Cheltenham Jim
New member
I'm in a right mess, please can someone help?!!
Yesterday, my laptop wouldn't allow me to log on and would would give me a warning box like this one:
http://www.f-secure.com/system/fsgalleries/security-pics/rpc.gif
(but mentioned services.exe somewhere)
I thought it was unlikely but it might be a Blaster virus, but the symantec patch said it wasn't.
Norton Antivirus picked up nothing.
I tried Malwarebytes and a free version of Dr Web and spyhunter. All these shut down afer only a short time and I could not run the applications again. I only got a dialogue box that read:
Windows cannot access the specified device, path or file. You may not have the appropriate permission to access the item.
user on thie site, Gary Deskin, sounds like he has a condition similar to this and was advised to run Win32kDiag.exe
These are my results:
[1] 2007-03-06 02:22:59 716000 C:\WINDOWS\$hf_mig$\KB946026\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:20:44 755576 C:\WINDOWS\$hf_mig$\KB946648\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:59 716000 C:\WINDOWS\$hf_mig$\KB947864\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\$hf_mig$\KB947864-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2007-03-06 02:22:59 716000 C:\WINDOWS\$hf_mig$\KB948590\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\$hf_mig$\KB948881\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:59 716000 C:\WINDOWS\$hf_mig$\KB950749\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\$hf_mig$\KB950759-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB950760\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB950762\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB950974\update\update.exe (M
icrosoft Corporation)
[1] 2007-12-03 16:25:31 755576 C:\WINDOWS\$hf_mig$\KB951066\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe
(Microsoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB951376-v2\update\update.exe
(Microsoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB951698\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB951748\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB951978\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB952004\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB952287\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB952954\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\$hf_mig$\KB953838-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB953839\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB954211\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB954459\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB954600\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB955069\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB955839\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:59 716000 C:\WINDOWS\$hf_mig$\KB956390-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB956391\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB956572\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB956744\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB956802\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB956803\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB956841\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB957095\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-08 14:02:04 755576 C:\WINDOWS\$hf_mig$\KB957097\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\$hf_mig$\KB958215-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB958644\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB958687\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB958690\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB959426\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB960225\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\$hf_mig$\KB960714-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2008-11-15 18:18:04 755576 C:\WINDOWS\$hf_mig$\KB960715\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB960803\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB960859\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:59 716000 C:\WINDOWS\$hf_mig$\KB961260-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB961371\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB961373\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB961501\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB963027-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB967715\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB968537\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB969897-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB969897-IE8\update\update.ex
e (Microsoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB969898\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB970238\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB971557\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB971633\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB971657\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB972260-IE8\update\update.ex
e (Microsoft Corporation)
[1] 2008-07-08 14:02:04 755576 C:\WINDOWS\$hf_mig$\KB972636-IE8\update\update.ex
e (Microsoft Corporation)
[1] 2008-07-08 14:02:04 755576 C:\WINDOWS\$hf_mig$\KB973346\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB973354\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB973507\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB973815\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-08 14:02:04 755576 C:\WINDOWS\$hf_mig$\KB973869\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\07a96de1
76867bc25b7dc839d22b07e2\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\0dd02448
16ffb4b094c1caba4c3b1178\update\update.exe (Microsoft Corporation)
[1] 2005-10-13 00:12:28 716000 C:\WINDOWS\SoftwareDistribution\Download\0facce61
15ab861022eae3087e064a2a\update\update.exe (Microsoft Corporation)
[1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\122ece42
0ea2cadf18cdf04c90b6d8f1\update\update.exe (Microsoft Corporation)
[1] 2008-07-08 14:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\2c95b283
51986132d7f36dd28eece9b0\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\4f16665a
c0e64727d0b09512c7b6d40c\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\555558d2
c7916b118ad5baef62b18136\update\update.exe ()
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\SoftwareDistribution\Download\574548bb
1821009dfc939b99bf38919d\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\67816263
9e69c808c1768ab6340eae25\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\6913c676
e5d33978934caa46c49fdc75\update\update.exe (Microsoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\SoftwareDistribution\Download\6b4e49f1
a78b9558feeb103a07b06a32\update\update.exe ()
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\SoftwareDistribution\Download\97fe76a2
0161cb86e78057600e7c82a0\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\9cf59263
a134ab3fbbee78365a2fa5fc\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\b7f0b289
2b21211a5630518d058f48d9\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\d48a3b96
7ba5709df048e8f2a49cf8a6\update\update.exe (Microsoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\SoftwareDistribution\Download\e5a204b0
8ee9dd0f7a20547e61486b27\update\update.exe (Microsoft Corporation)
[1] 2008-07-08 14:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\e740a724
58caa5dc68334c7afa82ebf3\update\update.exe (Microsoft Corporation)
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\b7f0b2892b212
11a5630518d058f48d9\backup\backup
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba57
09df048e8f2a49cf8a6\backup\backup
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SxsCaPendDel\SxsCaPendDel
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1025\1025
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1028\1028
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1031\1031
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1037\1037
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1041\1041
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1042\1042
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1054\1054
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\2052\2052
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\3076\3076
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\3com_dmi\3com_dmi
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Adobe\update\update
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application D
ata\Microsoft\Media Player\Media Player
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application D
ata\Microsoft\SystemCertificates\My\Certificates\Certificates
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application D
ata\Microsoft\SystemCertificates\My\CRLs\CRLs
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application D
ata\Microsoft\SystemCertificates\My\CTLs\CTLs
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Desktop\Deskt
op
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Favorites\Fav
orites
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Setting
s\Temp\Temp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\My Documents\
My Documents
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\NetHood\NetHo
od
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\PrintHood\Pri
ntHood
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Recent\Recent
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\dhcp\dhcp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\drivers\disdn\disdn
Mount point destination : \Device\__max++>\^
Cannot access: C:\WINDOWS\system32\dumprep.exe
[1] 2004-08-04 13:00:00 10752 C:\WINDOWS\$NtServicePackUninstall$\dumprep.exe (M
icrosoft Corporation)
[1] 2008-04-14 01:12:18 10752 C:\WINDOWS\ServicePackFiles\i386\dumprep.exe (Micr
osoft Corporation)
[1] 2008-04-14 01:12:18 10752 C:\WINDOWS\system32\dumprep.exe ()
Cannot access: C:\WINDOWS\system32\eventlog.dll
[1] 2004-08-04 13:00:00 55808 C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll (
Microsoft Corporation)
[1] 2008-04-14 01:11:53 56320 C:\WINDOWS\ServicePackFiles\i386\eventlog.dll (Mic
rosoft Corporation)
[1] 2008-04-14 01:11:53 62976 C:\WINDOWS\system32\eventlog.dll ()
[2] 2008-04-14 01:11:53 56320 C:\WINDOWS\system32\logevent.dll (Microsoft Corpor
ation)
Found mount point : C:\WINDOWS\system32\export\export
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\IME\CINTLGNT\CINTLGNT
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\IME\PINTLGNT\PINTLGNT
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\IME\TINTLGNT\TINTLGNT
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\inetsrv\inetsrv
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\mui\dispspec\dispspec
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\html\oemcust\oemcust
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\html\oemhw\oemhw
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\html\oemreg\oemreg
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\sample\sample
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\ShellExt\ShellExt
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\spool\PRINTERS\PRINTERS
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wbem\mof\bad\bad
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wbem\mof\good\good
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wbem\snmp\snmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wins\wins
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\xircom\xircom
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\Google Toolbar\Google Toolbar
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18
e3b_8.0.50727.1433_x-ww_5cf844d2\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.507
27.1433_x-ww_5cf844d2
Mount point destination : \Device\__max++>\^
Finished! Press any key to exit...
Yesterday, my laptop wouldn't allow me to log on and would would give me a warning box like this one:
http://www.f-secure.com/system/fsgalleries/security-pics/rpc.gif
(but mentioned services.exe somewhere)
I thought it was unlikely but it might be a Blaster virus, but the symantec patch said it wasn't.
Norton Antivirus picked up nothing.
I tried Malwarebytes and a free version of Dr Web and spyhunter. All these shut down afer only a short time and I could not run the applications again. I only got a dialogue box that read:
Windows cannot access the specified device, path or file. You may not have the appropriate permission to access the item.
user on thie site, Gary Deskin, sounds like he has a condition similar to this and was advised to run Win32kDiag.exe
These are my results:
[1] 2007-03-06 02:22:59 716000 C:\WINDOWS\$hf_mig$\KB946026\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:20:44 755576 C:\WINDOWS\$hf_mig$\KB946648\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:59 716000 C:\WINDOWS\$hf_mig$\KB947864\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\$hf_mig$\KB947864-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2007-03-06 02:22:59 716000 C:\WINDOWS\$hf_mig$\KB948590\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\$hf_mig$\KB948881\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:59 716000 C:\WINDOWS\$hf_mig$\KB950749\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\$hf_mig$\KB950759-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB950760\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB950762\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB950974\update\update.exe (M
icrosoft Corporation)
[1] 2007-12-03 16:25:31 755576 C:\WINDOWS\$hf_mig$\KB951066\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe
(Microsoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB951376-v2\update\update.exe
(Microsoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB951698\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB951748\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB951978\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB952004\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB952287\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB952954\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\$hf_mig$\KB953838-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB953839\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB954211\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB954459\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB954600\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB955069\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB955839\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:59 716000 C:\WINDOWS\$hf_mig$\KB956390-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB956391\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB956572\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB956744\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB956802\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB956803\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB956841\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB957095\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-08 14:02:04 755576 C:\WINDOWS\$hf_mig$\KB957097\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\$hf_mig$\KB958215-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB958644\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\$hf_mig$\KB958687\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB958690\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB959426\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB960225\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\$hf_mig$\KB960714-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2008-11-15 18:18:04 755576 C:\WINDOWS\$hf_mig$\KB960715\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB960803\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB960859\update\update.exe (M
icrosoft Corporation)
[1] 2007-03-06 02:22:59 716000 C:\WINDOWS\$hf_mig$\KB961260-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB961371\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB961373\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB961501\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB963027-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB967715\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB968537\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB969897-IE7\update\update.ex
e (Microsoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB969897-IE8\update\update.ex
e (Microsoft Corporation)
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\$hf_mig$\KB969898\update\update.exe (M
icrosoft Corporation)
[1] 2007-11-30 13:39:18 755576 C:\WINDOWS\$hf_mig$\KB970238\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB971557\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-09 08:38:29 755576 C:\WINDOWS\$hf_mig$\KB971633\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB971657\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB972260-IE8\update\update.ex
e (Microsoft Corporation)
[1] 2008-07-08 14:02:04 755576 C:\WINDOWS\$hf_mig$\KB972636-IE8\update\update.ex
e (Microsoft Corporation)
[1] 2008-07-08 14:02:04 755576 C:\WINDOWS\$hf_mig$\KB973346\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB973354\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB973507\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\$hf_mig$\KB973815\update\update.exe (M
icrosoft Corporation)
[1] 2008-07-08 14:02:04 755576 C:\WINDOWS\$hf_mig$\KB973869\update\update.exe (M
icrosoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\07a96de1
76867bc25b7dc839d22b07e2\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\0dd02448
16ffb4b094c1caba4c3b1178\update\update.exe (Microsoft Corporation)
[1] 2005-10-13 00:12:28 716000 C:\WINDOWS\SoftwareDistribution\Download\0facce61
15ab861022eae3087e064a2a\update\update.exe (Microsoft Corporation)
[1] 2007-07-27 10:41:48 755576 C:\WINDOWS\SoftwareDistribution\Download\122ece42
0ea2cadf18cdf04c90b6d8f1\update\update.exe (Microsoft Corporation)
[1] 2008-07-08 14:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\2c95b283
51986132d7f36dd28eece9b0\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\4f16665a
c0e64727d0b09512c7b6d40c\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\555558d2
c7916b118ad5baef62b18136\update\update.exe ()
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\SoftwareDistribution\Download\574548bb
1821009dfc939b99bf38919d\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\67816263
9e69c808c1768ab6340eae25\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\6913c676
e5d33978934caa46c49fdc75\update\update.exe (Microsoft Corporation)
[1] 2007-11-30 12:18:51 755576 C:\WINDOWS\SoftwareDistribution\Download\6b4e49f1
a78b9558feeb103a07b06a32\update\update.exe ()
[1] 2007-11-30 13:39:22 755576 C:\WINDOWS\SoftwareDistribution\Download\97fe76a2
0161cb86e78057600e7c82a0\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\9cf59263
a134ab3fbbee78365a2fa5fc\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\b7f0b289
2b21211a5630518d058f48d9\update\update.exe (Microsoft Corporation)
[1] 2009-05-26 12:40:52 755576 C:\WINDOWS\SoftwareDistribution\Download\d48a3b96
7ba5709df048e8f2a49cf8a6\update\update.exe (Microsoft Corporation)
[1] 2007-03-06 02:22:56 716000 C:\WINDOWS\SoftwareDistribution\Download\e5a204b0
8ee9dd0f7a20547e61486b27\update\update.exe (Microsoft Corporation)
[1] 2008-07-08 14:02:04 755576 C:\WINDOWS\SoftwareDistribution\Download\e740a724
58caa5dc68334c7afa82ebf3\update\update.exe (Microsoft Corporation)
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\b7f0b2892b212
11a5630518d058f48d9\backup\backup
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba57
09df048e8f2a49cf8a6\backup\backup
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SxsCaPendDel\SxsCaPendDel
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1025\1025
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1028\1028
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1031\1031
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1037\1037
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1041\1041
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1042\1042
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1054\1054
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\2052\2052
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\3076\3076
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\3com_dmi\3com_dmi
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Adobe\update\update
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application D
ata\Microsoft\Media Player\Media Player
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application D
ata\Microsoft\SystemCertificates\My\Certificates\Certificates
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application D
ata\Microsoft\SystemCertificates\My\CRLs\CRLs
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Application D
ata\Microsoft\SystemCertificates\My\CTLs\CTLs
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Desktop\Deskt
op
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Favorites\Fav
orites
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Setting
s\Temp\Temp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\My Documents\
My Documents
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\NetHood\NetHo
od
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\PrintHood\Pri
ntHood
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config\systemprofile\Recent\Recent
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\dhcp\dhcp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\drivers\disdn\disdn
Mount point destination : \Device\__max++>\^
Cannot access: C:\WINDOWS\system32\dumprep.exe
[1] 2004-08-04 13:00:00 10752 C:\WINDOWS\$NtServicePackUninstall$\dumprep.exe (M
icrosoft Corporation)
[1] 2008-04-14 01:12:18 10752 C:\WINDOWS\ServicePackFiles\i386\dumprep.exe (Micr
osoft Corporation)
[1] 2008-04-14 01:12:18 10752 C:\WINDOWS\system32\dumprep.exe ()
Cannot access: C:\WINDOWS\system32\eventlog.dll
[1] 2004-08-04 13:00:00 55808 C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll (
Microsoft Corporation)
[1] 2008-04-14 01:11:53 56320 C:\WINDOWS\ServicePackFiles\i386\eventlog.dll (Mic
rosoft Corporation)
[1] 2008-04-14 01:11:53 62976 C:\WINDOWS\system32\eventlog.dll ()
[2] 2008-04-14 01:11:53 56320 C:\WINDOWS\system32\logevent.dll (Microsoft Corpor
ation)
Found mount point : C:\WINDOWS\system32\export\export
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\IME\CINTLGNT\CINTLGNT
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\IME\PINTLGNT\PINTLGNT
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\IME\TINTLGNT\TINTLGNT
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\inetsrv\inetsrv
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\mui\dispspec\dispspec
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\html\oemcust\oemcust
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\html\oemhw\oemhw
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\html\oemreg\oemreg
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\sample\sample
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\ShellExt\ShellExt
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\spool\PRINTERS\PRINTERS
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wbem\mof\bad\bad
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wbem\mof\good\good
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wbem\snmp\snmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wins\wins
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\xircom\xircom
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\Google Toolbar\Google Toolbar
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18
e3b_8.0.50727.1433_x-ww_5cf844d2\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.507
27.1433_x-ww_5cf844d2
Mount point destination : \Device\__max++>\^
Finished! Press any key to exit...