Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: VistaAntispyware 2012 ???  (Read 30157 times)

0 Members and 1 Guest are viewing this topic.

MtlHab39

    Topic Starter


    Beginner

    • Experience: Beginner
    • OS: Unknown
    Re: VistaAntispyware 2012 ???
    « Reply #45 on: February 14, 2012, 04:41:11 PM »
    Done and  completed within ~10 seconds.
    Opened diagnosis and repair details

    Last successful boot time: 2/14/2012 10:58:55 PM (GMT)

    Session details
    System disk= device/harddisk0
    Windows directory= D:/Windows
    AutoChk Run = 0
    Number of root causes = 1

    Lists several tests (check for updates, system disk test, disk failure diagnosis, disk metadata test,  target OS test, volume content check, Boot manager diagnosis, system boot log diagnosis, event log diagnosis, internal state check, boot status test) that were all completed successfully.

    Last comment is

    Root cause found:
    Boot status indicates that the OS booted successfully.

    That is it.

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: VistaAntispyware 2012 ???
    « Reply #46 on: February 14, 2012, 05:03:34 PM »
    Ok. Please try running the FarBar Service Scanner in Reply # 34
    Windows 8 and Windows 10 dual boot with two SSD's

    MtlHab39

      Topic Starter


      Beginner

      • Experience: Beginner
      • OS: Unknown
      Re: VistaAntispyware 2012 ???
      « Reply #47 on: February 15, 2012, 04:32:09 PM »
      Guess it still can't find that 'file'

      Farbar Service Scanner Version: 10-02-2012
      Ran by Costa (administrator) on 15-02-2012 at 18:24:33
      Running from "E:\FarBar"
      Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86)
      Boot Mode: Nerwork
      ****************************************************************

      Internet Services:
      ============
      Dnscache Service is not running. Checking service configuration:
      The start type of Dnscache service is OK.
      The ImagePath of Dnscache service is OK.
      The ServiceDll of Dnscache service is OK.

      Dhcp Service is not running. Checking service configuration:
      The start type of Dhcp service is OK.
      The ImagePath of Dhcp service is OK.
      The ServiceDll of Dhcp service is OK.

      tdx Service is not running. Checking service configuration:
      The start type of tdx service is OK.
      The ImagePath of tdx service is OK.


      Connection Status:
      ==============
      Localhost is accessible.
      LAN connected.
      Google IP is accessible.
      Yahoo IP is accessible.


      Windows Firewall:
      =============
      mpsdrv Service is not running. Checking service configuration:
      The start type of mpsdrv service is OK.
      The ImagePath of mpsdrv service is OK.

      MpsSvc Service is not running. Checking service configuration:
      Checking Start type: Attention! Unable to open MpsSvc registry key. The service key does not exist.
      Checking ImagePath: Attention! Unable to open MpsSvc registry key. The service key does not exist.
      Checking ServiceDll: Attention! Unable to open MpsSvc registry key. The service key does not exist.
      Checking LEGACY_MpsSvc: Attention! Unable to open LEGACY_MpsSvc\0000 registry key. The key does not exist.

      bfe Service is not running. Checking service configuration:
      The start type of bfe service is set to Demand. The default start type is Auto.
      The ImagePath of bfe: "NADA".
      Checking ServiceDll: Attention! Unable to open bfe registry key. The service key does not exist.
      Checking LEGACY_bfe: Attention! Unable to open LEGACY_bfe\0000 registry key. The key does not exist.


      Firewall Disabled Policy:
      ==================


      System Restore:
      ============
      SDRSVC Service is not running. Checking service configuration:
      The start type of SDRSVC service is OK.
      The ImagePath of SDRSVC service is OK.
      The ServiceDll of SDRSVC service is OK.
      Checking LEGACY_SDRSVC: Attention! Unable to open LEGACY_SDRSVC\0000 registry key. The key does not exist.

      VSS Service is not running. Checking service configuration:
      The start type of VSS service is OK.
      The ImagePath of VSS service is OK.


      System Restore Disabled Policy:
      ========================


      Security Center:
      ============
      wscsvc Service is not running. Checking service configuration:
      The start type of wscsvc service is OK.
      The ImagePath of wscsvc service is OK.
      The ServiceDll of wscsvc service is OK.
      Checking LEGACY_wscsvc: Attention! Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist.


      Windows Update:
      ============
      wuauserv Service is not running. Checking service configuration:
      The start type of wuauserv service is OK.
      The ImagePath of wuauserv service is OK.
      The ServiceDll of wuauserv service is OK.

      BITS Service is not running. Checking service configuration:
      The start type of BITS service is OK.
      The ImagePath of BITS service is OK.
      The ServiceDll of BITS service is OK.
      Checking LEGACY_BITS: Attention! Unable to open LEGACY_BITS\0000 registry key. The key does not exist.

      EventSystem Service is not running. Checking service configuration:
      The start type of EventSystem service is OK.
      The ImagePath of EventSystem service is OK.
      The ServiceDll of EventSystem service is OK.


      File Check:
      ========
      C:\Windows\system32\nsisvc.dll => MD5 is legit
      C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
      C:\Windows\system32\dhcpcsvc.dll => MD5 is legit
      C:\Windows\system32\Drivers\afd.sys => MD5 is legit
      Attention! C:\Windows\system32\Drivers\tdx.sys is missing.
      C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
      C:\Windows\system32\dnsrslvr.dll => MD5 is legit
      C:\Windows\system32\mpssvc.dll => MD5 is legit
      C:\Windows\system32\bfe.dll => MD5 is legit
      C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
      C:\Windows\system32\SDRSVC.dll => MD5 is legit
      C:\Windows\system32\vssvc.exe => MD5 is legit
      C:\Windows\system32\wscsvc.dll => MD5 is legit
      C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
      C:\Windows\system32\wuaueng.dll => MD5 is legit
      C:\Windows\system32\qmgr.dll => MD5 is legit
      C:\Windows\system32\es.dll => MD5 is legit
      C:\Windows\system32\cryptsvc.dll => MD5 is legit
      C:\Windows\system32\svchost.exe => MD5 is legit
      C:\Windows\system32\rpcss.dll => MD5 is legit


      **** End of log ****

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: VistaAntispyware 2012 ???
      « Reply #48 on: February 15, 2012, 05:34:50 PM »
      Let's try to find this file again.You should already have this program on your desktop.

      Please download SystemLook from one of the links below and save it to your desktop.

      Link # 1
      Link # 2

      Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

      Double-click SystemLook.exe to run it.

      Copy the contents of the following codebox into the main textfield.
      Code: [Select]
      :filefind
      tdx.sys

      Click the Look button to start the scan.

      Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer).

      When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt
      Windows 8 and Windows 10 dual boot with two SSD's

      MtlHab39

        Topic Starter


        Beginner

        • Experience: Beginner
        • OS: Unknown
        Re: VistaAntispyware 2012 ???
        « Reply #49 on: February 15, 2012, 09:56:57 PM »
        SystemLook 30.07.11 by jpshortstuff
        System Look tonight

        Log created at 23:11 on 15/02/2012 by Costa
        Administrator - Elevation successful

        ========== filefind ==========

        Searching for "tdx.sys"
        C:\Windows\winsxs\x86_microsoft-windows-tdi-over-tcpip_31bf3856ad364e35_6.0.6001.18000_none_ea3dc84bdc15a8b7\tdx.sys   --a---- 71680 bytes   [02:34 21/01/2008]   [02:34 21/01/2008] D09276B1FAB033CE1D40DCBDF303D10F

        -= EOF =-

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: VistaAntispyware 2012 ???
        « Reply #50 on: February 16, 2012, 10:42:18 AM »
        Could you please check your Device Manager to see if there are any yellow warning flags?
        Please delete ComboFix from your desktop, download a new version and run another scan. The instructions are in Reply # 7.
        Windows 8 and Windows 10 dual boot with two SSD's

        MtlHab39

          Topic Starter


          Beginner

          • Experience: Beginner
          • OS: Unknown
          Re: VistaAntispyware 2012 ???
          « Reply #51 on: February 16, 2012, 04:46:22 PM »
          Clicked on Device manager; everything is listed; no yellow flags anywhere

          MtlHab39

            Topic Starter


            Beginner

            • Experience: Beginner
            • OS: Unknown
            Re: VistaAntispyware 2012 ???
            « Reply #52 on: February 16, 2012, 10:02:40 PM »
            Trying to run new combofix.
            Once autoscan opens up; first info tells me 'failed to get data for 'enableLVA'
            second separate window again pops up with

            You are infected with Rootkit.ZeroAccess!It has inserted itself into the tcp/ip stack.  This is a particularly difficult infection.  If for any reason that you're unable to connect to the internet, log off and reboot machine and rerun combofix.

            I left it alone and autoscan continues; its been 3 hrs on another pop up "detected rootkit activity and need to reboot" - finally x'ed it and then machine rebooted; placed it in safe mode (previous combofix attempt was in regular mode).

            Am leaving the laptop on to see what will happen with Rootkit box opened.

            Side question: my Java is outdated and reading around seems to pose a risk for intruders
            should I uninstall it?

            Thanks

            Geek-9pm


              Mastermind
            • Geek After Dark
            • Thanked: 1026
              • Gekk9pm bnlog
            • Certifications: List
            • Computer: Specs
            • Experience: Expert
            • OS: Windows 10
            Re: VistaAntispyware 2012 ???
            « Reply #53 on: February 16, 2012, 10:11:35 PM »
            Dear OP:
            Quote
            You are infected with Rootkit.ZeroAccess!It has inserted itself into the tcp/ip stack.  This is a particularly difficult infection.  If for any reason that you're unable to connect to the internet, log off and reboot machine and rerun combofix.
            That kind of warning is extremely serious.
            There are no shortcuts around it.
            Please pay attention to the experts who are trying to help you.

            SuperDave

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: VistaAntispyware 2012 ???
            « Reply #54 on: February 17, 2012, 08:03:27 AM »
            Quote
            Side question: my Java is outdated and reading around seems to pose a risk for intruders
            should I uninstall it?
            No. Just update it.

            Update Your Java (JRE)

            Old versions of Java have vulnerabilities that malware can use to infect your system.


            First Verify your Java Version

            If there are any other version(s) installed then update now.

            Get the new version (if needed)

            If your version is out of date install the newest version of the Sun Java Runtime Environment.

            Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

            Be sure to close ALL open web browsers before starting the installation.

            Remove any old versions

            1. Download JavaRa and unzip the file to your Desktop.
            2. Open JavaRA.exe and choose Remove Older Versions
            3. Once complete exit JavaRA.

            Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
            *************************************************************
            Let's try ComboFix with this:

            Delete your copy of ComboFix; download a fresh copy, except before you download it, rename it to blackpudding.bat

            Navigate to Start --> Run, and enter the following command exactly as shown:

            "%userprofile%\desktop\blackpudding.bat" /killall

            See if ComboFix will run now
            Windows 8 and Windows 10 dual boot with two SSD's

            MtlHab39

              Topic Starter


              Beginner

              • Experience: Beginner
              • OS: Unknown
              Re: VistaAntispyware 2012 ???
              « Reply #55 on: February 18, 2012, 08:19:24 AM »
              Did rename prior to downloading on PC; brought to laptop with USB; deleted old combofix on desktop; zipped new pudding name/file onto desktop; cut and paste the command and laptop is telling me that it cannot find it!!!

              After that no-go, am trying to run combofix via pudding from USB-pudding file, so far same discovery of rootkit message, another box opened with 'Rootkit is detected. Be patient as this may take some moments' message.  Two loud beeps and now box 'Combofix has detected the presence of rootkit activity and needs to reboot the machine'

              Will wait and see what happens and update a post.
              Have to say you must be one patient fellow; have felt numerous times to zing this laptop into the dumpster!!!!!!!!!!!!!!!!

              Also for Java, can I download onto the USB via desktop the latest version-link and carry it to laptop with USB?

              SuperDave

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: VistaAntispyware 2012 ???
              « Reply #56 on: February 18, 2012, 11:19:11 AM »
              Quote
              Also for Java, can I download onto the USB via desktop the latest version-link and carry it to laptop with USB? 
              That should work. Don't forget to uninstall the old versions.
              Windows 8 and Windows 10 dual boot with two SSD's

              MtlHab39

                Topic Starter


                Beginner

                • Experience: Beginner
                • OS: Unknown
                Re: VistaAntispyware 2012 ???
                « Reply #57 on: February 18, 2012, 11:55:07 AM »
                Did rename prior to downloading on PC; brought to laptop with USB; deleted old combofix on desktop; zipped new pudding name/file onto desktop; cut and paste the command and laptop is telling me that it cannot find it!!!

                After that no-go, am trying to run combofix via pudding from USB-pudding file, so far same discovery of rootkit message, another box opened with 'Rootkit is detected. Be patient as this may take some moments' message.  Two loud beeps and now box 'Combofix has detected the presence of rootkit activity and needs to reboot the machine'

                Will wait and see what happens and update a post.


                That box has remained on desktop for 3 hrs now.

                SuperDave

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: VistaAntispyware 2012 ???
                « Reply #58 on: February 18, 2012, 06:25:20 PM »
                Quote
                That box has remained on desktop for 3 hrs now.
                That's too long. You can abort that operation. I'm running out of tools to run on this computer. Soon we will have to look at saving your important data and running the Recovery Console to restore your computer back to the day you purchased it.

                Download BootKit Remover to your Desktop.

                •You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip

                •After extracing remover.exe to your Desktop, double-click on remover.exe to run the program (Vista/7 users,right click on remover.exe and click Run As Administrator.

                •It will show a Black screen with some data on it.

                •Right click on the screen and click Select All.

                •Press Enter

                •Open a Notepad and press CTRL V

                •Post the output back here.
                Windows 8 and Windows 10 dual boot with two SSD's

                MtlHab39

                  Topic Starter


                  Beginner

                  • Experience: Beginner
                  • OS: Unknown
                  Re: VistaAntispyware 2012 ???
                  « Reply #59 on: February 18, 2012, 08:52:52 PM »
                  This is a bootkit debug log; don't think you needed this but the file was there

                  .\debug.cpp(238) : Debug log started at 19.02.2012 - 03:38:14
                  .\boot_cleaner.cpp(527) : Bootkit Remover
                  .\boot_cleaner.cpp(528) : (c) 2009 Esage Lab
                  .\boot_cleaner.cpp(529) : www.esagelab.com
                  .\boot_cleaner.cpp(533) : Program version: 1.2.0.1
                  .\boot_cleaner.cpp(540) : OS Version: Microsoft Windows Vista Home Basic Edition Service Pack 2 (build 6002), 32-bit
                  .\debug.cpp(248) : **********************************************
                  .\debug.cpp(249) : *** [ LOADED MODULES INFORMATION ] ***********
                  .\debug.cpp(250) : **********************************************
                  .\debug.cpp(256) : 0x8304a000 0x003ba000 "\SystemRoot\system32\ntkrnlpa.exe"
                  .\debug.cpp(256) : 0x83017000 0x00033000 "\SystemRoot\system32\hal.dll"
                  .\debug.cpp(256) : 0x80409000 0x00007000 "\SystemRoot\system32\kdcom.dll"
                  .\debug.cpp(256) : 0x80410000 0x00070000 "\SystemRoot\system32\mcupdate_GenuineIntel.dll"
                  .\debug.cpp(256) : 0x80480000 0x00011000 "\SystemRoot\system32\PSHED.dll"
                  .\debug.cpp(256) : 0x80491000 0x00008000 "\SystemRoot\system32\BOOTVID.dll"
                  .\debug.cpp(256) : 0x80499000 0x00041000 "\SystemRoot\system32\CLFS.SYS"
                  .\debug.cpp(256) : 0x804da000 0x000e0000 "\SystemRoot\system32\CI.dll"
                  .\debug.cpp(256) : 0x8060f000 0x0007c000 "\SystemRoot\system32\drivers\Wdf01000.sys"
                  .\debug.cpp(256) : 0x8068b000 0x0000d000 "\SystemRoot\system32\drivers\WDFLDR.SYS"
                  .\debug.cpp(256) : 0x80698000 0x00032000 "\SystemRoot\system32\drivers\fltmgr.sys"
                  .\debug.cpp(256) : 0x806ca000 0x00046000 "\SystemRoot\system32\drivers\acpi.sys"
                  .\debug.cpp(256) : 0x80710000 0x00009000 "\SystemRoot\system32\drivers\WMILIB.SYS"
                  .\debug.cpp(256) : 0x80719000 0x00008000 "\SystemRoot\system32\drivers\msisadrv.sys"
                  .\debug.cpp(256) : 0x80721000 0x00027000 "\SystemRoot\system32\drivers\pci.sys"
                  .\debug.cpp(256) : 0x80748000 0x0000f000 "\SystemRoot\System32\drivers\partmgr.sys"
                  .\debug.cpp(256) : 0x80757000 0x00003000 "\SystemRoot\system32\DRIVERS\compbatt.sys"
                  .\debug.cpp(256) : 0x8075a000 0x0000a000 "\SystemRoot\system32\DRIVERS\BATTC.SYS"
                  .\debug.cpp(256) : 0x80764000 0x0000f000 "\SystemRoot\system32\drivers\volmgr.sys"
                  .\debug.cpp(256) : 0x80773000 0x0004a000 "\SystemRoot\System32\drivers\volmgrx.sys"
                  .\debug.cpp(256) : 0x807bd000 0x00010000 "\SystemRoot\System32\drivers\mountmgr.sys"
                  .\debug.cpp(256) : 0x8360d000 0x000da000 "\SystemRoot\system32\drivers\iastor.sys"
                  .\debug.cpp(256) : 0x836e7000 0x00010000 "\SystemRoot\system32\drivers\fileinfo.sys"
                  .\debug.cpp(256) : 0x836f7000 0x0003d000 "\SystemRoot\system32\drivers\PCTCore.sys"
                  .\debug.cpp(256) : 0x83734000 0x00057000 "\SystemRoot\system32\drivers\pctDS.sys"
                  .\debug.cpp(256) : 0x8900e000 0x000a5000 "\SystemRoot\system32\drivers\pctEFA.sys"
                  .\debug.cpp(256) : 0x890b3000 0x00017000 "\SystemRoot\System32\Drivers\DRVMCDB.SYS"
                  .\debug.cpp(256) : 0x890ca000 0x0000a000 "\SystemRoot\System32\Drivers\PxHelp20.sys"
                  .\debug.cpp(256) : 0x890d4000 0x00072000 "\SystemRoot\System32\Drivers\ksecdd.sys"
                  .\debug.cpp(256) : 0x8920b000 0x0010b000 "\SystemRoot\system32\drivers\ndis.sys"
                  .\debug.cpp(256) : 0x89316000 0x0002b000 "\SystemRoot\system32\drivers\msrpc.sys"
                  .\debug.cpp(256) : 0x89341000 0x0003b000 "\SystemRoot\system32\drivers\NETIO.SYS"
                  .\debug.cpp(256) : 0x8940a000 0x000ea000 "\SystemRoot\System32\drivers\tcpip.sys"
                  .\debug.cpp(256) : 0x894f4000 0x0001b000 "\SystemRoot\System32\drivers\fwpkclnt.sys"
                  .\debug.cpp(256) : 0x89608000 0x00110000 "\SystemRoot\System32\Drivers\Ntfs.sys"
                  .\debug.cpp(256) : 0x89718000 0x00039000 "\SystemRoot\system32\drivers\volsnap.sys"
                  .\debug.cpp(256) : 0x89751000 0x00008000 "\SystemRoot\System32\DRIVERS\ApsHM86.sys"
                  .\debug.cpp(256) : 0x89761000 0x0001e000 "\SystemRoot\System32\DRIVERS\Apsx86.sys"
                  .\debug.cpp(256) : 0x8977f000 0x0000f000 "\SystemRoot\System32\Drivers\mup.sys"
                  .\debug.cpp(256) : 0x8978e000 0x00027000 "\SystemRoot\System32\drivers\ecache.sys"
                  .\debug.cpp(256) : 0x897b5000 0x00011000 "\SystemRoot\system32\drivers\disk.sys"
                  .\debug.cpp(256) : 0x897c6000 0x00021000 "\SystemRoot\system32\drivers\CLASSPNP.SYS"
                  .\debug.cpp(256) : 0x897e7000 0x00009000 "\SystemRoot\system32\drivers\crcdisk.sys"
                  .\debug.cpp(256) : 0x895e9000 0x0000b000 "\SystemRoot\system32\DRIVERS\tunnel.sys"
                  .\debug.cpp(256) : 0x895f4000 0x00009000 "\SystemRoot\system32\DRIVERS\tunmp.sys"
                  .\debug.cpp(256) : 0x8937c000 0x0000b000 "\SystemRoot\system32\DRIVERS\usbuhci.sys"
                  .\debug.cpp(256) : 0x89387000 0x0003e000 "\SystemRoot\system32\DRIVERS\USBPORT.SYS"
                  .\debug.cpp(256) : 0x893c5000 0x0000f000 "\SystemRoot\system32\DRIVERS\usbehci.sys"
                  .\debug.cpp(256) : 0x89146000 0x0008d000 "\SystemRoot\system32\DRIVERS\HDAudBus.sys"
                  .\debug.cpp(256) : 0x8d40a000 0x000e4000 "\SystemRoot\system32\DRIVERS\athr.sys"
                  .\debug.cpp(256) : 0x8d4ee000 0x00021000 "\SystemRoot\system32\DRIVERS\Rtlh86.sys"
                  .\debug.cpp(256) : 0x8d50f000 0x00010000 "\SystemRoot\system32\DRIVERS\ohci1394.sys"
                  .\debug.cpp(256) : 0x8d51f000 0x0000e000 "\SystemRoot\system32\DRIVERS\1394BUS.SYS"
                  .\debug.cpp(256) : 0x8d52d000 0x00011000 "\SystemRoot\system32\DRIVERS\rimmptsk.sys"
                  .\debug.cpp(256) : 0x8d53e000 0x00014000 "\SystemRoot\system32\DRIVERS\rimsptsk.sys"
                  .\debug.cpp(256) : 0x8d552000 0x00052000 "\SystemRoot\system32\DRIVERS\rixdptsk.sys"
                  .\debug.cpp(256) : 0x8d5a4000 0x00013000 "\SystemRoot\system32\DRIVERS\i8042prt.sys"
                  .\debug.cpp(256) : 0x8d5b7000 0x0000b000 "\SystemRoot\system32\DRIVERS\kbdclass.sys"
                  .\debug.cpp(256) : 0x8d5c2000 0x00030000 "\SystemRoot\system32\DRIVERS\SynTP.sys"
                  .\debug.cpp(256) : 0x8d5f2000 0x00002000 "\SystemRoot\system32\DRIVERS\USBD.SYS"
                  .\debug.cpp(256) : 0x8d5f4000 0x0000b000 "\SystemRoot\system32\DRIVERS\mouclass.sys"
                  .\debug.cpp(256) : 0x8d400000 0x00004000 "\SystemRoot\system32\DRIVERS\ibmpmdrv.sys"
                  .\debug.cpp(256) : 0x8d404000 0x00002000 "\SystemRoot\System32\Drivers\DLACDBHM.SYS"
                  .\debug.cpp(256) : 0x893d4000 0x00018000 "\SystemRoot\system32\DRIVERS\cdrom.sys"
                  .\debug.cpp(256) : 0x89600000 0x00006000 "\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys"
                  .\debug.cpp(256) : 0x89759000 0x00008000 "\SystemRoot\system32\DRIVERS\A0101V32.sys"
                  .\debug.cpp(256) : 0x8378b000 0x0002f000 "\SystemRoot\system32\DRIVERS\msiscsi.sys"
                  .\debug.cpp(256) : 0x837ba000 0x00041000 "\SystemRoot\system32\DRIVERS\storport.sys"
                  .\debug.cpp(256) : 0x893ec000 0x0000b000 "\SystemRoot\system32\DRIVERS\TDI.SYS"
                  .\debug.cpp(256) : 0x891d3000 0x00017000 "\SystemRoot\system32\DRIVERS\rasl2tp.sys"
                  .\debug.cpp(256) : 0x89200000 0x0000b000 "\SystemRoot\system32\DRIVERS\ndistapi.sys"
                  .\debug.cpp(256) : 0x807cd000 0x00023000 "\SystemRoot\system32\DRIVERS\ndiswan.sys"
                  .\debug.cpp(256) : 0x891ea000 0x0000f000 "\SystemRoot\system32\DRIVERS\raspppoe.sys"
                  .\debug.cpp(256) : 0x805ba000 0x00014000 "\SystemRoot\system32\DRIVERS\raspptp.sys"
                  .\debug.cpp(256) : 0x805ce000 0x00015000 "\SystemRoot\system32\DRIVERS\rassstp.sys"
                  .\debug.cpp(256) : 0x807f0000 0x00010000 "\SystemRoot\system32\DRIVERS\termdd.sys"
                  .\debug.cpp(256) : 0x8d406000 0x00002000 "\SystemRoot\system32\DRIVERS\swenum.sys"
                  .\debug.cpp(256) : 0x8dc05000 0x0002a000 "\SystemRoot\system32\DRIVERS\ks.sys"
                  .\debug.cpp(256) : 0x8dc2f000 0x0000a000 "\SystemRoot\system32\DRIVERS\mssmbios.sys"
                  .\debug.cpp(256) : 0x8dc39000 0x0000d000 "\SystemRoot\system32\DRIVERS\umbus.sys"
                  .\debug.cpp(256) : 0x8dc46000 0x00035000 "\SystemRoot\system32\DRIVERS\usbhub.sys"
                  .\debug.cpp(256) : 0x8dc7b000 0x00011000 "\SystemRoot\System32\Drivers\NDProxy.SYS"
                  .\debug.cpp(256) : 0x8dc8c000 0x00009000 "\SystemRoot\System32\Drivers\Fs_Rec.SYS"
                  .\debug.cpp(256) : 0x8dc95000 0x00007000 "\SystemRoot\System32\Drivers\Null.SYS"
                  .\debug.cpp(256) : 0x8dc9c000 0x00007000 "\SystemRoot\System32\Drivers\Beep.SYS"
                  .\debug.cpp(256) : 0x8dca3000 0x00006000 "\SystemRoot\System32\Drivers\DLARTL_M.SYS"
                  .\debug.cpp(256) : 0x8dca9000 0x0000c000 "\SystemRoot\System32\drivers\vga.sys"
                  .\debug.cpp(256) : 0x8dcb5000 0x00021000 "\SystemRoot\System32\drivers\VIDEOPRT.SYS"
                  .\debug.cpp(256) : 0x8dcd6000 0x0000c000 "\SystemRoot\System32\drivers\watchdog.sys"
                  .\debug.cpp(256) : 0x8dce2000 0x00008000 "\SystemRoot\system32\drivers\rdpencdd.sys"
                  .\debug.cpp(256) : 0x8dcea000 0x0000b000 "\SystemRoot\System32\Drivers\Msfs.SYS"
                  .\debug.cpp(256) : 0x8dcf5000 0x0000e000 "\SystemRoot\System32\Drivers\Npfs.SYS"
                  .\debug.cpp(256) : 0x8dd03000 0x00009000 "\SystemRoot\System32\DRIVERS\rasacd.sys"
                  .\debug.cpp(256) : 0x8dd0c000 0x00014000 "\SystemRoot\system32\DRIVERS\smb.sys"
                  .\debug.cpp(256) : 0x8dd20000 0x00048000 "\SystemRoot\system32\drivers\afd.sys"
                  .\debug.cpp(256) : 0x8dd68000 0x00032000 "\SystemRoot\System32\DRIVERS\netbt.sys"
                  .\debug.cpp(256) : 0x8dd9a000 0x00009000 "\SystemRoot\system32\drivers\ws2ifsl.sys"
                  .\debug.cpp(256) : 0x8dda3000 0x00016000 "\SystemRoot\system32\DRIVERS\pacer.sys"
                  .\debug.cpp(256) : 0x8ddb9000 0x0000e000 "\SystemRoot\system32\DRIVERS\netbios.sys"
                  .\debug.cpp(256) : 0x8e003000 0x0003c000 "\SystemRoot\system32\DRIVERS\rdbss.sys"
                  .\debug.cpp(256) : 0x8e03f000 0x0000a000 "\SystemRoot\system32\drivers\nsiproxy.sys"
                  .\debug.cpp(256) : 0x8e049000 0x00017000 "\SystemRoot\System32\Drivers\dfsc.sys"
                  .\debug.cpp(256) : 0x8e060000 0x00017000 "\SystemRoot\system32\DRIVERS\usbccgp.sys"
                  .\debug.cpp(256) : 0x8e077000 0x00009000 "\SystemRoot\system32\DRIVERS\hidusb.sys"
                  .\debug.cpp(256) : 0x8e080000 0x00010000 "\SystemRoot\system32\DRIVERS\HIDCLASS.SYS"
                  .\debug.cpp(256) : 0x8e090000 0x00007000 "\SystemRoot\system32\DRIVERS\HIDPARSE.SYS"
                  .\debug.cpp(256) : 0x8e097000 0x00009000 "\SystemRoot\system32\DRIVERS\kbdhid.sys"
                  .\debug.cpp(256) : 0x8e0a0000 0x00008000 "\SystemRoot\system32\DRIVERS\mouhid.sys"
                  .\debug.cpp(256) : 0x8e0a8000 0x0000d000 "\SystemRoot\System32\Drivers\crashdmp.sys"
                  .\debug.cpp(256) : 0x8e0b5000 0x000da000 "\SystemRoot\System32\Drivers\dump_iaStor.sys"
                  .\debug.cpp(256) : 0x93ee0000 0x00204000 "\SystemRoot\System32\win32k.sys"
                  .\debug.cpp(256) : 0x8e18f000 0x0000a000 "\SystemRoot\System32\drivers\Dxapi.sys"
                  .\debug.cpp(256) : 0x940f0000 0x00017000 "\SystemRoot\System32\drivers\dxg.sys"
                  .\debug.cpp(256) : 0x94120000 0x00009000 "\SystemRoot\System32\TSDDD.dll"
                  .\debug.cpp(256) : 0x941a0000 0x00008000 "\SystemRoot\System32\framebuf.dll"
                  .\debug.cpp(256) : 0x8e199000 0x0002a000 "\SystemRoot\system32\DRIVERS\nwifi.sys"
                  .\debug.cpp(256) : 0x8e1c3000 0x0000a000 "\SystemRoot\system32\DRIVERS\ndisuio.sys"
                  .\debug.cpp(256) : 0x8e1cd000 0x00019000 "\SystemRoot\system32\DRIVERS\bowser.sys"
                  .\debug.cpp(256) : 0x8ddc7000 0x0001f000 "\SystemRoot\system32\DRIVERS\mrxsmb.sys"
                  .\debug.cpp(256) : 0x8950f000 0x00039000 "\SystemRoot\system32\DRIVERS\mrxsmb10.sys"
                  .\debug.cpp(256) : 0x8e1e6000 0x00018000 "\SystemRoot\system32\DRIVERS\mrxsmb20.sys"
                  .\debug.cpp(256) : 0x8dde6000 0x00016000 "\SystemRoot\system32\DRIVERS\cdfs.sys"
                  .\debug.cpp(256) : 0x8955d000 0x00028000 "\SystemRoot\System32\Drivers\fastfat.SYS"
                  .\debug.cpp(256) : 0x89585000 0x00015000 "\SystemRoot\system32\DRIVERS\USBSTOR.SYS"
                  .\debug.cpp(256) : 0x770c0000 0x00128000 "\Windows\System32\ntdll.dll"
                  .\debug.cpp(263) : **********************************************
                  .\debug.cpp(307) : *** [ DEVICE OBJECTS INFORMATION ] ***********
                  .\debug.cpp(308) : **********************************************
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\D:"
                  .\debug.cpp(400) :  Destination "\Device\CdRom0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\NDIS"
                  .\debug.cpp(400) :  Destination "\Device\Ndis"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\DISPLAY1"
                  .\debug.cpp(400) :  Destination "\Device\Video0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_NDISWANIPV6#0000#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\00000038"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\DISPLAY2"
                  .\debug.cpp(400) :  Destination "\Device\Video1"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\USB#ROOT_HUB#4&14bae781&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}"
                  .\debug.cpp(400) :  Destination "\Device\USBPDO-1"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#SYSTEM#0000#{ffbb6e3f-ccfe-4d84-90d9-421418b03a8e}"
                  .\debug.cpp(400) :  Destination "\Device\0000003f"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\00000039"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\00000036"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\ACPI#PNP0C0E#2&daba3ff&3#{4afa3d53-74a7-11d0-be5e-00a0c9062857}"
                  .\debug.cpp(400) :  Destination "\Device\0000004a"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\USB#ROOT_HUB20#4&2f6d72dd&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}"
                  .\debug.cpp(400) :  Destination "\Device\USBPDO-7"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\{368ABA44-F30B-4B9B-B006-B5A2DB131DBF}"
                  .\debug.cpp(400) :  Destination "\Device\NDMP13"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\{E34CD445-D9B5-45AC-8C30-61A9E6C9AE11}"
                  .\debug.cpp(400) :  Destination "\Device\NDMP12"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#*6TO4MP#0000#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\00000001"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy1"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy1"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\E:"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolume5"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\00000037"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\ATKACPI"
                  .\debug.cpp(400) :  Destination "\Device\ATKACPI"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy2"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy2"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\WMIAdminDevice"
                  .\debug.cpp(400) :  Destination "\Device\WMIAdminDevice"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\STORAGE#Volume#1&19f7e59c&0&Signature901C13D0Offset22D2200000Length 271000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolume3"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\{601A5F35-E01E-4A22-A307-3541312908BA}"
                  .\debug.cpp(400) :  Destination "\Device\NDMP11"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#*ISATAP#0014#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\00000004"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Tun0"
                  .\debug.cpp(400) :  Destination "\Device\Tun0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#*6TO4MP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\00000001"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy3"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy3"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\VolMgrControl"
                  .\debug.cpp(400) :  Destination "\Device\VolMgrControl"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#SYSTEM#0000#{3c0d501a-140b-11d1-b40f-00a0c9223196}"
                  .\debug.cpp(400) :  Destination "\Device\0000003f"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy4"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy4"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Volume{28192cc9-44a0-11de-aff2-806e6f6e6963}"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolume3"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\USB#ROOT_HUB#4&b460f2&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}"
                  .\debug.cpp(400) :  Destination "\Device\USBPDO-2"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy5"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy5"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\CompositeBattery"
                  .\debug.cpp(400) :  Destination "\Device\CompositeBattery"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\USB#VID_0781&PID_556B#200607749213F9337288#{a5dcbf10-6530-11d2-901f-00c04fb951ed}"
                  .\debug.cpp(400) :  Destination "\Device\USBPDO-9"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\WMIDataDevice"
                  .\debug.cpp(400) :  Destination "\Device\WMIDataDevice"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HID#VID_045E&PID_0745&MI_01&Col01#7&f8f2aa4&0&0000#{4d1e55b2-f16f-11cf-88cb-001111000030}"
                  .\debug.cpp(400) :  Destination "\Device\00000072"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_8086&DEV_293C&SUBSYS_20F117AA&REV_03#3&11583659&0&D7#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0006"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#*TUNMP#0000#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\00000005"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\IBMPmDrv"
                  .\debug.cpp(400) :  Destination "\Device\PMDRV"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy6"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy6"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Q:"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolume3"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\STORAGE#Volume#1&19f7e59c&0&Signature901C13D0Offset5DD00000Length22 744FF000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolume2"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_8086&DEV_293A&SUBSYS_20F117AA&REV_03#3&11583659&0&EF#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0015"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy7"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy7"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PIPE"
                  .\debug.cpp(400) :  Destination "\Device\NamedPipe"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy8"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy8"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\UNC"
                  .\debug.cpp(400) :  Destination "\Device\Mup"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HID#VID_045E&PID_0745&MI_02&Col02#7&2752b6e9&0&0001#{4d1e55b2-f16f-11cf-88cb-001111000030}"
                  .\debug.cpp(400) :  Destination "\Device\00000075"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Psched"
                  .\debug.cpp(400) :  Destination "\Device\Psched"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#SYSTEM#0000#{0a4252a0-7e70-11d0-a5d6-28db04c10000}"
                  .\debug.cpp(400) :  Destination "\Device\0000003f"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\GEARAspiWDMDevice"
                  .\debug.cpp(400) :  Destination "\Device\GEARAspiWDMDevice"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy9"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy9"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HCD0"
                  .\debug.cpp(400) :  Destination "\Device\USBFDO-0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\FltMgrMsg"
                  .\debug.cpp(400) :  Destination "\FileSystem\Filters\FltMgrMsg"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_8086&DEV_2936&SUBSYS_20F017AA&REV_03#3&11583659&0&EA#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0014"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HCD1"
                  .\debug.cpp(400) :  Destination "\Device\USBFDO-1"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\pctEFA"
                  .\debug.cpp(400) :  Destination "\Device\pctEFA"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PRN"
                  .\debug.cpp(400) :  Destination "\DosDevices\LPT1"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PhysicalDrive0"
                  .\debug.cpp(400) :  Destination "\Device\Harddisk0\DR0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#SYSTEM#0000#{cf1dda2c-9743-11d0-a3ee-00a0c9223196}"
                  .\debug.cpp(400) :  Destination "\Device\0000003f"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#SYSTEM#0000#{53172480-4791-11d0-a5d6-28db04c10000}"
                  .\debug.cpp(400) :  Destination "\Device\0000003f"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HCD2"
                  .\debug.cpp(400) :  Destination "\Device\USBFDO-2"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#*TUNMP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\00000005"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PhysicalDrive1"
                  .\debug.cpp(400) :  Destination "\Device\Harddisk1\DR2"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#UMBUS#0000#{65a9a6cf-64cd-480b-843e-32c86e1ba19f}"
                  .\debug.cpp(400) :  Destination "\Device\00000041"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\fsWrap"
                  .\debug.cpp(400) :  Destination "\Device\FsWrap"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#SYSTEM#0000#{97ebaacb-95bd-11d0-a3ea-00a0c9223196}"
                  .\debug.cpp(400) :  Destination "\Device\0000003f"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HCD3"
                  .\debug.cpp(400) :  Destination "\Device\USBFDO-3"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\CdRom0"
                  .\debug.cpp(400) :  Destination "\Device\CdRom0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Volume{bc73035e-449a-11de-93e7-00248cb3b119}"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolume2"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\S:"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolume1"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_PPTPMINIPORT#0000#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\0000003a"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HCD4"
                  .\debug.cpp(400) :  Destination "\Device\USBFDO-4"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#volmgr#0000#{53f5630e-b6bf-11d0-94f2-00a0c91efb8b}"
                  .\debug.cpp(400) :  Destination "\Device\00000042"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\pctDS"
                  .\debug.cpp(400) :  Destination "\Device\pctDS"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HID#VID_045E&PID_0745&MI_02&Col03#7&2752b6e9&0&0002#{4d1e55b2-f16f-11cf-88cb-001111000030}"
                  .\debug.cpp(400) :  Destination "\Device\00000076"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_NDISWANBH#0000#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\00000036"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#ISCSIPRT#0000#{2accfe60-c130-11d2-b082-00a0c91efb8b}"
                  .\debug.cpp(400) :  Destination "\Device\00000008"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HCD5"
                  .\debug.cpp(400) :  Destination "\Device\USBFDO-5"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Global"
                  .\debug.cpp(400) :  Destination "\GLOBAL??"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\LOG:"
                  .\debug.cpp(400) :  Destination "\clfs"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\USB#ROOT_HUB#4&2a2a2ff4&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}"
                  .\debug.cpp(400) :  Destination "\Device\USBPDO-0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\0000003b"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HCD6"
                  .\debug.cpp(400) :  Destination "\Device\USBFDO-6"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\{E11515E1-E1A9-47CC-A452-7F766AD61B50}"
                  .\debug.cpp(400) :  Destination "\Device\NDMP2"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HID#VID_045E&PID_0745&MI_02&Col01#7&2752b6e9&0&0000#{4d1e55b2-f16f-11cf-88cb-001111000030}"
                  .\debug.cpp(400) :  Destination "\Device\00000074"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HCD7"
                  .\debug.cpp(400) :  Destination "\Device\USBFDO-7"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_168C&DEV_001C&SUBSYS_0035168C&REV_01#4&2f9c0b34&0&00E1#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0019"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy10"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy10"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\ACPI#PNP0C0D#2&daba3ff&3#{4afa3d53-74a7-11d0-be5e-00a0c9062857}"
                  .\debug.cpp(400) :  Destination "\Device\0000004b"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\ACPI#ThermalZone#THRM#{4afa3d51-74a7-11d0-be5e-00a0c9062857}"
                  .\debug.cpp(400) :  Destination "\Device\00000048"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\{AE8C233E-0FF8-4B63-A88F-C59B54A2A7A5}"
                  .\debug.cpp(400) :  Destination "\Device\NDMP3"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy11"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy11"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\STORAGE#Volume#1&19f7e59c&0&Signature901C13D0Offset100000Length5DC0 0000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolume1"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy12"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy12"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Volume{28192ccc-44a0-11de-aff2-806e6f6e6963}"
                  .\debug.cpp(400) :  Destination "\Device\CdRom0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\nativewifip"
                  .\debug.cpp(400) :  Destination "\Device\nativewifip"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\ACPI#LEN0013#4&19087a06&0#{378de44c-56ef-11d1-bc8c-00a0c91405dd}"
                  .\debug.cpp(400) :  Destination "\Device\00000056"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_PPPOEMINIPORT#0000#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\00000039"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_8086&DEV_2934&SUBSYS_20F017AA&REV_03#3&11583659&0&E8#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0012"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy20"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy20"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy13"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy13"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_SSTPMINIPORT#0000#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\0000003b"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\{31D45F66-1FBA-464A-A198-F953D26B3D9E}"
                  .\debug.cpp(400) :  Destination "\Device\NDMP6"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\{47E42986-067B-4D6D-A977-3BFE22D64C3F}"
                  .\debug.cpp(400) :  Destination "\Device\NDMP5"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#*ISATAP#0014#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\00000004"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy21"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy21"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy14"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy14"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Shockpf0"
                  .\debug.cpp(400) :  Destination "\Device\Shockpf0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\MountPointManager"
                  .\debug.cpp(400) :  Destination "\Device\MountPointManager"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_NDISWANIP#0000#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\00000037"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\00000035"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_8086&DEV_2939&SUBSYS_20F017AA&REV_03#3&11583659&0&D2#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0005"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy22"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy22"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy15"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy15"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\STORAGE#Volume#1&19f7e59c&0&_??_USBSTOR#Disk&Ven_SanDisk&Prod_Cruzer_Edge&Rev_1.20#200607749213F9337288&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolume5"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Nsi"
                  .\debug.cpp(400) :  Destination "\Device\Nsi"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\USB#ROOT_HUB#4&39baf81a&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}"
                  .\debug.cpp(400) :  Destination "\Device\USBPDO-5"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_8086&DEV_2938&SUBSYS_20F017AA&REV_03#3&11583659&0&D1#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0004"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy23"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy23"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy16"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy16"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_8086&DEV_2929&SUBSYS_20F817AA&REV_03#3&11583659&0&FA#{2accfe60-c130-11d2-b082-00a0c91efb8b}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0018"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PartmgrControl"
                  .\debug.cpp(400) :  Destination "\Device\PartmgrControl"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\STORAGE#VolumeSnapshot#HarddiskVolumeSnapshot27#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy27"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\USBSTOR#Disk&Ven_SanDisk&Prod_Cruzer_Edge&Rev_1.20#200607749213F9337288&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}"
                  .\debug.cpp(400) :  Destination "\Device\0000007c"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_L2TPMINIPORT#0000#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\00000035"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\ShockMgr"
                  .\debug.cpp(400) :  Destination "\Device\ShockMgr"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\{850EA409-FC82-49A7-9DEB-BABC66146CA7}"
                  .\debug.cpp(400) :  Destination "\Device\NDMP7"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_1180&DEV_0843&SUBSYS_210B17AA&REV_12#4&7ee979b&0&02F0#{ba39d8e2-30c9-11d4-b3cd-d916bda91711}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0023"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy24"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy24"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy17"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy17"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\NXTIPSECDevice"
                  .\debug.cpp(400) :  Destination "\Device\NXTIPSEC"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Volume{f32bd873-5a4d-11e1-a7d8-00248cb3b119}"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy27"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HID#VID_045E&PID_0745&MI_02&Col04#7&2752b6e9&0&0003#{4d1e55b2-f16f-11cf-88cb-001111000030}"
                  .\debug.cpp(400) :  Destination "\Device\00000077"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\USB#ROOT_HUB20#4&2a372ade&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}"
                  .\debug.cpp(400) :  Destination "\Device\USBPDO-3"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\0000003f"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\NDISWANIP"
                  .\debug.cpp(400) :  Destination "\Device\NDMP9"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_8086&DEV_2935&SUBSYS_20F017AA&REV_03#3&11583659&0&E9#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0013"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#*ISATAP#0011#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\00000003"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy25"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy25"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy18"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy18"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\WFPDev"
                  .\debug.cpp(400) :  Destination "\Device\WFP"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Scsi0:"
                  .\debug.cpp(400) :  Destination "\Device\Ide\iaStor0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\IDE#CdRomHL-DT-ST_DVDRAM_GSA-T50N________________RE05____#4&1ec7b392&0&0.1.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}"
                  .\debug.cpp(400) :  Destination "\Device\Ide\IAAStorageDevice-0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_1180&DEV_0832&SUBSYS_210917AA&REV_05#4&7ee979b&0&00F0#{6bdd1fc1-810f-11d0-bec7-08002be2092f}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0021"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\{BB1484E4-9D4E-41BC-8D7D-D59FC7747231}"
                  .\debug.cpp(400) :  Destination "\Device\NDMP4"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\{402F775A-9265-4754-A371-C34AE3D84EBA}"
                  .\debug.cpp(400) :  Destination "\Device\NDMP1"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy26"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy26"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy19"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy19"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\ACPI#FixedButton#2&daba3ff&3#{4afa3d53-74a7-11d0-be5e-00a0c9062857}"
                  .\debug.cpp(400) :  Destination "\Device\0000004c"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HID#VID_045E&PID_0745&MI_01&Col01#7&f8f2aa4&0&0000#{378de44c-56ef-11d1-bc8c-00a0c91405dd}"
                  .\debug.cpp(400) :  Destination "\Device\00000072"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\1394BUS0"
                  .\debug.cpp(400) :  Destination "\Device\1394BUS0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HarddiskVolumeShadowCopy27"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolumeShadowCopy27"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\IDE#CdRomHL-DT-ST_DVDRAM_GSA-T50N________________RE05____#4&1ec7b392&0&0.1.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
                  .\debug.cpp(400) :  Destination "\Device\Ide\IAAStorageDevice-0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#SYSTEM#0000#{4747b320-62ce-11cf-a5d6-28db04c10000}"
                  .\debug.cpp(400) :  Destination "\Device\0000003f"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\0000003a"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_8086&DEV_2937&SUBSYS_20F017AA&REV_03#3&11583659&0&D0#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0003"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#*ISATAP#0011#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\00000003"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Volume{7f71fc5e-4d29-11e1-96c8-00248cb3b119}"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolume5"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Volume{bc730357-449a-11de-93e7-00248cb3b119}"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolume1"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Scsi1:"
                  .\debug.cpp(400) :  Destination "\Device\RaidPort0"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\IDE#DiskHITACHI_HTS543216L9SA00_________________FB2ZC4EC#4&1ec7b392&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}"
                  .\debug.cpp(400) :  Destination "\Device\Ide\IAAStorageDevice-1"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\NdisWan"
                  .\debug.cpp(400) :  Destination "\Device\NdisWan"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\NDISWANBH"
                  .\debug.cpp(400) :  Destination "\Device\NDMP8"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_10EC&DEV_8168&SUBSYS_210817AA&REV_02#FFFFFFFF00#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0020"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_10EC&DEV_8168&SUBSYS_210817AA&REV_02#FFFFFFFF00#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0020"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_1180&DEV_0852&SUBSYS_210D17AA&REV_12#4&7ee979b&0&04F0#{58b90d02-b4b0-4504-9bea-52b93082ddf6}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0025"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\drvmcdb"
                  .\debug.cpp(400) :  Destination "\Device\drvmcdb"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HID#VID_045E&PID_0745&MI_00#7&33666866&0&0000#{884b96c3-56ef-11d1-bc8c-00a0c91405dd}"
                  .\debug.cpp(400) :  Destination "\Device\00000071"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\FtControl"
                  .\debug.cpp(400) :  Destination "\Device\VolMgrControl"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\FltMgr"
                  .\debug.cpp(400) :  Destination "\FileSystem\Filters\FltMgr"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\C:"
                  .\debug.cpp(400) :  Destination "\Device\HarddiskVolume2"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\MAILSLOT"
                  .\debug.cpp(400) :  Destination "\Device\MailSlot"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\USB#VID_045E&PID_0745#5&26fbe77f&0&2#{a5dcbf10-6530-11d2-901f-00c04fb951ed}"
                  .\debug.cpp(400) :  Destination "\Device\USBPDO-8"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\AUX"
                  .\debug.cpp(400) :  Destination "\DosDevices\COM1"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\USB#ROOT_HUB#4&7b13611&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}"
                  .\debug.cpp(400) :  Destination "\Device\USBPDO-6"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\NDISWANIPV6"
                  .\debug.cpp(400) :  Destination "\Device\NDMP10"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCTCoreDriver"
                  .\debug.cpp(400) :  Destination "\Device\PCTCoreDevice"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Ndisuio"
                  .\debug.cpp(400) :  Destination "\Device\Ndisuio"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\ACPI#PNP0303#4&19087a06&0#{884b96c3-56ef-11d1-bc8c-00a0c91405dd}"
                  .\debug.cpp(400) :  Destination "\Device\00000055"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#RDP_MOU#0000#{378de44c-56ef-11d1-bc8c-00a0c91405dd}"
                  .\debug.cpp(400) :  Destination "\Device\0000003d"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\NUL"
                  .\debug.cpp(400) :  Destination "\Device\Null"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\USB#ROOT_HUB#4&244bafa7&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}"
                  .\debug.cpp(400) :  Destination "\Device\USBPDO-4"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\SstpDrv"
                  .\debug.cpp(400) :  Destination "\Device\SstpDrv"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\GLOBALROOT"
                  .\debug.cpp(400) :  Destination ""
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HID#VID_045E&PID_0745&MI_00#7&33666866&0&0000#{4d1e55b2-f16f-11cf-88cb-001111000030}"
                  .\debug.cpp(400) :  Destination "\Device\00000071"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#RDP_KBD#0000#{884b96c3-56ef-11d1-bc8c-00a0c91405dd}"
                  .\debug.cpp(400) :  Destination "\Device\0000003c"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_168C&DEV_001C&SUBSYS_0035168C&REV_01#4&2f9c0b34&0&00E1#{cac88484-7515-4c03-82e6-71a87abac361}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0019"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\SYNTP"
                  .\debug.cpp(400) :  Destination "\Device\SynTP"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\WfpAle"
                  .\debug.cpp(400) :  Destination "\Device\WfpAle"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\HID#VID_045E&PID_0745&MI_01&Col02#7&f8f2aa4&0&0001#{4d1e55b2-f16f-11cf-88cb-001111000030}"
                  .\debug.cpp(400) :  Destination "\Device\00000073"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}"
                  .\debug.cpp(400) :  Destination "\Device\00000038"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(369) : SymbolicLink "\GLOBAL??\PCI#VEN_1180&DEV_0592&SUBSYS_210C17AA&REV_12#4&7ee979b&0&03F0#{d2d3b8e3-2400-448c-8c0d-79abecfcfda3}"
                  .\debug.cpp(400) :  Destination "\Device\NTPNP_PCI0024"
                  .\debug.cpp(409) :  --
                  .\debug.cpp(453) : **********************************************
                  .\boot_cleaner.cpp(565) : System volume is \\.\C:
                  .\boot_cleaner.cpp(600) : \\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`5dd00000
                  .\boot_cleaner.cpp(276) : Boot sector MD5 is: 0ec6b2481fc707d1e901dc2a875f2826
                  .\boot_cleaner.cpp(1061) :
                  .\boot_cleaner.cpp(1062) :      Size  Device Name          MBR Status
                  .\boot_cleaner.cpp(1063) :  --------------------------------------------
                  .\boot_cleaner.cpp(1107) :    149 GB  \\.\PhysicalDrive0   OK (DOS/Win32 Boot code found)
                  .\boot_cleaner.cpp(1113) :
                  .\boot_cleaner.cpp(1152) : Done;