSI    000000d4 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:28, Info                  CSI    000000d5 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:28, Info                  CSI    000000d7 [SR] Verify complete
2014-08-10 22:26:29, Info                  CSI    000000d8 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:29, Info                  CSI    000000d9 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:33, Info                  CSI    000000ec [SR] Verify complete
2014-08-10 22:26:34, Info                  CSI    000000ed [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:34, Info                  CSI    000000ee [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:34, Info                  CSI    000000f0 [SR] Verify complete
2014-08-10 22:26:34, Info                  CSI    000000f1 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:34, Info                  CSI    000000f2 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:35, Info                  CSI    000000f4 [SR] Verify complete
2014-08-10 22:26:35, Info                  CSI    000000f5 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:35, Info                  CSI    000000f6 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:36, Info                  CSI    000000f8 [SR] Verify complete
2014-08-10 22:26:36, Info                  CSI    000000f9 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:36, Info                  CSI    000000fa [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:38, Info                  CSI    000000fc [SR] Verify complete
2014-08-10 22:26:38, Info                  CSI    000000fd [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:38, Info                  CSI    000000fe [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:42, Info                  CSI    00000102 [SR] Verify complete
2014-08-10 22:26:42, Info                  CSI    00000103 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:42, Info                  CSI    00000104 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:43, Info                  CSI    00000106 [SR] Verify complete
2014-08-10 22:26:43, Info                  CSI    00000107 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:43, Info                  CSI    00000108 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:44, Info                  CSI    0000010a [SR] Verify complete
2014-08-10 22:26:44, Info                  CSI    0000010b [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:44, Info                  CSI    0000010c [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:45, Info                  CSI    0000010e [SR] Verify complete
2014-08-10 22:26:46, Info                  CSI    0000010f [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:46, Info                  CSI    00000110 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:47, Info                  CSI    00000112 [SR] Verify complete
2014-08-10 22:26:47, Info                  CSI    00000113 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:47, Info                  CSI    00000114 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:49, Info                  CSI    00000116 [SR] Verify complete
2014-08-10 22:26:49, Info                  CSI    00000117 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:49, Info                  CSI    00000118 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:54, Info                  CSI    00000130 [SR] Verify complete
2014-08-10 22:26:55, Info                  CSI    00000131 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:55, Info                  CSI    00000132 [SR] Beginning Verify and Repair transaction
2014-08-10 22:26:57, Info                  CSI    00000134 [SR] Verify complete
2014-08-10 22:26:57, Info                  CSI    00000135 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:26:57, Info                  CSI    00000136 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:04, Info                  CSI    00000138 [SR] Verify complete
2014-08-10 22:27:04, Info                  CSI    00000139 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:04, Info                  CSI    0000013a [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:06, Info                  CSI    0000013d [SR] Verify complete
2014-08-10 22:27:06, Info                  CSI    0000013e [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:06, Info                  CSI    0000013f [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:09, Info                  CSI    00000141 [SR] Verify complete
2014-08-10 22:27:09, Info                  CSI    00000142 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:09, Info                  CSI    00000143 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:11, Info                  CSI    00000145 [SR] Verify complete
2014-08-10 22:27:11, Info                  CSI    00000146 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:11, Info                  CSI    00000147 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:12, Info                  CSI    00000149 [SR] Verify complete
2014-08-10 22:27:12, Info                  CSI    0000014a [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:12, Info                  CSI    0000014b [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:13, Info                  CSI    0000014d [SR] Verify complete
2014-08-10 22:27:13, Info                  CSI    0000014e [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:13, Info                  CSI    0000014f [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:15, Info                  CSI    00000153 [SR] Verify complete
2014-08-10 22:27:15, Info                  CSI    00000154 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:15, Info                  CSI    00000155 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:20, Info                  CSI    00000157 [SR] Verify complete
2014-08-10 22:27:20, Info                  CSI    00000158 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:20, Info                  CSI    00000159 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:23, Info                  CSI    0000015c [SR] Verify complete
2014-08-10 22:27:24, Info                  CSI    0000015d [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:24, Info                  CSI    0000015e [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:25, Info                  CSI    00000160 [SR] Verify complete
2014-08-10 22:27:26, Info                  CSI    00000161 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:26, Info                  CSI    00000162 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:27, Info                  CSI    00000165 [SR] Verify complete
2014-08-10 22:27:27, Info                  CSI    00000166 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:27, Info                  CSI    00000167 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:29, Info                  CSI    0000016a [SR] Verify complete
2014-08-10 22:27:30, Info                  CSI    0000016b [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:30, Info                  CSI    0000016c [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:32, Info                  CSI    0000016e [SR] Verify complete
2014-08-10 22:27:32, Info                  CSI    0000016f [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:32, Info                  CSI    00000170 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:34, Info                  CSI    00000172 [SR] Verify complete
2014-08-10 22:27:34, Info                  CSI    00000173 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:34, Info                  CSI    00000174 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:36, Info                  CSI    00000176 [SR] Verify complete
2014-08-10 22:27:36, Info                  CSI    00000177 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:36, Info                  CSI    00000178 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:37, Info                  CSI    0000017b [SR] Verify complete
2014-08-10 22:27:37, Info                  CSI    0000017c [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:37, Info                  CSI    0000017d [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:39, Info                  CSI    0000017f [SR] Verify complete
2014-08-10 22:27:39, Info                  CSI    00000180 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:39, Info                  CSI    00000181 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:40, Info                  CSI    00000183 [SR] Verify complete
2014-08-10 22:27:40, Info                  CSI    00000184 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:40, Info                  CSI    00000185 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:42, Info                  CSI    00000188 [SR] Verify complete
2014-08-10 22:27:42, Info                  CSI    00000189 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:42, Info                  CSI    0000018a [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:45, Info                  CSI    0000018d [SR] Verify complete
2014-08-10 22:27:45, Info                  CSI    0000018e [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:45, Info                  CSI    0000018f [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:47, Info                  CSI    00000192 [SR] Verify complete
2014-08-10 22:27:47, Info                  CSI    00000193 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:47, Info                  CSI    00000194 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:49, Info                  CSI    00000197 [SR] Verify complete
2014-08-10 22:27:49, Info                  CSI    00000198 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:49, Info                  CSI    00000199 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:51, Info                  CSI    0000019b [SR] Verify complete
2014-08-10 22:27:52, Info                  CSI    0000019c [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:52, Info                  CSI    0000019d [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:52, Info                  CSI    0000019f [SR] Verify complete
2014-08-10 22:27:52, Info                  CSI    000001a0 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:52, Info                  CSI    000001a1 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:54, Info                  CSI    000001a3 [SR] Verify complete
2014-08-10 22:27:54, Info                  CSI    000001a4 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:54, Info                  CSI    000001a5 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:54, Info                  CSI    000001a7 [SR] Verify complete
2014-08-10 22:27:55, Info                  CSI    000001a8 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:55, Info                  CSI    000001a9 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:56, Info                  CSI    000001ab [SR] Verify complete
2014-08-10 22:27:56, Info                  CSI    000001ac [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:56, Info                  CSI    000001ad [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:58, Info                  CSI    000001af [SR] Verify complete
2014-08-10 22:27:58, Info                  CSI    000001b0 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:58, Info                  CSI    000001b1 [SR] Beginning Verify and Repair transaction
2014-08-10 22:27:59, Info                  CSI    000001b3 [SR] Verify complete
2014-08-10 22:27:59, Info                  CSI    000001b4 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:27:59, Info                  CSI    000001b5 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:01, Info                  CSI    000001b7 [SR] Verify complete
2014-08-10 22:28:01, Info                  CSI    000001b8 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:01, Info                  CSI    000001b9 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:07, Info                  CSI    000001bb [SR] Verify complete
2014-08-10 22:28:07, Info                  CSI    000001bc [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:07, Info                  CSI    000001bd [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:08, Info                  CSI    000001bf [SR] Verify complete
2014-08-10 22:28:08, Info                  CSI    000001c0 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:08, Info                  CSI    000001c1 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:09, Info                  CSI    000001c3 [SR] Verify complete
2014-08-10 22:28:10, Info                  CSI    000001c4 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:10, Info                  CSI    000001c5 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:10, Info                  CSI    000001c7 [SR] Verify complete
2014-08-10 22:28:10, Info                  CSI    000001c8 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:10, Info                  CSI    000001c9 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:11, Info                  CSI    000001cb [SR] Verify complete
2014-08-10 22:28:11, Info                  CSI    000001cc [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:11, Info                  CSI    000001cd [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:12, Info                  CSI    000001cf [SR] Verify complete
2014-08-10 22:28:12, Info                  CSI    000001d0 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:12, Info                  CSI    000001d1 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:13, Info                  CSI    000001d3 [SR] Verify complete
2014-08-10 22:28:13, Info                  CSI    000001d4 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:13, Info                  CSI    000001d5 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:14, Info                  CSI    000001d7 [SR] Verify complete
2014-08-10 22:28:14, Info                  CSI    000001d8 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:14, Info                  CSI    000001d9 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:16, Info                  CSI    000001e1 [SR] Verify complete
2014-08-10 22:28:17, Info                  CSI    000001e2 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:17, Info                  CSI    000001e3 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:17, Info                  CSI    000001e5 [SR] Verify complete
2014-08-10 22:28:17, Info                  CSI    000001e6 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:17, Info                  CSI    000001e7 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:18, Info                  CSI    000001e9 [SR] Verify complete
2014-08-10 22:28:18, Info                  CSI    000001ea [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:18, Info                  CSI    000001eb [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:19, Info                  CSI    000001ed [SR] Verify complete
2014-08-10 22:28:19, Info                  CSI    000001ee [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:19, Info                  CSI    000001ef [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:21, Info                  CSI    000001f1 [SR] Verify complete
2014-08-10 22:28:21, Info                  CSI    000001f2 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:21, Info                  CSI    000001f3 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:23, Info                  CSI    000001f6 [SR] Verify complete
2014-08-10 22:28:23, Info                  CSI    000001f7 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:23, Info                  CSI    000001f8 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:26, Info                  CSI    000001fa [SR] Verify complete
2014-08-10 22:28:26, Info                  CSI    000001fb [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:26, Info                  CSI    000001fc [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:26, Info                  CSI    000001fe [SR] Verify complete
2014-08-10 22:28:26, Info                  CSI    000001ff [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:26, Info                  CSI    00000200 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:29, Info                  CSI    00000202 [SR] Verify complete
2014-08-10 22:28:29, Info                  CSI    00000203 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:29, Info                  CSI    00000204 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:34, Info                  CSI    00000209 [SR] Verify complete
2014-08-10 22:28:34, Info                  CSI    0000020a [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:34, Info                  CSI    0000020b [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:36, Info                  CSI    00000210 [SR] Verify complete
2014-08-10 22:28:36, Info                  CSI    00000211 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:36, Info                  CSI    00000212 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:38, Info                  CSI    00000218 [SR] Verify complete
2014-08-10 22:28:38, Info                  CSI    00000219 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:38, Info                  CSI    0000021a [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:41, Info                  CSI    00000223 [SR] Verify complete
2014-08-10 22:28:41, Info                  CSI    00000224 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:41, Info                  CSI    00000225 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:43, Info                  CSI    0000022a [SR] Verify complete
2014-08-10 22:28:43, Info                  CSI    0000022b [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:43, Info                  CSI    0000022c [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:44, Info                  CSI    0000022e [SR] Verify complete
2014-08-10 22:28:44, Info                  CSI    0000022f [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:44, Info                  CSI    00000230 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:45, Info                  CSI    00000234 [SR] Verify complete
2014-08-10 22:28:46, Info                  CSI    00000235 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:46, Info                  CSI    00000236 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:48, Info                  CSI    0000024d [SR] Verify complete
2014-08-10 22:28:48, Info                  CSI    0000024e [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:48, Info                  CSI    0000024f [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:50, Info                  CSI    0000025f [SR] Verify complete
2014-08-10 22:28:50, Info                  CSI    00000260 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:50, Info                  CSI    00000261 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:51, Info                  CSI    00000263 [SR] Verify complete
2014-08-10 22:28:51, Info                  CSI    00000264 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:51, Info                  CSI    00000265 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:53, Info                  CSI    00000267 [SR] Verify complete
2014-08-10 22:28:53, Info                  CSI    00000268 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:53, Info                  CSI    00000269 [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:54, Info                  CSI    0000026b [SR] Verify complete
2014-08-10 22:28:54, Info                  CSI    0000026c [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:54, Info                  CSI    0000026d [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:55, Info                  CSI    0000027b [SR] Verify complete
2014-08-10 22:28:55, Info                  CSI    0000027c [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:55, Info                  CSI    0000027d [SR] Beginning Verify and Repair transaction
2014-08-10 22:28:57, Info                  CSI    00000281 [SR] Verify complete
2014-08-10 22:28:57, Info                  CSI    00000282 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:28:57, Info                  CSI    00000283 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:00, Info                  CSI    0000028f [SR] Verify complete
2014-08-10 22:29:00, Info                  CSI    00000290 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:00, Info                  CSI    00000291 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:01, Info                  CSI    00000293 [SR] Verify complete
2014-08-10 22:29:01, Info                  CSI    00000294 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:01, Info                  CSI    00000295 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:03, Info                  CSI    00000298 [SR] Verify complete
2014-08-10 22:29:03, Info                  CSI    00000299 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:03, Info                  CSI    0000029a [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:03, Info                  CSI    0000029c [SR] Verify complete
2014-08-10 22:29:04, Info                  CSI    0000029d [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:04, Info                  CSI    0000029e [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:05, Info                  CSI    000002a0 [SR] Verify complete
2014-08-10 22:29:05, Info                  CSI    000002a1 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:05, Info                  CSI    000002a2 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:06, Info                  CSI    000002a4 [SR] Verify complete
2014-08-10 22:29:06, Info                  CSI    000002a5 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:06, Info                  CSI    000002a6 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:07, Info                  CSI    000002a8 [SR] Verify complete
2014-08-10 22:29:07, Info                  CSI    000002a9 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:07, Info                  CSI    000002aa [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:11, Info                  CSI    000002c4 [SR] Verify complete
2014-08-10 22:29:11, Info                  CSI    000002c5 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:11, Info                  CSI    000002c6 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:13, Info                  CSI    000002c8 [SR] Verify complete
2014-08-10 22:29:13, Info                  CSI    000002c9 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:13, Info                  CSI    000002ca [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:20, Info                  CSI    000002cc [SR] Verify complete
2014-08-10 22:29:20, Info                  CSI    000002cd [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:20, Info                  CSI    000002ce [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:21, Info                  CSI    000002d0 [SR] Verify complete
2014-08-10 22:29:21, Info                  CSI    000002d1 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:21, Info                  CSI    000002d2 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:22, Info                  CSI    000002d6 [SR] Verify complete
2014-08-10 22:29:22, Info                  CSI    000002d7 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:22, Info                  CSI    000002d8 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:23, Info                  CSI    000002da [SR] Verify complete
2014-08-10 22:29:23, Info                  CSI    000002db [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:23, Info                  CSI    000002dc [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:24, Info                  CSI    000002de [SR] Verify complete
2014-08-10 22:29:24, Info                  CSI    000002df [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:24, Info                  CSI    000002e0 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:25, Info                  CSI    000002e2 [SR] Verify complete
2014-08-10 22:29:25, Info                  CSI    000002e3 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:25, Info                  CSI    000002e4 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:27, Info                  CSI    000002e7 [SR] Verify complete
2014-08-10 22:29:27, Info                  CSI    000002e8 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:27, Info                  CSI    000002e9 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:28, Info                  CSI    000002eb [SR] Verify complete
2014-08-10 22:29:28, Info                  CSI    000002ec [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:28, Info                  CSI    000002ed [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:29, Info                  CSI    000002ef [SR] Verify complete
2014-08-10 22:29:29, Info                  CSI    000002f0 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:29, Info                  CSI    000002f1 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:30, Info                  CSI    000002f3 [SR] Verify complete
2014-08-10 22:29:31, Info                  CSI    000002f4 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:31, Info                  CSI    000002f5 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:32, Info                  CSI    000002f8 [SR] Verify complete
2014-08-10 22:29:32, Info                  CSI    000002f9 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:32, Info                  CSI    000002fa [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:34, Info                  CSI    000002fc [SR] Verify complete
2014-08-10 22:29:34, Info                  CSI    000002fd [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:34, Info                  CSI    000002fe [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:35, Info                  CSI    00000300 [SR] Verify complete
2014-08-10 22:29:35, Info                  CSI    00000301 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:35, Info                  CSI    00000302 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:36, Info                  CSI    00000304 [SR] Verify complete
2014-08-10 22:29:36, Info                  CSI    00000305 [SR] Verifying 100 (0x0000000000000064) components
2014-08-10 22:29:36, Info                  CSI    00000306 [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:38, Info                  CSI    00000308 [SR] Verify complete
2014-08-10 22:29:38, Info                  CSI    00000309 [SR] Verifying 0 components
2014-08-10 22:29:38, Info                  CSI    0000030a [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:38, Info                  CSI    0000030c [SR] Verify complete
2014-08-10 22:29:38, Info                  CSI    0000030d [SR] Repairing 0 components
2014-08-10 22:29:38, Info                  CSI    0000030e [SR] Beginning Verify and Repair transaction
2014-08-10 22:29:38, Info                  CSI    00000310 [SR] Repair complete
2014-08-11 00:41:49, Info                  CSI    00000009 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:49, Info                  CSI    0000000a [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:50, Info                  CSI    0000000c [SR] Verify complete
2014-08-11 00:41:50, Info                  CSI    0000000d [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:50, Info                  CSI    0000000e [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:50, Info                  CSI    00000010 [SR] Verify complete
2014-08-11 00:41:50, Info                  CSI    00000011 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:50, Info                  CSI    00000012 [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:50, Info                  CSI    00000014 [SR] Verify complete
2014-08-11 00:41:51, Info                  CSI    00000015 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:51, Info                  CSI    00000016 [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:51, Info                  CSI    00000018 [SR] Verify complete
2014-08-11 00:41:51, Info                  CSI    00000019 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:51, Info                  CSI    0000001a [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:51, Info                  CSI    0000001c [SR] Verify complete
2014-08-11 00:41:51, Info                  CSI    0000001d [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:51, Info                  CSI    0000001e [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:51, Info                  CSI    00000020 [SR] Verify complete
2014-08-11 00:41:52, Info                  CSI    00000021 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:52, Info                  CSI    00000022 [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:52, Info                  CSI    00000024 [SR] Verify complete
2014-08-11 00:41:52, Info                  CSI    00000025 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:52, Info                  CSI    00000026 [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:53, Info                  CSI    00000028 [SR] Verify complete
2014-08-11 00:41:53, Info                  CSI    00000029 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:53, Info                  CSI    0000002a [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:53, Info                  CSI    0000002c [SR] Verify complete
2014-08-11 00:41:54, Info                  CSI    0000002d [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:54, Info                  CSI    0000002e [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:54, Info                  CSI    00000030 [SR] Verify complete
2014-08-11 00:41:54, Info                  CSI    00000031 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:54, Info                  CSI    00000032 [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:54, Info                  CSI    00000034 [SR] Verify complete
2014-08-11 00:41:55, Info                  CSI    00000035 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:55, Info                  CSI    00000036 [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:55, Info                  CSI    00000038 [SR] Verify complete
2014-08-11 00:41:55, Info                  CSI    00000039 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:55, Info                  CSI    0000003a [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:56, Info                  CSI    0000003c [SR] Verify complete
2014-08-11 00:41:56, Info                  CSI    0000003d [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:56, Info                  CSI    0000003e [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:56, Info                  CSI    00000040 [SR] Verify complete
2014-08-11 00:41:57, Info                  CSI    00000041 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:57, Info                  CSI    00000042 [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:57, Info                  CSI    00000044 [SR] Verify complete
2014-08-11 00:41:57, Info                  CSI    00000045 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:57, Info                  CSI    00000046 [SR] Beginning Verify and Repair transaction
2014-08-11 00:41:59, Info                  CSI    00000049 [SR] Verify complete
2014-08-11 00:41:59, Info                  CSI    0000004a [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:41:59, Info                  CSI    0000004b [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:01, Info                  CSI    0000004f [SR] Verify complete
2014-08-11 00:42:02, Info                  CSI    00000050 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:02, Info                  CSI    00000051 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:03, Info                  CSI    00000054 [SR] Verify complete
2014-08-11 00:42:03, Info                  CSI    00000055 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:03, Info                  CSI    00000056 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:04, Info                  CSI    00000059 [SR] Verify complete
2014-08-11 00:42:04, Info                  CSI    0000005a [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:04, Info                  CSI    0000005b [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:06, Info                  CSI    0000005d [SR] Verify complete
2014-08-11 00:42:06, Info                  CSI    0000005e [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:06, Info                  CSI    0000005f [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:10, Info                  CSI    00000084 [SR] Verify complete
2014-08-11 00:42:10, Info                  CSI    00000085 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:10, Info                  CSI    00000086 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:12, Info                  CSI    00000088 [SR] Verify complete
2014-08-11 00:42:12, Info                  CSI    00000089 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:12, Info                  CSI    0000008a [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:14, Info                  CSI    0000008c [SR] Verify complete
2014-08-11 00:42:14, Info                  CSI    0000008d [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:14, Info                  CSI    0000008e [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:15, Info                  CSI    00000090 [SR] Verify complete
2014-08-11 00:42:15, Info                  CSI    00000091 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:15, Info                  CSI    00000092 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:17, Info                  CSI    00000094 [SR] Verify complete
2014-08-11 00:42:17, Info                  CSI    00000095 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:17, Info                  CSI    00000096 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:18, Info                  CSI    00000098 [SR] Verify complete
2014-08-11 00:42:18, Info                  CSI    00000099 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:18, Info                  CSI    0000009a [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:22, Info                  CSI    0000009e [SR] Verify complete
2014-08-11 00:42:22, Info                  CSI    0000009f [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:22, Info                  CSI    000000a0 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:25, Info                  CSI    000000c1 [SR] Verify complete
2014-08-11 00:42:25, Info                  CSI    000000c2 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:25, Info                  CSI    000000c3 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:29, Info                  CSI    000000c5 [SR] Verify complete
2014-08-11 00:42:30, Info                  CSI    000000c6 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:30, Info                  CSI    000000c7 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:33, Info                  CSI    000000cb [SR] Verify complete
2014-08-11 00:42:34, Info                  CSI    000000cc [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:34, Info                  CSI    000000cd [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:34, Info                  CSI    000000cf [SR] Verify complete
2014-08-11 00:42:34, Info                  CSI    000000d0 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:34, Info                  CSI    000000d1 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:35, Info                  CSI    000000d3 [SR] Verify complete
2014-08-11 00:42:35, Info                  CSI    000000d4 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:35, Info                  CSI    000000d5 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:36, Info                  CSI    000000d7 [SR] Verify complete
2014-08-11 00:42:36, Info                  CSI    000000d8 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:36, Info                  CSI    000000d9 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:41, Info                  CSI    000000ec [SR] Verify complete
2014-08-11 00:42:41, Info                  CSI    000000ed [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:41, Info                  CSI    000000ee [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:42, Info                  CSI    000000f0 [SR] Verify complete
2014-08-11 00:42:42, Info                  CSI    000000f1 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:42, Info                  CSI    000000f2 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:43, Info                  CSI    000000f4 [SR] Verify complete
2014-08-11 00:42:43, Info                  CSI    000000f5 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:43, Info                  CSI    000000f6 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:44, Info                  CSI    000000f8 [SR] Verify complete
2014-08-11 00:42:44, Info                  CSI    000000f9 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:44, Info                  CSI    000000fa [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:46, Info                  CSI    000000fc [SR] Verify complete
2014-08-11 00:42:46, Info                  CSI    000000fd [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:46, Info                  CSI    000000fe [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:50, Info                  CSI    00000102 [SR] Verify complete
2014-08-11 00:42:50, Info                  CSI    00000103 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:50, Info                  CSI    00000104 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:52, Info                  CSI    00000106 [SR] Verify complete
2014-08-11 00:42:52, Info                  CSI    00000107 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:52, Info                  CSI    00000108 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:52, Info                  CSI    0000010a [SR] Verify complete
2014-08-11 00:42:52, Info                  CSI    0000010b [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:52, Info                  CSI    0000010c [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:54, Info                  CSI    0000010e [SR] Verify complete
2014-08-11 00:42:54, Info                  CSI    0000010f [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:54, Info                  CSI    00000110 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:55, Info                  CSI    00000112 [SR] Verify complete
2014-08-11 00:42:56, Info                  CSI    00000113 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:56, Info                  CSI    00000114 [SR] Beginning Verify and Repair transaction
2014-08-11 00:42:57, Info                  CSI    00000116 [SR] Verify complete
2014-08-11 00:42:58, Info                  CSI    00000117 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:42:58, Info                  CSI    00000118 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:04, Info                  CSI    00000130 [SR] Verify complete
2014-08-11 00:43:04, Info                  CSI    00000131 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:04, Info                  CSI    00000132 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:06, Info                  CSI    00000134 [SR] Verify complete
2014-08-11 00:43:06, Info                  CSI    00000135 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:06, Info                  CSI    00000136 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:14, Info                  CSI    00000138 [SR] Verify complete
2014-08-11 00:43:14, Info                  CSI    00000139 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:14, Info                  CSI    0000013a [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:16, Info                  CSI    0000013d [SR] Verify complete
2014-08-11 00:43:16, Info                  CSI    0000013e [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:16, Info                  CSI    0000013f [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:19, Info                  CSI    00000141 [SR] Verify complete
2014-08-11 00:43:19, Info                  CSI    00000142 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:19, Info                  CSI    00000143 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:21, Info                  CSI    00000145 [SR] Verify complete
2014-08-11 00:43:21, Info                  CSI    00000146 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:21, Info                  CSI    00000147 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:22, Info                  CSI    00000149 [SR] Verify complete
2014-08-11 00:43:23, Info                  CSI    0000014a [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:23, Info                  CSI    0000014b [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:24, Info                  CSI    0000014d [SR] Verify complete
2014-08-11 00:43:24, Info                  CSI    0000014e [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:24, Info                  CSI    0000014f [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:25, Info                  CSI    00000153 [SR] Verify complete
2014-08-11 00:43:25, Info                  CSI    00000154 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:25, Info                  CSI    00000155 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:31, Info                  CSI    00000157 [SR] Verify complete
2014-08-11 00:43:31, Info                  CSI    00000158 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:31, Info                  CSI    00000159 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:34, Info                  CSI    0000015c [SR] Verify complete
2014-08-11 00:43:34, Info                  CSI    0000015d [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:34, Info                  CSI    0000015e [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:36, Info                  CSI    00000160 [SR] Verify complete
2014-08-11 00:43:36, Info                  CSI    00000161 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:36, Info                  CSI    00000162 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:38, Info                  CSI    00000165 [SR] Verify complete
2014-08-11 00:43:38, Info                  CSI    00000166 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:38, Info                  CSI    00000167 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:40, Info                  CSI    0000016a [SR] Verify complete
2014-08-11 00:43:41, Info                  CSI    0000016b [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:41, Info                  CSI    0000016c [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:43, Info                  CSI    0000016e [SR] Verify complete
2014-08-11 00:43:43, Info                  CSI    0000016f [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:43, Info                  CSI    00000170 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:45, Info                  CSI    00000172 [SR] Verify complete
2014-08-11 00:43:45, Info                  CSI    00000173 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:45, Info                  CSI    00000174 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:47, Info                  CSI    00000176 [SR] Verify complete
2014-08-11 00:43:47, Info                  CSI    00000177 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:47, Info                  CSI    00000178 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:48, Info                  CSI    0000017b [SR] Verify complete
2014-08-11 00:43:49, Info                  CSI    0000017c [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:49, Info                  CSI    0000017d [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:50, Info                  CSI    0000017f [SR] Verify complete
2014-08-11 00:43:51, Info                  CSI    00000180 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:51, Info                  CSI    00000181 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:51, Info                  CSI    00000183 [SR] Verify complete
2014-08-11 00:43:52, Info                  CSI    00000184 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:52, Info                  CSI    00000185 [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:53, Info                  CSI    00000188 [SR] Verify complete
2014-08-11 00:43:54, Info                  CSI    00000189 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:54, Info                  CSI    0000018a [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:56, Info                  CSI    0000018d [SR] Verify complete
2014-08-11 00:43:56, Info                  CSI    0000018e [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:56, Info                  CSI    0000018f [SR] Beginning Verify and Repair transaction
2014-08-11 00:43:58, Info                  CSI    00000192 [SR] Verify complete
2014-08-11 00:43:58, Info                  CSI    00000193 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:43:58, Info                  CSI    00000194 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:01, Info                  CSI    00000197 [SR] Verify complete
2014-08-11 00:44:01, Info                  CSI    00000198 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:01, Info                  CSI    00000199 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:03, Info                  CSI    0000019b [SR] Verify complete
2014-08-11 00:44:03, Info                  CSI    0000019c [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:03, Info                  CSI    0000019d [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:04, Info                  CSI    0000019f [SR] Verify complete
2014-08-11 00:44:04, Info                  CSI    000001a0 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:04, Info                  CSI    000001a1 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:05, Info                  CSI    000001a3 [SR] Verify complete
2014-08-11 00:44:05, Info                  CSI    000001a4 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:05, Info                  CSI    000001a5 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:06, Info                  CSI    000001a7 [SR] Verify complete
2014-08-11 00:44:06, Info                  CSI    000001a8 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:06, Info                  CSI    000001a9 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:08, Info                  CSI    000001ab [SR] Verify complete
2014-08-11 00:44:08, Info                  CSI    000001ac [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:08, Info                  CSI    000001ad [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:09, Info                  CSI    000001af [SR] Verify complete
2014-08-11 00:44:10, Info                  CSI    000001b0 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:10, Info                  CSI    000001b1 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:10, Info                  CSI    000001b3 [SR] Verify complete
2014-08-11 00:44:10, Info                  CSI    000001b4 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:10, Info                  CSI    000001b5 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:13, Info                  CSI    000001b7 [SR] Verify complete
2014-08-11 00:44:13, Info                  CSI    000001b8 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:13, Info                  CSI    000001b9 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:18, Info                  CSI    000001bb [SR] Verify complete
2014-08-11 00:44:19, Info                  CSI    000001bc [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:19, Info                  CSI    000001bd [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:20, Info                  CSI    000001bf [SR] Verify complete
2014-08-11 00:44:20, Info                  CSI    000001c0 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:20, Info                  CSI    000001c1 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:21, Info                  CSI    000001c3 [SR] Verify complete
2014-08-11 00:44:21, Info                  CSI    000001c4 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:21, Info                  CSI    000001c5 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:22, Info                  CSI    000001c7 [SR] Verify complete
2014-08-11 00:44:22, Info                  CSI    000001c8 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:22, Info                  CSI    000001c9 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:23, Info                  CSI    000001cb [SR] Verify complete
2014-08-11 00:44:23, Info                  CSI    000001cc [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:23, Info                  CSI    000001cd [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:24, Info                  CSI    000001cf [SR] Verify complete
2014-08-11 00:44:24, Info                  CSI    000001d0 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:24, Info                  CSI    000001d1 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:25, Info                  CSI    000001d3 [SR] Verify complete
2014-08-11 00:44:25, Info                  CSI    000001d4 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:25, Info                  CSI    000001d5 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:26, Info                  CSI    000001d7 [SR] Verify complete
2014-08-11 00:44:26, Info                  CSI    000001d8 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:26, Info                  CSI    000001d9 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:28, Info                  CSI    000001e1 [SR] Verify complete
2014-08-11 00:44:29, Info                  CSI    000001e2 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:29, Info                  CSI    000001e3 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:29, Info                  CSI    000001e5 [SR] Verify complete
2014-08-11 00:44:30, Info                  CSI    000001e6 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:30, Info                  CSI    000001e7 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:30, Info                  CSI    000001e9 [SR] Verify complete
2014-08-11 00:44:31, Info                  CSI    000001ea [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:31, Info                  CSI    000001eb [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:31, Info                  CSI    000001ed [SR] Verify complete
2014-08-11 00:44:31, Info                  CSI    000001ee [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:31, Info                  CSI    000001ef [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:33, Info                  CSI    000001f1 [SR] Verify complete
2014-08-11 00:44:33, Info                  CSI    000001f2 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:33, Info                  CSI    000001f3 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:35, Info                  CSI    000001f6 [SR] Verify complete
2014-08-11 00:44:35, Info                  CSI    000001f7 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:35, Info                  CSI    000001f8 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:38, Info                  CSI    000001fa [SR] Verify complete
2014-08-11 00:44:38, Info                  CSI    000001fb [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:38, Info                  CSI    000001fc [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:38, Info                  CSI    000001fe [SR] Verify complete
2014-08-11 00:44:39, Info                  CSI    000001ff [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:39, Info                  CSI    00000200 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:42, Info                  CSI    00000202 [SR] Verify complete
2014-08-11 00:44:42, Info                  CSI    00000203 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:42, Info                  CSI    00000204 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:46, Info                  CSI    00000209 [SR] Verify complete
2014-08-11 00:44:46, Info                  CSI    0000020a [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:46, Info                  CSI    0000020b [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:48, Info                  CSI    00000210 [SR] Verify complete
2014-08-11 00:44:48, Info                  CSI    00000211 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:48, Info                  CSI    00000212 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:51, Info                  CSI    00000218 [SR] Verify complete
2014-08-11 00:44:51, Info                  CSI    00000219 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:51, Info                  CSI    0000021a [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:54, Info                  CSI    00000223 [SR] Verify complete
2014-08-11 00:44:54, Info                  CSI    00000224 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:54, Info                  CSI    00000225 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:56, Info                  CSI    0000022a [SR] Verify complete
2014-08-11 00:44:56, Info                  CSI    0000022b [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:56, Info                  CSI    0000022c [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:57, Info                  CSI    0000022e [SR] Verify complete
2014-08-11 00:44:57, Info                  CSI    0000022f [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:57, Info                  CSI    00000230 [SR] Beginning Verify and Repair transaction
2014-08-11 00:44:58, Info                  CSI    00000234 [SR] Verify complete
2014-08-11 00:44:59, Info                  CSI    00000235 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:44:59, Info                  CSI    00000236 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:01, Info                  CSI    0000024d [SR] Verify complete
2014-08-11 00:45:01, Info                  CSI    0000024e [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:01, Info                  CSI    0000024f [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:03, Info                  CSI    0000025f [SR] Verify complete
2014-08-11 00:45:03, Info                  CSI    00000260 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:03, Info                  CSI    00000261 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:04, Info                  CSI    00000263 [SR] Verify complete
2014-08-11 00:45:04, Info                  CSI    00000264 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:04, Info                  CSI    00000265 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:06, Info                  CSI    00000267 [SR] Verify complete
2014-08-11 00:45:06, Info                  CSI    00000268 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:06, Info                  CSI    00000269 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:07, Info                  CSI    0000026b [SR] Verify complete
2014-08-11 00:45:07, Info                  CSI    0000026c [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:07, Info                  CSI    0000026d [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:08, Info                  CSI    0000027b [SR] Verify complete
2014-08-11 00:45:08, Info                  CSI    0000027c [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:08, Info                  CSI    0000027d [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:10, Info                  CSI    00000281 [SR] Verify complete
2014-08-11 00:45:10, Info                  CSI    00000282 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:10, Info                  CSI    00000283 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:13, Info                  CSI    0000028f [SR] Verify complete
2014-08-11 00:45:14, Info                  CSI    00000290 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:14, Info                  CSI    00000291 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:14, Info                  CSI    00000293 [SR] Verify complete
2014-08-11 00:45:14, Info                  CSI    00000294 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:14, Info                  CSI    00000295 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:16, Info                  CSI    00000298 [SR] Verify complete
2014-08-11 00:45:16, Info                  CSI    00000299 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:16, Info                  CSI    0000029a [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:17, Info                  CSI    0000029c [SR] Verify complete
2014-08-11 00:45:17, Info                  CSI    0000029d [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:17, Info                  CSI    0000029e [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:18, Info                  CSI    000002a0 [SR] Verify complete
2014-08-11 00:45:18, Info                  CSI    000002a1 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:18, Info                  CSI    000002a2 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:19, Info                  CSI    000002a4 [SR] Verify complete
2014-08-11 00:45:20, Info                  CSI    000002a5 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:20, Info                  CSI    000002a6 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:21, Info                  CSI    000002a8 [SR] Verify complete
2014-08-11 00:45:21, Info                  CSI    000002a9 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:21, Info                  CSI    000002aa [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:25, Info                  CSI    000002c4 [SR] Verify complete
2014-08-11 00:45:25, Info                  CSI    000002c5 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:25, Info                  CSI    000002c6 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:26, Info                  CSI    000002c8 [SR] Verify complete
2014-08-11 00:45:26, Info                  CSI    000002c9 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:26, Info                  CSI    000002ca [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:33, Info                  CSI    000002cc [SR] Verify complete
2014-08-11 00:45:33, Info                  CSI    000002cd [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:33, Info                  CSI    000002ce [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:34, Info                  CSI    000002d0 [SR] Verify complete
2014-08-11 00:45:35, Info                  CSI    000002d1 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:35, Info                  CSI    000002d2 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:35, Info                  CSI    000002d6 [SR] Verify complete
2014-08-11 00:45:36, Info                  CSI    000002d7 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:36, Info                  CSI    000002d8 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:37, Info                  CSI    000002da [SR] Verify complete
2014-08-11 00:45:37, Info                  CSI    000002db [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:37, Info                  CSI    000002dc [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:38, Info                  CSI    000002de [SR] Verify complete
2014-08-11 00:45:38, Info                  CSI    000002df [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:38, Info                  CSI    000002e0 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:39, Info                  CSI    000002e2 [SR] Verify complete
2014-08-11 00:45:39, Info                  CSI    000002e3 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:39, Info                  CSI    000002e4 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:41, Info                  CSI    000002e7 [SR] Verify complete
2014-08-11 00:45:41, Info                  CSI    000002e8 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:41, Info                  CSI    000002e9 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:42, Info                  CSI    000002eb [SR] Verify complete
2014-08-11 00:45:42, Info                  CSI    000002ec [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:42, Info                  CSI    000002ed [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:43, Info                  CSI    000002ef [SR] Verify complete
2014-08-11 00:45:43, Info                  CSI    000002f0 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:43, Info                  CSI    000002f1 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:45, Info                  CSI    000002f3 [SR] Verify complete
2014-08-11 00:45:45, Info                  CSI    000002f4 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:45, Info                  CSI    000002f5 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:46, Info                  CSI    000002f8 [SR] Verify complete
2014-08-11 00:45:46, Info                  CSI    000002f9 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:46, Info                  CSI    000002fa [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:48, Info                  CSI    000002fc [SR] Verify complete
2014-08-11 00:45:48, Info                  CSI    000002fd [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:48, Info                  CSI    000002fe [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:49, Info                  CSI    00000300 [SR] Verify complete
2014-08-11 00:45:50, Info                  CSI    00000301 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:50, Info                  CSI    00000302 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:50, Info                  CSI    00000304 [SR] Verify complete
2014-08-11 00:45:51, Info                  CSI    00000305 [SR] Verifying 100 (0x0000000000000064) components
2014-08-11 00:45:51, Info                  CSI    00000306 [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:52, Info                  CSI    00000308 [SR] Verify complete
2014-08-11 00:45:52, Info                  CSI    00000309 [SR] Verifying 0 components
2014-08-11 00:45:52, Info                  CSI    0000030a [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:52, Info                  CSI    0000030c [SR] Verify complete
2014-08-11 00:45:52, Info                  CSI    0000030d [SR] Repairing 0 components
2014-08-11 00:45:52, Info                  CSI    0000030e [SR] Beginning Verify and Repair transaction
2014-08-11 00:45:52, Info                  CSI    00000310 [SR] Repair complete


#10 OCD

OCD

    SuperHelper

  • Malware Team
  • 5,574 posts

Posted 11 August 2014 - 12:56 AM

Hi Temujin,
 

My computer has lately been skipping, pausing (with mouse not moving / freezing) for 5-10 seconds at a time, and frequently (1-2 times a day) shuts down on its own (oddly, it also turns on on its own sometimes, after I've shut it down for the night).

 

This might also be some sort of an electrical connection issue. Let's do a few more scans and see if we can rule out malware as the source of the problem.

=========================

bullseye_zpse9eaf36e.gif Malwarebytes' Anti-Malware

Download Malwarebytes' Anti-Malware (save it to your desktop).

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Select Scan tab.
    MBAMDashboard_zpsddef9b5f.gif
  • Select type of scan to perform:
    MBAMScanTab_zps2c5e74bd.gif
    • Threat Scan < --- Select this type of scan
    • Custom Scan
    • Hyper Scan
  • Next click the Scan button.
  • When the scan is complete, if no malicious items are found you can close the program.
  • If malicious items are found be sure that everything is checked, and click Quarantine .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

=========================

bullseye_zpse9eaf36e.gif ESET Online Scanner

*Note:

  • It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
  • Please don't go surfing while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.

** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

= = = = = = = = = = = = = = = = = = = =

Go here to run ESET Online Scanner

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notification Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Checked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.

=========================

In your next post please provide the following:


  • MBAM log
  • ESET's log.txt

OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days








If you are satisfied with the help you have received, please consider making a donation.

    Advertisements

Register to Remove


#11 Temujin

Temujin

    Authentic Member

  • Authentic Member
  • PipPip
  • 30 posts

Posted 13 August 2014 - 09:01 PM

Hi OCD,

 

Sorry for the delay in posting this time, once the workweek started, it was hard for me to pull together the chunk of time needed to run these scans. Here they are below!

 

Thanks again for your tireless help.

 

Basilio

 

----------------------

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 8/12/2014
Scan Time: 9:47:15 AM
Logfile: Malwarebytes Log.txt
Administrator: Yes
 
Version: 2.00.2.1012
Malware Database: v2014.08.12.04
Rootkit Database: v2014.08.04.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Temujin
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 349039
Time Elapsed: 9 min, 1 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
-------------------------
(ESET Log)
 
 
F:\Users\Temujin\AppData\Local\Temp\bitool.dll Win32/Somoto.B potentially unwanted application deleted - quarantined
F:\Users\Temujin\Downloads\MS Tools 8 FREE\MS Tools 8 FREE\load_it!.exe a variant of Win32/HackTool.Loader.B potentially unsafe application deleted - quarantined
I:\Movies\Astro Boy [2009]\Jaybob's_Movies_Toolbar_Internet Explorer.exe a variant of Win32/Toolbar.Conduit.B potentially unwanted application deleted - quarantined
 


#12 OCD

OCD

    SuperHelper

  • Malware Team
  • 5,574 posts

Posted 13 August 2014 - 09:26 PM

Hi Temujin,
 

once the workweek started, it was hard for me to pull together the chunk of time needed to run these scans.

 
That's completely understandable. Most volunteers will generally send a courtesy reminder after 3 days, and close the thread after 5 days of no response. So there is some "wiggle room" with your reply
 
==========================

Your logs seem pretty normal, and I'm not seeing any malware that would be causing the issues you have described.

  • I take it the condition hasn't improved?
  • Do any of the keys on the keyboard appear to be stuck, or slightly depressed?
  • What about the power on button for the computer, does it appear to be working properly?

Do you have access to a can of compressed air to clean both the keyboard and the power on button?


OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days








If you are satisfied with the help you have received, please consider making a donation.


#13 OCD

OCD

    SuperHelper

  • Malware Team
  • 5,574 posts

Posted 16 August 2014 - 08:29 PM

Hi Temujin,

Just checking in to see if you still need help?
OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days








If you are satisfied with the help you have received, please consider making a donation.


#14 Temujin

Temujin

    Authentic Member

  • Authentic Member
  • PipPip
  • 30 posts

Posted 18 August 2014 - 10:00 PM

Hi OCD,

 

My sincerest apologies being so late in replying! I really appreciate how diligent you've been following up with me. I can't express how great this service is you guys provide for everyone.

 

To effectively answer your question, I wanted to see if my computer showed any further signs of being weird after all those cleanings. Oddly, it does still after some time using it (maybe about 30 mins. to an hour or so), start to kind of "hiccup" - everything locks and freezes noticeably for a time, but then unlocks again after about 10 seconds or so, and continues as if nothing happened. Then it will do it again a few mins. later.

 

The other odd symptom I'm seeing when it does this is, even after it starts running again, the mouse cursor becomes a tiny thin line that is near-impossible to see when waving the mouse around. (It looks similar to the way a cursor is shaped when you're inputting a command on a command line.)

 

The only thing that makes this behavior go away, with subsequent regular hiccups and the cursor arrow looking odd, is to restart the system again. Once in awhile even when I don't restart, the system will finally get completely locked without stopping, then power off and restart itself. Very odd!

 

I wonder if there is a hardware failure then, happening somewhere in the system.

 

Anyway if there's no viruses/malware involved, I'm guessing that might have to be what I consider next. Shame, since it's just a 2 year old system!

 

Thanks for your help and advice through all this however, OCD.



#15 OCD

OCD

    SuperHelper

  • Malware Team
  • 5,574 posts

Posted 18 August 2014 - 11:43 PM

Hi Temujin,

At this point I'm kind of stumped as to what might be causing the problems you have described. If you like, I can refer you over to our Tech Team to see if they have any ideas about what might be causing your issues.

 

Start a new topic for the Tech Team in the General Hardware Forum

Give a brief description of the problem along with a link to this thread so the Tech Team helper can see what we have done already.
http://forums.whatth...opic=128491&hl=

We also need to do a bit of housekeeping, so let me know how you are planning to proceed. If you are going to seek help via the Tech Team we should do the housekeeping prior to you starting that process.


OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days








If you are satisfied with the help you have received, please consider making a donation.

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users