130207_1900est
Good evening (here anyway),
Since my post has not elicted any REPLY as yet (maybe everyone else is as puzzled by this as I am),
I proceeded to do and document some more investigating via CMD
EXCEPT NOW from ??YYYY (Win7) looking at ??YYYY (Win7) [vs from ??XXXX (WinXP) looking at ??YYYY PRIOR]
website wouldn't accept prior text (no pictures or links allowed)
looked for \ as 1st char on ea line and where found put that line in " "
still bombed; then replaced those "\ as 1st chars on ea line with "? THEN TRY AGAIN
Understand its "a lot of data" but seems this data should now be adequate for someone to ID the ROOT CAUSE of this problem.
IF anyone can now ID the (or likely) ROOT CAUSE and give me the MS recommended FIX (or best workaround opts), I'd very much
appreciate your REPLYING with your suggestions.
Thanks,
Steveg722 (tempalias=Steveg722_thatsme)
USA_RI_02917
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
FROM ??YYYY (Win7) then in a std CMD window (logged on as me with Admin rights)
OBJECTIVE
EXAMINE
C:\>
C:\Users>
Re <JUNCTION> <SYMLINKD> and TARGETS of same
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
??YYYY?C
C:\>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\>dir /x /q /a:d
Volume in drive C has no label.
Volume Serial Number is AE07-327D
Directory of C:\
01/23/2013 09:17 PM <DIR> BUILTIN\Administrators $Recy
cle.Bin
01/23/2013 09:17 PM <DIR> ASUSVI~1 BUILTIN\Administrators AsusV
ibeData
05/12/2011 07:21 AM <DIR> BUILTIN\Administrators aws
01/23/2013 09:17 PM <DIR> BIGFIS~1 HelensNetbook\Helen BigFi
shGamesCache
02/23/2012 11:16 PM <DIR> BUILTIN\Administrators Boot
07/13/2009 11:53 PM <JUNCTION> DOCUME~1 BUILTIN\Administrators Docum
ents and Settings [C:\Users]
06/24/2010 10:59 AM <DIR> BUILTIN\Administrators Intel
01/23/2013 09:17 PM <DIR> ... MSOCa
che
07/13/2009 09:37 PM <DIR> BUILTIN\Administrators PerfL
ogs
01/23/2013 11:09 PM <DIR> PROGRA~1 NT SERVICE\TrustedInstaProgr
am Files
01/23/2013 10:48 PM <DIR> PROGRA~2 BUILTIN\Administrators Progr
amData
01/29/2011 05:23 PM <DIR> ... Recov
ery
02/07/2013 06:39 AM <DIR> SYSTEM~1 ... Syste
m Volume Information
01/23/2013 11:09 PM <DIR> BUILTIN\Administrators Users
01/23/2013 11:20 PM <DIR> NT SERVICE\TrustedInstaWindo
ws
01/22/2013 11:38 PM <DIR> _$ROBO~2 HelensNetbook\Helen _$Rob
ocopyDEST_hnetbook
01/22/2013 11:37 PM <DIR> _$ROBO~1 HelensNetbook\Helen _$Rob
ocopySOURCE_hnetbook
0 File(s) 0 bytes
17 Dir(s) 51,280,654,336 bytes free
C:\>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\>dir /x /q /a:dL
Volume in drive C has no label.
Volume Serial Number is AE07-327D
Directory of C:\
07/13/2009 11:53 PM <JUNCTION> DOCUME~1 BUILTIN\Administrators Docum
ents and Settings [C:\Users]
0 File(s) 0 bytes
1 Dir(s) 51,280,650,240 bytes free
C:\>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\>junction *
Junction v1.06 - Windows junction creator and reparse point viewer
Copyright (C) 2000-2010 Mark Russinovich
Sysinternals - www.sysinternals.com
"?\?\C:\Documents and Settings: JUNCTION"
Print Name : C:\Users
Substitute Name: C:\Users
Failed to open \\?\C:\hiberfil.sys: The process cannot access the file because i
t is being used by another process.
Failed to open \\?\C:\MSOCache: Access is denied.
Failed to open \\?\C:\pagefile.sys: The process cannot access the file because i
t is being used by another process.
Failed to open \\?\C:\Recovery: Access is denied.
Failed to open \\?\C:\System Volume Information: Access is denied.
C:\>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\>junction DOCUME~1
Junction v1.06 - Windows junction creator and reparse point viewer
Copyright (C) 2000-2010 Mark Russinovich
Sysinternals - www.sysinternals.com
C:\Documents and Settings: JUNCTION
Print Name : C:\Users
Substitute Name: C:\Users
C:\>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\>cacls DOCUME~1
C:\Documents and Settings Everyone:R
NT AUTHORITY\SYSTEM:F
BUILTIN\Administrators:F
C:\>cacls DOCUME~1 /L
C:\Documents and Settings Everyone:R
NT AUTHORITY\SYSTEM:F
BUILTIN\Administrators:F
C:\>cacls PROGRA~2
C:\ProgramData NT AUTHORITY\SYSTEM:(OI)(CI)F
BUILTIN\Administrators:(OI)(CI)F
CREATOR OWNER:(OI)(CI)(IO)F
BUILTIN\Users:(OI)(CI)R
BUILTIN\Users:(CI)(special access:)
FILE_WRITE_DATA
FILE_APPEND_DATA
FILE_WRITE_EA
FILE_WRITE_ATTRIBUTES
C:\>cacls PROGRA~2 /L
C:\ProgramData NT AUTHORITY\SYSTEM:(OI)(CI)F
BUILTIN\Administrators:(OI)(CI)F
CREATOR OWNER:(OI)(CI)(IO)F
BUILTIN\Users:(OI)(CI)R
BUILTIN\Users:(CI)(special access:)
FILE_WRITE_DATA
FILE_APPEND_DATA
FILE_WRITE_EA
FILE_WRITE_ATTRIBUTES
C:\>cacls USERS
C:\Users NT AUTHORITY\Authenticated Users:(OI)(CI)(ID)C
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Administrators:(OI)(CI)(ID)F
Everyone:(OI)(CI)(ID)R
BUILTIN\Users:(OI)(CI)(ID)R
C:\>cacls SYSTEM~1
C:\System Volume Information
Access is denied.
C:\>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\>icacls DOCUME~1
DOCUME~1 Everyone:(RX)
NT AUTHORITY\SYSTEM:(F)
BUILTIN\Administrators:(F)
Successfully processed 1 files; Failed processing 0 files
C:\>icacls DOCUME~1 /L
DOCUME~1 Everyone:(RX)
NT AUTHORITY\SYSTEM:(F)
BUILTIN\Administrators:(F)
Successfully processed 1 files; Failed processing 0 files
C:\>icacls PROGRA~2
PROGRA~2 NT AUTHORITY\SYSTEM:(OI)(CI)(F)
BUILTIN\Administrators:(OI)(CI)(F)
CREATOR OWNER:(OI)(CI)(IO)(F)
BUILTIN\Users:(OI)(CI)(RX)
BUILTIN\Users:(CI)(WD,AD,WEA,WA)
Successfully processed 1 files; Failed processing 0 files
C:\>icacls PROGRA~2 /L
PROGRA~2 NT AUTHORITY\SYSTEM:(OI)(CI)(F)
BUILTIN\Administrators:(OI)(CI)(F)
CREATOR OWNER:(OI)(CI)(IO)(F)
BUILTIN\Users:(OI)(CI)(RX)
BUILTIN\Users:(CI)(WD,AD,WEA,WA)
Successfully processed 1 files; Failed processing 0 files
C:\>icacls USERS
USERS NT AUTHORITY\Authenticated Users:(I)(OI)(CI)(M)
NT AUTHORITY\SYSTEM:(I)(OI)(CI)(F)
BUILTIN\Administrators:(I)(OI)(CI)(F)
Everyone:(I)(OI)(CI)(RX)
BUILTIN\Users:(I)(OI)(CI)(RX)
Successfully processed 1 files; Failed processing 0 files
C:\>icacls SYSTEM~1
SYSTEM~1: Access is denied.
Successfully processed 0 files; Failed processing 1 files
C:\>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
CHECK SECURITY VIA WinExplorer
C:\System Volume Information
C:\>SYSTEM~1
hnetbook,FROM
PROPERTIES; SECURITY TAB
GROUPS PERMISSIONS OWNER
SYSTEM FULL NOT AVAILBLE
NO ADVANCED BUTTON SHOWING (so can't get to OWNER data)
(NOTE; quick trip to hlaptop found no security tab showing)
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
??YYYY?C
C:\Users>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\Helen>cd..
C:\Users>dir /x /q /a:d
Volume in drive C has no label.
Volume Serial Number is AE07-327D
Directory of C:\Users
01/23/2013 11:09 PM <DIR> BUILTIN\Administrators .
01/23/2013 11:09 PM <DIR> BUILTIN\Administrators ..
07/13/2009 11:53 PM <SYMLINKD> ALLUSE~1 BUILTIN\Administrators All U
sers [C:\ProgramData]
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Defau
lt
07/13/2009 11:53 PM <JUNCTION> DEFAUL~1 BUILTIN\Administrators Defau
lt User [C:\Users\Default]
01/23/2013 11:22 PM <DIR> NT AUTHORITY\SYSTEM Helen
01/23/2013 11:09 PM <DIR> BUILTIN\Administrators Publi
c
0 File(s) 0 bytes
7 Dir(s) 51,015,692,288 bytes free
C:\Users>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\Users>dir /x /q /a:dL
Volume in drive C has no label.
Volume Serial Number is AE07-327D
Directory of C:\Users
07/13/2009 11:53 PM <SYMLINKD> ALLUSE~1 BUILTIN\Administrators All U
sers [C:\ProgramData]
07/13/2009 11:53 PM <JUNCTION> DEFAUL~1 BUILTIN\Administrators Defau
lt User [C:\Users\Default]
0 File(s) 0 bytes
2 Dir(s) 51,446,972,416 bytes free
C:\Users>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\Users>linkd ALLUSE~1
'linkd' is not recognized as an internal or external command,
operable program or batch file.
C:\Users>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\Users>junction -e
Junction v1.06 - Windows junction creator and reparse point viewer
Copyright (C) 2000-2010 Mark Russinovich
Sysinternals - www.sysinternals.com
No matching files were found.
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\Users>junction *
Junction v1.06 - Windows junction creator and reparse point viewer
Copyright (C) 2000-2010 Mark Russinovich
Sysinternals - www.sysinternals.com
"?\?\C:\Users\All Users: SYMBOLIC LINK"
Print Name : C:\ProgramData
Substitute Name: \??\C:\ProgramData
"?\?\C:\Users\Default User: JUNCTION"
Print Name : C:\Users\Default
Substitute Name: C:\Users\Default
C:\Users>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\Users>junction ALLUSE~1
Junction v1.06 - Windows junction creator and reparse point viewer
Copyright (C) 2000-2010 Mark Russinovich
Sysinternals - www.sysinternals.com
C:\Users\All Users: SYMBOLIC LINK
Print Name : C:\ProgramData
Substitute Name: \??\C:\ProgramData
C:\Users>junction DEFAUL~1
Junction v1.06 - Windows junction creator and reparse point viewer
Copyright (C) 2000-2010 Mark Russinovich
Sysinternals - www.sysinternals.com
C:\Users\Default User: JUNCTION
Print Name : C:\Users\Default
Substitute Name: C:\Users\Default
C:\Users>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\Users>icacls ALLUSE~1 /L
ALLUSE~1 NT AUTHORITY\Authenticated Users:(I)(OI)(CI)(M)
NT AUTHORITY\SYSTEM:(I)(OI)(CI)(F)
BUILTIN\Administrators:(I)(OI)(CI)(F)
Everyone:(I)(OI)(CI)(RX)
BUILTIN\Users:(I)(OI)(CI)(RX)
Successfully processed 1 files; Failed processing 0 files
C:\Users>icacls DEFAUL~1 /L
DEFAUL~1 NT AUTHORITY\Authenticated Users:(I)(OI)(CI)(M)
NT AUTHORITY\SYSTEM:(I)(OI)(CI)(F)
BUILTIN\Administrators:(I)(OI)(CI)(F)
Everyone:(I)(OI)(CI)(RX)
BUILTIN\Users:(I)(OI)(CI)(RX)
Successfully processed 1 files; Failed processing 0 files
C:\Users>
C:\Users>icacls DEFAULT
DEFAULT NT AUTHORITY\Authenticated Users:(I)(OI)(CI)(M)
NT AUTHORITY\SYSTEM:(I)(OI)(CI)(F)
BUILTIN\Administrators:(I)(OI)(CI)(F)
Everyone:(I)(OI)(CI)(RX)
BUILTIN\Users:(I)(OI)(CI)(RX)
Successfully processed 1 files; Failed processing 0 files
C:\Users>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\Users>cacls ALLUSE~1
C:\Users\All Users NT AUTHORITY\SYSTEM:(OI)(CI)F
BUILTIN\Administrators:(OI)(CI)F
CREATOR OWNER:(OI)(CI)(IO)F
BUILTIN\Users:(OI)(CI)R
BUILTIN\Users:(CI)(special access:)
FILE_WRITE_DATA
FILE_APPEND_DATA
FILE_WRITE_EA
FILE_WRITE_ATTRIBUTES
C:\Users>cacls DEFAUL~1
C:\Users\Default User NT AUTHORITY\Authenticated Users:(OI)(CI)(ID)C
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Administrators:(OI)(CI)(ID)F
Everyone:(OI)(CI)(ID)R
BUILTIN\Users:(OI)(CI)(ID)R
C:\Users>
C:\Users>cacls DEFAULT
C:\Users\Default NT AUTHORITY\Authenticated Users:(OI)(CI)(ID)C
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Administrators:(OI)(CI)(ID)F
Everyone:(OI)(CI)(ID)R
BUILTIN\Users:(OI)(CI)(ID)R
C:\Users>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\Users>dir ALLUSE~1 /x /q /a:d
Volume in drive C has no label.
Volume Serial Number is AE07-327D
Directory of C:\Users\ALLUSE~1
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators .
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators ..
01/23/2013 09:23 PM <DIR> BUILTIN\Administrators Adobe
07/13/2009 11:53 PM <JUNCTION> APPLIC~1 BUILTIN\Administrators Appli
cation Data [C:\ProgramData]
01/23/2013 10:48 PM <DIR> ASUSWE~1 BUILTIN\Administrators ASUS
WebStorage
06/24/2010 11:02 AM <DIR> BUILTIN\Administrators Ather
os
01/23/2013 09:23 PM <DIR> BIGFIS~1 BUILTIN\Administrators Big F
ish Games
07/13/2009 11:53 PM <JUNCTION> BUILTIN\Administrators Deskt
op [C:\Users\Public\Desktop]
07/13/2009 11:53 PM <JUNCTION> DOCUME~1 BUILTIN\Administrators Docum
ents [C:\Users\Public\Documents]
06/24/2010 11:08 AM <DIR> BUILTIN\Administrators EBI
07/13/2009 11:53 PM <JUNCTION> FAVORI~1 BUILTIN\Administrators Favor
ites [C:\Users\Public\Favorites]
01/29/2011 05:30 PM <DIR> BUILTIN\Administrators GoBoi
ngo
11/22/2012 04:29 PM <DIR> BUILTIN\Administrators McAfe
e
01/23/2013 10:48 PM <DIR> MICROS~1 BUILTIN\Administrators Micro
soft
01/23/2013 10:48 PM <DIR> MICROS~2 HelensNetbook\Helen Micro
soft Help
01/23/2013 09:24 PM <DIR> OBERON~1 BUILTIN\Administrators Obero
nGameConsole
01/23/2013 09:24 PM <DIR> RALINK~1 BUILTIN\Administrators Ralin
k Driver
06/24/2010 11:08 AM <DIR> BUILTIN\Administrators RSMR
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Skype
07/13/2009 11:53 PM <JUNCTION> STARTM~1 BUILTIN\Administrators Start
Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
01/10/2013 12:37 PM <DIR> BUILTIN\Administrators TEMP
07/13/2009 11:53 PM <JUNCTION> TEMPLA~1 BUILTIN\Administrators Templ
ates [C:\ProgramData\Microsoft\Windows\Templates]
01/23/2013 09:24 PM <DIR> TRENDM~1 BUILTIN\Administrators Trend
Micro
09/03/2012 08:32 PM <DIR> USTECH~1 BUILTIN\Administrators USTec
hSupport
01/31/2011 05:40 PM <DIR> VIRTUA~1 BUILTIN\Administrators Virtu
alizedApplications
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Xilis
oft
0 File(s) 0 bytes
26 Dir(s) 51,280,748,544 bytes free
C:\Users>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\Users>dir DEFAUL~1 /x /q /a:d
Volume in drive C has no label.
Volume Serial Number is AE07-327D
Directory of C:\Users\DEFAUL~1
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators .
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators ..
01/23/2013 09:24 PM <DIR> BUILTIN\Administrators AppDa
ta
07/13/2009 11:53 PM <JUNCTION> APPLIC~1 BUILTIN\Administrators Appli
cation Data [C:\Users\Default\AppData\Roaming]
01/23/2013 10:48 PM <DIR> NT AUTHORITY\SYSTEM Conta
cts
07/13/2009 11:53 PM <JUNCTION> BUILTIN\Administrators Cooki
es [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Deskt
op
01/23/2013 10:48 PM <DIR> DOCUME~1 BUILTIN\Administrators Docum
ents
01/23/2013 10:48 PM <DIR> DOWNLO~1 BUILTIN\Administrators Downl
oads
01/23/2013 10:48 PM <DIR> FAVORI~1 BUILTIN\Administrators Favor
ites
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Links
07/13/2009 11:53 PM <JUNCTION> LOCALS~1 BUILTIN\Administrators Local
Settings [C:\Users\Default\AppData\Local]
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Music
07/13/2009 11:53 PM <JUNCTION> MYDOCU~1 BUILTIN\Administrators My Do
cuments [C:\Users\Default\Documents]
07/13/2009 11:53 PM <JUNCTION> BUILTIN\Administrators NetHo
od [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Pictu
res
07/13/2009 11:53 PM <JUNCTION> PRINTH~1 BUILTIN\Administrators Print
Hood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/13/2009 11:53 PM <JUNCTION> BUILTIN\Administrators Recen
t [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
01/23/2013 10:48 PM <DIR> SAVEDG~1 BUILTIN\Administrators Saved
Games
01/23/2013 10:48 PM <DIR> NT AUTHORITY\SYSTEM Searc
hes
07/13/2009 11:53 PM <JUNCTION> BUILTIN\Administrators SendT
o [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/13/2009 11:53 PM <JUNCTION> STARTM~1 BUILTIN\Administrators Start
Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/13/2009 11:53 PM <JUNCTION> TEMPLA~1 BUILTIN\Administrators Templ
ates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Video
s
0 File(s) 0 bytes
24 Dir(s) 51,280,674,816 bytes free
C:\Users>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
C:\Users>dir DEFAULT /x /q /a:d
Volume in drive C has no label.
Volume Serial Number is AE07-327D
Directory of C:\Users\DEFAULT
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators .
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators ..
01/23/2013 09:24 PM <DIR> BUILTIN\Administrators AppDa
ta
07/13/2009 11:53 PM <JUNCTION> APPLIC~1 BUILTIN\Administrators Appli
cation Data [C:\Users\Default\AppData\Roaming]
01/23/2013 10:48 PM <DIR> NT AUTHORITY\SYSTEM Conta
cts
07/13/2009 11:53 PM <JUNCTION> BUILTIN\Administrators Cooki
es [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Deskt
op
01/23/2013 10:48 PM <DIR> DOCUME~1 BUILTIN\Administrators Docum
ents
01/23/2013 10:48 PM <DIR> DOWNLO~1 BUILTIN\Administrators Downl
oads
01/23/2013 10:48 PM <DIR> FAVORI~1 BUILTIN\Administrators Favor
ites
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Links
07/13/2009 11:53 PM <JUNCTION> LOCALS~1 BUILTIN\Administrators Local
Settings [C:\Users\Default\AppData\Local]
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Music
07/13/2009 11:53 PM <JUNCTION> MYDOCU~1 BUILTIN\Administrators My Do
cuments [C:\Users\Default\Documents]
07/13/2009 11:53 PM <JUNCTION> BUILTIN\Administrators NetHo
od [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Pictu
res
07/13/2009 11:53 PM <JUNCTION> PRINTH~1 BUILTIN\Administrators Print
Hood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/13/2009 11:53 PM <JUNCTION> BUILTIN\Administrators Recen
t [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
01/23/2013 10:48 PM <DIR> SAVEDG~1 BUILTIN\Administrators Saved
Games
01/23/2013 10:48 PM <DIR> NT AUTHORITY\SYSTEM Searc
hes
07/13/2009 11:53 PM <JUNCTION> BUILTIN\Administrators SendT
o [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/13/2009 11:53 PM <JUNCTION> STARTM~1 BUILTIN\Administrators Start
Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/13/2009 11:53 PM <JUNCTION> TEMPLA~1 BUILTIN\Administrators Templ
ates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
01/23/2013 10:48 PM <DIR> BUILTIN\Administrators Video
s
0 File(s) 0 bytes
24 Dir(s) 51,280,674,816 bytes free
C:\Users>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
END OF POST