Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Skorpion saver/ adpeak proxy and something unknown


  • This topic is locked This topic is locked
19 replies to this topic

#1 totalsiege

totalsiege

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:04 AM

Posted 06 December 2013 - 11:26 PM

Hello, appreciate any help I can get can't seem to be rid of whatever is causing this. And has gotten progressively worse.

 

 I have tried Avast, Malewarebytes, Revo uninstaller, CC cleaner. I was able to get rid of it or so I thought. As time went on it was changing settings in avast and slowly taking control and responding to my efforts to rid myself of it. Only can get tools and antivirus programs work correctly in safe mode now. Whatever I seem to do in safemode doesn't effect anything when I try to run in normal mode after.

 

Ran a Maleware bytes scan attached that log also.

 

Thank you

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 9.0.8112.16520  BrowserJavaVersion: 10.21.2
Run by James at 22:37:42 on 2013-12-06
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.8190.5925 [GMT -5:00]
.
AV: avast! Internet Security *Enabled/Outdated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Internet Security *Enabled/Outdated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: avast! Internet Security *Enabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\explorer.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bing.com
uSearch Bar = hxxp://www.bing.com
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Pavilion&pf=cndt
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Pavilion&pf=cndt
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Pavilion&pf=cndt
uURLSearchHooks: {0cc09160-108c-4759-bab1-5c12c216e005} - <orphaned>
uURLSearchHooks: {b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - <orphaned>
mURLSearchHooks: {0cc09160-108c-4759-bab1-5c12c216e005} - <orphaned>
mURLSearchHooks: {b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - <orphaned>
mWinlogon: Userinit = userinit.exe,
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: ChromeFrame BHO: {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files (x86)\Google\Chrome Frame\Application\31.0.1650.57\npchrome_frame.dll
TB: Microsoft Live Search Toolbar: {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll
uRun: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW,SYSTRAY
uRun: [Google Update] "C:\Users\James\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [UpdateP2GoShortCut] "c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
mRun: [UpdateLBPShortCut] "c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
mRun: [UpdatePDIRShortCut] "c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
mRun: [UpdatePSTShortCut] "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
mRun: [TSMAgent] "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
mRun: [CLMLServer for HP TouchSmart] "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
mRun: [DVDAgent] "c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"
mRun: [Microsoft Default Manager] "c:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
TCP: NameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{BD5D0805-E5E7-4CE5-8B7C-615DC494A13B} : DHCPNameServer = 209.18.47.61 209.18.47.62
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files (x86)\Google\Chrome Frame\Application\31.0.1650.57\npchrome_frame.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
LSA: Security Packages =  kerberos msv1_0 schannel wdigest tspkg
x64-mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Pavilion&pf=cndt
x64-mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Pavilion&pf=cndt
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Run: [NVRaidService] C:\Windows\System32\nvraidservice.exe
x64-Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe /minimized
x64-mPolicies-Explorer: NoActiveDesktop = dword:1
x64-mPolicies-Explorer: NoActiveDesktopChanges = dword:1
x64-mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
x64-mPolicies-System: EnableUIADesktopToggle = dword:0
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - LocalServer32 - <no file>
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\txg0x96c.default-1386298911882\
FF - ExtSQL: 2013-11-15 16:24; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
.
============= SERVICES / DRIVERS ===============
.
.
=============== File Associations ===============
.
FileExt: .js: JSFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
FileExt: .jse: JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
.
==================== Find3M  ====================
.
.
============= FINISH: 22:38:11.26 ===============

 

Attached Files



BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:12:04 PM

Posted 07 December 2013 - 02:46 AM


Hello totalsiege

I would like to welcome you to the Malware Removal section of the forum.

Around here they call me Gringo and I will be glad to help you with your malware problems.


Very Important --> Please read this post completely, I have spent my time to put together somethings for you to keep in mind while I am helping you to make things go easier, faster and smoother for both of us!

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the "Follow This Topic" Button, make sure that the "Receive notification" box is checked and that it is set to "Instantly" - This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.


These are the programs I would like you to run next, if you have any problems with one of these just skip it and move on to the next one.

-AdwCleaner-

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
-Junkware-Removal-Tool-

Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
When they are complete let me have the two reports and let me know how things are running.

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 totalsiege

totalsiege
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:04 AM

Posted 07 December 2013 - 02:35 PM

Have been trying to get the junkware tool to work. When I attempt to run it i get this error Error during execution %temp%\jrt\get.bat  the system cannot find the file specified. Nothing is running and I am trying to run it as admin also. Is there something I am doing wrong? thanks for your time



#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:12:04 PM

Posted 07 December 2013 - 02:59 PM

Hello

run the first one then please


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#5 totalsiege

totalsiege
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:04 AM

Posted 07 December 2013 - 03:22 PM

I have run the first one. The scan and clean logs I have are

 

# AdwCleaner v3.014 - Report created 07/12/2013 at 12:34:07
# Updated 01/12/2013 by Xplode
# Operating System : Windows ™ Vista Home Premium Service Pack 2 (64 bits)
# Username : James - JAMES-PC
# Running from : C:\Users\James\Downloads\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\END
File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml
File Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
File Found : C:\Users\James\AppData\Local\funmoods-speeddial.crx
File Found : C:\Users\Public\Desktop\eBay.lnk
File Found : C:\Users\Public\Desktop\jZip.lnk
Folder Found : C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
Folder Found : C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\brgzokvb.default\Extensions\{C9B68337-E93A-44EA-94DC-CB300EC06444}
Folder Found C:\Program Files (x86)\1ClickDownload
Folder Found C:\Program Files (x86)\appbario8
Folder Found C:\Program Files (x86)\appbario8
Folder Found C:\Program Files (x86)\BitTorrentControl_v12
Folder Found C:\Program Files (x86)\Common Files\Software Update Utility
Folder Found C:\Program Files (x86)\Conduit
Folder Found C:\Program Files (x86)\jZip
Folder Found C:\Program Files (x86)\MyPC Backup
Folder Found C:\Program Files (x86)\RegClean Pro
Folder Found C:\Program Files (x86)\ScorpionSaver
Folder Found C:\Program Files (x86)\Yontoo
Folder Found C:\ProgramData\boost_interprocess
Folder Found C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jZip
Folder Found C:\ProgramData\Tarma Installer
Folder Found C:\ProgramData\WeCareReminder
Folder Found C:\Users\James\AppData\Local\Conduit
Folder Found C:\Users\James\AppData\Local\jZip
Folder Found C:\Users\James\AppData\LocalLow\appbario8
Folder Found C:\Users\James\AppData\LocalLow\appbario8
Folder Found C:\Users\James\AppData\LocalLow\BitTorrentControl_v12
Folder Found C:\Users\James\AppData\LocalLow\Conduit
Folder Found C:\Users\James\AppData\LocalLow\PriceGong
Folder Found C:\Users\James\AppData\Roaming\digitalsite
Folder Found C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sidekick Manager
Folder Found C:\Users\James\AppData\Roaming\Systweak
Folder Found C:\Users\James\Documents\Sidekick Manager
Folder Found C:\Windows\SysWOW64\Sidekick Manager

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\AppDataLow\Software\appbario8
Key Found : HKCU\Software\AppDataLow\Software\BitTorrentControl_v12
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Google\Chrome\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\appbario8 Toolbar
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BitTorrentControl_v12 Toolbar
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Funmoods
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\jZip
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SoftwareUpdUtility
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\wecarereminder
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Key Found : [x64] HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\wecarereminder
Key Found : HKLM\Software\appbario8
Key Found : HKLM\Software\BitTorrentControl_v12
Key Found : HKLM\Software\bProtector
Key Found : HKLM\SOFTWARE\Classes\AppID\{3A188115-B81B-48F2-A958-F974C8F3F309}
Key Found : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Found : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\SMBarBroker.EXE
Key Found : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{43769158-3B03-4932-8D8A-8F0F344BF024}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Found : HKLM\SOFTWARE\Classes\dnUpdate
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Found : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Found : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Found : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Found : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Found : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{78CE34FD-F6D4-4866-B79C-A37268D06A04}
Key Found : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Found : HKLM\SOFTWARE\Classes\Interface\{80904944-C726-4C7D-A452-3FFF2A882095}
Key Found : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Found : HKLM\SOFTWARE\Classes\jZip.file
Key Found : HKLM\SOFTWARE\Classes\SMBarBroker.SMBarDealer
Key Found : HKLM\SOFTWARE\Classes\SMBarBroker.SMBarDealer.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2D9B1B31-D034-4738-8F6E-40F0AFCC742C}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Key Found : HKLM\Software\Iminent
Key Found : HKLM\Software\jZip
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3614D305-2DBB-4991-9297-750DD60FFC73}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{39327B1A-38AD-413B-A2D1-4918FED71C62}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{69349727-9581-4E2E-819A-3AF278736C54}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E32E26D7-69A2-457C-9221-51725E00576F}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E54D1D08-5C7C-4B45-8300-4A9A71953288}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{17FBAC21-3A8E-43BD-AB17-F02E52037EDB}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E20AC1DB-792A-41CC-BC36-70C2EFE618C2}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\appbario8 Toolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrentControl_v12 Toolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\jZip
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{43769158-3B03-4932-8D8A-8F0F344BF024}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{78CE34FD-F6D4-4866-B79C-A37268D06A04}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{80904944-C726-4C7D-A452-3FFF2A882095}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Found : [x64] HKLM\SOFTWARE\DataMngr
Key Found : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh
Key Found : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Found : [x64] HKLM\SOFTWARE\Tarma Installer
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14}]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [webbooster@iminent.com]

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16520


-\\ Mozilla Firefox v25.0.1 (en-US)

[ File : C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\txg0x96c.default-1386298911882\prefs.js ]


-\\ Google Chrome v

[ File : C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [19424 octets] - [07/12/2013 12:34:07]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [19485 octets] ##########

 

 

# AdwCleaner v3.014 - Report created 07/12/2013 at 13:16:32
# Updated 01/12/2013 by Xplode
# Operating System : Windows ™ Vista Home Premium Service Pack 2 (64 bits)
# Username : James - JAMES-PC
# Running from : C:\Users\James\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

[!] Folder Deleted : C:\ProgramData\boost_interprocess
[!] Folder Deleted : C:\ProgramData\Tarma Installer
[!] Folder Deleted : C:\ProgramData\WeCareReminder
[!] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jZip
[!] Folder Deleted : C:\Program Files (x86)\1ClickDownload
[!] Folder Deleted : C:\Program Files (x86)\appbario8
[!] Folder Deleted : C:\Program Files (x86)\Conduit
[!] Folder Deleted : C:\Program Files (x86)\jZip
[!] Folder Deleted : C:\Program Files (x86)\MyPC Backup
[!] Folder Deleted : C:\Program Files (x86)\RegClean Pro
[!] Folder Deleted : C:\Program Files (x86)\ScorpionSaver
[!] Folder Deleted : C:\Program Files (x86)\Yontoo
[!] Folder Deleted : C:\Program Files (x86)\appbario8
[!] Folder Deleted : C:\Program Files (x86)\BitTorrentControl_v12
[!] Folder Deleted : C:\Program Files (x86)\Common Files\Software Update Utility
[!] Folder Deleted : C:\Windows\SysWOW64\Sidekick Manager
[!] Folder Deleted : C:\Users\James\AppData\Local\Conduit
[!] Folder Deleted : C:\Users\James\AppData\Local\jZip
[!] Folder Deleted : C:\Users\James\AppData\LocalLow\appbario8
[!] Folder Deleted : C:\Users\James\AppData\LocalLow\Conduit
[!] Folder Deleted : C:\Users\James\AppData\LocalLow\PriceGong
[!] Folder Deleted : C:\Users\James\AppData\LocalLow\appbario8
[!] Folder Deleted : C:\Users\James\AppData\LocalLow\BitTorrentControl_v12
[!] Folder Deleted : C:\Users\James\AppData\Roaming\digitalsite
[!] Folder Deleted : C:\Users\James\AppData\Roaming\Systweak
[!] Folder Deleted : C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sidekick Manager
[!] Folder Deleted : C:\Users\James\Documents\Sidekick Manager
[!] Folder Deleted : C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\brgzokvb.default\Extensions\{C9B68337-E93A-44EA-94DC-CB300EC06444}
[!] Folder Deleted : C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
File Deleted : C:\END
File Deleted : C:\Users\Public\Desktop\eBay.lnk
File Deleted : C:\Users\Public\Desktop\jZip.lnk
File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
File Deleted : C:\Users\James\AppData\Local\funmoods-speeddial.crx
File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [webbooster@iminent.com]
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Key Deleted : HKCU\Software\Google\Chrome\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\SMBarBroker.EXE
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Classes\jZip.file
Key Deleted : HKLM\SOFTWARE\Classes\SMBarBroker.SMBarDealer
Key Deleted : HKLM\SOFTWARE\Classes\SMBarBroker.SMBarDealer.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3A188115-B81B-48F2-A958-F974C8F3F309}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{43769158-3B03-4932-8D8A-8F0F344BF024}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78CE34FD-F6D4-4866-B79C-A37268D06A04}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{80904944-C726-4C7D-A452-3FFF2A882095}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D9B1B31-D034-4738-8F6E-40F0AFCC742C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{17FBAC21-3A8E-43BD-AB17-F02E52037EDB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E20AC1DB-792A-41CC-BC36-70C2EFE618C2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3614D305-2DBB-4991-9297-750DD60FFC73}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E32E26D7-69A2-457C-9221-51725E00576F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{39327B1A-38AD-413B-A2D1-4918FED71C62}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E54D1D08-5C7C-4B45-8300-4A9A71953288}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{69349727-9581-4E2E-819A-3AF278736C54}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\wecarereminder
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\appbario8
Key Deleted : HKCU\Software\AppDataLow\Software\BitTorrentControl_v12
Key Deleted : HKLM\Software\bProtector
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\Software\jZip
Key Deleted : HKLM\Software\appbario8
Key Deleted : HKLM\Software\BitTorrentControl_v12
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\jZip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\appbario8 Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrentControl_v12 Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Funmoods
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\jZip
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SoftwareUpdUtility
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\appbario8 Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BitTorrentControl_v12 Toolbar
Key Deleted : [x64] HKLM\SOFTWARE\DataMngr
Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16520


-\\ Mozilla Firefox v25.0.1 (en-US)

[ File : C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\txg0x96c.default-1386298911882\prefs.js ]


-\\ Google Chrome v

[ File : C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [19818 octets] - [07/12/2013 12:34:07]
AdwCleaner[S0].txt - [15389 octets] - [07/12/2013 13:16:32]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [15450 octets] ##########


 



#6 totalsiege

totalsiege
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:04 AM

Posted 07 December 2013 - 06:17 PM

found this in a temp folder with a skorpion saver app file. Hope this can help to solve the problem.

=== Verbose logging started: 12/3/2013  10:11:03  Build type: SHIP UNICODE 4.05.6002.00  Calling process: c:\windows\system32\msiexec.exe ===
MSI © (84:70) [10:11:03:287]: Resetting cached policy values
MSI © (84:70) [10:11:03:287]: Machine policy value 'Debug' is 0
MSI © (84:70) [10:11:03:287]: ******* RunEngine:
           ******* Product: c:\\temp\\ScorpionSaver.msi
           ******* Action:
           ******* CommandLine: **********
MSI © (84:70) [10:11:03:288]: Client-side and UI is none or basic: Running entire install on the server.
MSI © (84:70) [10:11:03:288]: Grabbed execution mutex.
MSI © (84:70) [10:11:03:395]: Cloaking enabled.
MSI © (84:70) [10:11:03:395]: Attempting to enable all disabled privileges before calling Install on Server
MSI © (84:70) [10:11:03:399]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (84:F8) [10:11:03:409]: Running installation inside multi-package transaction c:\\temp\\ScorpionSaver.msi
MSI (s) (84:F8) [10:11:03:409]: Grabbed execution mutex.
MSI (s) (84:7C) [10:11:03:410]: Resetting cached policy values
MSI (s) (84:7C) [10:11:03:410]: Machine policy value 'Debug' is 0
MSI (s) (84:7C) [10:11:03:410]: ******* RunEngine:
           ******* Product: c:\\temp\\ScorpionSaver.msi
           ******* Action:
           ******* CommandLine: **********
MSI (s) (84:7C) [10:11:03:411]: Machine policy value 'DisableUserInstalls' is 0
MSI (s) (84:7C) [10:11:03:434]: SRSetRestorePoint skipped for this transaction.
MSI (s) (84:7C) [10:11:03:436]: File will have security applied from OpCode.
MSI (s) (84:7C) [10:11:03:448]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'c:\\temp\\ScorpionSaver.msi' against software restriction policy
MSI (s) (84:7C) [10:11:03:448]: SOFTWARE RESTRICTION POLICY: c:\\temp\\ScorpionSaver.msi has a digital signature
MSI (s) (84:7C) [10:11:03:554]: SOFTWARE RESTRICTION POLICY: c:\\temp\\ScorpionSaver.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (84:7C) [10:11:03:554]: End dialog not enabled
MSI (s) (84:7C) [10:11:03:554]: Original package ==> c:\\temp\\ScorpionSaver.msi
MSI (s) (84:7C) [10:11:03:554]: Package we're running from ==> c:\Windows\Installer\18cc22d.msi
MSI (s) (84:7C) [10:11:03:572]: APPCOMPAT: looking for appcompat database entry with ProductCode '{9B65F9A3-9D24-452A-B6EF-1457D65E4259}'.
MSI (s) (84:7C) [10:11:03:572]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (84:7C) [10:11:03:578]: MSCOREE not loaded loading copy from system32
MSI (s) (84:7C) [10:11:03:597]: Machine policy value 'TransformsSecure' is 0
MSI (s) (84:7C) [10:11:03:597]: User policy value 'TransformsAtSource' is 0
MSI (s) (84:7C) [10:11:03:598]: Machine policy value 'DisablePatch' is 0
MSI (s) (84:7C) [10:11:03:598]: Machine policy value 'AllowLockdownPatch' is 0
MSI (s) (84:7C) [10:11:03:598]: Machine policy value 'DisableMsi' is 0
MSI (s) (84:7C) [10:11:03:598]: Machine policy value 'AlwaysInstallElevated' is 1
MSI (s) (84:7C) [10:11:03:598]: User policy value 'AlwaysInstallElevated' is 1
MSI (s) (84:7C) [10:11:03:598]: Running product '{9B65F9A3-9D24-452A-B6EF-1457D65E4259}' with elevated privileges: All apps run elevated.
MSI (s) (84:7C) [10:11:03:598]: Machine policy value 'DisableLUAPatching' is 0
MSI (s) (84:7C) [10:11:03:599]: Machine policy value 'DisableFlyWeightPatching' is 0
MSI (s) (84:7C) [10:11:03:599]: APPCOMPAT: looking for appcompat database entry with ProductCode '{9B65F9A3-9D24-452A-B6EF-1457D65E4259}'.
MSI (s) (84:7C) [10:11:03:599]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (84:7C) [10:11:03:599]: Transforms are not secure.
MSI (s) (84:7C) [10:11:03:599]: Note: 1: 2205 2:  3: Control
MSI (s) (84:7C) [10:11:03:599]: PROPERTY CHANGE: Adding MsiLogFileLocation property. Its value is 'c:\\temp\\foo.txt'.
MSI (s) (84:7C) [10:11:03:599]: Command Line: sourceguid=F5D333A8-C748-4686-AE0A-9E008F670C22 userguid=4C4108F8-17B8-4CBA-E710-4E7812FCAD1F options=01110010000000000000000000000000 CURRENTDIRECTORY=C:\Windows\system32 CLIENTUILEVEL=3 CLIENTPROCESSID=5764
MSI (s) (84:7C) [10:11:03:599]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{A5122D60-0F73-4E51-B932-09546C8362F3}'.
MSI (s) (84:7C) [10:11:03:599]: Product Code passed to Engine.Initialize:           ''
MSI (s) (84:7C) [10:11:03:599]: Product Code from property table before transforms: '{9B65F9A3-9D24-452A-B6EF-1457D65E4259}'
MSI (s) (84:7C) [10:11:03:599]: Product Code from property table after transforms:  '{9B65F9A3-9D24-452A-B6EF-1457D65E4259}'
MSI (s) (84:7C) [10:11:03:599]: Product not registered: beginning first-time install
MSI (s) (84:7C) [10:11:03:599]: Product {9B65F9A3-9D24-452A-B6EF-1457D65E4259} is not managed.
MSI (s) (84:7C) [10:11:03:600]: Machine policy value 'AlwaysInstallElevated' is 1
MSI (s) (84:7C) [10:11:03:600]: User policy value 'AlwaysInstallElevated' is 1
MSI (s) (84:7C) [10:11:03:600]: MSI_LUA: No credentials required as all installs will run elevated due to AlwaysInstallElevated policy setting
MSI (s) (84:7C) [10:11:03:600]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.
MSI (s) (84:7C) [10:11:03:600]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (84:7C) [10:11:03:600]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (84:7C) [10:11:03:600]: Adding new sources is allowed.
MSI (s) (84:7C) [10:11:03:600]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.
MSI (s) (84:7C) [10:11:03:600]: Package name extracted from package path: 'ScorpionSaver.msi'
MSI (s) (84:7C) [10:11:03:600]: Package to be registered: 'ScorpionSaver.msi'
MSI (s) (84:7C) [10:11:03:600]: Note: 1: 2205 2:  3: Error
MSI (s) (84:7C) [10:11:03:601]: Note: 1: 2262 2: AdminProperties 3: -2147287038
MSI (s) (84:7C) [10:11:03:601]: Machine policy value 'AlwaysInstallElevated' is 1
MSI (s) (84:7C) [10:11:03:601]: User policy value 'AlwaysInstallElevated' is 1
MSI (s) (84:7C) [10:11:03:601]: Running product '{9B65F9A3-9D24-452A-B6EF-1457D65E4259}' with elevated privileges: All apps run elevated.
MSI (s) (84:7C) [10:11:03:601]: Machine policy value 'EnableUserControl' is 0
MSI (s) (84:7C) [10:11:03:601]: PROPERTY CHANGE: Adding RestrictedUserControl property. Its value is '1'.
MSI (s) (84:7C) [10:11:03:601]: PROPERTY CHANGE: Modifying SOURCEGUID property. Its current value is 'CCC9642C-CB76-46E5-AF27-7D7B5DD2348B'. Its new value: 'F5D333A8-C748-4686-AE0A-9E008F670C22'.
MSI (s) (84:7C) [10:11:03:601]: PROPERTY CHANGE: Modifying USERGUID property. Its current value is '00000000-0000-0000-0000-000000000000'. Its new value: '4C4108F8-17B8-4CBA-E710-4E7812FCAD1F'.
MSI (s) (84:7C) [10:11:03:601]: PROPERTY CHANGE: Modifying OPTIONS property. Its current value is '-1'. Its new value: '01110010000000000000000000000000'.
MSI (s) (84:7C) [10:11:03:601]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'C:\Windows\system32'.
MSI (s) (84:7C) [10:11:03:601]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.
MSI (s) (84:7C) [10:11:03:602]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '5764'.
MSI (s) (84:7C) [10:11:03:602]: Machine policy value 'DisableAutomaticApplicationShutdown' is 0
MSI (s) (84:7C) [10:11:03:603]: PROPERTY CHANGE: Adding MsiRestartManagerSessionKey property. Its value is 'd9b9348fcfdda54b8ad29800182bd107'.
MSI (s) (84:7C) [10:11:03:603]: RESTART MANAGER: Session opened.
MSI (s) (84:7C) [10:11:03:603]: TRANSFORMS property is now:
MSI (s) (84:7C) [10:11:03:603]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '300'.
MSI (s) (84:7C) [10:11:03:604]: SHELL32::SHGetFolderPath returned: C:\Users\James\AppData\Roaming
MSI (s) (84:7C) [10:11:03:605]: SHELL32::SHGetFolderPath returned: C:\Users\James\Favorites
MSI (s) (84:7C) [10:11:03:607]: SHELL32::SHGetFolderPath returned: C:\Users\James\AppData\Roaming\Microsoft\Windows\Network Shortcuts
MSI (s) (84:7C) [10:11:03:608]: SHELL32::SHGetFolderPath returned: C:\Users\James\Documents
MSI (s) (84:7C) [10:11:03:609]: SHELL32::SHGetFolderPath returned: C:\Users\James\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
MSI (s) (84:7C) [10:11:03:610]: SHELL32::SHGetFolderPath returned: C:\Users\James\AppData\Roaming\Microsoft\Windows\Recent
MSI (s) (84:7C) [10:11:03:611]: SHELL32::SHGetFolderPath returned: C:\Users\James\AppData\Roaming\Microsoft\Windows\SendTo
MSI (s) (84:7C) [10:11:03:612]: SHELL32::SHGetFolderPath returned: C:\Users\James\AppData\Roaming\Microsoft\Windows\Templates
MSI (s) (84:7C) [10:11:03:612]: SHELL32::SHGetFolderPath returned: C:\ProgramData
MSI (s) (84:7C) [10:11:03:613]: SHELL32::SHGetFolderPath returned: C:\Users\James\AppData\Local
MSI (s) (84:7C) [10:11:03:614]: SHELL32::SHGetFolderPath returned: C:\Users\James\Pictures
MSI (s) (84:7C) [10:11:03:616]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
MSI (s) (84:7C) [10:11:03:617]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
MSI (s) (84:7C) [10:11:03:618]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs
MSI (s) (84:7C) [10:11:03:619]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu
MSI (s) (84:7C) [10:11:03:620]: SHELL32::SHGetFolderPath returned: C:\Users\Public\Desktop
MSI (s) (84:7C) [10:11:03:622]: SHELL32::SHGetFolderPath returned: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
MSI (s) (84:7C) [10:11:03:624]: SHELL32::SHGetFolderPath returned: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MSI (s) (84:7C) [10:11:03:625]: SHELL32::SHGetFolderPath returned: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
MSI (s) (84:7C) [10:11:03:626]: SHELL32::SHGetFolderPath returned: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu
MSI (s) (84:7C) [10:11:03:627]: SHELL32::SHGetFolderPath returned: C:\Users\James\Desktop
MSI (s) (84:7C) [10:11:03:628]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Templates
MSI (s) (84:7C) [10:11:03:628]: SHELL32::SHGetFolderPath returned: C:\Windows\Fonts
MSI (s) (84:7C) [10:11:03:629]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16
MSI (s) (84:7C) [10:11:03:635]: MSI_LUA: Setting MsiRunningElevated property to 1 because the install is already running elevated.
MSI (s) (84:7C) [10:11:03:635]: PROPERTY CHANGE: Adding MsiRunningElevated property. Its value is '1'.
MSI (s) (84:7C) [10:11:03:635]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
MSI (s) (84:7C) [10:11:03:635]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (84:7C) [10:11:03:635]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'James'.
MSI (s) (84:7C) [10:11:03:635]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (84:7C) [10:11:03:635]: PROPERTY CHANGE: Adding COMPANYNAME property. Its value is 'Hewlett-Packard Company'.
MSI (s) (84:7C) [10:11:03:635]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'c:\Windows\Installer\18cc22d.msi'.
MSI (s) (84:7C) [10:11:03:635]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'c:\\temp\\ScorpionSaver.msi'.
MSI (s) (84:7C) [10:11:03:635]: Machine policy value 'MsiDisableEmbeddedUI' is 0
MSI (s) (84:7C) [10:11:03:635]: EEUI - Disabling MsiEmbeddedUI for service because it's not a quiet/basic install
MSI (s) (84:7C) [10:11:03:636]: Note: 1: 2205 2:  3: PatchPackage
MSI (s) (84:7C) [10:11:03:636]: Machine policy value 'DisableRollback' is 0
MSI (s) (84:7C) [10:11:03:636]: User policy value 'DisableRollback' is 0
MSI (s) (84:7C) [10:11:03:636]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.
=== Logging started: 12/3/2013  10:11:03 ===
MSI (s) (84:7C) [10:11:03:636]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
MSI (s) (84:7C) [10:11:03:636]: Doing action: INSTALL
MSI (s) (84:7C) [10:11:03:636]: Note: 1: 2205 2:  3: ActionText
Action start 10:11:03: INSTALL.
MSI (s) (84:7C) [10:11:03:638]: Running ExecuteSequence
MSI (s) (84:7C) [10:11:03:638]: Doing action: FindRelatedProducts
MSI (s) (84:7C) [10:11:03:638]: Note: 1: 2205 2:  3: ActionText
Action start 10:11:03: FindRelatedProducts.
MSI (s) (84:7C) [10:11:03:661]: Doing action: AppSearch
MSI (s) (84:7C) [10:11:03:661]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: FindRelatedProducts. Return value 1.
Action start 10:11:03: AppSearch.
MSI (s) (84:7C) [10:11:03:662]: Note: 1: 2262 2: Signature 3: -2147287038
MSI (s) (84:7C) [10:11:03:662]: PROPERTY CHANGE: Adding MYLOCALAPPDATA property. Its value is 'c:\Users\James\AppData\Local\'.
MSI (s) (84:7C) [10:11:03:663]: Doing action: LaunchConditions
MSI (s) (84:7C) [10:11:03:663]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: AppSearch. Return value 1.
Action start 10:11:03: LaunchConditions.
MSI (s) (84:7C) [10:11:03:663]: Doing action: ValidateProductID
MSI (s) (84:7C) [10:11:03:663]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: LaunchConditions. Return value 1.
Action start 10:11:03: ValidateProductID.
MSI (s) (84:7C) [10:11:03:665]: Doing action: CostInitialize
MSI (s) (84:7C) [10:11:03:665]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: ValidateProductID. Return value 1.
MSI (s) (84:7C) [10:11:03:665]: Machine policy value 'MaxPatchCacheSize' is 10
Action start 10:11:03: CostInitialize.
MSI (s) (84:7C) [10:11:03:667]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'c:\'.
MSI (s) (84:7C) [10:11:03:667]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.
MSI (s) (84:7C) [10:11:03:667]: Note: 1: 2205 2:  3: Patch
MSI (s) (84:7C) [10:11:03:667]: Note: 1: 2205 2:  3: PatchPackage
MSI (s) (84:7C) [10:11:03:667]: Note: 1: 2205 2:  3: MsiPatchHeaders
MSI (s) (84:7C) [10:11:03:667]: Note: 1: 2205 2:  3: __MsiPatchFileList
MSI (s) (84:7C) [10:11:03:668]: Note: 1: 2205 2:  3: PatchPackage
MSI (s) (84:7C) [10:11:03:668]: Note: 1: 2228 2:  3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId`  
MSI (s) (84:7C) [10:11:03:668]: Note: 1: 2205 2:  3: Patch
MSI (s) (84:7C) [10:11:03:668]: Doing action: SetINSTALLLOCATION
MSI (s) (84:7C) [10:11:03:668]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: CostInitialize. Return value 1.
MSI (s) (84:7C) [10:11:03:669]: PROPERTY CHANGE: Adding INSTALLLOCATION property. Its value is 'C:\Program Files (x86)\ScorpionSaver'.
Action start 10:11:03: SetINSTALLLOCATION.
MSI (s) (84:7C) [10:11:03:670]: Doing action: FileCost
MSI (s) (84:7C) [10:11:03:670]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: SetINSTALLLOCATION. Return value 1.
MSI (s) (84:7C) [10:11:03:670]: Note: 1: 2205 2:  3: MsiAssembly
MSI (s) (84:7C) [10:11:03:670]: Note: 1: 2205 2:  3: Class
MSI (s) (84:7C) [10:11:03:670]: Note: 1: 2205 2:  3: Extension
MSI (s) (84:7C) [10:11:03:670]: Note: 1: 2205 2:  3: TypeLib
Action start 10:11:03: FileCost.
MSI (s) (84:7C) [10:11:03:671]: Doing action: SetChromeIdPath
MSI (s) (84:7C) [10:11:03:671]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: FileCost. Return value 1.
MSI (s) (84:7C) [10:11:03:672]: PROPERTY CHANGE: Adding ChromeIdPath property. Its value is 'c:\Users\James\AppData\Local\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg'.
Action start 10:11:03: SetChromeIdPath.
MSI (s) (84:7C) [10:11:03:672]: Doing action: SetChromeVersionPath
MSI (s) (84:7C) [10:11:03:672]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: SetChromeIdPath. Return value 1.
MSI (s) (84:7C) [10:11:03:673]: PROPERTY CHANGE: Adding ChromeVersionPath property. Its value is 'c:\Users\James\AppData\Local\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0'.
Action start 10:11:03: SetChromeVersionPath.
MSI (s) (84:7C) [10:11:03:674]: Doing action: CostFinalize
MSI (s) (84:7C) [10:11:03:674]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: SetChromeVersionPath. Return value 1.
MSI (s) (84:7C) [10:11:03:674]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.
MSI (s) (84:7C) [10:11:03:674]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.
MSI (s) (84:7C) [10:11:03:674]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.
MSI (s) (84:7C) [10:11:03:674]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.
MSI (s) (84:7C) [10:11:03:674]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.
MSI (s) (84:7C) [10:11:03:674]: Note: 1: 2205 2:  3: Patch
MSI (s) (84:7C) [10:11:03:674]: Note: 1: 2205 2:  3: Condition
MSI (s) (84:7C) [10:11:03:675]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'c:\'.
MSI (s) (84:7C) [10:11:03:675]: PROPERTY CHANGE: Modifying WindowsFolder property. Its current value is 'C:\Windows\'. Its new value: 'c:\Windows\'.
MSI (s) (84:7C) [10:11:03:675]: PROPERTY CHANGE: Modifying ProgramFilesFolder property. Its current value is 'C:\Program Files (x86)\'. Its new value: 'c:\Program Files (x86)\'.
MSI (s) (84:7C) [10:11:03:675]: PROPERTY CHANGE: Modifying INSTALLLOCATION property. Its current value is 'C:\Program Files (x86)\ScorpionSaver'. Its new value: 'c:\Program Files (x86)\ScorpionSaver\'.
MSI (s) (84:7C) [10:11:03:675]: PROPERTY CHANGE: Adding Google property. Its value is 'c:\Users\James\AppData\Local\Google\'.
MSI (s) (84:7C) [10:11:03:675]: PROPERTY CHANGE: Adding Chrome property. Its value is 'c:\Users\James\AppData\Local\Google\Chrome\'.
MSI (s) (84:7C) [10:11:03:675]: PROPERTY CHANGE: Adding User_Data property. Its value is 'c:\Users\James\AppData\Local\Google\Chrome\User Data\'.
MSI (s) (84:7C) [10:11:03:675]: PROPERTY CHANGE: Adding Default property. Its value is 'c:\Users\James\AppData\Local\Google\Chrome\User Data\Default\'.
MSI (s) (84:7C) [10:11:03:675]: PROPERTY CHANGE: Adding Extensions property. Its value is 'c:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\'.
MSI (s) (84:7C) [10:11:03:675]: PROPERTY CHANGE: Modifying ChromeIdPath property. Its current value is 'c:\Users\James\AppData\Local\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg'. Its new value: 'c:\Users\James\AppData\Local\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\'.
MSI (s) (84:7C) [10:11:03:676]: PROPERTY CHANGE: Modifying ChromeVersionPath property. Its current value is 'c:\Users\James\AppData\Local\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0'. Its new value: 'c:\Users\James\AppData\Local\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\'.
MSI (s) (84:7C) [10:11:03:676]: Target path resolution complete. Dumping Directory table...
MSI (s) (84:7C) [10:11:03:676]: Note: target paths subject to change (via custom actions or browsing)
MSI (s) (84:7C) [10:11:03:676]: Dir (target): Key: TARGETDIR    , Object: c:\
MSI (s) (84:7C) [10:11:03:676]: Dir (target): Key: WindowsFolder    , Object: c:\Windows\
MSI (s) (84:7C) [10:11:03:676]: Dir (target): Key: ProgramFilesFolder    , Object: c:\Program Files (x86)\
MSI (s) (84:7C) [10:11:03:676]: Dir (target): Key: INSTALLLOCATION    , Object: c:\Program Files (x86)\ScorpionSaver\
MSI (s) (84:7C) [10:11:03:676]: Dir (target): Key: MYLOCALAPPDATA    , Object: c:\Users\James\AppData\Local\
MSI (s) (84:7C) [10:11:03:676]: Dir (target): Key: Google    , Object: c:\Users\James\AppData\Local\Google\
MSI (s) (84:7C) [10:11:03:676]: Dir (target): Key: Chrome    , Object: c:\Users\James\AppData\Local\Google\Chrome\
MSI (s) (84:7C) [10:11:03:676]: Dir (target): Key: User_Data    , Object: c:\Users\James\AppData\Local\Google\Chrome\User Data\
MSI (s) (84:7C) [10:11:03:676]: Dir (target): Key: Default    , Object: c:\Users\James\AppData\Local\Google\Chrome\User Data\Default\
MSI (s) (84:7C) [10:11:03:676]: Dir (target): Key: Extensions    , Object: c:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\
MSI (s) (84:7C) [10:11:03:676]: Dir (target): Key: ChromeIdPath    , Object: c:\Users\James\AppData\Local\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\
MSI (s) (84:7C) [10:11:03:676]: Dir (target): Key: ChromeVersionPath    , Object: c:\Users\James\AppData\Local\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg\5.0_0\
MSI (s) (84:7C) [10:11:03:676]: PROPERTY CHANGE: Adding INSTALLLEVEL property. Its value is '1'.
MSI (s) (84:7C) [10:11:03:676]: Note: 1: 2205 2:  3: MsiAssembly
MSI (s) (84:7C) [10:11:03:676]: Note: 1: 2228 2:  3: MsiAssembly 4:  SELECT `MsiAssembly`.`Attributes`, `MsiAssembly`.`File_Application`, `MsiAssembly`.`File_Manifest`,  `Component`.`KeyPath` FROM `MsiAssembly`, `Component` WHERE  `MsiAssembly`.`Component_` = `Component`.`Component` AND `MsiAssembly`.`Component_` = ?
Action start 10:11:03: CostFinalize.
MSI (s) (84:7C) [10:11:03:676]: Doing action: MigrateFeatureStates
MSI (s) (84:7C) [10:11:03:676]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: CostFinalize. Return value 1.
Action start 10:11:03: MigrateFeatureStates.
MSI (s) (84:7C) [10:11:03:677]: Doing action: InstallValidate
MSI (s) (84:7C) [10:11:03:677]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: MigrateFeatureStates. Return value 0.
MSI (s) (84:7C) [10:11:03:678]: PROPERTY CHANGE: Deleting MsiRestartManagerSessionKey property. Its current value is 'd9b9348fcfdda54b8ad29800182bd107'.
MSI (s) (84:7C) [10:11:03:678]: Note: 1: 2205 2:  3: Dialog
MSI (s) (84:7C) [10:11:03:678]: Feature: ProductFeature; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: ChromeFiles; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: INSTALLLOCATION; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: SendJson; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: RegistryEntries; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: IECore.dll; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: ChromeCAs; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: FirefoxFiles; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: RemoveChromeGoogle; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: RemoveChromeChrome; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: RemoveChromeUser_Data; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: RemoveChromeDefault; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: RemoveChromeExtensions; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: RemoveChromeId; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: RemoveChromeVersion; Installed: Absent;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: __ChromeFiles65; Installed: Null;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: __RegistryEntries65; Installed: Null;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: __RemoveChromeGoogle65; Installed: Null;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: __RemoveChromeChrome65; Installed: Null;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: __RemoveChromeUser_Data65; Installed: Null;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: __RemoveChromeDefault65; Installed: Null;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: __RemoveChromeExtensions65; Installed: Null;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: __RemoveChromeId65; Installed: Null;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Component: __RemoveChromeVersion65; Installed: Null;   Request: Local;   Action: Local
MSI (s) (84:7C) [10:11:03:678]: Note: 1: 2205 2:  3: BindImage
MSI (s) (84:7C) [10:11:03:678]: Note: 1: 2205 2:  3: ProgId
MSI (s) (84:7C) [10:11:03:678]: Note: 1: 2205 2:  3: PublishComponent
MSI (s) (84:7C) [10:11:03:678]: Note: 1: 2205 2:  3: SelfReg
MSI (s) (84:7C) [10:11:03:678]: Note: 1: 2205 2:  3: Extension
MSI (s) (84:7C) [10:11:03:678]: Note: 1: 2205 2:  3: Font
MSI (s) (84:7C) [10:11:03:678]: Note: 1: 2205 2:  3: Shortcut
MSI (s) (84:7C) [10:11:03:678]: Note: 1: 2205 2:  3: Class
Action start 10:11:03: InstallValidate.
MSI (s) (84:7C) [10:11:03:679]: Note: 1: 2205 2:  3: _RemoveFilePath
MSI (s) (84:7C) [10:11:03:691]: PROPERTY CHANGE: Modifying CostingComplete property. Its current value is '0'. Its new value: '1'.
MSI (s) (84:7C) [10:11:03:691]: Note: 1: 2205 2:  3: BindImage
MSI (s) (84:7C) [10:11:03:691]: Note: 1: 2205 2:  3: ProgId
MSI (s) (84:7C) [10:11:03:691]: Note: 1: 2205 2:  3: PublishComponent
MSI (s) (84:7C) [10:11:03:691]: Note: 1: 2205 2:  3: SelfReg
MSI (s) (84:7C) [10:11:03:691]: Note: 1: 2205 2:  3: Extension
MSI (s) (84:7C) [10:11:03:691]: Note: 1: 2205 2:  3: Font
MSI (s) (84:7C) [10:11:03:691]: Note: 1: 2205 2:  3: Shortcut
MSI (s) (84:7C) [10:11:03:691]: Note: 1: 2205 2:  3: Class
MSI (s) (84:7C) [10:11:03:691]: Note: 1: 2727 2:  
MSI (s) (84:7C) [10:11:03:711]: Note: 1: 2727 2:  
MSI (s) (84:7C) [10:11:03:712]: Doing action: RemoveExistingProducts
MSI (s) (84:7C) [10:11:03:712]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: InstallValidate. Return value 1.
MSI (s) (84:7C) [10:11:03:712]: Note: 1: 2205 2:  3: Error
MSI (s) (84:7C) [10:11:03:713]: Note: 1: 2228 2:  3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 22
Action start 10:11:03: RemoveExistingProducts.
MSI (s) (84:7C) [10:11:03:713]: Note: 1: 2205 2:  3: Error
MSI (s) (84:7C) [10:11:03:713]: Note: 1: 2228 2:  3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 23
MSI (s) (84:7C) [10:11:03:713]: Note: 1: 2205 2:  3: Error
MSI (s) (84:7C) [10:11:03:713]: Note: 1: 2228 2:  3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 16
MSI (s) (84:7C) [10:11:03:713]: Note: 1: 2205 2:  3: Error
MSI (s) (84:7C) [10:11:03:713]: Note: 1: 2228 2:  3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 21
MSI (s) (84:7C) [10:11:03:713]: Doing action: InstallInitialize
MSI (s) (84:7C) [10:11:03:713]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: RemoveExistingProducts. Return value 1.
MSI (s) (84:7C) [10:11:03:715]: Machine policy value 'AlwaysInstallElevated' is 1
MSI (s) (84:7C) [10:11:03:715]: User policy value 'AlwaysInstallElevated' is 1
MSI (s) (84:7C) [10:11:03:715]: BeginTransaction: Locking Server
MSI (s) (84:7C) [10:11:03:715]: SRSetRestorePoint skipped for this transaction.
MSI (s) (84:7C) [10:11:03:715]: Server not locked: locking for product {9B65F9A3-9D24-452A-B6EF-1457D65E4259}
Action start 10:11:03: InstallInitialize.
MSI (s) (84:7C) [10:11:03:760]: Doing action: ProcessComponents
MSI (s) (84:7C) [10:11:03:760]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: InstallInitialize. Return value 1.
MSI (s) (84:7C) [10:11:03:761]: Note: 1: 2205 2:  3: MsiPatchCertificate
MSI (s) (84:7C) [10:11:03:761]: LUA patching is disabled: missing MsiPatchCertificate table
MSI (s) (84:7C) [10:11:03:761]: Resolving source.
MSI (s) (84:7C) [10:11:03:761]: Resolving source to launched-from source.
MSI (s) (84:7C) [10:11:03:761]: Setting launched-from source as last-used.
MSI (s) (84:7C) [10:11:03:761]: PROPERTY CHANGE: Adding SourceDir property. Its value is 'c:\\temp\\'.
MSI (s) (84:7C) [10:11:03:761]: PROPERTY CHANGE: Adding SOURCEDIR property. Its value is 'c:\\temp\\'.
MSI (s) (84:7C) [10:11:03:761]: PROPERTY CHANGE: Adding SourcedirProduct property. Its value is '{9B65F9A3-9D24-452A-B6EF-1457D65E4259}'.
MSI (s) (84:7C) [10:11:03:761]: SOURCEDIR ==> c:\\temp\\
MSI (s) (84:7C) [10:11:03:761]: SOURCEDIR product ==> {9B65F9A3-9D24-452A-B6EF-1457D65E4259}
MSI (s) (84:7C) [10:11:03:761]: Determining source type
MSI (s) (84:7C) [10:11:03:762]: Source type from package 'ScorpionSaver.msi': 2
MSI (s) (84:7C) [10:11:03:762]: Source path resolution complete. Dumping Directory table...
MSI (s) (84:7C) [10:11:03:762]: Dir (source): Key: TARGETDIR    , Object: c:\temp\    , LongSubPath:     , ShortSubPath:
MSI (s) (84:7C) [10:11:03:762]: Dir (source): Key: WindowsFolder    , Object: c:\temp\    , LongSubPath:     , ShortSubPath:
MSI (s) (84:7C) [10:11:03:762]: Dir (source): Key: ProgramFilesFolder    , Object: c:\temp\    , LongSubPath:     , ShortSubPath:
MSI (s) (84:7C) [10:11:03:762]: Dir (source): Key: INSTALLLOCATION    , Object: c:\temp\    , LongSubPath:     , ShortSubPath:
MSI (s) (84:7C) [10:11:03:762]: Dir (source): Key: MYLOCALAPPDATA    , Object: c:\temp\    , LongSubPath:     , ShortSubPath:
MSI (s) (84:7C) [10:11:03:762]: Dir (source): Key: Google    , Object: c:\temp\    , LongSubPath: Google\    , ShortSubPath:
MSI (s) (84:7C) [10:11:03:762]: Dir (source): Key: Chrome    , Object: c:\temp\    , LongSubPath: Google\Chrome\    , ShortSubPath:
MSI (s) (84:7C) [10:11:03:762]: Dir (source): Key: User_Data    , Object: c:\temp\    , LongSubPath: Google\Chrome\User Data\    , ShortSubPath: Google\Chrome\7irmzgvy\
MSI (s) (84:7C) [10:11:03:762]: Dir (source): Key: Default    , Object: c:\temp\    , LongSubPath: Google\Chrome\User Data\Default\    , ShortSubPath: Google\Chrome\7irmzgvy\Default\
MSI (s) (84:7C) [10:11:03:762]: Dir (source): Key: Extensions    , Object: c:\temp\    , LongSubPath: Google\Chrome\User Data\Default\Extensions\    , ShortSubPath: Google\Chrome\7irmzgvy\Default\xrskbwz_\
MSI (s) (84:7C) [10:11:03:762]: Dir (source): Key: ChromeIdPath    , Object: c:\temp\    , LongSubPath: Google\Chrome\User Data\Default\Extensions\ChromeIdPath\    , ShortSubPath: Google\Chrome\7irmzgvy\Default\xrskbwz_\aktvvl6_\
MSI (s) (84:7C) [10:11:03:762]: Dir (source): Key: ChromeVersionPath    , Object: c:\temp\    , LongSubPath: Google\Chrome\User Data\Default\Extensions\ChromeIdPath\ChromeVersionPath\    , ShortSubPath: Google\Chrome\7irmzgvy\Default\xrskbwz_\aktvvl6_\zxzkj_de\
MSI (s) (84:7C) [10:11:03:762]: Note: 1: 2205 2:  3: ActionText
MSI (s) (84:7C) [10:11:03:762]: Note: 1: 2205 2:  3: ActionText
MSI (s) (84:7C) [10:11:03:764]: Note: 1: 2205 2:  3: ActionText
Action start 10:11:03: ProcessComponents.
MSI (s) (84:7C) [10:11:03:767]: Doing action: UnpublishFeatures
MSI (s) (84:7C) [10:11:03:767]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: ProcessComponents. Return value 1.
Action start 10:11:03: UnpublishFeatures.
MSI (s) (84:7C) [10:11:03:768]: Doing action: RemoveRegistryValues
MSI (s) (84:7C) [10:11:03:768]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: UnpublishFeatures. Return value 1.
Action start 10:11:03: RemoveRegistryValues.
MSI (s) (84:7C) [10:11:03:769]: Doing action: RemoveFiles
MSI (s) (84:7C) [10:11:03:769]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: RemoveRegistryValues. Return value 1.
Action start 10:11:03: RemoveFiles.
MSI (s) (84:7C) [10:11:03:770]: Doing action: InstallFiles
MSI (s) (84:7C) [10:11:03:770]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: RemoveFiles. Return value 1.
Action start 10:11:03: InstallFiles.
MSI (s) (84:7C) [10:11:03:774]: Note: 1: 2205 2:  3: Patch
MSI (s) (84:7C) [10:11:03:774]: Note: 1: 2228 2:  3: Patch 4: SELECT `Patch`.`File_`, `Patch`.`Header`, `Patch`.`Attributes`, `Patch`.`Sequence`, `Patch`.`StreamRef_` FROM `Patch` WHERE `Patch`.`File_` = ? AND `Patch`.`#_MsiActive`=? ORDER BY `Patch`.`Sequence`
MSI (s) (84:7C) [10:11:03:774]: Note: 1: 2205 2:  3: Error
MSI (s) (84:7C) [10:11:03:774]: Note: 1: 2228 2:  3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1302
MSI (s) (84:7C) [10:11:03:774]: Note: 1: 2205 2:  3: MsiSFCBypass
MSI (s) (84:7C) [10:11:03:774]: Note: 1: 2228 2:  3: MsiSFCBypass 4: SELECT `File_` FROM `MsiSFCBypass` WHERE `File_` = ?
MSI (s) (84:7C) [10:11:03:774]: Note: 1: 2205 2:  3: MsiPatchHeaders
MSI (s) (84:7C) [10:11:03:774]: Note: 1: 2228 2:  3: MsiPatchHeaders 4: SELECT `Header` FROM `MsiPatchHeaders` WHERE `StreamRef` = ?
MSI (s) (84:7C) [10:11:03:774]: Note: 1: 2205 2:  3: PatchPackage
MSI (s) (84:7C) [10:11:03:775]: Note: 1: 2205 2:  3: MsiPatchHeaders
MSI (s) (84:7C) [10:11:03:775]: Note: 1: 2205 2:  3: PatchPackage
MSI (s) (84:7C) [10:11:03:784]: Doing action: DuplicateFiles
MSI (s) (84:7C) [10:11:03:784]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: InstallFiles. Return value 1.
Action start 10:11:03: DuplicateFiles.
MSI (s) (84:7C) [10:11:03:785]: Doing action: GetBrowsers
MSI (s) (84:7C) [10:11:03:785]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: DuplicateFiles. Return value 1.
MSI (s) (84:B4) [10:11:03:807]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIC395.tmp, Entrypoint: ListRegisteredBrowsers
MSI (s) (84:FC) [10:11:03:807]: Generating random cookie.
MSI (s) (84:FC) [10:11:03:825]: Created Custom Action Server with PID 1380 (0x564).
MSI (s) (84:FC) [10:11:03:952]: Running as a service.
MSI (s) (84:FC) [10:11:03:955]: Hello, I'm your 32bit Impersonated custom action server.
Action start 10:11:03: GetBrowsers.
ListRegisteredBrowsers:  Initialized.
ListRegisteredBrowsers:  In GetRegisteredBrowsers.
ListRegisteredBrowsers:  In Is64BitOS, getting ProcAddress for IsWow64Process.
ListRegisteredBrowsers:  In Is64BitOS, retrieved ProcAddress for IsWow64Process.
ListRegisteredBrowsers:  In Is64BitOS, bIs64Bit = 1.
ListRegisteredBrowsers:  In GetRegisteredBrowsers, opened registry key.
ListRegisteredBrowsers:  In GetRegisteredBrowsers, queried registry key.
ListRegisteredBrowsers:  In GetRegisteredBrowsers, enumerated registry subkeys.
ListRegisteredBrowsers:  In GetRegisteredBrowsers, filename = IEXPLORE.EXE.
ListRegisteredBrowsers:  In GetRegisteredBrowsers, filename = IEXPLORE.EXE.
ListRegisteredBrowsers:  In GetIEPath
ListRegisteredBrowsers:  In Is64BitOS, getting ProcAddress for IsWow64Process.
ListRegisteredBrowsers:  In Is64BitOS, retrieved ProcAddress for IsWow64Process.
ListRegisteredBrowsers:  In Is64BitOS, bIs64Bit = 1.
ListRegisteredBrowsers:  In GetIEPath, Is 64BitOS
ListRegisteredBrowsers:  In GetIEPath, opened registry key
ListRegisteredBrowsers:  In GetIEPath, called RegQueryValueEx
ListRegisteredBrowsers:  In GetIEPath, called ConvertCharOrByteArrayToString, retString = C:\Program Files (x86)\Internet Explorer\iexplore.exe
ListRegisteredBrowsers:  In StripExtraApostrophes, filename = C:\Program Files (x86)\Internet Explorer\iexplore.exe
ListRegisteredBrowsers:  In StripExtraApostrophes, filename = C:\Program Files (x86)\Internet Explorer\iexplore.exe
ListRegisteredBrowsers:  In GetIEPath, stripped extra chars, IEPath = C:\Program Files (x86)\Internet Explorer\iexplore.exe
ListRegisteredBrowsers:  In GetRegisteredBrowsers, Internet Explorer path found.
ListRegisteredBrowsers:  C:\Program Files (x86)\Internet Explorer\iexplore.exe
ListRegisteredBrowsers:  In FileExists: filename = 44960232
ListRegisteredBrowsers:  In DoubleEscape, string length = 53
ListRegisteredBrowsers:  After calling DoubleEscape stemp = C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe
ListRegisteredBrowsers:  In FileExists, returning true
MSI (s) (84!C0) [10:11:03:971]: PROPERTY CHANGE: Adding IEENABLED property. Its value is 'TRUE'.
ListRegisteredBrowsers:  In GetRegisteredBrowsers, returned true from FileExists for C:\Program Files (x86)\Internet Explorer\iexplore.exe
ListRegisteredBrowsers:  In GetRegisteredBrowsers, IE file found.
ListRegisteredBrowsers:  In GetRegisteredBrowsers, file exists.
ListRegisteredBrowsers:  In GetRegisteredBrowsers, retrieved browser paths and checked for existence.
ListRegisteredBrowsers:  Completed GetRegisteredBrowsers.
ListRegisteredBrowsers:  Called GetRegisteredBrowsers.
MSI (s) (84:7C) [10:11:03:974]: Doing action: SetParamsInstall
MSI (s) (84:7C) [10:11:03:974]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: GetBrowsers. Return value 1.
MSI (s) (84:7C) [10:11:03:976]: PROPERTY CHANGE: Adding CustomActionInstall property. Its value is 'SourceGUID:F5D333A8-C748-4686-AE0A-9E008F670C22 VMFlag: UserGUID:4C4108F8-17B8-4CBA-E710-4E7812FCAD1F FFEnabled: IEEnabled:TRUE ChromeEnabled: Options:01110010000000000000000000000000'.
Action start 10:11:03: SetParamsInstall.
MSI (s) (84:7C) [10:11:03:976]: Doing action: CustomActionInstall
MSI (s) (84:7C) [10:11:03:976]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: SetParamsInstall. Return value 1.
Action start 10:11:03: CustomActionInstall.
MSI (s) (84:7C) [10:11:03:982]: Skipping action: SetParamsUninstall (condition is false)
MSI (s) (84:7C) [10:11:03:982]: Skipping action: CustomActionUninstall (condition is false)
MSI (s) (84:7C) [10:11:03:982]: Doing action: SetParamsJson
MSI (s) (84:7C) [10:11:03:982]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: CustomActionInstall. Return value 1.
MSI (s) (84:7C) [10:11:03:983]: PROPERTY CHANGE: Adding SendJson property. Its value is 'UserGUID:4C4108F8-17B8-4CBA-E710-4E7812FCAD1F SourceGUID:F5D333A8-C748-4686-AE0A-9E008F670C22 AdminPrivileges:1'.
Action start 10:11:03: SetParamsJson.
MSI (s) (84:7C) [10:11:03:983]: Doing action: SendJson
MSI (s) (84:7C) [10:11:03:983]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: SetParamsJson. Return value 1.
Action start 10:11:03: SendJson.
MSI (s) (84:7C) [10:11:03:987]: Doing action: WriteRegistryValues
MSI (s) (84:7C) [10:11:03:987]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: SendJson. Return value 1.
Action start 10:11:03: WriteRegistryValues.
MSI (s) (84:7C) [10:11:03:993]: Doing action: RegisterUser
MSI (s) (84:7C) [10:11:03:993]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: WriteRegistryValues. Return value 1.
Action start 10:11:03: RegisterUser.
MSI (s) (84:7C) [10:11:03:994]: Doing action: RegisterProduct
MSI (s) (84:7C) [10:11:03:994]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: RegisterUser. Return value 1.
MSI (s) (84:7C) [10:11:03:995]: Note: 1: 2205 2:  3: Error
MSI (s) (84:7C) [10:11:03:995]: Note: 1: 2228 2:  3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1302
Action start 10:11:03: RegisterProduct.
MSI (s) (84:7C) [10:11:03:996]: PROPERTY CHANGE: Adding ProductToBeRegistered property. Its value is '1'.
MSI (s) (84:7C) [10:11:03:996]: Doing action: PublishFeatures
MSI (s) (84:7C) [10:11:03:996]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: RegisterProduct. Return value 1.
Action start 10:11:03: PublishFeatures.
MSI (s) (84:7C) [10:11:03:998]: Doing action: PublishProduct
MSI (s) (84:7C) [10:11:03:998]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:03: PublishFeatures. Return value 1.
Action start 10:11:03: PublishProduct.
MSI (s) (84:7C) [10:11:04:000]: Doing action: InstallFinalize
MSI (s) (84:7C) [10:11:04:000]: Note: 1: 2205 2:  3: ActionText
Action ended 10:11:04: PublishProduct. Return value 1.
MSI (s) (84:7C) [10:11:04:002]: Running Script: C:\Windows\Installer\MSIC375.tmp
MSI (s) (84:7C) [10:11:04:002]: PROPERTY CHANGE: Adding UpdateStarted property. Its value is '1'.
MSI (s) (84:7C) [10:11:04:004]: Machine policy value 'DisableRollback' is 0
MSI (s) (84:7C) [10:11:04:007]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (84:7C) [10:11:04:009]: Executing op: Header(Signature=1397708873,Version=405,Timestamp=1132679522,LangId=1033,Platform=0,ScriptType=1,ScriptMajorVersion=21,ScriptMinorVersion=4,ScriptAttributes=1)
Action start 10:11:04: InstallFinalize.
MSI (s) (84:7C) [10:11:04:009]: Executing op: ProductInfo(ProductKey={9B65F9A3-9D24-452A-B6EF-1457D65E4259},ProductName=ScorpionSaver,PackageName=ScorpionSaver.msi,Language=1033,Version=16777216,Assignment=1,ObsoleteArg=0,ProductIcon=icon64.ico,,PackageCode={A5122D60-0F73-4E51-B932-09546C8362F3},,,InstanceType=0,LUASetting=0,RemoteURTInstalls=0,ProductDeploymentFlags=3)
MSI (s) (84:7C) [10:11:04:010]: Executing op: DialogInfo(Type=0,Argument=1033)
MSI (s) (84:7C) [10:11:04:010]: Executing op: DialogInfo(Type=1,Argument=ScorpionSaver)
MSI (s) (84:7C) [10:11:04:010]: Executing op: RollbackInfo(,RollbackAction=Rollback,RollbackDescription=Rolling back action:,RollbackTemplate=[1],CleanupAction=RollbackCleanup,CleanupDescription=Removing backup files,CleanupTemplate=File: [1])
MSI (s) (84:7C) [10:11:04:010]: Executing op: SetBaseline(Baseline=0,)
MSI (s) (84:7C) [10:11:04:010]: Executing op: SetBaseline(Baseline=1,)
MSI (s) (84:7C) [10:11:04:010]: Executing op: ActionStart(Name=ProcessComponents,Description=Updating component registration,)
MSI (s) (84:7C) [10:11:04:010]: Executing op: ProgressTotal(Total=14,Type=1,ByteEquivalent=24000)
MSI (s) (84:7C) [10:11:04:010]: Executing op: ComponentRegister(ComponentId={0B31B7B7-7A73-4A2C-A23C-3EAE1FD41770},KeyPath=01:\Software\Adpeak, Inc.\ScorpionSaver\Chrome\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:011]: Executing op: ComponentRegister(ComponentId={8433A517-B029-4356-9600-7695B46BF906},KeyPath=c:\Program Files (x86)\ScorpionSaver\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:012]: Executing op: ComponentRegister(ComponentId={548EFF05-555C-4E6A-ABBD-C77B1A54FBBE},KeyPath=c:\Program Files (x86)\ScorpionSaver\SendJson.dll,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:012]: WIN64DUALFOLDERS: Substitution in 'c:\Program Files (x86)\ScorpionSaver\SendJson.dll' folder had been blocked by the 1 mask argument (the folder pair's iSwapAttrib member = 0).
MSI (s) (84:7C) [10:11:04:012]: Executing op: ComponentRegister(ComponentId={5C4AE273-5CEE-4611-9813-5304304474B1},KeyPath=01:\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\F5D333A8-C748-4686-AE0A-9E008F670C22,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:013]: Executing op: ComponentRegister(ComponentId={F5C148D8-13CE-4261-BC88-4DD93B88F47A},KeyPath=c:\Program Files (x86)\ScorpionSaver\IECore.dll,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:013]: WIN64DUALFOLDERS: Substitution in 'c:\Program Files (x86)\ScorpionSaver\IECore.dll' folder had been blocked by the 1 mask argument (the folder pair's iSwapAttrib member = 0).
MSI (s) (84:7C) [10:11:04:013]: Executing op: ComponentRegister(ComponentId={498B1958-C1E8-40A4-9F50-503BDCEE5855},KeyPath=c:\Program Files (x86)\ScorpionSaver\CustomActionInstall,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:014]: WIN64DUALFOLDERS: Substitution in 'c:\Program Files (x86)\ScorpionSaver\CustomActionInstall' folder had been blocked by the 1 mask argument (the folder pair's iSwapAttrib member = 0).
MSI (s) (84:7C) [10:11:04:014]: Executing op: ComponentRegister(ComponentId={35CA91C1-0982-4089-B560-0BDDD173BCBA},KeyPath=c:\Program Files (x86)\ScorpionSaver\ff_bootstrap.js,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:014]: WIN64DUALFOLDERS: Substitution in 'c:\Program Files (x86)\ScorpionSaver\ff_bootstrap.js' folder had been blocked by the 1 mask argument (the folder pair's iSwapAttrib member = 0).
MSI (s) (84:7C) [10:11:04:014]: Executing op: ComponentRegister(ComponentId={1F1AEE32-7A50-454F-9479-D4B9597ECA98},KeyPath=01:\Software\Adpeak, Inc.\ScorpionSaver\Chrome\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:015]: Executing op: ComponentRegister(ComponentId={69728962-FA8A-421D-B659-0E20569AB59F},KeyPath=01:\Software\Adpeak, Inc.\ScorpionSaver\Chrome\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:015]: Executing op: ComponentRegister(ComponentId={BD0F553F-E2A7-41A3-8B7E-5A86BF2A9573},KeyPath=01:\Software\Adpeak, Inc.\ScorpionSaver\Chrome\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:016]: Executing op: ComponentRegister(ComponentId={2D9E9D32-E4B1-4E77-B1F9-05DD222FE402},KeyPath=01:\Software\Adpeak, Inc.\ScorpionSaver\Chrome\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:016]: Executing op: ComponentRegister(ComponentId={D0D29D24-FA57-47FE-92E7-3078C6D8D933},KeyPath=01:\Software\Adpeak, Inc.\ScorpionSaver\Chrome\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:017]: Executing op: ComponentRegister(ComponentId={3FB647DA-3B3B-48DF-908B-6640AB5889A2},KeyPath=01:\Software\Adpeak, Inc.\ScorpionSaver\Chrome\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:017]: Executing op: ComponentRegister(ComponentId={492B50D7-C9E2-408C-993F-796F11D4BF53},KeyPath=01:\Software\Adpeak, Inc.\ScorpionSaver\Chrome\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (84:7C) [10:11:04:018]: Executing op: ActionStart(Name=InstallFiles,Description=Copying new files,Template=File: [1],  Directory: [9],  Size: [6])
MSI (s) (84:7C) [10:11:04:018]: Executing op: ProgressTotal(Total=3074167,Type=0,ByteEquivalent=1)
MSI (s) (84:7C) [10:11:04:018]: Executing op: SetTargetFolder(Folder=c:\Program Files (x86)\ScorpionSaver\)
MSI (s) (84:7C) [10:11:04:018]: Executing op: SetSourceFolder(Folder=1\)
MSI (s) (84:7C) [10:11:04:018]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,MediaCabinet=cab1.cab,BytesPerTick=32768,CopierType=2,ModuleFileName=c:\Windows\Installer\18cc22d.msi,,,,,IsFirstPhysicalMedia=1)
MSI (s) (84:7C) [10:11:04:018]: Executing op: FileCopy(SourceName=qptwvo4w.js|bootstrap.js,SourceCabKey=bootstrap.js,DestName=bootstrap.js,Attributes=512,FileSize=785,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1801788448,HashPart2=754767944,HashPart3=138751016,HashPart4=-1742177758,,)
MSI (s) (84:7C) [10:11:04:019]: File: c:\Program Files (x86)\ScorpionSaver\bootstrap.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:019]: Source for file 'bootstrap.js' is compressed
MSI (s) (84:7C) [10:11:04:021]: SOFTWARE RESTRICTION POLICY: Verifying object --> 'c:\Windows\Installer\18cc22d.msi' against software restriction policy
MSI (s) (84:7C) [10:11:04:021]: SOFTWARE RESTRICTION POLICY: c:\Windows\Installer\18cc22d.msi has a digital signature
MSI (s) (84:7C) [10:11:04:042]: SOFTWARE RESTRICTION POLICY: c:\Windows\Installer\18cc22d.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (84:7C) [10:11:04:043]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\bootstrap.js
MSI (s) (84:7C) [10:11:04:100]: Executing op: FileCopy(SourceName=mxtxdgod.old|bootstrap.js.old,SourceCabKey=bootstrap.js.old,DestName=bootstrap.js.old,Attributes=512,FileSize=705,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1912754502,HashPart2=-2034729674,HashPart3=1986408764,HashPart4=1618839821,,)
MSI (s) (84:7C) [10:11:04:101]: File: c:\Program Files (x86)\ScorpionSaver\bootstrap.js.old;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:101]: Source for file 'bootstrap.js.old' is compressed
MSI (s) (84:7C) [10:11:04:101]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\bootstrap.js.old
MSI (s) (84:7C) [10:11:04:102]: Executing op: FileCopy(SourceName=8wsvgm2z.js|background.js,SourceCabKey=chromebackground.js,DestName=background.js,Attributes=512,FileSize=3943,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1199374625,HashPart2=946599617,HashPart3=1485913324,HashPart4=-600817969,,)
MSI (s) (84:7C) [10:11:04:102]: File: c:\Program Files (x86)\ScorpionSaver\background.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:102]: Source for file 'chromebackground.js' is compressed
MSI (s) (84:7C) [10:11:04:102]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\background.js
MSI (s) (84:7C) [10:11:04:105]: Executing op: FileCopy(SourceName=_vagkn0p|CustomActionInstall,SourceCabKey=CustomActionInstall,DestName=CustomActionInstall,Attributes=512,FileSize=743944,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1742879736,HashPart2=441019389,HashPart3=-1310708987,HashPart4=-1052002543,,)
MSI (s) (84:7C) [10:11:04:105]: File: c:\Program Files (x86)\ScorpionSaver\CustomActionInstall;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:105]: Source for file 'CustomActionInstall' is compressed
MSI (s) (84:7C) [10:11:04:106]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\CustomActionInstall
MSI (s) (84:7C) [10:11:04:106]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:107]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:108]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:108]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:109]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:110]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:110]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:111]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:111]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:112]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:113]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:113]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:114]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:114]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:115]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:115]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:116]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:117]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:117]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:118]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:118]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:154]: Executing op: FileCopy(SourceName=v1r51pgm|CustomActionUninstall,SourceCabKey=CustomActionUninstall,DestName=CustomActionUninstall,Attributes=512,FileSize=685576,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=919298364,HashPart2=-736375856,HashPart3=-714012716,HashPart4=1406137453,,)
MSI (s) (84:7C) [10:11:04:155]: File: c:\Program Files (x86)\ScorpionSaver\CustomActionUninstall;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:155]: Source for file 'CustomActionUninstall' is compressed
MSI (s) (84:7C) [10:11:04:155]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\CustomActionUninstall
MSI (s) (84:7C) [10:11:04:156]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:157]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:157]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:158]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:159]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:159]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:160]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:160]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:161]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:162]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:162]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:163]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:163]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:164]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:164]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:165]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:166]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:166]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:167]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:167]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:244]: Executing op: FileCopy(SourceName=fqsd7jr9.js|ff_addon_runner.js,SourceCabKey=ff_addon_runner.js,DestName=ff_addon_runner.js,Attributes=512,FileSize=4931,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1350003814,HashPart2=-161944819,HashPart3=1270624866,HashPart4=-333340548,,)
MSI (s) (84:7C) [10:11:04:244]: File: c:\Program Files (x86)\ScorpionSaver\ff_addon_runner.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:244]: Source for file 'ff_addon_runner.js' is compressed
MSI (s) (84:7C) [10:11:04:244]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_addon_runner.js
MSI (s) (84:7C) [10:11:04:248]: Executing op: FileCopy(SourceName=3-fb7qwe.js|ff_addonkit_page-mod.js,SourceCabKey=ff_addonkit_pagemod.js,DestName=ff_addonkit_page-mod.js,Attributes=512,FileSize=12993,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=883860745,HashPart2=-602934867,HashPart3=1799567804,HashPart4=-541831337,,)
MSI (s) (84:7C) [10:11:04:248]: File: c:\Program Files (x86)\ScorpionSaver\ff_addonkit_page-mod.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:248]: Source for file 'ff_addonkit_pagemod.js' is compressed
MSI (s) (84:7C) [10:11:04:248]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_addonkit_page-mod.js
MSI (s) (84:7C) [10:11:04:256]: Executing op: FileCopy(SourceName=nama2kz8.js|ff_addonkit_private-browsing.js,SourceCabKey=ff_addonkit_privatebrowsing.js,DestName=ff_addonkit_private-browsing.js,Attributes=512,FileSize=1393,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1152710605,HashPart2=1565800409,HashPart3=297624955,HashPart4=-2076665396,,)
MSI (s) (84:7C) [10:11:04:256]: File: c:\Program Files (x86)\ScorpionSaver\ff_addonkit_private-browsing.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:256]: Source for file 'ff_addonkit_privatebrowsing.js' is compressed
MSI (s) (84:7C) [10:11:04:256]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_addonkit_private-browsing.js
MSI (s) (84:7C) [10:11:04:258]: Executing op: FileCopy(SourceName=yczi23kx.js|ff_addonkit_request.js,SourceCabKey=ff_addonkit_request.js,DestName=ff_addonkit_request.js,Attributes=512,FileSize=7043,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-297691359,HashPart2=89862601,HashPart3=-114588686,HashPart4=-1450983065,,)
MSI (s) (84:7C) [10:11:04:258]: File: c:\Program Files (x86)\ScorpionSaver\ff_addonkit_request.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:258]: Source for file 'ff_addonkit_request.js' is compressed
MSI (s) (84:7C) [10:11:04:259]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_addonkit_request.js
MSI (s) (84:7C) [10:11:04:263]: Executing op: FileCopy(SourceName=ofkhuusb.js|ff_addonkit_windows.js,SourceCabKey=ff_addonkit_windows.js,DestName=ff_addonkit_windows.js,Attributes=512,FileSize=8543,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1508363051,HashPart2=-1147328341,HashPart3=-82232759,HashPart4=-793687781,,)
MSI (s) (84:7C) [10:11:04:263]: File: c:\Program Files (x86)\ScorpionSaver\ff_addonkit_windows.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:263]: Source for file 'ff_addonkit_windows.js' is compressed
MSI (s) (84:7C) [10:11:04:263]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_addonkit_windows.js
MSI (s) (84:7C) [10:11:04:268]: Executing op: FileCopy(SourceName=u-zqgmb2.js|ff_base_api-utils.js,SourceCabKey=ff_base_apiutils.js,DestName=ff_base_api-utils.js,Attributes=512,FileSize=5985,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-707659028,HashPart2=-1819343566,HashPart3=1837791572,HashPart4=1381418845,,)
MSI (s) (84:7C) [10:11:04:268]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_api-utils.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:268]: Source for file 'ff_base_apiutils.js' is compressed
MSI (s) (84:7C) [10:11:04:269]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_api-utils.js
MSI (s) (84:7C) [10:11:04:272]: Executing op: FileCopy(SourceName=llrj7shm.js|ff_base_base64.js,SourceCabKey=ff_base_base64.js,DestName=ff_base_base64.js,Attributes=512,FileSize=1102,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1027132917,HashPart2=433902698,HashPart3=1451181622,HashPart4=-1061279128,,)
MSI (s) (84:7C) [10:11:04:273]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_base64.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:273]: Source for file 'ff_base_base64.js' is compressed
MSI (s) (84:7C) [10:11:04:273]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_base64.js
MSI (s) (84:7C) [10:11:04:275]: Executing op: FileCopy(SourceName=ey2keouk.js|ff_base_byte-streams.js,SourceCabKey=ff_base_bytestreams.js,DestName=ff_base_byte-streams.js,Attributes=512,FileSize=2929,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1397104542,HashPart2=1192379877,HashPart3=-698467104,HashPart4=1190481085,,)
MSI (s) (84:7C) [10:11:04:275]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_byte-streams.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:275]: Source for file 'ff_base_bytestreams.js' is compressed
MSI (s) (84:7C) [10:11:04:275]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_byte-streams.js
MSI (s) (84:7C) [10:11:04:278]: Executing op: FileCopy(SourceName=u3dwdeuq.js|ff_base_collection.js,SourceCabKey=ff_base_collection.js,DestName=ff_base_collection.js,Attributes=512,FileSize=3427,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=477085000,HashPart2=-1987620141,HashPart3=512989169,HashPart4=107804815,,)
MSI (s) (84:7C) [10:11:04:278]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_collection.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:278]: Source for file 'ff_base_collection.js' is compressed
MSI (s) (84:7C) [10:11:04:278]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_collection.js
MSI (s) (84:7C) [10:11:04:281]: Executing op: FileCopy(SourceName=sj1z_bka.js|ff_base_content.js,SourceCabKey=ff_base_content.js,DestName=ff_base_content.js,Attributes=512,FileSize=566,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1661333291,HashPart2=-2064769034,HashPart3=74571336,HashPart4=462181860,,)
MSI (s) (84:7C) [10:11:04:281]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_content.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:281]: Source for file 'ff_base_content.js' is compressed
MSI (s) (84:7C) [10:11:04:281]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_content.js
MSI (s) (84:7C) [10:11:04:283]: Executing op: FileCopy(SourceName=kp89bfeq.js|ff_base_cortex.js,SourceCabKey=ff_base_cortex.js,DestName=ff_base_cortex.js,Attributes=512,FileSize=4908,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-2040201911,HashPart2=-1087463635,HashPart3=766987962,HashPart4=1122950108,,)
MSI (s) (84:7C) [10:11:04:283]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_cortex.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:283]: Source for file 'ff_base_cortex.js' is compressed
MSI (s) (84:7C) [10:11:04:283]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_cortex.js
MSI (s) (84:7C) [10:11:04:286]: Executing op: FileCopy(SourceName=e7d_rk4-.js|ff_base_cuddlefish.js,SourceCabKey=ff_base_cuddlefish.js,DestName=ff_base_cuddlefish.js,Attributes=512,FileSize=2670,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1406063151,HashPart2=810188985,HashPart3=-214159820,HashPart4=2047856205,,)
MSI (s) (84:7C) [10:11:04:286]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_cuddlefish.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:286]: Source for file 'ff_base_cuddlefish.js' is compressed
MSI (s) (84:7C) [10:11:04:287]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_cuddlefish.js
MSI (s) (84:7C) [10:11:04:289]: Executing op: FileCopy(SourceName=fpa8wxzn.js|ff_base_deprecate.js,SourceCabKey=ff_base_deprecate.js,DestName=ff_base_deprecate.js,Attributes=512,FileSize=827,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-322368621,HashPart2=-916832735,HashPart3=1348347356,HashPart4=493216433,,)
MSI (s) (84:7C) [10:11:04:289]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_deprecate.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:289]: Source for file 'ff_base_deprecate.js' is compressed
MSI (s) (84:7C) [10:11:04:289]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_deprecate.js
MSI (s) (84:7C) [10:11:04:291]: Executing op: FileCopy(SourceName=54_wuacj.js|ff_base_environment.js,SourceCabKey=ff_base_environment.js,DestName=ff_base_environment.js,Attributes=512,FileSize=2558,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-683166481,HashPart2=-1375107837,HashPart3=754030168,HashPart4=170974232,,)
MSI (s) (84:7C) [10:11:04:291]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_environment.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:291]: Source for file 'ff_base_environment.js' is compressed
MSI (s) (84:7C) [10:11:04:292]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_environment.js
MSI (s) (84:7C) [10:11:04:294]: Executing op: FileCopy(SourceName=fkr-ktgh.js|ff_base_errors.js,SourceCabKey=ff_base_errors.js,DestName=ff_base_errors.js,Attributes=512,FileSize=2089,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=422913570,HashPart2=1094039835,HashPart3=-1146493019,HashPart4=1848292775,,)
MSI (s) (84:7C) [10:11:04:294]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_errors.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:294]: Source for file 'ff_base_errors.js' is compressed
MSI (s) (84:7C) [10:11:04:294]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_errors.js
MSI (s) (84:7C) [10:11:04:296]: Executing op: FileCopy(SourceName=1noafklq.js|ff_base_events.js,SourceCabKey=ff_base_events.js,DestName=ff_base_events.js,Attributes=512,FileSize=6600,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1065498327,HashPart2=-699940309,HashPart3=2071170609,HashPart4=235445004,,)
MSI (s) (84:7C) [10:11:04:296]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_events.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:296]: Source for file 'ff_base_events.js' is compressed
MSI (s) (84:7C) [10:11:04:297]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_events.js
MSI (s) (84:7C) [10:11:04:300]: Executing op: FileCopy(SourceName=rwgtf90u.js|ff_base_file.js,SourceCabKey=ff_base_file.js,DestName=ff_base_file.js,Attributes=512,FileSize=5375,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1735748717,HashPart2=453886431,HashPart3=-946118946,HashPart4=-412821731,,)
MSI (s) (84:7C) [10:11:04:300]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_file.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:300]: Source for file 'ff_base_file.js' is compressed
MSI (s) (84:7C) [10:11:04:301]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_file.js
MSI (s) (84:7C) [10:11:04:305]: Executing op: FileCopy(SourceName=aviy6jnf.js|ff_base_functional.js,SourceCabKey=ff_base_functional.js,DestName=ff_base_functional.js,Attributes=512,FileSize=5394,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1969878232,HashPart2=268273797,HashPart3=980786541,HashPart4=-750483487,,)
MSI (s) (84:7C) [10:11:04:305]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_functional.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:305]: Source for file 'ff_base_functional.js' is compressed
MSI (s) (84:7C) [10:11:04:305]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_functional.js
MSI (s) (84:7C) [10:11:04:309]: Executing op: FileCopy(SourceName=gs1nrmuv.js|ff_base_globals.js,SourceCabKey=ff_base_globals.js,DestName=ff_base_globals.js,Attributes=512,FileSize=2022,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1036891416,HashPart2=-1146392038,HashPart3=-1153333734,HashPart4=1790794185,,)
MSI (s) (84:7C) [10:11:04:309]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_globals.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:309]: Source for file 'ff_base_globals.js' is compressed
MSI (s) (84:7C) [10:11:04:309]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_globals.js
MSI (s) (84:7C) [10:11:04:311]: Executing op: FileCopy(SourceName=38mbfwua.js|ff_base_heritage.js,SourceCabKey=ff_base_heritage.js,DestName=ff_base_heritage.js,Attributes=512,FileSize=5980,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=250665215,HashPart2=-1545909810,HashPart3=1791965619,HashPart4=2023345945,,)
MSI (s) (84:7C) [10:11:04:311]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_heritage.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:311]: Source for file 'ff_base_heritage.js' is compressed
MSI (s) (84:7C) [10:11:04:312]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_heritage.js
MSI (s) (84:7C) [10:11:04:315]: Executing op: FileCopy(SourceName=zcyct5jl.js|ff_base_hidden-frame.js,SourceCabKey=ff_base_hiddenframe.js,DestName=ff_base_hidden-frame.js,Attributes=512,FileSize=6112,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1227930040,HashPart2=274082143,HashPart3=398092098,HashPart4=1179833345,,)
MSI (s) (84:7C) [10:11:04:316]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_hidden-frame.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:316]: Source for file 'ff_base_hiddenframe.js' is compressed
MSI (s) (84:7C) [10:11:04:316]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_hidden-frame.js
MSI (s) (84:7C) [10:11:04:320]: Executing op: FileCopy(SourceName=5rmrgvof.js|ff_base_light-traits.js,SourceCabKey=ff_base_lighttraits.js,DestName=ff_base_light-traits.js,Attributes=512,FileSize=23106,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1017360317,HashPart2=-1237487891,HashPart3=-902598800,HashPart4=1422736164,,)
MSI (s) (84:7C) [10:11:04:320]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_light-traits.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:320]: Source for file 'ff_base_lighttraits.js' is compressed
MSI (s) (84:7C) [10:11:04:320]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_light-traits.js
MSI (s) (84:7C) [10:11:04:334]: Executing op: FileCopy(SourceName=rmoviceq.js|ff_base_list.js,SourceCabKey=ff_base_list.js,DestName=ff_base_list.js,Attributes=512,FileSize=4005,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-792071509,HashPart2=1788843386,HashPart3=893467060,HashPart4=1719270732,,)
MSI (s) (84:7C) [10:11:04:334]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_list.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:334]: Source for file 'ff_base_list.js' is compressed
MSI (s) (84:7C) [10:11:04:335]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_list.js
MSI (s) (84:7C) [10:11:04:338]: Executing op: FileCopy(SourceName=tjzs_oiv.js|ff_base_loader.js,SourceCabKey=ff_base_loader.js,DestName=ff_base_loader.js,Attributes=512,FileSize=15683,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1520795343,HashPart2=-1215858420,HashPart3=306384371,HashPart4=-1692705136,,)
MSI (s) (84:7C) [10:11:04:338]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_loader.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:338]: Source for file 'ff_base_loader.js' is compressed
MSI (s) (84:7C) [10:11:04:339]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_loader.js
MSI (s) (84:7C) [10:11:04:345]: Executing op: FileCopy(SourceName=f4v_2djh.js|ff_base_match-pattern.js,SourceCabKey=ff_base_matchpattern.js,DestName=ff_base_match-pattern.js,Attributes=512,FileSize=3784,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-226197591,HashPart2=1195499668,HashPart3=-406579244,HashPart4=-14692873,,)
MSI (s) (84:7C) [10:11:04:345]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_match-



#7 totalsiege

totalsiege
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:04 AM

Posted 07 December 2013 - 06:18 PM

continued

 

pattern.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:346]: Source for file 'ff_base_matchpattern.js' is compressed
MSI (s) (84:7C) [10:11:04:346]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_match-pattern.js
MSI (s) (84:7C) [10:11:04:349]: Executing op: FileCopy(SourceName=pw9x5utw.js|ff_base_memory.js,SourceCabKey=ff_base_memory.js,DestName=ff_base_memory.js,Attributes=512,FileSize=3491,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-38657918,HashPart2=2137767097,HashPart3=-1746511253,HashPart4=-110466320,,)
MSI (s) (84:7C) [10:11:04:349]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_memory.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:349]: Source for file 'ff_base_memory.js' is compressed
MSI (s) (84:7C) [10:11:04:349]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_memory.js
MSI (s) (84:7C) [10:11:04:352]: Executing op: FileCopy(SourceName=fdu2oypw.js|ff_base_namespace.js,SourceCabKey=ff_base_namespace.js,DestName=ff_base_namespace.js,Attributes=512,FileSize=1548,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1310633565,HashPart2=605422930,HashPart3=247190219,HashPart4=-1208545960,,)
MSI (s) (84:7C) [10:11:04:352]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_namespace.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:352]: Source for file 'ff_base_namespace.js' is compressed
MSI (s) (84:7C) [10:11:04:352]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_namespace.js
MSI (s) (84:7C) [10:11:04:354]: Executing op: FileCopy(SourceName=jh6gouah.js|ff_base_observer-service.js,SourceCabKey=ff_base_observerservice.js,DestName=ff_base_observer-service.js,Attributes=512,FileSize=4081,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1133423192,HashPart2=-2078478918,HashPart3=1706917474,HashPart4=959357215,,)
MSI (s) (84:7C) [10:11:04:354]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_observer-service.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:354]: Source for file 'ff_base_observerservice.js' is compressed
MSI (s) (84:7C) [10:11:04:355]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_observer-service.js
MSI (s) (84:7C) [10:11:04:357]: Executing op: FileCopy(SourceName=f-iwquul.js|ff_base_plain-text-console.js,SourceCabKey=ff_base_plaintextconsole.js,DestName=ff_base_plain-text-console.js,Attributes=512,FileSize=2456,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=556501460,HashPart2=2090292707,HashPart3=-1546789793,HashPart4=-225413379,,)
MSI (s) (84:7C) [10:11:04:357]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_plain-text-console.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:357]: Source for file 'ff_base_plaintextconsole.js' is compressed
MSI (s) (84:7C) [10:11:04:358]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_plain-text-console.js
MSI (s) (84:7C) [10:11:04:360]: Executing op: FileCopy(SourceName=mekpjt7-.js|ff_base_preferences-service.js,SourceCabKey=ff_base_preferencesservice.js,DestName=ff_base_preferences-service.js,Attributes=512,FileSize=5534,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=456844347,HashPart2=-1074194309,HashPart3=-1500001231,HashPart4=-1188332881,,)
MSI (s) (84:7C) [10:11:04:360]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_preferences-service.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:360]: Source for file 'ff_base_preferencesservice.js' is compressed
MSI (s) (84:7C) [10:11:04:361]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_preferences-service.js
MSI (s) (84:7C) [10:11:04:364]: Executing op: FileCopy(SourceName=qiwghqjc.js|ff_base_promise.js,SourceCabKey=ff_base_promise.js,DestName=ff_base_promise.js,Attributes=512,FileSize=7710,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=778070876,HashPart2=-245174839,HashPart3=1782094506,HashPart4=-1307060594,,)
MSI (s) (84:7C) [10:11:04:364]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_promise.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:364]: Source for file 'ff_base_promise.js' is compressed
MSI (s) (84:7C) [10:11:04:365]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_promise.js
MSI (s) (84:7C) [10:11:04:369]: Executing op: FileCopy(SourceName=qzj9cwlr.js|ff_base_querystring.js,SourceCabKey=ff_base_querystring.js,DestName=ff_base_querystring.js,Attributes=512,FileSize=4018,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1600909424,HashPart2=-1351288825,HashPart3=-1800025052,HashPart4=447279310,,)
MSI (s) (84:7C) [10:11:04:369]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_querystring.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:369]: Source for file 'ff_base_querystring.js' is compressed
MSI (s) (84:7C) [10:11:04:369]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_querystring.js
MSI (s) (84:7C) [10:11:04:372]: Executing op: FileCopy(SourceName=qvnslqwe.js|ff_base_runtime.js,SourceCabKey=ff_base_runtime.js,DestName=ff_base_runtime.js,Attributes=512,FileSize=636,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=23881790,HashPart2=-94032851,HashPart3=-1881796859,HashPart4=1990658962,,)
MSI (s) (84:7C) [10:11:04:372]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_runtime.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:372]: Source for file 'ff_base_runtime.js' is compressed
MSI (s) (84:7C) [10:11:04:372]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_runtime.js
MSI (s) (84:7C) [10:11:04:374]: Executing op: FileCopy(SourceName=vj0fgjgw.js|ff_base_sandbox.js,SourceCabKey=ff_base_sandbox.js,DestName=ff_base_sandbox.js,Attributes=512,FileSize=1708,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1534931667,HashPart2=907941365,HashPart3=650038333,HashPart4=474485676,,)
MSI (s) (84:7C) [10:11:04:375]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_sandbox.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:375]: Source for file 'ff_base_sandbox.js' is compressed
MSI (s) (84:7C) [10:11:04:375]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_sandbox.js
MSI (s) (84:7C) [10:11:04:377]: Executing op: FileCopy(SourceName=wld8k640.js|ff_base_self.js,SourceCabKey=ff_base_self.js,DestName=ff_base_self.js,Attributes=512,FileSize=1508,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1834385886,HashPart2=22064017,HashPart3=-1549924696,HashPart4=1894126801,,)
MSI (s) (84:7C) [10:11:04:377]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_self.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:377]: Source for file 'ff_base_self.js' is compressed
MSI (s) (84:7C) [10:11:04:378]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_self.js
MSI (s) (84:7C) [10:11:04:379]: Executing op: FileCopy(SourceName=dzvbxxlx.js|ff_base_system.js,SourceCabKey=ff_base_system.js,DestName=ff_base_system.js,Attributes=512,FileSize=4825,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-533134232,HashPart2=13536599,HashPart3=-392610325,HashPart4=296744029,,)
MSI (s) (84:7C) [10:11:04:380]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_system.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:380]: Source for file 'ff_base_system.js' is compressed
MSI (s) (84:7C) [10:11:04:380]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_system.js
MSI (s) (84:7C) [10:11:04:383]: Executing op: FileCopy(SourceName=9a6y65dg.js|ff_base_text-streams.js,SourceCabKey=ff_base_textstreams.js,DestName=ff_base_text-streams.js,Attributes=512,FileSize=8277,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-216496531,HashPart2=-1352632755,HashPart3=-591922922,HashPart4=911098776,,)
MSI (s) (84:7C) [10:11:04:383]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_text-streams.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:383]: Source for file 'ff_base_textstreams.js' is compressed
MSI (s) (84:7C) [10:11:04:384]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_text-streams.js
MSI (s) (84:7C) [10:11:04:388]: Executing op: FileCopy(SourceName=bw7y8-iv.js|ff_base_timer.js,SourceCabKey=ff_base_timer.js,DestName=ff_base_timer.js,Attributes=512,FileSize=1495,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-101000780,HashPart2=-1100381007,HashPart3=-415770927,HashPart4=-1215888511,,)
MSI (s) (84:7C) [10:11:04:388]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_timer.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:388]: Source for file 'ff_base_timer.js' is compressed
MSI (s) (84:7C) [10:11:04:388]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_timer.js
MSI (s) (84:7C) [10:11:04:390]: Executing op: FileCopy(SourceName=hstlbioa.js|ff_base_traceback.js,SourceCabKey=ff_base_traceback.js,DestName=ff_base_traceback.js,Attributes=512,FileSize=4034,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=52539111,HashPart2=2129161886,HashPart3=-682999998,HashPart4=-269651370,,)
MSI (s) (84:7C) [10:11:04:390]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_traceback.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:390]: Source for file 'ff_base_traceback.js' is compressed
MSI (s) (84:7C) [10:11:04:391]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_traceback.js
MSI (s) (84:7C) [10:11:04:393]: Executing op: FileCopy(SourceName=tqvwbm5b.js|ff_base_traits.js,SourceCabKey=ff_base_traits.js,DestName=ff_base_traits.js,Attributes=512,FileSize=6292,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1836090366,HashPart2=952112427,HashPart3=331837265,HashPart4=-1331030797,,)
MSI (s) (84:7C) [10:11:04:394]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_traits.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:394]: Source for file 'ff_base_traits.js' is compressed
MSI (s) (84:7C) [10:11:04:394]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_traits.js
MSI (s) (84:7C) [10:11:04:398]: Executing op: FileCopy(SourceName=eetpmyzo.js|ff_base_unload.js,SourceCabKey=ff_base_unload.js,DestName=ff_base_unload.js,Attributes=512,FileSize=2304,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-364165376,HashPart2=1346334729,HashPart3=49550309,HashPart4=-854455479,,)
MSI (s) (84:7C) [10:11:04:398]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_unload.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:398]: Source for file 'ff_base_unload.js' is compressed
MSI (s) (84:7C) [10:11:04:398]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_unload.js
MSI (s) (84:7C) [10:11:04:400]: Executing op: FileCopy(SourceName=q3o1t2fn.js|ff_base_url.js,SourceCabKey=ff_base_url.js,DestName=ff_base_url.js,Attributes=512,FileSize=6353,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=112011760,HashPart2=-1241774975,HashPart3=-2137319100,HashPart4=-780785665,,)
MSI (s) (84:7C) [10:11:04:400]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_url.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:401]: Source for file 'ff_base_url.js' is compressed
MSI (s) (84:7C) [10:11:04:401]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_url.js
MSI (s) (84:7C) [10:11:04:405]: Executing op: FileCopy(SourceName=j7irzaxp.js|ff_base_uuid.js,SourceCabKey=ff_base_uuid.js,DestName=ff_base_uuid.js,Attributes=512,FileSize=662,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1403528827,HashPart2=-1956440267,HashPart3=1682557724,HashPart4=848765358,,)
MSI (s) (84:7C) [10:11:04:405]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_uuid.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:405]: Source for file 'ff_base_uuid.js' is compressed
MSI (s) (84:7C) [10:11:04:405]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_uuid.js
MSI (s) (84:7C) [10:11:04:407]: Executing op: FileCopy(SourceName=hzun1goe.js|ff_base_window-utils.js,SourceCabKey=ff_base_windowutils.js,DestName=ff_base_window-utils.js,Attributes=512,FileSize=6171,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=830187611,HashPart2=-241977704,HashPart3=-1103026916,HashPart4=807967056,,)
MSI (s) (84:7C) [10:11:04:407]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_window-utils.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:407]: Source for file 'ff_base_windowutils.js' is compressed
MSI (s) (84:7C) [10:11:04:407]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_window-utils.js
MSI (s) (84:7C) [10:11:04:412]: Executing op: FileCopy(SourceName=p5axqd-0.js|ff_base_xhr.js,SourceCabKey=ff_base_xhr.js,DestName=ff_base_xhr.js,Attributes=512,FileSize=5108,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-2109004806,HashPart2=-2098760343,HashPart3=-1494247929,HashPart4=-1072491031,,)
MSI (s) (84:7C) [10:11:04:412]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_xhr.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:412]: Source for file 'ff_base_xhr.js' is compressed
MSI (s) (84:7C) [10:11:04:412]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_xhr.js
MSI (s) (84:7C) [10:11:04:415]: Executing op: FileCopy(SourceName=kxnyxytz.js|ff_base_xpcom.js,SourceCabKey=ff_base_xpcom.js,DestName=ff_base_xpcom.js,Attributes=512,FileSize=8954,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1924279091,HashPart2=1543411754,HashPart3=-1014138249,HashPart4=-720392500,,)
MSI (s) (84:7C) [10:11:04:415]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_xpcom.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:415]: Source for file 'ff_base_xpcom.js' is compressed
MSI (s) (84:7C) [10:11:04:416]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_xpcom.js
MSI (s) (84:7C) [10:11:04:420]: Executing op: FileCopy(SourceName=crlghlvu.js|ff_base_xul-app.js,SourceCabKey=ff_base_xulapp.js,DestName=ff_base_xul-app.js,Attributes=512,FileSize=2437,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-65934538,HashPart2=89776365,HashPart3=970974247,HashPart4=1169539084,,)
MSI (s) (84:7C) [10:11:04:420]: File: c:\Program Files (x86)\ScorpionSaver\ff_base_xul-app.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:420]: Source for file 'ff_base_xulapp.js' is compressed
MSI (s) (84:7C) [10:11:04:421]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_base_xul-app.js
MSI (s) (84:7C) [10:11:04:440]: Executing op: FileCopy(SourceName=lyyqxwg3.js|ff_bootstrap.js,SourceCabKey=ff_bootstrap.js,DestName=ff_bootstrap.js,Attributes=512,FileSize=9295,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-2015397450,HashPart2=-1005117999,HashPart3=-1821280262,HashPart4=-1561690606,,)
MSI (s) (84:7C) [10:11:04:441]: File: c:\Program Files (x86)\ScorpionSaver\ff_bootstrap.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:441]: Source for file 'ff_bootstrap.js' is compressed
MSI (s) (84:7C) [10:11:04:441]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_bootstrap.js
MSI (s) (84:7C) [10:11:04:446]: Executing op: FileCopy(SourceName=euvowbhc.js|ff_content_content-proxy.js,SourceCabKey=ff_content_contentproxy.js,DestName=ff_content_content-proxy.js,Attributes=512,FileSize=30630,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1800150227,HashPart2=2010480943,HashPart3=-1270848403,HashPart4=1743205242,,)
MSI (s) (84:7C) [10:11:04:446]: File: c:\Program Files (x86)\ScorpionSaver\ff_content_content-proxy.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:446]: Source for file 'ff_content_contentproxy.js' is compressed
MSI (s) (84:7C) [10:11:04:447]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_content_content-proxy.js
MSI (s) (84:7C) [10:11:04:459]: Executing op: FileCopy(SourceName=t7iosqfb.js|ff_content_content-worker.js,SourceCabKey=ff_content_contentworker.js,DestName=ff_content_content-worker.js,Attributes=512,FileSize=11263,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=643413824,HashPart2=499604227,HashPart3=-89823119,HashPart4=-841331149,,)
MSI (s) (84:7C) [10:11:04:459]: File: c:\Program Files (x86)\ScorpionSaver\ff_content_content-worker.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:459]: Source for file 'ff_content_contentworker.js' is compressed
MSI (s) (84:7C) [10:11:04:459]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_content_content-worker.js
MSI (s) (84:7C) [10:11:04:464]: Executing op: FileCopy(SourceName=zmg1bfgy.js|ff_content_loader.js,SourceCabKey=ff_content_loader.js,DestName=ff_content_loader.js,Attributes=512,FileSize=6597,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-275044088,HashPart2=594172990,HashPart3=2055543178,HashPart4=1047758583,,)
MSI (s) (84:7C) [10:11:04:464]: File: c:\Program Files (x86)\ScorpionSaver\ff_content_loader.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:465]: Source for file 'ff_content_loader.js' is compressed
MSI (s) (84:7C) [10:11:04:465]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_content_loader.js
MSI (s) (84:7C) [10:11:04:469]: Executing op: FileCopy(SourceName=i5ddjrer.js|ff_content_symbiont.js,SourceCabKey=ff_content_symbiont.js,DestName=ff_content_symbiont.js,Attributes=512,FileSize=6923,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1649897267,HashPart2=2004902274,HashPart3=787602574,HashPart4=1736312685,,)
MSI (s) (84:7C) [10:11:04:469]: File: c:\Program Files (x86)\ScorpionSaver\ff_content_symbiont.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:469]: Source for file 'ff_content_symbiont.js' is compressed
MSI (s) (84:7C) [10:11:04:469]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_content_symbiont.js
MSI (s) (84:7C) [10:11:04:473]: Executing op: FileCopy(SourceName=vggezw_s.js|ff_content_worker.js,SourceCabKey=ff_content_worker.js,DestName=ff_content_worker.js,Attributes=512,FileSize=20670,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1511403779,HashPart2=-1147310639,HashPart3=840078423,HashPart4=53450448,,)
MSI (s) (84:7C) [10:11:04:473]: File: c:\Program Files (x86)\ScorpionSaver\ff_content_worker.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:473]: Source for file 'ff_content_worker.js' is compressed
MSI (s) (84:7C) [10:11:04:474]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_content_worker.js
MSI (s) (84:7C) [10:11:04:482]: Executing op: FileCopy(SourceName=qb_lcnmw.js|ff_dom_events.js,SourceCabKey=ff_dom_events.js,DestName=ff_dom_events.js,Attributes=512,FileSize=6072,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-630192660,HashPart2=-983064950,HashPart3=-124197887,HashPart4=-1040141370,,)
MSI (s) (84:7C) [10:11:04:483]: File: c:\Program Files (x86)\ScorpionSaver\ff_dom_events.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:483]: Source for file 'ff_dom_events.js' is compressed
MSI (s) (84:7C) [10:11:04:483]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_dom_events.js
MSI (s) (84:7C) [10:11:04:527]: Executing op: FileCopy(SourceName=ltq5ovek.js|ff_event_core.js,SourceCabKey=ff_event_core.js,DestName=ff_event_core.js,Attributes=512,FileSize=5116,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1422479130,HashPart2=-108632931,HashPart3=1356762625,HashPart4=-1363911710,,)
MSI (s) (84:7C) [10:11:04:527]: File: c:\Program Files (x86)\ScorpionSaver\ff_event_core.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:527]: Source for file 'ff_event_core.js' is compressed
MSI (s) (84:7C) [10:11:04:527]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_event_core.js
MSI (s) (84:7C) [10:11:04:530]: Executing op: FileCopy(SourceName=qhyypdwa.js|ff_event_target.js,SourceCabKey=ff_event_target.js,DestName=ff_event_target.js,Attributes=512,FileSize=2910,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1080312914,HashPart2=-338230572,HashPart3=1531917604,HashPart4=824419106,,)
MSI (s) (84:7C) [10:11:04:530]: File: c:\Program Files (x86)\ScorpionSaver\ff_event_target.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:530]: Source for file 'ff_event_target.js' is compressed
MSI (s) (84:7C) [10:11:04:531]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_event_target.js
MSI (s) (84:7C) [10:11:04:559]: Executing op: FileCopy(SourceName=nleqkvyp.js|ff_events_assembler.js,SourceCabKey=ff_events_assembler.js,DestName=ff_events_assembler.js,Attributes=512,FileSize=1979,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-360817316,HashPart2=1709499628,HashPart3=-1682688271,HashPart4=-70058227,,)
MSI (s) (84:7C) [10:11:04:559]: File: c:\Program Files (x86)\ScorpionSaver\ff_events_assembler.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:559]: Source for file 'ff_events_assembler.js' is compressed
MSI (s) (84:7C) [10:11:04:559]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_events_assembler.js
MSI (s) (84:7C) [10:11:04:561]: Executing op: FileCopy(SourceName=lcvt4bph.jso|ff_harness-options.json,SourceCabKey=ff_harnessoptions.json,DestName=ff_harness-options.json,Attributes=512,FileSize=42375,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-956030305,HashPart2=1727235858,HashPart3=1447952967,HashPart4=973858358,,)
MSI (s) (84:7C) [10:11:04:561]: File: c:\Program Files (x86)\ScorpionSaver\ff_harness-options.json;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:562]: Source for file 'ff_harnessoptions.json' is compressed
MSI (s) (84:7C) [10:11:04:562]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_harness-options.json
MSI (s) (84:7C) [10:11:04:563]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:573]: Executing op: FileCopy(SourceName=ff_icon.png,SourceCabKey=ff_icon.png,DestName=ff_icon.png,Attributes=512,FileSize=7661,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1028961819,HashPart2=-1261529403,HashPart3=172587596,HashPart4=-846895395,,)
MSI (s) (84:7C) [10:11:04:573]: File: c:\Program Files (x86)\ScorpionSaver\ff_icon.png;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:573]: Source for file 'ff_icon.png' is compressed
MSI (s) (84:7C) [10:11:04:728]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_icon.png
MSI (s) (84:7C) [10:11:04:730]: Executing op: FileCopy(SourceName=8rl5zltd.png|ff_icon64.png,SourceCabKey=ff_icon64.png,DestName=ff_icon64.png,Attributes=512,FileSize=7661,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1028961819,HashPart2=-1261529403,HashPart3=172587596,HashPart4=-846895395,,)
MSI (s) (84:7C) [10:11:04:730]: File: c:\Program Files (x86)\ScorpionSaver\ff_icon64.png;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:730]: Source for file 'ff_icon64.png' is compressed
MSI (s) (84:7C) [10:11:04:730]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_icon64.png
MSI (s) (84:7C) [10:11:04:731]: Executing op: FileCopy(SourceName=j3pf67r-.rdf|ff_install.rdf,SourceCabKey=ff_install.rdf,DestName=ff_install.rdf,Attributes=512,FileSize=1220,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1216690864,HashPart2=-493448227,HashPart3=-2068839582,HashPart4=1038131310,,)
MSI (s) (84:7C) [10:11:04:731]: File: c:\Program Files (x86)\ScorpionSaver\ff_install.rdf;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:731]: Source for file 'ff_install.rdf' is compressed
MSI (s) (84:7C) [10:11:04:732]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_install.rdf
MSI (s) (84:7C) [10:11:04:732]: Executing op: FileCopy(SourceName=-vmgo_9z.js|ff_l10n_core.js,SourceCabKey=ff_l10n_core.js,DestName=ff_l10n_core.js,Attributes=512,FileSize=1122,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=798111964,HashPart2=2047979461,HashPart3=2108869952,HashPart4=-1380742606,,)
MSI (s) (84:7C) [10:11:04:732]: File: c:\Program Files (x86)\ScorpionSaver\ff_l10n_core.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:733]: Source for file 'ff_l10n_core.js' is compressed
MSI (s) (84:7C) [10:11:04:733]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_l10n_core.js
MSI (s) (84:7C) [10:11:04:735]: Executing op: FileCopy(SourceName=t_5o73ja.js|ff_l10n_html.js,SourceCabKey=ff_l10n_html.js,DestName=ff_l10n_html.js,Attributes=512,FileSize=2902,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=552705128,HashPart2=424691016,HashPart3=-491083601,HashPart4=1724090738,,)
MSI (s) (84:7C) [10:11:04:735]: File: c:\Program Files (x86)\ScorpionSaver\ff_l10n_html.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:735]: Source for file 'ff_l10n_html.js' is compressed
MSI (s) (84:7C) [10:11:04:735]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_l10n_html.js
MSI (s) (84:7C) [10:11:04:738]: Executing op: FileCopy(SourceName=yxpxeo6_.js|ff_l10n_loader.js,SourceCabKey=ff_l10n_loader.js,DestName=ff_l10n_loader.js,Attributes=512,FileSize=3003,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-395430131,HashPart2=-1735365122,HashPart3=938830867,HashPart4=1009490401,,)
MSI (s) (84:7C) [10:11:04:738]: File: c:\Program Files (x86)\ScorpionSaver\ff_l10n_loader.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:738]: Source for file 'ff_l10n_loader.js' is compressed
MSI (s) (84:7C) [10:11:04:738]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_l10n_loader.js
MSI (s) (84:7C) [10:11:04:741]: Executing op: FileCopy(SourceName=urwhkjdo.js|ff_l10n_locale.js,SourceCabKey=ff_l10n_locale.js,DestName=ff_l10n_locale.js,Attributes=512,FileSize=4662,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1570410495,HashPart2=2026488823,HashPart3=-642233251,HashPart4=-54536299,,)
MSI (s) (84:7C) [10:11:04:741]: File: c:\Program Files (x86)\ScorpionSaver\ff_l10n_locale.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:741]: Source for file 'ff_l10n_locale.js' is compressed
MSI (s) (84:7C) [10:11:04:741]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_l10n_locale.js
MSI (s) (84:7C) [10:11:04:744]: Executing op: FileCopy(SourceName=43log48n.js|ff_l10n_prefs.js,SourceCabKey=ff_l10n_prefs.js,DestName=ff_l10n_prefs.js,Attributes=512,FileSize=1286,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-80028497,HashPart2=-872748808,HashPart3=-42590183,HashPart4=-964223024,,)
MSI (s) (84:7C) [10:11:04:744]: File: c:\Program Files (x86)\ScorpionSaver\ff_l10n_prefs.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:744]: Source for file 'ff_l10n_prefs.js' is compressed
MSI (s) (84:7C) [10:11:04:745]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_l10n_prefs.js
MSI (s) (84:7C) [10:11:04:747]: Executing op: FileCopy(SourceName=4wwthjz0.jso|ff_locales.json,SourceCabKey=ff_locales.json,DestName=ff_locales.json,Attributes=512,FileSize=17,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=82858458,HashPart2=958956719,HashPart3=-576468482,HashPart4=-483045674,,)
MSI (s) (84:7C) [10:11:04:747]: File: c:\Program Files (x86)\ScorpionSaver\ff_locales.json;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:747]: Source for file 'ff_locales.json' is compressed
MSI (s) (84:7C) [10:11:04:747]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_locales.json
MSI (s) (84:7C) [10:11:04:776]: Executing op: FileCopy(SourceName=ff_main.js,SourceCabKey=ff_main.js,DestName=ff_main.js,Attributes=512,FileSize=4977,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1906505747,HashPart2=50983312,HashPart3=114584310,HashPart4=-817666723,,)
MSI (s) (84:7C) [10:11:04:776]: File: c:\Program Files (x86)\ScorpionSaver\ff_main.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:776]: Source for file 'ff_main.js' is compressed
MSI (s) (84:7C) [10:11:04:777]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_main.js
MSI (s) (84:7C) [10:11:04:780]: Executing op: FileCopy(SourceName=ad3aj21-.old|ff_main.js.old,SourceCabKey=ff_main.js.old,DestName=ff_main.js.old,Attributes=512,FileSize=4982,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1798967591,HashPart2=1670058611,HashPart3=-1254426618,HashPart4=-1737187747,,)
MSI (s) (84:7C) [10:11:04:780]: File: c:\Program Files (x86)\ScorpionSaver\ff_main.js.old;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:780]: Source for file 'ff_main.js.old' is compressed
MSI (s) (84:7C) [10:11:04:780]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_main.js.old
MSI (s) (84:7C) [10:11:04:781]: Executing op: FileCopy(SourceName=ff_prefs.js,SourceCabKey=ff_prefs.js,DestName=ff_prefs.js,Attributes=512,FileSize=0,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=0,HashPart2=0,HashPart3=0,HashPart4=0,,)
MSI (s) (84:7C) [10:11:04:781]: File: c:\Program Files (x86)\ScorpionSaver\ff_prefs.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:781]: Source for file 'ff_prefs.js' is compressed
MSI (s) (84:7C) [10:11:04:781]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_prefs.js
MSI (s) (84:7C) [10:11:04:782]: Executing op: FileCopy(SourceName=k4t_r1pi.js|ff_privatebrowsing_utils.js,SourceCabKey=ff_privatebrowsing_utils.js,DestName=ff_privatebrowsing_utils.js,Attributes=512,FileSize=2731,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1598800911,HashPart2=781152107,HashPart3=-1085059069,HashPart4=-1605048366,,)
MSI (s) (84:7C) [10:11:04:782]: File: c:\Program Files (x86)\ScorpionSaver\ff_privatebrowsing_utils.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:782]: Source for file 'ff_privatebrowsing_utils.js' is compressed
MSI (s) (84:7C) [10:11:04:782]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_privatebrowsing_utils.js
MSI (s) (84:7C) [10:11:04:785]: Executing op: FileCopy(SourceName=dbyhegsi.js|ff_system_events.js,SourceCabKey=ff_system_events.js,DestName=ff_system_events.js,Attributes=512,FileSize=3724,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-428230867,HashPart2=-776152042,HashPart3=847745381,HashPart4=-136088894,,)
MSI (s) (84:7C) [10:11:04:785]: File: c:\Program Files (x86)\ScorpionSaver\ff_system_events.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:785]: Source for file 'ff_system_events.js' is compressed
MSI (s) (84:7C) [10:11:04:786]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_system_events.js
MSI (s) (84:7C) [10:11:04:788]: Executing op: FileCopy(SourceName=utkdfwic.js|ff_tabs_events.js,SourceCabKey=ff_tabs_events.js,DestName=ff_tabs_events.js,Attributes=512,FileSize=742,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=444527278,HashPart2=-177288345,HashPart3=-891656105,HashPart4=-1279968233,,)
MSI (s) (84:7C) [10:11:04:788]: File: c:\Program Files (x86)\ScorpionSaver\ff_tabs_events.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:788]: Source for file 'ff_tabs_events.js' is compressed
MSI (s) (84:7C) [10:11:04:789]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_tabs_events.js
MSI (s) (84:7C) [10:11:04:790]: Executing op: FileCopy(SourceName=uobbm94l.js|ff_tabs_observer.js,SourceCabKey=ff_tabs_observer.js,DestName=ff_tabs_observer.js,Attributes=512,FileSize=3718,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=894555955,HashPart2=-1098011533,HashPart3=1585422503,HashPart4=-948001142,,)
MSI (s) (84:7C) [10:11:04:790]: File: c:\Program Files (x86)\ScorpionSaver\ff_tabs_observer.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:790]: Source for file 'ff_tabs_observer.js' is compressed
MSI (s) (84:7C) [10:11:04:791]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_tabs_observer.js
MSI (s) (84:7C) [10:11:04:794]: Executing op: FileCopy(SourceName=jdf8bcfh.js|ff_tabs_tab.js,SourceCabKey=ff_tabs_tab.js,DestName=ff_tabs_tab.js,Attributes=512,FileSize=8011,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-8615032,HashPart2=1535631357,HashPart3=-1622234276,HashPart4=-1990537551,,)
MSI (s) (84:7C) [10:11:04:794]: File: c:\Program Files (x86)\ScorpionSaver\ff_tabs_tab.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:794]: Source for file 'ff_tabs_tab.js' is compressed
MSI (s) (84:7C) [10:11:04:794]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_tabs_tab.js
MSI (s) (84:7C) [10:11:04:799]: Executing op: FileCopy(SourceName=2ky3nafq.js|ff_tabs_utils.js,SourceCabKey=ff_tabs_utils.js,DestName=ff_tabs_utils.js,Attributes=512,FileSize=3409,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1140880555,HashPart2=-1318869531,HashPart3=1967363656,HashPart4=198346386,,)
MSI (s) (84:7C) [10:11:04:799]: File: c:\Program Files (x86)\ScorpionSaver\ff_tabs_utils.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:799]: Source for file 'ff_tabs_utils.js' is compressed
MSI (s) (84:7C) [10:11:04:799]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_tabs_utils.js
MSI (s) (84:7C) [10:11:04:802]: Executing op: FileCopy(SourceName=nz4fcn0n.js|ff_traits_core.js,SourceCabKey=ff_traits_core.js,DestName=ff_traits_core.js,Attributes=512,FileSize=10743,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1665453346,HashPart2=-2139750040,HashPart3=-2030628176,HashPart4=-1712519874,,)
MSI (s) (84:7C) [10:11:04:802]: File: c:\Program Files (x86)\ScorpionSaver\ff_traits_core.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:802]: Source for file 'ff_traits_core.js' is compressed
MSI (s) (84:7C) [10:11:04:802]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_traits_core.js
MSI (s) (84:7C) [10:11:04:871]: Executing op: FileCopy(SourceName=lmzdwzji.js|ff_utils_data.js,SourceCabKey=ff_utils_data.js,DestName=ff_utils_data.js,Attributes=512,FileSize=2645,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1730485583,HashPart2=-1865648435,HashPart3=1124626423,HashPart4=-2096561063,,)
MSI (s) (84:7C) [10:11:04:871]: File: c:\Program Files (x86)\ScorpionSaver\ff_utils_data.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:871]: Source for file 'ff_utils_data.js' is compressed
MSI (s) (84:7C) [10:11:04:872]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_utils_data.js
MSI (s) (84:7C) [10:11:04:874]: Executing op: FileCopy(SourceName=x_clszqz.js|ff_utils_object.js,SourceCabKey=ff_utils_object.js,DestName=ff_utils_object.js,Attributes=512,FileSize=1663,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-480416023,HashPart2=1413414383,HashPart3=2067260224,HashPart4=-500543042,,)
MSI (s) (84:7C) [10:11:04:874]: File: c:\Program Files (x86)\ScorpionSaver\ff_utils_object.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:874]: Source for file 'ff_utils_object.js' is compressed
MSI (s) (84:7C) [10:11:04:875]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_utils_object.js
MSI (s) (84:7C) [10:11:04:877]: Executing op: FileCopy(SourceName=ykryhnia.js|ff_utils_registry.js,SourceCabKey=ff_utils_registry.js,DestName=ff_utils_registry.js,Attributes=512,FileSize=1919,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1716792603,HashPart2=453513140,HashPart3=-1709479017,HashPart4=2098480990,,)
MSI (s) (84:7C) [10:11:04:877]: File: c:\Program Files (x86)\ScorpionSaver\ff_utils_registry.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:877]: Source for file 'ff_utils_registry.js' is compressed
MSI (s) (84:7C) [10:11:04:877]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_utils_registry.js
MSI (s) (84:7C) [10:11:04:879]: Executing op: FileCopy(SourceName=bu0lswtr.js|ff_utils_thumbnail.js,SourceCabKey=ff_utils_thumbnail.js,DestName=ff_utils_thumbnail.js,Attributes=512,FileSize=1660,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1478465502,HashPart2=867794997,HashPart3=100262669,HashPart4=1947530628,,)
MSI (s) (84:7C) [10:11:04:880]: File: c:\Program Files (x86)\ScorpionSaver\ff_utils_thumbnail.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:880]: Source for file 'ff_utils_thumbnail.js' is compressed
MSI (s) (84:7C) [10:11:04:880]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_utils_thumbnail.js
MSI (s) (84:7C) [10:11:04:882]: Executing op: FileCopy(SourceName=tptkwbx8.js|ff_window_utils.js,SourceCabKey=ff_window_utils.js,DestName=ff_window_utils.js,Attributes=512,FileSize=5704,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1549022575,HashPart2=-1761251221,HashPart3=-521267706,HashPart4=-664871246,,)
MSI (s) (84:7C) [10:11:04:882]: File: c:\Program Files (x86)\ScorpionSaver\ff_window_utils.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:882]: Source for file 'ff_window_utils.js' is compressed
MSI (s) (84:7C) [10:11:04:883]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_window_utils.js
MSI (s) (84:7C) [10:11:04:886]: Executing op: FileCopy(SourceName=vhhtmrw7.js|ff_windows_dom.js,SourceCabKey=ff_windows_dom.js,DestName=ff_windows_dom.js,Attributes=512,FileSize=941,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1580469946,HashPart2=-1405758725,HashPart3=-75134505,HashPart4=180565606,,)
MSI (s) (84:7C) [10:11:04:887]: File: c:\Program Files (x86)\ScorpionSaver\ff_windows_dom.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:887]: Source for file 'ff_windows_dom.js' is compressed
MSI (s) (84:7C) [10:11:04:887]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_windows_dom.js
MSI (s) (84:7C) [10:11:04:889]: Executing op: FileCopy(SourceName=0t6xfjhw.js|ff_windows_loader.js,SourceCabKey=ff_windows_loader.js,DestName=ff_windows_loader.js,Attributes=512,FileSize=4346,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=319529862,HashPart2=1593243653,HashPart3=-1900036315,HashPart4=-1585572100,,)
MSI (s) (84:7C) [10:11:04:889]: File: c:\Program Files (x86)\ScorpionSaver\ff_windows_loader.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:889]: Source for file 'ff_windows_loader.js' is compressed
MSI (s) (84:7C) [10:11:04:889]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_windows_loader.js
MSI (s) (84:7C) [10:11:04:892]: Executing op: FileCopy(SourceName=turusgap.js|ff_windows_observer.js,SourceCabKey=ff_windows_observer.js,DestName=ff_windows_observer.js,Attributes=512,FileSize=1757,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1293771185,HashPart2=-876296447,HashPart3=79874953,HashPart4=1971559458,,)
MSI (s) (84:7C) [10:11:04:893]: File: c:\Program Files (x86)\ScorpionSaver\ff_windows_observer.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:893]: Source for file 'ff_windows_observer.js' is compressed
MSI (s) (84:7C) [10:11:04:893]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_windows_observer.js
MSI (s) (84:7C) [10:11:04:895]: Executing op: FileCopy(SourceName=5vrohn6p.js|ff_windows_tabs.js,SourceCabKey=ff_windows_tabs.js,DestName=ff_windows_tabs.js,Attributes=512,FileSize=6872,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-896289187,HashPart2=-675513253,HashPart3=190837964,HashPart4=1399970721,,)
MSI (s) (84:7C) [10:11:04:895]: File: c:\Program Files (x86)\ScorpionSaver\ff_windows_tabs.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:895]: Source for file 'ff_windows_tabs.js' is compressed
MSI (s) (84:7C) [10:11:04:895]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\ff_windows_tabs.js
MSI (s) (84:7C) [10:11:04:899]: Executing op: FileCopy(SourceName=icon128.png,SourceCabKey=icon128.png,DestName=icon128.png,Attributes=512,FileSize=16837,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=2115057586,HashPart2=133269868,HashPart3=210670133,HashPart4=-852912179,,)
MSI (s) (84:7C) [10:11:04:899]: File: c:\Program Files (x86)\ScorpionSaver\icon128.png;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:899]: Source for file 'icon128.png' is compressed
MSI (s) (84:7C) [10:11:04:900]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\icon128.png
MSI (s) (84:7C) [10:11:04:901]: Executing op: FileCopy(SourceName=icon16.png,SourceCabKey=icon16.png,DestName=icon16.png,Attributes=512,FileSize=3388,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1577313478,HashPart2=-1355926979,HashPart3=-221881210,HashPart4=1313744799,,)
MSI (s) (84:7C) [10:11:04:901]: File: c:\Program Files (x86)\ScorpionSaver\icon16.png;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:901]: Source for file 'icon16.png' is compressed
MSI (s) (84:7C) [10:11:04:901]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\icon16.png
MSI (s) (84:7C) [10:11:04:902]: Executing op: FileCopy(SourceName=icon32.png,SourceCabKey=icon32.png,DestName=icon32.png,Attributes=512,FileSize=4765,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1638966732,HashPart2=464742534,HashPart3=-1520629642,HashPart4=1586181244,,)
MSI (s) (84:7C) [10:11:04:902]: File: c:\Program Files (x86)\ScorpionSaver\icon32.png;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:902]: Source for file 'icon32.png' is compressed
MSI (s) (84:7C) [10:11:04:903]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\icon32.png
MSI (s) (84:7C) [10:11:04:903]: Executing op: FileCopy(SourceName=icon48.png,SourceCabKey=icon48.png,DestName=icon48.png,Attributes=512,FileSize=6406,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1581966188,HashPart2=-620162111,HashPart3=1986524793,HashPart4=-1457750254,,)
MSI (s) (84:7C) [10:11:04:904]: File: c:\Program Files (x86)\ScorpionSaver\icon48.png;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:904]: Source for file 'icon48.png' is compressed
MSI (s) (84:7C) [10:11:04:904]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\icon48.png
MSI (s) (84:7C) [10:11:04:905]: Executing op: FileCopy(SourceName=icon64.png,SourceCabKey=icon64.png,DestName=icon64.png,Attributes=512,FileSize=7661,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1028961819,HashPart2=-1261529403,HashPart3=172587596,HashPart4=-846895395,,)
MSI (s) (84:7C) [10:11:04:905]: File: c:\Program Files (x86)\ScorpionSaver\icon64.png;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:905]: Source for file 'icon64.png' is compressed
MSI (s) (84:7C) [10:11:04:905]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\icon64.png
MSI (s) (84:7C) [10:11:04:906]: Executing op: FileCopy(SourceName=icon8.png,SourceCabKey=icon8.png,DestName=icon8.png,Attributes=512,FileSize=3023,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-21759877,HashPart2=-920018226,HashPart3=-467096166,HashPart4=2037918590,,)
MSI (s) (84:7C) [10:11:04:906]: File: c:\Program Files (x86)\ScorpionSaver\icon8.png;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:906]: Source for file 'icon8.png' is compressed
MSI (s) (84:7C) [10:11:04:907]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\icon8.png
MSI (s) (84:7C) [10:11:04:908]: Executing op: FileCopy(SourceName=IECore.dll,SourceCabKey=IECore.dll,DestName=IECore.dll,Attributes=512,FileSize=87560,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=2051983510,HashPart2=1656176687,HashPart3=-1968813634,HashPart4=969607923,,)
MSI (s) (84:7C) [10:11:04:908]: File: c:\Program Files (x86)\ScorpionSaver\IECore.dll;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:908]: Source for file 'IECore.dll' is compressed
MSI (s) (84:7C) [10:11:04:908]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\IECore.dll
MSI (s) (84:7C) [10:11:04:909]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:953]: Executing op: FileCopy(SourceName=jmqdfyrj.jso|manifest.json,SourceCabKey=manifest.json,DestName=manifest.json,Attributes=512,FileSize=1273,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1893363490,HashPart2=-1389868375,HashPart3=-2061356825,HashPart4=1583403325,,)
MSI (s) (84:7C) [10:11:04:953]: File: c:\Program Files (x86)\ScorpionSaver\manifest.json;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:953]: Source for file 'manifest.json' is compressed
MSI (s) (84:7C) [10:11:04:954]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\manifest.json
MSI (s) (84:7C) [10:11:04:956]: Executing op: FileCopy(SourceName=3iioeqgh.js|marcopolo.js,SourceCabKey=marcopolo.js,DestName=marcopolo.js,Attributes=512,FileSize=607,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1150160956,HashPart2=-879076789,HashPart3=942927881,HashPart4=-1817786394,,)
MSI (s) (84:7C) [10:11:04:956]: File: c:\Program Files (x86)\ScorpionSaver\marcopolo.js;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:956]: Source for file 'marcopolo.js' is compressed
MSI (s) (84:7C) [10:11:04:956]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\marcopolo.js
MSI (s) (84:7C) [10:11:04:958]: Executing op: FileCopy(SourceName=SendJson.dll,SourceCabKey=SendJson,DestName=SendJson.dll,Attributes=512,FileSize=368128,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-59094699,HashPart2=1004813978,HashPart3=595056615,HashPart4=1575835997,,)
MSI (s) (84:7C) [10:11:04:958]: File: c:\Program Files (x86)\ScorpionSaver\SendJson.dll;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:958]: Source for file 'SendJson' is compressed
MSI (s) (84:7C) [10:11:04:959]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\SendJson.dll
MSI (s) (84:7C) [10:11:04:959]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:960]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:961]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:961]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:962]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:962]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:963]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:964]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:964]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:965]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:965]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:982]: Executing op: FileCopy(SourceName=bcdeaqcu.dll|Microsoft.Deployment.WindowsInstaller.dll,SourceCabKey=WindowsInstallerdll,DestName=Microsoft.Deployment.WindowsInstaller.dll,Attributes=512,FileSize=180224,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,Version=3.6.3303.0,Language=0,InstallMode=58982400,,,,,,,)
MSI (s) (84:7C) [10:11:04:982]: File: c:\Program Files (x86)\ScorpionSaver\Microsoft.Deployment.WindowsInstaller.dll;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:982]: Source for file 'WindowsInstallerdll' is compressed
MSI (s) (84:7C) [10:11:04:983]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\Microsoft.Deployment.WindowsInstaller.dll
MSI (s) (84:7C) [10:11:04:984]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:985]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:985]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:986]: Note: 1: 2360
MSI (s) (84:7C) [10:11:04:998]: Executing op: FileCopy(SourceName=teowi4lc.xml|Microsoft.Deployment.WindowsInstaller.xml,SourceCabKey=WindowsInstallerxml,DestName=Microsoft.Deployment.WindowsInstaller.xml,Attributes=512,FileSize=485807,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-529702913,HashPart2=120212815,HashPart3=-1778603535,HashPart4=-1307356715,,)
MSI (s) (84:7C) [10:11:04:998]: File: c:\Program Files (x86)\ScorpionSaver\Microsoft.Deployment.WindowsInstaller.xml;    To be installed;    Won't patch;    No existing file
MSI (s) (84:7C) [10:11:04:998]: Source for file 'WindowsInstallerxml' is compressed
MSI (s) (84:7C) [10:11:04:999]: Note: 1: 2318 2: c:\Program Files (x86)\ScorpionSaver\Microsoft.Deployment.WindowsInstaller.xml
MSI (s) (84:7C) [10:11:04:999]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:000]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:000]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:001]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:001]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:001]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:002]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:002]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:003]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:003]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:003]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:004]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:004]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:005]: Note: 1: 2360
MSI (s) (84:7C) [10:11:05:005]: Executing op: CacheSizeFlush(,)
MSI (s) (84:7C) [10:11:05:005]: Executing op: ActionStart(Name=CustomActionInstall,,)
MSI (s) (84:7C) [10:11:05:006]: Executing op: CustomActionSchedule(Action=CustomActionInstall,ActionType=3137,Source=BinaryData,Target=Install,CustomActionData=SourceGUID:F5D333A8-C748-4686-AE0A-9E008F670C22 VMFlag: UserGUID:4C4108F8-17B8-4CBA-E710-4E7812FCAD1F FFEnabled: IEEnabled:TRUE ChromeEnabled: Options:01110010000000000000000000000000)
MSI (s) (84:E8) [10:11:05:029]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIC858.tmp, Entrypoint: Install
MSI (s) (84:FC) [10:11:05:029]: Generating random cookie.
MSI (s) (84:FC) [10:11:05:047]: Created Custom Action Server with PID 3748 (0xEA4).
MSI (s) (84:FC) [10:11:05:088]: Running as a service.
MSI (s) (84:FC) [10:11:05:090]: Hello, I'm your 32bit Elevated custom action server.
Install:  Initialized.
Install:  Custom Action Data = 'SourceGUID:F5D333A8-C748-4686-AE0A-9E008F670C22 VMFlag: UserGUID:4C4108F8-17B8-4CBA-E710-4E7812FCAD1F FFEnabled: IEEnabled:TRUE ChromeEnabled: Options:01110010000000000000000000000000'.
Install:  In GetParameters
Install:  SourceGUID = F5D333A8-C748-4686-AE0A-9E008F670C22
Install:  VMFlag =
Install:  UserGUID = 4C4108F8-17B8-4CBA-E710-4E7812FCAD1F
Install:  FFEnabled =
Install:  IEEnabled = TRUE
Install:  ChromeEnabled =
Install:  OptionsArg Before GetParameters =
Install:  OptionsArg After GetParameters= 01110010000000000000000000000000
Install:  Completed GetParameters
Install:  In Install, retrieved parameters.
Install:  Attempting to open registry key Software
Install:  Attempting to create registry key Adpeak, Inc.
Install:  Attempting to create registry key ScorpionSaver
Install:  Attempting to create registry key Chrome
Install:  Attempting to create registry key IE
Install:  Attempting to create registry key Firefox



#8 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:12:04 PM

Posted 07 December 2013 - 08:46 PM


Hello totalsiege

I Would like you to do the following.

Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"
  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?
Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#9 totalsiege

totalsiege
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:04 AM

Posted 07 December 2013 - 10:28 PM

Hi just finnished running it. Problems I had even with all avast shields disabled it still was showing up to combofix. Nothing else was running. One other problem was during the combofix one of the items item said it needed administrator rights, but I was runing it as administrator the cmd window also showed as administrator. I am still in safemode should I restart in normal now?

 

 

ComboFix 13-12-07.01 - James 12/07/2013  21:49:31.1.4 - x64 NETWORK
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.8190.6867 [GMT -5:00]
Running from: c:\users\James\Desktop\ComboFix.exe
AV: avast! Internet Security *Enabled/Outdated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Enabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Enabled/Outdated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\programdata\uninstaller.exe
c:\users\James\~DF5AB0.tmp
c:\users\James\~Qil1609.tmp
c:\users\James\~Qil2350.tmp
c:\users\James\A9RE767.tmp
c:\users\James\LEX1CB8.tmp
c:\users\James\Quarantine.exe
c:\users\James\tmp1954.tmp
c:\users\James\tmp1955.tmp
c:\users\James\tmpA3D9.tmp
c:\users\James\WKS199B.tmp
.
.
(((((((((((((((((((((((((   Files Created from 2013-11-08 to 2013-12-08  )))))))))))))))))))))))))))))))
.
.
2013-12-08 02:57 . 2013-12-08 02:57    --------    d-----w-    c:\users\James\AppData\Local\temp
2013-12-08 02:57 . 2013-12-08 02:57    --------    d-----w-    c:\users\Default\AppData\Local\temp
2013-12-08 01:30 . 2013-12-08 02:32    --------    d-----w-    c:\program files\3
2013-12-07 23:42 . 2013-12-07 23:42    --------    d-----w-    c:\program files (x86)\FileASSASSIN
2013-12-07 18:26 . 2013-12-07 18:26    --------    d-----w-    c:\users\James\WPDNSE
2013-12-07 17:32 . 2013-12-07 18:16    --------    d-----w-    C:\AdwCleaner
2013-12-07 01:23 . 2013-12-07 01:23    --------    d-----w-    c:\users\James\Deployment
2013-12-07 01:19 . 2013-12-07 03:26    --------    d-----w-    c:\users\James\plugtmp-1
2013-12-07 00:48 . 2013-12-07 00:48    --------    d-----w-    c:\program files\CCleaner
2013-12-06 04:13 . 2013-12-06 04:13    --------    d-----w-    c:\users\James\Skype
2013-12-06 04:12 . 2013-12-06 04:12    --------    d-----w-    c:\users\James\MWTrace
2013-12-06 04:10 . 2013-12-06 04:10    --------    d-----w-    c:\windows\SysWow64\_avast_
2013-12-06 04:10 . 2013-12-06 22:45    --------    d-----w-    c:\windows\system32\_avast_
2013-12-06 04:07 . 2013-12-06 04:07    --------    d-----w-    c:\users\James\plugtmp
2013-12-06 04:07 . 2013-12-08 02:32    --------    d---a-w-    c:\users\James\acro_rd_dir
2013-12-06 01:44 . 2013-12-08 00:04    --------    d-----w-    c:\programdata\Malwarebytes' Anti-Malware (portable)
2013-12-06 01:43 . 2013-12-06 01:43    91352    ----a-w-    c:\windows\system32\drivers\mbamchameleon.sys
2013-12-06 01:32 . 2013-12-06 01:32    --------    d-----w-    c:\users\James\AppData\Roaming\Malwarebytes
2013-12-06 01:32 . 2013-12-06 01:32    --------    d-----w-    c:\programdata\Malwarebytes
2013-12-06 01:32 . 2013-12-06 01:32    --------    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
2013-12-06 01:32 . 2013-04-04 19:50    25928    ----a-w-    c:\windows\system32\drivers\mbam.sys
2013-12-06 01:27 . 2013-12-06 01:27    --------    d-----w-    c:\users\James\Low
2013-12-05 02:17 . 2013-12-06 04:02    --------    d-----w-    C:\sfzone_profile
2013-12-04 12:06 . 2013-11-08 03:12    10285968    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{B50E1DE8-7EB6-4210-BEE4-1E9513332C25}\mpengine.dll
2013-12-04 08:44 . 2013-12-04 11:39    --------    d-----w-    c:\users\Guest
2013-12-03 11:00 . 2013-12-03 11:00    --------    d-----w-    C:\sh4ldr
2013-12-03 11:00 . 2013-12-03 11:00    --------    d-----w-    c:\program files\Enigma Software Group
2013-12-03 10:59 . 2013-12-03 11:00    --------    d-----w-    c:\windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
2013-12-03 05:24 . 2013-12-03 05:24    --------    d-----w-    c:\users\James\AppData\Local\VS Revo Group
2013-12-03 05:24 . 2013-12-03 05:24    --------    d-----w-    c:\program files\VS Revo Group
2013-12-03 01:50 . 2013-12-03 01:50    --------    d-----w-    c:\program files (x86)\VS Revo Group
2013-11-30 20:37 . 2013-11-30 20:53    --------    d-----w-    c:\users\James\AppData\Local\cache
2013-11-30 20:37 . 2013-12-08 02:56    --------    d-----w-    c:\users\James\AppData\Local\Mobogenie
2013-11-29 06:56 . 2013-11-29 06:56    --------    d-----w-    c:\users\James\AppData\Local\LogMeIn
2013-11-29 06:56 . 2013-11-29 06:56    --------    d-----w-    c:\programdata\LogMeIn
2013-11-28 19:43 . 2013-11-28 19:43    --------    d-----w-    c:\users\James\AppData\Local\LogMeIn Rescue
2013-11-28 19:41 . 2013-12-04 11:35    --------    d-----w-    c:\program files (x86)\LogMeIn Rescue Technician Console
2013-11-14 08:01 . 2013-10-13 15:09    10926080    ----a-w-    c:\windows\system32\ieframe.dll
2013-11-13 11:45 . 2013-10-11 04:23    462848    ----a-w-    c:\windows\system32\IKEEXT.DLL
2013-11-13 11:45 . 2013-10-11 04:23    781824    ----a-w-    c:\windows\system32\FWPUCLNT.DLL
2013-11-13 11:45 . 2013-10-11 02:07    596480    ----a-w-    c:\windows\SysWow64\FWPUCLNT.DLL
2013-11-13 11:45 . 2013-10-03 15:02    1278976    ----a-w-    c:\windows\system32\crypt32.dll
2013-11-13 11:45 . 2013-10-03 12:45    993792    ----a-w-    c:\windows\SysWow64\crypt32.dll
2013-11-13 11:45 . 2013-10-03 15:03    389632    ----a-w-    c:\windows\system32\gdi32.dll
2013-11-13 11:45 . 2013-10-03 12:46    304128    ----a-w-    c:\windows\SysWow64\gdi32.dll
2013-11-13 11:45 . 2013-09-04 02:31    404992    ----a-w-    c:\windows\system32\drivers\afd.sys
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-11 10:50 . 2012-05-10 05:56    267936    ------w-    c:\windows\system32\MpSigStub.exe
2013-10-09 17:16 . 2012-05-10 11:37    71048    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-09 17:16 . 2012-05-10 11:37    692616    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2009-04-11 . E68D9B3A3905619732F7FE039466A623 . 20952 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
[7] 2008-01-21 . 1898FAE8E07D97F2F6C2D5326C633FAC . 22584 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[7] 2009-04-11 . E68D9B3A3905619732F7FE039466A623 . 20952 . . [6.0.6002.18005] .. c:\windows\system32\DriverStore\FileRepository\mshdc.inf_b6d20d6f\atapi.sys
[7] 2008-01-21 . 1898FAE8E07D97F2F6C2D5326C633FAC . 22584 . . [6.0.6001.18000] .. c:\windows\system32\drivers\atapi.sys
[7] 2008-01-21 . 1898FAE8E07D97F2F6C2D5326C633FAC . 22584 . . [6.0.6001.18000] .. c:\windows\system32\DriverStore\FileRepository\mshdc.inf_1d87dda2\atapi.sys
[7] 2006-11-02 . DF96CF8885724430024B7522E5C95722 . 20072 . . [6.0.6000.16386] .. c:\windows\system32\DriverStore\FileRepository\mshdc.inf_f8cccc79\atapi.sys
.
[7] 2008-01-21 . 22D13FF3DAFEC2A80634752B1EAA2DE6 . 22016 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-rasbase-asyncmac_31bf3856ad364e35_6.0.6001.18000_none_80766a66ed36afa5\asyncmac.sys
[7] 2008-01-21 . 22D13FF3DAFEC2A80634752B1EAA2DE6 . 22016 . . [6.0.6001.18000] .. c:\windows\system32\drivers\asyncmac.sys
.
[7] 2008-01-21 . 423696F3BA6472DD17699209B933BC26 . 42040 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_keyboard.inf_31bf3856ad364e35_6.0.6001.18000_none_f36d095c91565db4\kbdclass.sys
[7] 2008-01-21 . 423696F3BA6472DD17699209B933BC26 . 42040 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_keyboard.inf_31bf3856ad364e35_6.0.6002.18005_none_f55882688e782900\kbdclass.sys
[7] 2008-01-21 . AC1BA7446D5343DFD4267A6E0D4FC0AF . 42040 . . [6.0.6000.16609] .. c:\windows\winsxs\amd64_keyboard.inf_31bf3856ad364e35_6.0.6000.16609_none_f18fcd509427b0d2\kbdclass.sys
[7] 2008-01-21 . 88EE8513158979334FEEBFD777DFF390 . 42040 . . [6.0.6000.20734] .. c:\windows\winsxs\amd64_keyboard.inf_31bf3856ad364e35_6.0.6000.20734_none_f1f3f8e5ad6225bc\kbdclass.sys
[7] 2008-01-21 . 423696F3BA6472DD17699209B933BC26 . 42040 . . [6.0.6000.16386] .. c:\windows\system32\drivers\kbdclass.sys
[7] 2008-01-21 . 423696F3BA6472DD17699209B933BC26 . 42040 . . [6.0.6001.18000] .. c:\windows\system32\DriverStore\FileRepository\keyboard.inf_917586af\kbdclass.sys
[7] 2008-01-21 . 423696F3BA6472DD17699209B933BC26 . 42040 . . [6.0.6001.18000] .. c:\windows\system32\DriverStore\FileRepository\keyboard.inf_d1a065f2\kbdclass.sys
[7] 2006-11-02 . 4324BBE0D86A15107C670E16218BF9C9 . 39528 . . [6.0.6000.16386] .. c:\windows\system32\DriverStore\FileRepository\keyboard.inf_c5bba9ff\kbdclass.sys
.
[7] 2009-04-11 . 65950E07329FCEE8E6516B17C8D0ABB6 . 738264 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6002.18005_none_05d14056d18e499a\ndis.sys
[7] 2008-01-21 . 2A2EE457AF36C5C9A6808C768BD3A12B . 739384 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_03e5c74ad46c7e4e\ndis.sys
[7] 2009-04-11 . 65950E07329FCEE8E6516B17C8D0ABB6 . 738264 . . [6.0.6002.18005] .. c:\windows\system32\drivers\ndis.sys
.
[7] 2013-03-03 . 2ACCAA3C3C55370A32F17B3595E1A217 . 1513320 . . [6.0.6002.18799] .. c:\windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6002.18799_none_041dfd72d2b022fb\ntfs.sys
[7] 2013-03-03 . AED552361D97B9C49D51902B70CE713D . 1501032 . . [6.0.6002.23070] .. c:\windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6002.23070_none_04b41183ebc5d73d\ntfs.sys
[7] 2009-04-11 . BAC869DFB98E499BA4D9BB1FB43270E1 . 1515496 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6002.18005_none_047b3e4cd26ad615\ntfs.sys
[7] 2008-01-21 . FE86BA5AC3B50E2CA911E9C60C07B638 . 1540152 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6001.18000_none_028fc540d5490ac9\ntfs.sys
[7] 2013-03-03 . 2ACCAA3C3C55370A32F17B3595E1A217 . 1513320 . . [6.0.6000.16386] .. c:\windows\system32\drivers\ntfs.sys
.
[7] 2006-11-02 . DD5D684975352B85B52E3FD5347C20CB . 6144 . . [6.0.6000.16386] .. c:\windows\winsxs\amd64_microsoft-windows-null_31bf3856ad364e35_6.0.6001.18000_none_05848900d35a7bfd\null.sys
[7] 2006-11-02 . DD5D684975352B85B52E3FD5347C20CB . 6144 . . [6.0.6000.16386] .. c:\windows\system32\drivers\null.sys
.
[7] 2013-07-05 . C2CB949645C299E23FBFD26CAD3FC96E . 1423808 . . [6.0.6002.18880] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18880_none_10ccb5401c2ac785\tcpip.sys
[7] 2013-07-05 . EA8623BDD511A1ACD18DA4883860ADDE . 1417664 . . [6.0.6002.23152] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.23152_none_11789c6b352e7693\tcpip.sys
[7] 2013-05-08 . C7C60777592EEF169A11647AAE7A91C3 . 1423720 . . [6.0.6002.18835] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18835_none_1107c64e1bfdba83\tcpip.sys
[7] 2013-05-08 . 19A5E570048788BE9343FA96C15CEF6F . 1417576 . . [6.0.6002.23106] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.23106_none_11b2ad2f3502503a\tcpip.sys
[7] 2013-01-04 . 0E970F59D7FBB838316176B19A2ADB82 . 1423720 . . [6.0.6002.18764] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18764_none_10e6545a1c16f7d8\tcpip.sys
[7] 2013-01-04 . 2860D16C5021F72130212DDB1C53018F . 1417576 . . [6.0.6002.23013] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.23013_none_11a4da7f350d22ff\tcpip.sys
[7] 2012-03-30 . 46D448E9117464E4D3BBF36D7E3FA48E . 1423744 . . [6.0.6002.18604] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18604_none_112731fc1be6530b\tcpip.sys
[7] 2012-03-30 . AC8D5728E6AD6A7C4819D9A67008337A . 1422720 . . [6.0.6002.22828] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22828_none_119f31fd35108d3a\tcpip.sys
[7] 2010-06-16 . D43D5336BE9DD93E02EE124297295713 . 1414544 . . [6.0.6001.22713] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_0fbe86f737e6a8d6\tcpip.sys
[7] 2010-06-16 . 0011810B5211FDACD784DE585262ECFE . 1424264 . . [6.0.6002.22425] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22425_none_119c298735134c99\tcpip.sys
[7] 2010-06-16 . 973658A2EA9C06B2976884B9046DFC6C . 1426816 . . [6.0.6002.18272] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18272_none_10d97a5c1c20ef58\tcpip.sys
[7] 2010-06-16 . 7D86275FB640011B372FD566C0EAFA8D . 1420176 . . [6.0.6001.18493] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_0ede67001f09ee46\tcpip.sys
[7] 2010-02-18 . 4680D08A2E8A2509CD9B751D7AF59606 . 1414032 . . [6.0.6001.22636] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_0fabe61737f42f96\tcpip.sys
[7] 2010-02-18 . 30C4ABC8075DEA44D7E775D434AF1753 . 1420688 . . [6.0.6001.18427] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18427_none_0f2e179c1ecd900b\tcpip.sys
[7] 2010-02-18 . B4B7B375FDD672AF79B0CBE9B9A48B47 . 1427336 . . [6.0.6002.18209] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18209_none_112c2bd61be1dd22\tcpip.sys
[7] 2010-02-18 . 4AD4600DF1F09EE7462152C061B683C8 . 1423752 . . [6.0.6002.22341] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22341_none_118286a1352721f8\tcpip.sys
[7] 2010-02-18 . 7B0B928E318CADC23C87226BE0A1097D . 1198080 . . [6.0.6000.21226] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21226_none_bc37d12363b92291\tcpip.sys
[7] 2010-02-18 . 396CF3FD8D2A4FDF55570C01894DB9DF . 1200640 . . [6.0.6000.17021] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.17021_none_bba931004aa006ed\tcpip.sys
[7] 2009-08-15 . D4E30E6BADFF21865C3A075457CF9C00 . 1196032 . . [6.0.6000.21108] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21108_none_bc4f6fa963a72036\tcpip.sys
[7] 2009-08-14 . 3BCD46BE9988B09D3510A0EF54F0D65B . 1418840 . . [6.0.6001.18311] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18311_none_0f32e3e61ecadee9\tcpip.sys
[7] 2009-08-14 . 74B776CA1B328095FE23A3306B1613A3 . 1413208 . . [6.0.6001.22497] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_0f6c030d3823f645\tcpip.sys
[7] 2009-08-14 . A7BFF59C2F610F62E6C292074FF36A1E . 1425992 . . [6.0.6002.18091] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18091_none_10c2d66e1c321395\tcpip.sys
[7] 2009-08-14 . D45D67A18C9FD4CC637BC9D4585C0646 . 1424952 . . [6.0.6002.22200] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22200_none_11acc42135079bb6\tcpip.sys
[7] 2009-08-14 . 34B30202AECCB530FDDC6C6CCFA2FB46 . 1200640 . . [6.0.6000.16908] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16908_none_bbc5fabc4a894d2a\tcpip.sys
[7] 2009-05-12 . 8E041924441FF8755E5B4F135C8C3767 . 1421368 . . [6.0.6001.18063] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_0efecf2c1ef1a5d7\tcpip.sys
[7] 2009-05-12 . F10A60005FB50698E33A1940C6EBB010 . 1421368 . . [6.0.6001.22167] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22167_none_0f8c6d1f380baafd\tcpip.sys
[7] 2009-04-11 . 99D07AD0EF2C535610F6573C29BC045E . 1426408 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18005_none_112826e21be57d78\tcpip.sys
[7] 2008-01-21 . 7A1183FBB802F5ABAD7FA18BC67E0858 . 1421368 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18000_none_0f3cadd61ec3b22c\tcpip.sys
[7] 2013-07-05 . C2CB949645C299E23FBFD26CAD3FC96E . 1423808 . . [6.0.6002.18880] .. c:\windows\system32\drivers\tcpip.sys
.
[7] 2009-04-11 . 458919C8C42E398DC4802178D5FFEE27 . 94720 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-tdi-over-tcpip_31bf3856ad364e35_6.0.6002.18005_none_4847dcdb9194e539\tdx.sys
[7] 2008-01-21 . 8C39C72E0E853DE04748C0337D9B9216 . 94208 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-tdi-over-tcpip_31bf3856ad364e35_6.0.6001.18000_none_465c63cf947319ed\tdx.sys
[7] 2009-04-11 . 458919C8C42E398DC4802178D5FFEE27 . 94720 . . [6.0.6002.18005] .. c:\windows\system32\drivers\tdx.sys
.
[7] 2008-01-21 . A1B39DE453433B115B4EA69EE0343816 . 103424 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-browserservice_31bf3856ad364e35_6.0.6001.18000_none_d507c23d565be6a3\browser.dll
[7] 2008-01-21 . A1B39DE453433B115B4EA69EE0343816 . 103424 . . [6.0.6000.16386] .. c:\windows\system32\browser.dll
.
[7] 2012-06-01 . 0688C6F0E5B1E0ADB1E10BF6A9023063 . 11264 . . [6.0.6002.22869] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22869_none_04a16b072b950d95\lsass.exe
[7] 2011-11-16 . 260BF9C43EE12C6898A9F5AAB0FB0E5D . 11264 . . [6.0.6002.18541] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18541_none_042567f8126e70e3\lsass.exe
[7] 2011-11-16 . 260BF9C43EE12C6898A9F5AAB0FB0E5D . 11264 . . [6.0.6002.18541] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18643_none_04276a72126ca0b8\lsass.exe
[7] 2011-11-16 . 54BC2124F6BCF2050D7C3057C0611AD4 . 11264 . . [6.0.6002.22742] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22742_none_04b006f32b8b272b\lsass.exe
[7] 2009-09-10 . 1104B18819392FEA12FB5F9E170E66B3 . 9728 . . [6.0.6000.21125] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_00fbc3d9312b9991\lsass.exe
[7] 2009-09-10 . BBBCE2DACDCCD5EA60A50D0023AE2DE9 . 11264 . . [6.0.6002.22223] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_04c69d972b7a16dd\lsass.exe
[7] 2009-09-09 . 41FB90DF49F203672F459122EF1F13B1 . 11264 . . [6.0.6001.22518] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_02effd0d2e47247b\lsass.exe
[7] 2009-06-15 . 1E766E4C5BF9E230AD37A56BF7DB6C94 . 9728 . . [6.0.6000.21067] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21067_none_00d282d7314a3edc\lsass.exe
[7] 2009-06-15 . 306E4503E083A498AE797FF59FA72839 . 9728 . . [6.0.6000.16870] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16870_none_00373bf8183ad660\lsass.exe
[7] 2009-06-15 . 80F4593E92FF960E4763380D3168E498 . 11264 . . [6.0.6001.18272] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18272_none_021f7b32155f99ff\lsass.exe
[7] 2009-06-15 . 02474FBCB00AA5C622E92F620DB9A041 . 11264 . . [6.0.6001.22450] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22450_none_02bcb9272e6ecc60\lsass.exe
[7] 2009-06-15 . 40348DCEC0712ED42231C5F90A69A690 . 11264 . . [6.0.6002.18051] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18051_none_041a8e8e12769b11\lsass.exe
[7] 2009-06-15 . EBDAEE60E442BEA413E5D7CEDFB09463 . 11264 . . [6.0.6002.22152] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22152_none_04a52ba32b935432\lsass.exe
[7] 2009-02-13 . 1979F94B28107233315DD6220F2304DD . 11264 . . [6.0.6001.22376] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22376_none_02ad19252e799f25\lsass.exe
[7] 2009-02-13 . E231BDBD7D69857EEFFDEB3A48A53824 . 9728 . . [6.0.6000.16820] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16820_none_006d4b9418124aab\lsass.exe
[7] 2009-02-13 . 563B71CEF1D46A24C5980FA2988DB67F . 9728 . . [6.0.6000.21010] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21010_none_0101906d312801c6\lsass.exe
[7] 2008-01-21 . 1B461E9F6DB0EF829B4369F47A24BBEC . 11264 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_026926461528a96c\lsass.exe
[7] 2008-01-21 . 1B461E9F6DB0EF829B4369F47A24BBEC . 11264 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18215_none_02635b98152c3e5e\lsass.exe
[7] 2008-01-21 . 1B461E9F6DB0EF829B4369F47A24BBEC . 11264 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_04549f52124a74b8\lsass.exe
[7] 2011-11-16 . 260BF9C43EE12C6898A9F5AAB0FB0E5D . 11264 . . [6.0.6000.16386] .. c:\windows\system32\lsass.exe
.
[7] 2008-01-21 . 9B63B29DEFC0F3115A559D2597BF5D75 . 348160 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-netman_31bf3856ad364e35_6.0.6001.18000_none_6bdbb71a0a2d4469\netman.dll
[7] 2008-01-21 . 9B63B29DEFC0F3115A559D2597BF5D75 . 348160 . . [6.0.6000.16386] .. c:\windows\system32\netman.dll
.
[7] 2009-04-11 . 6D316F4859634071CC25C4FD4589AD2C . 1081856 . . [7.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6002.18005_none_819ad97caef1480e\qmgr.dll
[7] 2008-01-21 . D896A0D43F8AB81ECB1FC6C24DECFD58 . 1082368 . . [7.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6001.18000_none_7faf6070b1cf7cc2\qmgr.dll
[7] 2009-04-11 . 6D316F4859634071CC25C4FD4589AD2C . 1081856 . . [7.0.6001.18000] .. c:\windows\system32\qmgr.dll
.
[7] 2009-04-11 . CF8B9A3A5E7DC57724A89D0C3E8CF9EF . 719872 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6002.18005_none_c7d4f08bf35f3abe\rpcss.dll
[7] 2009-03-03 . 857E04C16007E60FCC0803239C853E78 . 717824 . . [6.0.6001.22389] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6001.22389_none_c6259b510f93cd21\rpcss.dll
[7] 2009-03-03 . 52CDADE8289FF21F1F2215FF51A5F36C . 718336 . . [6.0.6001.18226] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6001.18226_none_c5d9dd2ff64839ac\rpcss.dll
[7] 2009-03-03 . 007F8DE7AC0F9386C3FD2EC7DC87C37A . 724992 . . [6.0.6000.16830] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6000.16830_none_c3e2cce1f92f2ca2\rpcss.dll
[7] 2009-03-03 . 54FF562C2710BB610B019D723B16FB2A . 724992 . . [6.0.6000.21023] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6000.21023_none_c47a129912422fc2\rpcss.dll
[7] 2008-01-21 . FF27BE0BA7B3C48D5C99AFCB56D436C2 . 713728 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6001.18000_none_c5e9777ff63d6f72\rpcss.dll
[7] 2009-04-11 . CF8B9A3A5E7DC57724A89D0C3E8CF9EF . 719872 . . [6.0.6000.16386] .. c:\windows\system32\rpcss.dll
.
[7] 2009-04-11 . 934E0B7D77FF78C18D9F8891221B6DE3 . 384512 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.exe
[7] 2008-01-21 . DFAC660F0F139276CC9299812DE42719 . 384512 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_2b7e5beb85a67240\services.exe
[7] 2009-04-11 . 934E0B7D77FF78C18D9F8891221B6DE3 . 384512 . . [6.0.6000.16386] .. c:\windows\system32\services.exe
.
[7] 2010-08-17 . 439017BE66398AB809D81B3AE8393883 . 273920 . . [6.0.6002.22468] .. c:\windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6002.22468_none_34a17b8490538c82\spoolsv.exe
[7] 2010-08-17 . F66FF751E7EFC816D266977939EF5DC3 . 273920 . . [6.0.6002.18294] .. c:\windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6002.18294_none_33f36be77751de08\spoolsv.exe
[7] 2010-08-17 . 92E6738D25C2123BE9515C0EAC0776CD . 267776 . . [6.0.6001.18511] .. c:\windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6001.18511_none_3260788179ed5d57\spoolsv.exe
[7] 2010-08-17 . 7F59AA690212241B398D6DBE4071EE3C . 270848 . . [6.0.6001.22743] .. c:\windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6001.22743_none_32cba802932180c9\spoolsv.exe
[7] 2009-04-11 . EADA445EAEDD1D7DF4C5EB42B3612729 . 268288 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6002.18005_none_3455b7b177080198\spoolsv.exe
[7] 2008-01-21 . E6519A9E756D74DC51C697BA62162F51 . 267264 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6001.18000_none_326a3ea579e6364c\spoolsv.exe
[7] 2010-08-17 . F66FF751E7EFC816D266977939EF5DC3 . 273920 . . [6.0.6000.16386] .. c:\windows\system32\spoolsv.exe
.
[7] 2009-04-11 . 6D0773A3A65D28B663F334C90441D01A . 405504 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[7] 2008-01-21 . 856491FCED98093D824B9EB2892F564A . 406016 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[7] 2009-04-11 . 6D0773A3A65D28B663F334C90441D01A . 405504 . . [6.0.6001.18000] .. c:\windows\system32\winlogon.exe
.
[7] 2012-06-02 . C1C03EA437EDDA8A7D4D8786E5AE6751 . 57880 . . [7.6.7600.256] .. c:\windows\winsxs\amd64_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.6.7600.256_none_d5f513f25190f276\wuauclt.exe
[7] 2009-08-07 . 0CAF9B387CC42FC365626003E0751937 . 57560 . . [7.4.7600.226] .. c:\windows\winsxs\amd64_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.4.7600.226_none_4597bdc113f9f351\wuauclt.exe
[7] 2008-01-21 . 44E38EB04F48FCD1D0D230C10A3EED39 . 45568 . . [7.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.0.6001.18000_none_fc7174b1ecdd9336\wuauclt.exe
[7] 2008-01-21 . 44E38EB04F48FCD1D0D230C10A3EED39 . 45568 . . [7.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.0.6002.18005_none_fe5cedbde9ff5e82\wuauclt.exe
[7] 2006-11-02 . 82979850A3E9B7581E28852139EB9D01 . 44032 . . [6.0.6000.16386] .. c:\windows\winsxs\amd64_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_6.0.6000.16386_none_08ca3670650bd993\wuauclt.exe
[7] 2012-06-02 . C1C03EA437EDDA8A7D4D8786E5AE6751 . 57880 . . [7.6.7600.256] .. c:\windows\system32\wuauclt.exe
.
[7] 2013-07-04 . 2E2B796F36C4DA7BDDA70DF95E3D217A . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6002.18879_none_975e94748dabd227\comctl32.dll
[7] 2013-07-04 . 04BE188624096B6D2F8C760940B2D100 . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.18879_none_414ad6405542c1e6\comctl32.dll
[7] 2013-07-04 . 0F00CDCB55EEC73DA4F32331DEA2A0D7 . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6002.23151_none_97f5a8cfa6c09fc0\comctl32.dll
[7] 2013-07-04 . 33EF2E827B1292A5CD06E2E937EE9DE1 . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.23151_none_432a6ae8526f3f0f\comctl32.dll
[7] 2010-09-02 . E5763ED4A35DE72855B731EDF2081B6E . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6002.22480_none_97d4553ba6d9b810\comctl32.dll
[7] 2010-09-02 . 55EAEF6344C328416969AA1622100139 . 2050048 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.22480_none_fe44c5cb0dae9066\comctl32.dll
[7] 2010-09-02 . F80C6985B787E40EB2B6B99A453A243A . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.22480_none_432d25ac526cda7f\comctl32.dll
[7] 2010-09-01 . EB00FFCBB31A4CA35F80D92F14CBF04B . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6001.22755_none_96135489a9968dcc\comctl32.dll
[7] 2010-09-01 . CA41B0BFB677D1261E68EA138CE106C2 . 2050048 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.22755_none_fe655b750d60b18a\comctl32.dll
[7] 2010-09-01 . 16C1CC7E5B6A5B6A21C368D39DC4B03F . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.22755_none_42a7622b394b8efb\comctl32.dll
[7] 2010-08-31 . 74ABE02BF1937B32C6FC169A782FCF60 . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6002.18305_none_97a639428d76b771\comctl32.dll
[7] 2010-08-31 . 46662CD685A6341AB4AED86D134D80E9 . 2050048 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd\comctl32.dll
[7] 2010-08-31 . 09451F87CFF73FF22D9479FB0A73861C . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.18305_none_41466cae55469b30\comctl32.dll
[7] 2010-08-31 . 058BE5961AC5D6ACFD1961C2471F61B5 . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6001.18523_none_95a8250890626a5a\comctl32.dll
[7] 2010-08-31 . 6D98A7638947F0C9DAB31F094A591795 . 2049024 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_15302f0af3bbd1ec\comctl32.dll
[7] 2010-08-31 . F39DFA95BC391B166B40F4E38E5F1223 . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18523_none_40bf29b13c26ca69\comctl32.dll
[7] 2009-04-11 . 94B60C9A7AEE8A9F3C1028F8DC5CED41 . 2050048 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da\comctl32.dll
[7] 2008-01-21 . BD3133E6B73195A95C67F7B09E012DE0 . 2049024 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_152e7382f3bd50c6\comctl32.dll
[7] 2008-01-21 . 67DA61D3B12CEB5A4C86646AB468F0BA . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6001.18000_none_95baba849054f4b0\comctl32.dll
[7] 2008-01-21 . 23797D89BE03772F411E387A3C81DBF8 . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_40ba501d3c2b20ff\comctl32.dll
[7] 2006-11-02 . C6FFCA00D8C81D66C4194378EFF34199 . 2017792 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_1559f1c6f365a7fa\comctl32.dll
[7] 2006-11-02 . E47109C2D7D95962D08C9FD061A9BAD3 . 629248 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_40339432230aebeb\comctl32.dll
[7] 2013-07-04 . 2E2B796F36C4DA7BDDA70DF95E3D217A . 633856 . . [5.82] .. c:\windows\system32\comctl32.dll
.
[7] 2008-01-21 . DDEE5FE5C3C3141CE02DE6B7B2BF686B . 1291264 . . [2001.12.6931.18000] .. c:\windows\winsxs\amd64_microsoft-windows-com-complus.res_31bf3856ad364e35_6.0.6001.18000_none_88cf765b9e8f4a59\comres.dll
[7] 2008-01-21 . DDEE5FE5C3C3141CE02DE6B7B2BF686B . 1291264 . . [2001.12.6930.16386] .. c:\windows\system32\comres.dll
.
[7] 2013-10-03 . 66C5431A70C1EA482819DA8AB5B7D274 . 177664 . . [6.0.6002.23235] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23235_none_d472c619698494d0\cryptsvc.dll
[7] 2013-07-08 . 5AAC48EAF8EACF247DB44FB61B900D89 . 174592 . . [6.0.6002.18881] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18881_none_d3af3c9c5092edcf\cryptsvc.dll
[7] 2013-07-08 . C848E7E63A1A56F092AF5C6032048BD6 . 177664 . . [6.0.6002.23154] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23154_none_d45c24116995b634\cryptsvc.dll
[7] 2013-04-24 . 1B22BC0B71F65001479DAB792C3F626C . 174592 . . [6.0.6002.18831] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18831_none_d3e54c38506a621a\cryptsvc.dll
[7] 2013-04-24 . F47B316D81160CB2A0BC5F87046B6EFE . 177664 . . [6.0.6002.23101] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23101_none_d48f32cf696fde7a\cryptsvc.dll
[7] 2013-04-17 . 6D151DA5731286E52FD2D40DCB8623DB . 174592 . . [6.0.6002.18827] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18827_none_d3f61de0505cde33\cryptsvc.dll
[7] 2013-04-17 . F4F2EB4634C783874EFA0516BF3D088F . 177664 . . [6.0.6002.23097] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23097_none_d433e35969b374d6\cryptsvc.dll
[7] 2012-06-02 . CA78B312C44E4D52E842C2C8BD48E452 . 174592 . . [6.0.6002.18643] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18643_none_d3dc79145070b66b\cryptsvc.dll
[7] 2012-06-01 . 256B8B96B83AEA5213EE90782446DA38 . 177664 . . [6.0.6002.22869] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.22869_none_d45679a969992348\cryptsvc.dll
[7] 2012-04-23 . 62740B9D2A137E8CED41A9E4239A7A31 . 174592 . . [6.0.6002.18618] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18618_none_d401ea4a5053e14b\cryptsvc.dll
[7] 2012-04-23 . DD9C01648A6455278A441775CA59E2FD . 177664 . . [6.0.6002.22840] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.22840_none_d46316e769910757\cryptsvc.dll
[7] 2009-04-11 . 18918613E63F387CDE4D95CA7D49DCF7 . 166912 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18005_none_d409adf4504e8a6b\cryptsvc.dll
[7] 2008-01-21 . 4374F784121D8B3BB466B03F5E5EBD33 . 165376 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_d21e34e8532cbf1f\cryptsvc.dll
[7] 2013-07-08 . 5AAC48EAF8EACF247DB44FB61B900D89 . 174592 . . [6.0.6000.16386] .. c:\windows\system32\cryptsvc.dll
.
[7] 2009-05-12 . 1782416278B378F80862187EEBC0A51C . 361472 . . [2001.12.6930.16677] .. c:\windows\winsxs\amd64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6000.16677_none_66e14e8d0d26f566\es.dll
[7] 2009-05-12 . 7143F5F8D7FF0712B6D2F336495554FE . 361472 . . [2001.12.6930.20818] .. c:\windows\winsxs\amd64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6000.20818_none_67accd1026130408\es.dll
[7] 2009-05-12 . 6B1A97BF9FEFBDC83F3C7C7D0F826C66 . 361984 . . [2001.12.6931.18057] .. c:\windows\winsxs\amd64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.18057_none_68dd2d0b0a3d4e75\es.dll
[7] 2009-05-12 . AE5538074DF0BB8EE5A3ECB9F5460965 . 361984 . . [2001.12.6931.22162] .. c:\windows\winsxs\amd64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.22162_none_6956f87823678b7d\es.dll
[7] 2009-04-11 . E12F22B73F153DECE721CD45EC05B4AF . 361984 . . [2001.12.6932.18005] .. c:\windows\winsxs\amd64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6002.18005_none_6af7b3ad073cdcab\es.dll
[7] 2008-01-21 . D8338E6B3C23AD36096A6FDABD039283 . 354304 . . [2001.12.6931.18000] .. c:\windows\winsxs\amd64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.18000_none_690c3aa10a1b115f\es.dll
[7] 2009-04-11 . E12F22B73F153DECE721CD45EC05B4AF . 361984 . . [2001.12.6932.18005] .. c:\windows\system32\es.dll
.
[7] 2009-04-11 . 62C15795629FA290656C6A7E5CD25F52 . 163840 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.0.6002.18005_none_ba6032a62fea3984\imm32.dll
[7] 2008-01-21 . 8D2C00D198598AAE77B1648FFBF39895 . 163840 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.0.6001.18000_none_b874b99a32c86e38\imm32.dll
[7] 2009-04-11 . 62C15795629FA290656C6A7E5CD25F52 . 163840 . . [6.0.6002.18005] .. c:\windows\system32\imm32.dll
.
[7] 2010-04-16 . 1795848538EA2328648E9FAB31351157 . 622080 . . [1.0626.6002.22384] .. c:\windows\winsxs\amd64_microsoft-windows-usp_31bf3856ad364e35_6.0.6002.22384_none_0b36ae8b275afcf9\usp10.dll
[7] 2010-04-16 . 11EAF90B44A9E378CB6F4ECBF2471F60 . 621568 . . [1.0626.6002.18244] .. c:\windows\winsxs\amd64_microsoft-windows-usp_31bf3856ad364e35_6.0.6002.18244_none_0ad851700e1ced6b\usp10.dll
[7] 2010-04-16 . 718AA06AE8741F8C7877C25F4AD97280 . 622080 . . [1.0626.6001.18461] .. c:\windows\winsxs\amd64_microsoft-windows-usp_31bf3856ad364e35_6.0.6001.18461_none_08d93cec110986fd\usp10.dll
[7] 2010-04-16 . EB7E9B4E65D014EF958330C3E55735DD . 622592 . . [1.0626.6001.22672] .. c:\windows\winsxs\amd64_microsoft-windows-usp_31bf3856ad364e35_6.0.6001.22672_none_09590bfb2a2e5936\usp10.dll
[7] 2009-04-11 . 6C7812812F7F343100EA655DC26C9888 . 621568 . . [1.0626.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-usp_31bf3856ad364e35_6.0.6002.18005_none_0b048d9e0dfb9cb0\usp10.dll
[7] 2008-01-21 . 8745227FAB62C0886B4B122CAD1D799E . 622080 . . [1.0626.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-usp_31bf3856ad364e35_6.0.6001.18000_none_0919149210d9d164\usp10.dll
[7] 2010-04-16 . 11EAF90B44A9E378CB6F4ECBF2471F60 . 621568 . . [1.0626.6002.18244] .. c:\windows\system32\usp10.dll
.
[7] 2012-09-28 . A02EB771DAE80667E3C877CF19E3F6EE . 1210368 . . [6.0.6002.18704] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6002.18704_none_f1c706d10bcb97ea\kernel32.dll
[7] 2012-09-28 . 53864C438B27EAC653D35F8ACF0A17FC . 1211904 . . [6.0.6002.22942] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6002.22942_none_f223653e250b71f1\kernel32.dll
[7] 2011-04-12 . 2299078C1E59FE69ADDF49897D6A373A . 1210880 . . [6.0.6002.18449] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6002.18449_none_f1a0c2e10be78eec\kernel32.dll
[7] 2011-04-12 . F2338C94CDCD7AD28A14428D46A05D0B . 1211904 . . [6.0.6002.22625] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6002.22625_none_f23c004224f88e9f\kernel32.dll
[7] 2011-04-12 . 6ADB508FEADBDEC41C194B4C03FA5201 . 1208832 . . [6.0.6001.18631] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18631_none_efbd1caf0ec055f8\kernel32.dll
[7] 2011-04-12 . 777DF7F47BEE82833E324F0EB18B7ED1 . 1213440 . . [6.0.6001.22898] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.22898_none_f00cddde28084bf0\kernel32.dll
[7] 2009-04-11 . A1489655AB04BBB5290C3FC274D33E57 . 1217536 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6002.18005_none_f1c7f9d10bcac530\kernel32.dll
[7] 2009-02-13 . 8331C9E592358DE5157169699BD836D7 . 1208832 . . [6.0.6001.18215] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18215_none_efd6b6170eac8ed6\kernel32.dll
[7] 2009-02-13 . 2EEE45C483BA534A84CACC9D8001FE0E . 1210880 . . [6.0.6001.22376] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.22376_none_f02073a427f9ef9d\kernel32.dll
[7] 2009-02-13 . 1A5CE3CDE414ED758D4E1616F422C20B . 1233408 . . [6.0.6000.16820] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.16820_none_ede0a61311929b23\kernel32.dll
[7] 2009-02-13 . 08E8EF6A8D18BD1D89896903DCD103D2 . 1233920 . . [6.0.6000.21010] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.21010_none_ee74eaec2aa8523e\kernel32.dll
[7] 2008-01-21 . 1122C8BE4BC4F392598A9543DC1014E0 . 1213952 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18000_none_efdc80c50ea8f9e4\kernel32.dll
[7] 2012-09-28 . A02EB771DAE80667E3C877CF19E3F6EE . 1210368 . . [6.0.6001.18000] .. c:\windows\system32\kernel32.dll
.
[7] 2008-01-21 . 8BDE3074EE7BB92030448419E33635C7 . 29184 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-linkinfo_31bf3856ad364e35_6.0.6001.18000_none_9483cda05db182e8\linkinfo.dll
[7] 2008-01-21 . 8BDE3074EE7BB92030448419E33635C7 . 29184 . . [6.0.6001.18000] .. c:\windows\system32\linkinfo.dll
.
[7] 2013-06-04 . B70E66A6B5ACF14AEAE3B52D8739D1C6 . 32768 . . [6.0.6002.23132] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.23132_none_08434269293e5b07\lpk.dll
[7] 2012-12-16 . 29BC2630B5E1A782F7C1A765F6641E39 . 32768 . . [6.0.6002.23004] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.23004_none_0865b0db29243cbb\lpk.dll
[7] 2011-02-16 . C95E1180E721401CE923FD4381216F45 . 32768 . . [6.0.6002.22589] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22589_none_0814533329607318\lpk.dll
[7] 2011-02-16 . EBADCE0742E19CAE2F1FE37D12AE9512 . 32768 . . [6.0.6001.22854] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22854_none_06494f9d2c264b6e\lpk.dll
[7] 2009-10-19 . 35E625ED9FE3A7F29CA7694BA02AEA7B . 32768 . . [6.0.6001.22544] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22544_none_065419d72c1e3808\lpk.dll
[7] 2009-10-19 . 96975D0384839E4FA2BE137B0F386ADA . 33280 . . [6.0.6000.21142] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21142_none_046bb0d92ef9aa84\lpk.dll
[7] 2009-10-19 . B96C6EA864956C49B8426ED10340C772 . 33280 . . [6.0.6000.16939] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16939_none_03f40dde15cd6ce8\lpk.dll
[7] 2009-10-19 . B9A0B9E32F7AB5717A9CEC1B4DC05C62 . 32768 . . [6.0.6002.22247] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22247_none_083d8c9d2941d931\lpk.dll
[7] 2008-01-21 . 891E1D0DCDE747C8F1EE71E61EA193F5 . 32768 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18000_none_05f1b3fc12e3ce82\lpk.dll
[7] 2008-01-21 . 891E1D0DCDE747C8F1EE71E61EA193F5 . 32768 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18344_none_05ca7b2613009b17\lpk.dll
[7] 2008-01-21 . 891E1D0DCDE747C8F1EE71E61EA193F5 . 32768 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18599_none_059970c813249fcd\lpk.dll
[7] 2008-01-21 . 891E1D0DCDE747C8F1EE71E61EA193F5 . 32768 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18005_none_07dd2d08100599ce\lpk.dll
[7] 2008-01-21 . 891E1D0DCDE747C8F1EE71E61EA193F5 . 32768 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18124_none_07c68ecc1016b580\lpk.dll
[7] 2008-01-21 . 891E1D0DCDE747C8F1EE71E61EA193F5 . 32768 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18405_none_07dd34a010058e6a\lpk.dll
[7] 2008-01-21 . 891E1D0DCDE747C8F1EE71E61EA193F5 . 32768 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18725_none_07c79a7a1015bdc1\lpk.dll
[7] 2008-01-21 . 891E1D0DCDE747C8F1EE71E61EA193F5 . 32768 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18755_none_07a72ab6102e1194\lpk.dll
[7] 2008-01-21 . 891E1D0DCDE747C8F1EE71E61EA193F5 . 32768 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18861_none_07985b881039c550\lpk.dll
[7] 2008-01-21 . 891E1D0DCDE747C8F1EE71E61EA193F5 . 32768 . . [6.0.6001.18000] .. c:\windows\system32\lpk.dll
.
[7] 2008-01-21 . D23E5184266747DDCE9D0C6581D916B3 . 433664 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-i..ectionsharingconfig_31bf3856ad364e35_6.0.6001.18000_none_0c54e1384cf6f7c7\hnetcfg.dll
[7] 2008-01-21 . D23E5184266747DDCE9D0C6581D916B3 . 433664 . . [6.0.6000.16386] .. c:\windows\system32\hnetcfg.dll
.
[7] 2013-10-13 . 1CFBE5D5844FDB11E1589BC74260FBB4 . 17847296 . . [9.00.8112.16520] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16520_none_2f53eaac186c1634\mshtml.dll
[7] 2013-10-13 . 65A4309620ABFDF28CF94127930BB0E7 . 17847296 . . [9.00.8112.20631] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20631_none_2fd3b7d53190eb46\mshtml.dll
[7] 2013-09-22 . 88664D38A94CDBD372ABB617E2928C37 . 17833984 . . [9.00.8112.16514] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16514_none_2f62bbc018605f9f\mshtml.dll
[7] 2013-09-22 . 446C4A7C199224815CDD280F281E8253 . 17835008 . . [9.00.8112.20625] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20625_none_2fe288e9318534b1\mshtml.dll
[7] 2013-07-31 . DA908B28F07804BD648756B8FFAE9305 . 17833472 . . [9.00.8112.16506] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16506_none_2f6f8c401856765c\mshtml.dll
[7] 2013-07-31 . 8D29405AC33ED98ADE0DF26151FF7C89 . 17834496 . . [9.00.8112.20617] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20617_none_2fef5969317b4b6e\mshtml.dll
[7] 2013-07-25 . EEC97B8A669093E4797ECD0B56DFEC51 . 17832960 . . [9.00.8112.20613] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20613_none_2feb5841317ee612\mshtml.dll
[7] 2013-07-25 . 7D9371E3C8CF927D0A2A1D9E1161C324 . 17830400 . . [9.00.8112.16502] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16502_none_2f6b8b18185a1100\mshtml.dll
[7] 2013-05-29 . 34426D52FBA4F3E31739DB840D2601AD . 17829376 . . [9.00.8112.16496] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16496_none_2f0e3b0e189f74ae\mshtml.dll
[7] 2013-05-29 . 04EFE9DFE4F0318DED06B47479026706 . 17831424 . . [9.00.8112.20606] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20606_none_2ff9290b31741626\mshtml.dll
[7] 2013-05-17 . A820869140978CCAF33CF7770EEE19F5 . 17824768 . . [9.00.8112.16490] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16490_none_2f08395218a4dca4\mshtml.dll
[7] 2013-05-17 . CD451FEE119B7557633039CA39290331 . 17824768 . . [9.00.8112.20600] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20600_none_2ff3274f31797e1c\mshtml.dll
[7] 2013-05-05 . E139A28843F52F383D414BF0AAEF6CE4 . 17819136 . . [9.00.8112.20594] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20594_none_2f95d74531bee1ca\mshtml.dll
[7] 2013-05-05 . 7212340908E00AD2F28E58EA04CEB852 . 17818624 . . [9.00.8112.16484] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16484_none_2f170a661899260f\mshtml.dll
[7] 2013-04-05 . F63D8615292792D36EDF24913636685D . 17818624 . . [9.00.8112.16483] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16483_none_2f160a1c189a0cb8\mshtml.dll
[7] 2013-04-05 . 43FEF944FF64BE0354A5C129C98EB13D . 17818624 . . [9.00.8112.20593] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20593_none_2f94d6fb31bfc873\mshtml.dll
[7] 2013-02-22 . 0E860BF2BCDDD94202A6AB9A10EE95EB . 17817600 . . [9.00.8112.20586] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20586_none_2fa2a7c531b4f887\mshtml.dll
[7] 2013-02-22 . 1154FEFC73880A2EF44295EF0DBDC59F . 17817088 . . [9.00.8112.16476] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16476_none_2f23dae6188f3ccc\mshtml.dll
[7] 2013-02-02 . 1CD82D510D370CB04BB6BD1C660AA96F . 17815040 . . [9.00.8112.20580] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20580_none_2f9ca60931ba607d\mshtml.dll
[7] 2013-02-02 . 460723A080D6F22E56D45BC8C1F15B2A . 17815040 . . [9.00.8112.16470] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16470_none_2f1dd92a1894a4c2\mshtml.dll
[7] 2013-01-09 . 14DEB733ACB08A71CC0783ED02FF1F8D . 17812992 . . [9.00.8112.16464] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16464_none_2f2caa3e1888ee2d\mshtml.dll
[7] 2013-01-09 . B6C5BC6D4E1D79CB8DF107112A9F37CB . 17814528 . . [9.00.8112.20573] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20573_none_2faa76d331af9091\mshtml.dll
[7] 2012-11-14 . CFF3C4ABDCC5356B0674743BDF0FB674 . 17811968 . . [9.00.8112.16457] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16457_none_2f3a7b08187e1e41\mshtml.dll
[7] 2012-11-14 . 5024CACD183E4C0FCCDE6DB8A38EEC7B . 17811968 . . [9.00.8112.20565] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20565_none_2fb7475331a5a74e\mshtml.dll
[7] 2012-10-04 . 4CBD0521FD359BAFC01F0BA60CB66197 . 17811968 . . [9.00.8112.16455] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16455_none_2f387a74187feb93\mshtml.dll
[7] 2012-10-04 . 0669C8FC9DE682F831C947E391670815 . 17812992 . . [9.00.8112.20562] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20562_none_2fb4467531a85b49\mshtml.dll
[7] 2012-08-24 . F244DA6DD2C365ABAFD076222C22C2BE . 17810944 . . [9.00.8112.16450] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16450_none_2f33790218846ce0\mshtml.dll
[7] 2012-08-24 . 522A528C296A9AEF3F0C289FF7093315 . 17810944 . . [9.00.8112.20557] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20557_none_2fc417d3319bbe0b\mshtml.dll
[7] 2012-06-28 . 864DFCF19D99711E6449255DD1F4F2B0 . 17809920 . . [9.00.8112.16448] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16448_none_2f464b3e18751ba7\mshtml.dll
[7] 2012-06-28 . 994C146724EB4EE8ABF14B3DEDDBC25D . 17809920 . . [9.00.8112.20554] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20554_none_2fc116f5319e7206\mshtml.dll
[7] 2012-06-02 . 89C4B3BF66D3C2F3D83F9DEDF1B218D6 . 17807360 . . [9.00.8112.16447] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16447_none_2f454af418760250\mshtml.dll
[7] 2012-06-02 . 0C26F50D6C347CE294C84347E6FAEAA8 . 17807360 . . [9.00.8112.20553] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20553_none_2fc016ab319f58af\mshtml.dll
[7] 2012-05-18 . DE469470D93DEB4A1A81EDE72B848198 . 17807360 . . [9.00.8112.16446] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16446_none_2f444aaa1876e8f9\mshtml.dll
[7] 2012-05-18 . BE1E4779329040ED334651CD877C416D . 17807360 . . [9.00.8112.20551] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20551_none_2fbe161731a12601\mshtml.dll
[7] 2012-05-16 . E61288581AD9E647ABEFB1489B250B5C . 17790464 . . [9.00.8112.16441] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16441_none_2f3f4938187b6a46\mshtml.dll
[7] 2012-02-28 . 2E39D547A0EBB0B978571CB77956559C . 5722624 . . [7.00.6002.22805] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.22805_none_71d6d140f0c64379\mshtml.dll
[7] 2012-02-28 . D5397ACF0C56F7F4A68859555475AAB0 . 5720064 . . [7.00.6002.18591] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.18591_none_70e7e035d7f53f7e\mshtml.dll
[7] 2013-10-13 . 1CFBE5D5844FDB11E1589BC74260FBB4 . 17847296 . . [9.00.8112.16421] .. c:\windows\system32\mshtml.dll
.
[7] 2011-12-14 . 2C74308C8A20F3F3A2226DFE36914CBF . 621056 . . [7.0.6002.18551] .. c:\windows\winsxs\amd64_microsoft-windows-msvcrt_31bf3856ad364e35_6.0.6002.18551_none_2f25436a5491724b\msvcrt.dll
[7] 2011-12-14 . 4B2F10ED918CA8B29A04B8B1B34D9349 . 621056 . . [7.0.6002.22755] .. c:\windows\winsxs\amd64_microsoft-windows-msvcrt_31bf3856ad364e35_6.0.6002.22755_none_2fb2e3436dab7498\msvcrt.dll
[7] 2009-04-11 . 37B71108BFD6E276695CE24171F2889B . 621056 . . [7.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-msvcrt_31bf3856ad364e35_6.0.6002.18005_none_2f5f4ab054655a2f\msvcrt.dll
[7] 2008-01-21 . 11DB261E8EE318CA41498300327CB5F2 . 621056 . . [7.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-msvcrt_31bf3856ad364e35_6.0.6001.18000_none_2d73d1a457438ee3\msvcrt.dll
[7] 2011-12-14 . 2C74308C8A20F3F3A2226DFE36914CBF . 621056 . . [7.0.6002.18551] .. c:\windows\system32\msvcrt.dll
.
[7] 2009-04-11 . BB08D93011B82883EC33C7707A9627BE . 304128 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.0.6002.18005_none_165d6b95e2cafb10\mswsock.dll
[7] 2008-01-21 . 66306D7E90650EBE667811C1AF010BAC . 304128 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.0.6001.18000_none_1471f289e5a92fc4\mswsock.dll
[7] 2009-04-11 . BB08D93011B82883EC33C7707A9627BE . 304128 . . [6.0.6000.16386] .. c:\windows\system32\mswsock.dll
.
[7] 2009-04-11 . A3F1B171702CA04744EE514243B45BFB . 717312 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[7] 2008-01-21 . 5D0A4891F8CD0E9E64FF57A6A34044F5 . 716800 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[7] 2009-04-11 . A3F1B171702CA04744EE514243B45BFB . 717312 . . [6.0.6001.18000] .. c:\windows\system32\netlogon.dll
.
[7] 2009-04-11 . 7823A58BF0FE3CAAA555C12B5CF91290 . 123392 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-userpowermanagement_31bf3856ad364e35_6.0.6002.18005_none_0123b2f0b2579bf3\powrprof.dll
[7] 2008-01-21 . 6FF12A84BDBA50AFE7FCF3A524E14B71 . 121344 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-userpowermanagement_31bf3856ad364e35_6.0.6001.18000_none_ff3839e4b535d0a7\powrprof.dll
[7] 2009-04-11 . 7823A58BF0FE3CAAA555C12B5CF91290 . 123392 . . [6.0.6001.18000] .. c:\windows\system32\powrprof.dll
.
[7] 2009-04-11 . 9922ADB6DCA8F0F5EA038BEFF339C08B . 235520 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
[7] 2008-01-21 . 35F1DD99F9903BC267C2AF16B09F9BF7 . 235520 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[7] 2009-04-11 . 9922ADB6DCA8F0F5EA038BEFF339C08B . 235520 . . [6.0.6000.16386] .. c:\windows\system32\scecli.dll
.
[7] 2006-11-02 . 2CCA759379C220D29F0066CA49E9259F . 6144 . . [6.0.6000.16386] .. c:\windows\winsxs\amd64_microsoft-windows-sfc_31bf3856ad364e35_6.0.6001.18000_none_03545ed0148f16ae\sfc.dll
[7] 2006-11-02 . 2CCA759379C220D29F0066CA49E9259F . 6144 . . [6.0.6000.16386] .. c:\windows\system32\sfc.dll
.
[7] 2008-01-21 . CDA9F1373805AF88F6FA4F2064BBA24D . 27648 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_11d9f524bdab2f1b\svchost.exe
[7] 2008-01-21 . CDA9F1373805AF88F6FA4F2064BBA24D . 27648 . . [6.0.6000.16386] .. c:\windows\system32\svchost.exe
.
[7] 2009-04-11 . CC2562B4D55E0B6A4758C65407F63B79 . 318976 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-tapiservice_31bf3856ad364e35_6.0.6002.18005_none_4146ed6b9a71d501\tapisrv.dll
[7] 2008-01-21 . 52091001CAF20AE84CF47023EE21B4BB . 318464 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-tapiservice_31bf3856ad364e35_6.0.6001.18000_none_3f5b745f9d5009b5\tapisrv.dll
[7] 2009-04-11 . CC2562B4D55E0B6A4758C65407F63B79 . 318976 . . [6.0.6000.16386] .. c:\windows\system32\tapisrv.dll
.
[7] 2009-04-11 . F3F5549E69AE8509342E67E4F972CA1C . 820224 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_2b4280d122dbbbb4\user32.dll
[7] 2008-01-21 . 32B87D215905F648EBE36A621978442C . 820224 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_295707c525b9f068\user32.dll
[7] 2009-04-11 . F3F5549E69AE8509342E67E4F972CA1C . 820224 . . [6.0.6001.18000] .. c:\windows\system32\user32.dll
.
[7] 2008-01-21 . A0AB2BB9A92293D9CE66E252719AB5FE . 28160 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
[7] 2008-01-21 . A0AB2BB9A92293D9CE66E252719AB5FE . 28160 . . [6.0.6000.16386] .. c:\windows\system32\userinit.exe
.
[7] 2013-10-13 . C4AA30C01694001B8374CC62BF9AE6FF . 1392128 . . [9.00.8112.16520] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16520_none_1df9cb8d9815acfe\wininet.dll
[7] 2013-10-13 . 732555988D4CC24CBAE268FDD09B0D6F . 1392640 . . [9.00.8112.20631] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20631_none_1e7998b6b13a8210\wininet.dll
[7] 2013-09-22 . 3CD6F07E6416ED6E18A1965CD2B9144A . 1392128 . . [9.00.8112.16514] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16514_none_1e089ca19809f669\wininet.dll
[7] 2013-09-22 . D9BE2BD72318B7E8E030195112D4333B . 1392640 . . [9.00.8112.20625] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20625_none_1e8869cab12ecb7b\wininet.dll
[7] 2013-07-31 . 75F110F4005DAE430AECA787FDEA9CBB . 1392128 . . [9.00.8112.16506] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16506_none_1e156d2198000d26\wininet.dll
[7] 2013-07-31 . 3B45760D1548C258F56E804328E3BC9B . 1392640 . . [9.00.8112.20617] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20617_none_1e953a4ab124e238\wininet.dll
[7] 2013-07-25 . EF560100034BF6C78A979BBB0FF9641C . 1392640 . . [9.00.8112.20613] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20613_none_1e913922b1287cdc\wininet.dll
[7] 2013-07-25 . CA87556BBA37D1B4F67C331186618673 . 1392128 . . [9.00.8112.16502] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16502_none_1e116bf99803a7ca\wininet.dll
[7] 2013-05-29 . 5536F6E7B74DA37D3EDBB509DE9CE3F5 . 1392128 . . [9.00.8112.16496] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16496_none_1db41bef98490b78\wininet.dll
[7] 2013-05-29 . 6B1D554302FB8A5601D972177D7A866D . 1392640 . . [9.00.8112.20606] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20606_none_1e9f09ecb11dacf0\wininet.dll
[7] 2013-05-17 . 4FBE96D97A1E070A06F76F67255C756D . 1392128 . . [9.00.8112.16490] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16490_none_1dae1a33984e736e\wininet.dll
[7] 2013-05-17 . 5548A99796DB5DDAA32ED9B53BC3AADC . 1392640 . . [9.00.8112.20600] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20600_none_1e990830b12314e6\wininet.dll
[7] 2013-04-05 . 563C71A913CAC0C3DE5FFCD36EDB43A0 . 1392128 . . [9.00.8112.16483] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16483_none_1dbbeafd9843a382\wininet.dll
[7] 2013-04-04 . 7FD2D2BE22F9A319AB2FD23DD2C9968A . 1392640 . . [9.00.8112.20593] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20593_none_1e3ab7dcb1695f3d\wininet.dll
[7] 2013-02-22 . E6A459C8E90C4A873C923C44F3D9510B . 1392640 . . [9.00.8112.20586] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20586_none_1e4888a6b15e8f51\wininet.dll
[7] 2013-02-22 . A4F6142CABA82FB7293ECE5FF864B440 . 1392128 . . [9.00.8112.16476] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16476_none_1dc9bbc79838d396\wininet.dll
[7] 2013-02-02 . 4E0669B513805A7C2A303C8EDEDC8E03 . 1392128 . . [9.00.8112.20580] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20580_none_1e4286eab163f747\wininet.dll
[7] 2013-02-02 . FA274190682AA41A46B285208ED46A74 . 1392128 . . [9.00.8112.16470] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16470_none_1dc3ba0b983e3b8c\wininet.dll
[7] 2013-01-09 . 435E9C764E1EF70058580996452BE6A2 . 1392128 . . [9.00.8112.16464] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16464_none_1dd28b1f983284f7\wininet.dll
[7] 2013-01-08 . 43A6A68F1F41B13CA4D580D40DFA57EE . 1392128 . . [9.00.8112.20573] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20573_none_1e5057b4b159275b\wininet.dll
[7] 2012-11-14 . 5121DB613E10A46A3C5085B479026AA7 . 1392128 . . [9.00.8112.16457] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16457_none_1de05be99827b50b\wininet.dll
[7] 2012-11-14 . 5CAF48F12E8CBD96D520F4EFD5B97F76 . 1392128 . . [9.00.8112.20565] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20565_none_1e5d2834b14f3e18\wininet.dll
[7] 2012-10-04 . 78ECC235E21DF618234E5CC451E1DBBB . 1392128 . . [9.00.8112.16455] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16455_none_1dde5b559829825d\wininet.dll
[7] 2012-10-04 . 40E71E30D6FCFC01AC58C6C4F2578357 . 1392128 . . [9.00.8112.20562] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20562_none_1e5a2756b151f213\wininet.dll
[7] 2012-08-24 . 3D165C53E40236A68B7102D1A622D4E0 . 1392128 . . [9.00.8112.16450] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16450_none_1dd959e3982e03aa\wininet.dll
[7] 2012-08-24 . 456D4E9006DF149C250D40B813290471 . 1392128 . . [9.00.8112.20557] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20557_none_1e69f8b4b14554d5\wininet.dll
[7] 2012-06-28 . 807CAA713A27CDF8ABE91BC367DBB269 . 1392128 . . [9.00.8112.16448] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16448_none_1dec2c1f981eb271\wininet.dll
[7] 2012-06-28 . 7BE278BB0CC3DF017DEC2610D1EA228A . 1392128 . . [9.00.8112.20554] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20554_none_1e66f7d6b14808d0\wininet.dll
[7] 2012-06-02 . 5A45FA344F4AD99D903F4B20E43B89EC . 1392128 . . [9.00.8112.16447] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16447_none_1deb2bd5981f991a\wininet.dll
[7] 2012-06-02 . 571E809181EBF0A04FEFAA9BC9961F5B . 1392128 . . [9.00.8112.20553] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20553_none_1e65f78cb148ef79\wininet.dll
[7] 2012-05-18 . 870ECFEBD41C7B8F9C6777748368D51F . 1392128 . . [9.00.8112.16446] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16446_none_1dea2b8b98207fc3\wininet.dll
[7] 2012-05-18 . BDC16D105BF011D4B1C3F09CF7A64314 . 1392128 . . [9.00.8112.20551] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20551_none_1e63f6f8b14abccb\wininet.dll
[7] 2012-05-16 . B1AC85B6ADC005CF3F9EB4E28DFDCCE6 . 1390080 . . [9.00.8112.16441] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16441_none_1de52a1998250110\wininet.dll
[7] 2012-02-28 . BA06B1D2A5F6BB9B6BB88C44216FF41A . 1041408 . . [7.00.6002.22805] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22805_none_607cb222706fda43\wininet.dll
[7] 2012-02-28 . 9BCDB46B79691B239DCE0B8DBE4EF477 . 1032192 . . [7.00.6002.18591] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18591_none_5f8dc117579ed648\wininet.dll
[7] 2012-02-28 . 228443FF3A1FB0B974D278F7C6403FAD . 1390080 . . [9.00.8112.16443] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16443_none_1de72aad982333be\wininet.dll
[7] 2012-02-28 . B70CDC073F70E6D082A62AB5880D6B07 . 1390080 . . [9.00.8112.20548] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20548_none_1e75c8eab13c523b\wininet.dll
[7] 2011-04-21 . 29B0AB34A243558E6FDBA15442CFB744 . 1032192 . . [7.00.6002.18457] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18457_none_5fbf009d57790167\wininet.dll
[7] 2011-04-21 . 70BC625F25EDE67FFD655916A3F3A103 . 1032704 . . [7.00.6001.18639] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18639_none_5df02d3b5a40a9e8\wininet.dll
[7] 2011-04-21 . CCA3226A7921EB080E359C1AE63CABDB . 1041408 . . [7.00.6002.22629] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22629_none_606b0fa6707c7d33\wininet.dll
[7] 2011-04-21 . 28D6C1B66F511E25B0CB62E716C12C47 . 1041920 . . [7.00.6001.22905] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22905_none_5e963c6e73498ad1\wininet.dll
[7] 2009-05-12 . A0662CC26EEDC71C8598CBD7C986B09D . 1022464 . . [7.00.6000.16809] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16809_none_5c2a56c15d01d088\wininet.dll
[7] 2009-05-12 . BC8E5ED3269BF174B939B07FC167044E . 1024512 . . [7.00.6000.20996] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20996_none_5c4fa362766b1fc6\wininet.dll
[7] 2009-05-12 . 4C45D9EEB15838F96D77178CD6CD4244 . 1013248 . . [7.00.6001.18203] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18203_none_5e0a93ab5a2dc96f\wininet.dll
[7] 2009-05-12 . DE2EFEAC81EE3AEF9A0A297D06DEA73C . 1014272 . . [7.00.6001.22355] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22355_none_5e60216e7372279c\wininet.dll
[7] 2009-05-12 . D9E8399459565B4E8A7FF2B01CB55F8D . 1022464 . . [7.00.6000.16764] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16764_none_5be473e15d36fc54\wininet.dll
[7] 2009-05-12 . 428A8BB8016D66089CF1EFFA9970A76C . 1024512 . . [7.00.6000.20937] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20937_none_5c91833476399177\wininet.dll
[7] 2009-05-12 . 8CDADEC7D01F5AE41FD9C49A7053E89B . 1013248 . . [7.00.6001.18157] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18157_none_5dd883515a52bd59\wininet.dll
[7] 2009-05-12 . 80C4706935A12EF0DC73F0D0F5A1E577 . 1014272 . . [7.00.6001.22288] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22288_none_5e42b0a27387ca4d\wininet.dll
[7] 2009-05-12 . 50020130D79D6829116B0F5084653271 . 1022464 . . [7.00.6000.16757] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16757_none_5bf244ab5d2c2c68\wininet.dll
[7] 2009-05-12 . 0F2E5251DB62D7D47A553DB329DB4B4B . 1024512 . . [7.00.6000.20927] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20927_none_5c9c532076317586\wininet.dll
[7] 2009-05-12 . FE420A633F07F015B4D6C5A90346FF5D . 1013248 . . [7.00.6001.18148] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18148_none_5de453875a49babf\wininet.dll
[7] 2009-05-12 . 0C3985837353FD84BC2E0B2FFFD75FA2 . 1014272 . . [7.00.6001.22278] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22278_none_5e4d808e737fae5c\wininet.dll
[7] 2009-05-12 . 9D5E76B1D6941D2BB836655C1B6AE83B . 1022464 . . [7.00.6000.16711] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16711_none_5c17829f5d11249a\wininet.dll
[7] 2009-05-12 . 3488EDAF6B3459A6D29B8EFAC70DC35B . 1024512 . . [7.00.6000.20868] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20868_none_5c7211d47651017a\wininet.dll
[7] 2009-05-12 . B006FBF83BA6CAE854996F0A1319B5AB . 1013248 . . [7.00.6001.18099] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18099_none_5daf424f5a7162a4\wininet.dll
[7] 2009-05-12 . CAE8E1894C7FDEC9A18F4B9B95036105 . 1014272 . . [7.00.6001.22212] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22212_none_5e885e5a73546eac\wininet.dll
[7] 2009-05-12 . EEFC1D846B86CFD92865FFD255B87CFC . 1022464 . . [7.00.6000.16681] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16681_none_5bcbd1455d49eb0a\wininet.dll
[7] 2009-05-12 . CB2F683EB47B75F6E83DB0AC87DBFD9A . 1024000 . . [7.00.6000.20823] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20823_none_5c98501276351303\wininet.dll
[7] 2009-05-12 . A549050BABB436A7F3867911D302D19F . 1013248 . . [7.00.6001.18063] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18063_none_5dc9b0575a5e76c7\wininet.dll
[7] 2009-05-12 . B2BB90B07E1B87F41A0477ED2432AFB9 . 1013248 . . [7.00.6001.22167] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22167_none_5e574e4a73787bed\wininet.dll
[7] 2009-05-12 . 4C48ACC0299116CD22A9522D5C7CFFC4 . 1022464 . . [7.00.6000.16643] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16643_none_5bf911895d27adf4\wininet.dll
[7] 2009-05-12 . 3166E2EE2060D11A783A1B812B6F4945 . 1022976 . . [7.00.6000.20777] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20777_none_5c663fb8765a06ed\wininet.dll
[7] 2009-05-12 . 3CC83953BA4B51B32BD67982A1AF2AF5 . 1013760 . . [7.00.6001.18023] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18023_none_5df4f0075a3e0703\wininet.dll
[7] 2009-05-12 . E06F53F091B3567EA83308E5DDFF4094 . 1013760 . . [7.00.6001.22120] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22120_none_5e7b8bf4735e5ac8\wininet.dll
[7] 2009-04-11 . 1FA5623B49F69207B2E1DA94DB1C5B7D . 1014272 . . [7.00.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18005_none_5ff3080d57524e68\wininet.dll
[7] 2008-01-21 . 364B631BCD934D95CCD2E373F8DD8D7C . 1011712 . . [7.00.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18000_none_5e078f015a30831c\wininet.dll
[7] 2013-10-13 . C4AA30C01694001B8374CC62BF9AE6FF . 1392128 . . [9.00.8112.16421] .. c:\windows\system32\wininet.dll
.
[7] 2009-04-11 . BAB10B35E2D5EE0DC3DE05A177C52C50 . 264704 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6002.18005_none_50c1c55283d54246\ws2_32.dll
[7] 2008-01-21 . 63944ECFE4878C1C4889689324CABFAB . 265216 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6001.18000_none_4ed64c4686b376fa\ws2_32.dll
[7] 2009-04-11 . BAB10B35E2D5EE0DC3DE05A177C52C50 . 264704 . . [6.0.6000.16386] .. c:\windows\system32\ws2_32.dll
.
[7] 2008-01-21 . 9CD45523D76E4177C612B03C879E0AFF . 5120 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6001.18000_none_60a39df1afb86c9f\ws2help.dll
[7] 2008-01-21 . 9CD45523D76E4177C612B03C879E0AFF . 5120 . . [6.0.6001.18000] .. c:\windows\system32\ws2help.dll
.
[7] 2010-06-28 . 48E49F1EFE1F20A078DD656DE81AFBA8 . 1916928 . . [6.0.6002.22433] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6002.22433_none_0a8eee10c108556a\ole32.dll
[7] 2010-06-28 . 0CB93E3F36C4F4122E7CBBAA731F67D1 . 1915904 . . [6.0.6002.18277] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6002.18277_none_09de10d7a8078d99\ole32.dll
[7] 2010-06-28 . C7E11F8B2F3130FB7C3866F1816C4E7D . 1923584 . . [6.0.6001.18498] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6001.18498_none_07e2fd7baaf08c87\ole32.dll
[7] 2010-06-28 . 6F9FBFDF627A958ECDD1CB65704CB846 . 1922560 . . [6.0.6001.22720] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6001.22720_none_08b04b36c3dc9850\ole32.dll
[7] 2009-04-11 . 19915DB5B186D91CD4B459210C41741B . 1915392 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6002.18005_none_0a27bbeba7d09d06\ole32.dll
[7] 2008-01-21 . F36E23B80AC04538726699670050121D . 1923072 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6001.18000_none_083c42dfaaaed1ba\ole32.dll
[7] 2010-06-28 . 0CB93E3F36C4F4122E7CBBAA731F67D1 . 1915904 . . [6.0.6000.16386] .. c:\windows\system32\ole32.dll
.
[7] 2006-11-02 . 21322B1A2AD337C579F4A65EA0D25193 . 14848 . . [6.0.6000.16386] .. c:\windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[7] 2006-11-02 . 21322B1A2AD337C579F4A65EA0D25193 . 14848 . . [6.0.6000.16386] .. c:\windows\system32\cngaudit.dll
.
[7] 2008-01-21 . 117EA87DF785CA1B9D821F6F213DCE07 . 123904 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
[7] 2008-01-21 . 117EA87DF785CA1B9D821F6F213DCE07 . 123904 . . [6.0.6000.16386] .. c:\windows\system32\wininit.exe
.
[7] 2006-11-02 . 7E370DF3743B39CD375C52F7995783C4 . 9728 . . [6.0.6000.16386] .. c:\windows\winsxs\amd64_microsoft-windows-t..cesframework-ctfmon_31bf3856ad364e35_6.0.6000.16386_none_f718665b4c03ea89\ctfmon.exe
[7] 2006-11-02 . 7E370DF3743B39CD375C52F7995783C4 . 9728 . . [6.0.6000.16386] .. c:\windows\system32\ctfmon.exe
.
[7] 2009-07-10 . 9235EC680D3DB17464B39C7C7DECB4DD . 301568 . . [6.0.6001.18287] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18287_none_28ff7f1fd585934f\shsvcs.dll
[7] 2009-07-10 . 3F6101365E6319171054ADD75788516C . 300032 . . [6.0.6000.21081] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6000.21081_none_279cb3aaf1823d60\shsvcs.dll
[7] 2009-07-10 . C2409C9B7C7E422E7680AE4E1738BFC8 . 302080 . . [6.0.6001.22467] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.22467_none_299ebda8ee92f85e\shsvcs.dll
[7] 2009-07-10 . F33C4D0B9EEFCDE346F8753DC4D6867F . 299520 . . [6.0.6000.16883] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6000.16883_none_27153f51d8629d02\shsvcs.dll
[7] 2009-07-10 . 00DD742B99B278429714DEE859A73DD0 . 302080 . . [6.0.6002.22169] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.22169_none_2b873024ebb78030\shsvcs.dll
[7] 2009-07-10 . 56793271ECDEDD350C5ADD305603E963 . 302080 . . [6.0.6002.18063] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.18063_none_2af7919dd29f485c\shsvcs.dll
[7] 2009-04-11 . 2AD15758174DCC7993FF3C00A955DD66 . 301568 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.18005_none_2b3a71b9d26cd364\shsvcs.dll
[7] 2008-01-21 . EB3114330236CF030E8EDF62881BAF67 . 301568 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18000_none_294ef8add54b0818\shsvcs.dll
[7] 2009-07-10 . 56793271ECDEDD350C5ADD305603E963 . 302080 . . [6.0.6000.16386] .. c:\windows\system32\shsvcs.dll
.
[7] 2009-04-11 . 44B9D8EC2F3EF3A0EFB00857AF70D861 . 206848 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-remoteregistry-service_31bf3856ad364e35_6.0.6002.18005_none_e7701a4938f68d83\regsvc.dll
[7] 2008-01-21 . 416C611369CBE49074B89CEE2F83ABEF . 206336 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-remoteregistry-service_31bf3856ad364e35_6.0.6001.18000_none_e584a13d3bd4c237\regsvc.dll
[7] 2009-04-11 . 44B9D8EC2F3EF3A0EFB00857AF70D861 . 206848 . . [6.0.6000.16386] .. c:\windows\system32\regsvc.dll
.
[7] 2010-11-06 . 0F838C811AD295D2A4489B9993096C63 . 855040 . . [6.0.6002.18342] .. c:\windows\winsxs\amd64_microsoft-windows-taskscheduler-service_31bf3856ad364e35_6.0.6002.18342_none_8cdcf8454ca4d06e\schedsvc.dll
[7] 2010-11-06 . CE75D26E0A1106129F4D156851E298ED . 854528 . . [6.0.6001.18551] .. c:\windows\winsxs\amd64_microsoft-windows-taskscheduler-service_31bf3856ad364e35_6.0.6001.18551_none_8aeab4414f8780bd\schedsvc.dll
[7] 2010-11-04 . C40E431210CAF3DB00203F5796A31FDE . 856064 . . [6.0.6002.22519] .. c:\windows\winsxs\amd64_microsoft-windows-taskscheduler-service_31bf3856ad364e35_6.0.6002.22519_none_8d8e08c065a3caed\schedsvc.dll
[7] 2010-11-04 . 596404B1E48657168BDAA69B9CD1DB74 . 856064 . . [6.0.6001.22791] .. c:\windows\winsxs\amd64_microsoft-windows-taskscheduler-service_31bf3856ad364e35_6.0.6001.22791_none_8b49134268c58d72\schedsvc.dll
[7] 2009-05-12 . C315E4CD537736E53D1F28A497FBE29B . 844288 . . [6.0.6000.20779] .. c:\windows\winsxs\amd64_microsoft-windows-taskscheduler-service_31bf3856ad364e35_6.0.6000.20779_none_89806b606b87a06d\schedsvc.dll
[7] 2009-04-11 . 717C12DF4B7C93FEC97D146AC1342B25 . 843776 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-taskscheduler-service_31bf3856ad364e35_6.0.6002.18005_none_8d0b33214c81b53a\schedsvc.dll
[7] 2008-01-21 . C74C6C01353D87AAFE1193B426D667B0 . 843776 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-taskscheduler-service_31bf3856ad364e35_6.0.6001.18000_none_8b1fba154f5fe9ee\schedsvc.dll
[7] 2008-01-21 . 5AEA4C9E2B3656B2B53D3886BB6DFC35 . 844288 . . [6.0.6000.16609] .. c:\windows\winsxs\amd64_microsoft-windows-taskscheduler-service_31bf3856ad364e35_6.0.6000.16609_none_89427e0952313d0c\schedsvc.dll
[7] 2010-11-06 . 0F838C811AD295D2A4489B9993096C63 . 855040 . . [6.0.6001.18000] .. c:\windows\system32\schedsvc.dll
.
[7] 2008-01-21 . 192C74646EC5725AEF3F80D19FF75F6A . 185856 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-upnpssdp_31bf3856ad364e35_6.0.6001.18000_none_dbe80e6f8995baeb\ssdpsrv.dll
[7] 2008-01-21 . 192C74646EC5725AEF3F80D19FF75F6A . 185856 . . [6.0.6000.16386] .. c:\windows\system32\ssdpsrv.dll
.
[7] 2009-04-11 . 5CDD30BC217082DAC71A9878D9BFD566 . 547328 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.0.6002.18005_none_eca9565809c353e4\termsrv.dll
[7] 2008-01-21 . F870A5589D6A94B426EFB13689023946 . 546816 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.0.6001.18000_none_eabddd4c0ca18898\termsrv.dll
[7] 2009-04-11 . 5CDD30BC217082DAC71A9878D9BFD566 . 547328 . . [6.0.6001.18000] .. c:\windows\system32\termsrv.dll
.
[7] 2013-07-08 . 82272D72710ED6A40E9A2A2286A9BBF4 . 4691904 . . [6.0.6002.18881] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18881_none_c9e004d869e6b24e\ntoskrnl.exe
[7] 2013-07-08 . B1AAE884320029A58F72B7CE0ABBDDB2 . 4664256 . . [6.0.6002.23154] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.23154_none_ca8cec4d82e97ab3\ntoskrnl.exe
[7] 2013-03-11 . 1F8B1075A863117A35EE94436E2962E7 . 4691304 . . [6.0.6002.18805] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18805_none_ca3a856069a23822\ntoskrnl.exe
[7] 2013-03-11 . 1873B95FCEAA40EC9CADF2C1BB61ABF2 . 4678504 . . [6.0.6002.23076] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.23076_none_ca794b2382f7e81c\ntoskrnl.exe
[7] 2013-01-22 . B1266A731C2326EBE8E01F46F18728AC . 4681592 . . [6.0.6002.23025] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.23025_none_caae5a7582d04310\ntoskrnl.exe
[7] 2013-01-05 . 8A3AB79510C3384BF14D1731DD1ED963 . 4695400 . . [6.0.6002.18765] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18765_none_c9f9a3f269d2e2a1\ntoskrnl.exe
[7] 2012-08-29 . 1A14913D51571403CF8A3941BDC3BA67 . 4699520 . . [6.0.6002.18686] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18686_none_c9e5027e69e236b3\ntoskrnl.exe
[7] 2012-08-29 . 34C970A45CCC0D65A4A0F8D306E12844 . 4686208 . . [6.0.6002.22920] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22920_none_caa980e182d4911b\ntoskrnl.exe
[7] 2012-04-03 . B59E026F49BF06B435795F867AD46009 . 4687232 . . [6.0.6002.22831] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22831_none_ca9faf5982dbc93c\ntoskrnl.exe
[7] 2012-04-03 . 7180984A68411B9D2F2495E03561B47E . 4699520 . . [6.0.6002.18607] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18607_none_ca3c822869a07082\ntoskrnl.exe
[7] 2012-03-06 . 98581CA6B029D491F60E32A045BC4FF1 . 4699520 . . [6.0.6002.18595] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18595_none_c9d9306269eb3c26\ntoskrnl.exe
[7] 2012-03-06 . B448C24F801DC79661E30DBC8E739DB2 . 4687744 . . [6.0.6002.22811] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22811_none_cab54f3182cb915a\ntoskrnl.exe
[7] 2010-10-15 . 760A67A51D409EB396D1942D5555435C . 4692368 . . [6.0.6001.18538] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18538_none_c836992e6c9193ec\ntoskrnl.exe
[7] 2010-10-15 . 4065E920FB6ED05B5F62A1FB6908C6C5 . 4699024 . . [6.0.6002.18327] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18327_none_ca26dc9e69b0b0ef\ntoskrnl.exe
[7] 2010-10-15 . 255A6D981139EFEF605A88E003D1B2A2 . 4689808 . . [6.0.6002.22505] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22505_none_cac41a9382bfe350\ntoskrnl.exe
[7] 2010-10-15 . 3A22B135BC4341025E19B9ADFB26C02A . 4678032 . . [6.0.6001.22777] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22777_none_c893f7e585d0874a\ntoskrnl.exe
[7] 2009-05-12 . 2A87B3D380E3800BF247D82E58F0FCBA . 4429368 . . [6.0.6000.16754] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16754_none_c636b1f06f7ee0e5\ntoskrnl.exe
[7] 2009-05-12 . EFAAC7A874B65DF3F26B5092291D4859 . 4416056 . . [6.0.6000.20921] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20921_none_c6ddbf878886ddfe\ntoskrnl.exe
[7] 2009-05-12 . 247A2AAF7E5189716192EE19EC6EC6FB . 4694584 . . [6.0.6001.18145] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18145_none_c828c0cc6c9c6f3c\ntoskrnl.exe
[7] 2009-05-12 . 5E31190EF331709EAB9FB66C3683540B . 4694584 . . [6.0.6001.22269] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22269_none_c8a0bee785c6ac44\ntoskrnl.exe
[7] 2009-05-12 . 6DEA6827709FC6F047580111651DFF02 . 4694584 . . [6.0.6001.18063] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18063_none_c8111e7a6cae7749\ntoskrnl.exe
[7] 2009-05-12 . A1DC0EFF401FE35688F1046F10BEE5BF . 4694584 . . [6.0.6001.22167] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22167_none_c89ebc6d85c87c6f\ntoskrnl.exe
[7] 2009-04-11 . 1B60CCC70788044404EEFBBB389FC111 . 4699608 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18005_none_ca3a763069a24eea\ntoskrnl.exe
[7] 2009-03-03 . 65252FED486E5BF1E384CA65C16148C7 . 4691424 . . [6.0.6001.22389] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22389_none_c88b20f585d6e14d\ntoskrnl.exe
[7] 2009-03-03 . ED97E8551F0B1844250ED1B07393B10D . 4692448 . . [6.0.6001.18226] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18226_none_c83f62d46c8b4dd8\ntoskrnl.exe
[7] 2009-03-03 . 8B3095B00E832ABFC7047A04E681CCDE . 4427232 . . [6.0.6000.16830] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16830_none_c64852866f7240ce\ntoskrnl.exe
[7] 2009-03-03 . CC172711FF2FCE0673321A951B02C379 . 4413936 . . [6.0.6000.21023] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21023_none_c6df983d888543ee\ntoskrnl.exe
[7] 2008-01-21 . 6760643D6400CA78640E9DD3824115B1 . 4694072 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18000_none_c84efd246c80839e\ntoskrnl.exe
[7] 2013-07-08 . 82272D72710ED6A40E9A2A2286A9BBF4 . 4691904 . . [6.0.6002.18881] .. c:\windows\system32\ntoskrnl.exe
.
[7] 2008-01-21 . 17BF3BF5296936B153FDDDA189B60E07 . 5120 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-d..tshow-kernelsupport_31bf3856ad364e35_6.0.6001.18000_none_442037e04fa9b5c7\ksuser.dll
[7] 2008-01-21 . 17BF3BF5296936B153FDDDA189B60E07 . 5120 . . [6.0.6001.18000] .. c:\windows\system32\ksuser.dll
.
[7] 2008-01-21 . 6B58266234B36ABCDD43C797B0D1932E . 8192 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-gdi-painting_31bf3856ad364e35_6.0.6001.18000_none_d38a739ed46982f7\msimg32.dll
[7] 2008-01-21 . 6B58266234B36ABCDD43C797B0D1932E . 8192 . . [6.0.6001.18000] .. c:\windows\system32\msimg32.dll
.
[7] 2013-07-04 . 58035212AB7869A5FC3AF186ACBA8F09 . 532480 . . [5.82] .. c:\windows\SysWOW64\comctl32.dll
[7] 2013-07-04 . 58035212AB7869A5FC3AF186ACBA8F09 . 532480 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6002.18879_none_3b3ff8f0d54e60f1\comctl32.dll
[7] 2013-07-04 . 9474AD3584430D24DA87517F9DB0CBB2 . 532480 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.18879_none_88f80d1769beeaec\comctl32.dll
[7] 2013-07-04 . 059F04344FD96993C4F207BB4E281DF3 . 532480 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6002.23151_none_3bd70d4bee632e8a\comctl32.dll
[7] 2013-07-04 . C0A115C660134FD0A97735DE368702A5 . 532480 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.23151_none_8ad7a1bf66eb6815\comctl32.dll
[7] 2010-09-02 . 542A806C74798410ADA0623B9E745C38 . 531968 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6002.22480_none_3bb5b9b7ee7c46da\comctl32.dll
[7] 2010-09-02 . 2429BBFFCE9EDB193232DE902F88C688 . 1686016 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.22480_none_45f1fca2222ab96c\comctl32.dll
[7] 2010-09-02 . 63A65EA959BD32B01F02E847CB16C63D . 531968 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.22480_none_8ada5c8366e90385\comctl32.dll
[7] 2010-09-01 . FFBE05ED8338B17940DEA55FA6BC6F03 . 531968 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6001.22755_none_39f4b905f1391c96\comctl32.dll
[7] 2010-09-01 . 168B034C75B85AFD667AC8D0C9003312 . 1685504 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.22755_none_4612924c21dcda90\comctl32.dll
[7] 2010-09-01 . 640C4514157B3C6FE1E05B135FCB95B4 . 531968 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.22755_none_8a5499024dc7b801\comctl32.dll
[7] 2010-08-31 . DC8891A9203810FC994E7FCCF76E94C8 . 531968 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6002.18305_none_3b879dbed519463b\comctl32.dll
[7] 2010-08-31 . BE3C082837866C4C291ADAF163C10EA6 . 1686016 . . [6.10] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
[7] 2010-08-31 . 35ACD5EA63D75E97DD0E9A1629E582B2 . 531968 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.18305_none_88f3a38569c2c436\comctl32.dll
[7] 2010-08-31 . 457366B876CEAB9E92DDF976B8520CB6 . 531968 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6001.18523_none_39898984d804f924\comctl32.dll
[7] 2010-08-31 . D702B4E30B31BFCAB7BD4E5965C1A5DC . 1684480 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll
[7] 2010-08-31 . E402A6E79D1E4DBFEBA8B364C67A3158 . 531968 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18523_none_886c608850a2f36f\comctl32.dll
[7] 2009-04-11 . 0C2236FB7195A1CF2A632D530349E673 . 1686016 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
[7] 2008-01-21 . 50CDFD99E606D172875E73B87C64053D . 531968 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.0.6001.18000_none_399c1f00d7f7837a\comctl32.dll
[7] 2008-01-21 . 58D3C1519096F3D9E07EEC5F5FC64885 . 531968 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\comctl32.dll
[7] 2008-01-21 . A5BB4537004C8DCC096A952EF1E20FE9 . 1684480 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
[7] 2006-11-02 . B28A9B2300A250B703D44C1759AF2605 . 1648128 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll
[7] 2006-11-02 . 4A05089F43041903A3C523A3C16E3350 . 537088 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\comctl32.dll
.
[7] 2013-10-03 . 165E9D93A84A7F55EBEEB1B554110680 . 135168 . . [6.0.6002.23235] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23235_none_78542a95b127239a\cryptsvc.dll
[7] 2013-07-08 . 684C130BBC6DB681BAD4920A4C944AA5 . 133120 . . [6.0.6000.16386] .. c:\windows\SysWOW64\cryptsvc.dll
[7] 2013-07-08 . 684C130BBC6DB681BAD4920A4C944AA5 . 133120 . . [6.0.6002.18881] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18881_none_7790a11898357c99\cryptsvc.dll
[7] 2013-07-08 . 828805E2E7F529B24849AD52740288DA . 135168 . . [6.0.6002.23154] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23154_none_783d888db13844fe\cryptsvc.dll
[7] 2013-04-24 . 3EDE4C1F9672C972479201544969ADCB . 133120 . . [6.0.6002.18831] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18831_none_77c6b0b4980cf0e4\cryptsvc.dll
[7] 2013-04-24 . FBE051C07C3D2B9011ECB1C7A73120C1 . 135168 . . [6.0.6002.23101] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23101_none_7870974bb1126d44\cryptsvc.dll
[7] 2013-04-17 . 58CEF2D243575512657452B9E89A2E1F . 133120 . . [6.0.6002.18827] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18827_none_77d7825c97ff6cfd\cryptsvc.dll
[7] 2013-04-17 . CC8E2C87016A07892B5448D764BF8A30 . 135168 . . [6.0.6002.23097] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23097_none_781547d5b15603a0\cryptsvc.dll
[7] 2012-06-02 . DD9CCF40ED80DD0D62F1B607A1EA4449 . 135168 . . [6.0.6002.22869] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.22869_none_7837de25b13bb212\cryptsvc.dll
[7] 2012-06-02 . F1E8C34892336D33EDDCDFE44E474F64 . 133120 . . [6.0.6002.18643] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18643_none_77bddd9098134535\cryptsvc.dll
[7] 2012-04-23 . 75C6A297E364014840B48ECCD7525E30 . 133120 . . [6.0.6002.18618] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18618_none_77e34ec697f67015\cryptsvc.dll
[7] 2012-04-23 . C979AEA8C4D8F875CD25507D08980006 . 135168 . . [6.0.6002.22840] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.22840_none_78447b63b1339621\cryptsvc.dll
[7] 2009-04-11 . FB27772BEAF8E1D28CCD825C09DA939B . 129024 . . [6.0.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18005_none_77eb127097f11935\cryptsvc.dll
[7] 2008-01-21 . 6DE363F9F99334514C46AEC02D3E3678 . 128000 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_75ff99649acf4de9\cryptsvc.dll
.
[7] 2009-05-12 . 7B4971C3D43525175A4EA0D143E0412E . 268800 . . [2001.12.6930.16677] .. c:\windows\winsxs\wow64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6000.16677_none_7135f8df4187b761\es.dll
[7] 2009-05-12 . 131B7E46A7ACD49CB56BB03917A76DE3 . 268800 . . [2001.12.6930.20818] .. c:\windows\winsxs\wow64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6000.20818_none_720177625a73c603\es.dll
[7] 2009-05-12 . 3CB3343D720168B575133A0A20DC2465 . 269312 . . [2001.12.6931.18057] .. c:\windows\winsxs\wow64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.18057_none_7331d75d3e9e1070\es.dll
[7] 2009-05-12 . 776D75AF432C598068CC933C7421171B . 269312 . . [2001.12.6931.22162] .. c:\windows\winsxs\wow64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.22162_none_73aba2ca57c84d78\es.dll
[7] 2009-04-11 . 67058C46504BC12D821F38CF99B7B28F . 268800 . . [2001.12.6932.18005] .. c:\windows\SysWOW64\es.dll
[7] 2009-04-11 . 67058C46504BC12D821F38CF99B7B28F . 268800 . . [2001.12.6932.18005] .. c:\windows\winsxs\wow64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6002.18005_none_754c5dff3b9d9ea6\es.dll
[7] 2008-01-21 . F4BF4FA769DB51B106D2B4B35256988B . 262144 . . [2001.12.6931.18000] .. c:\windows\winsxs\wow64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.18000_none_7360e4f33e7bd35a\es.dll
.
[7] 2009-04-11 . B8FBE5F40B09F5D20E1E5CCFEF893D62 . 116224 . . [6.0.6002.18005] .. c:\windows\SysWOW64\imm32.dll
[7] 2009-04-11 . B8FBE5F40B09F5D20E1E5CCFEF893D62 . 116224 . . [6.0.6002.18005] .. c:\windows\winsxs\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.0.6002.18005_none_c4b4dcf8644afb7f\imm32.dll
[7] 2008-01-21 . CA3091655E2257B3E3EA86F79A696C56 . 116224 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.0.6001.18000_none_c2c963ec67293033\imm32.dll
.
[7] 2012-09-28 . D59DD2AAFF94EAB9BD6C7940C2851735 . 860160 . . [6.0.6001.18000] .. c:\windows\SysWOW64\kernel32.dll
[7] 2012-09-28 . D59DD2AAFF94EAB9BD6C7940C2851735 . 860160 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6002.18704_none_fc1bb123402c59e5\kernel32.dll
[7] 2012-09-28 . 04876F4758D10B768D4CF792D03FC9CF . 860672 . . [6.0.6002.22942] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6002.22942_none_fc780f90596c33ec\kernel32.dll
[7] 2011-04-12 . 7F4CAEAC24592FA9F574E1F8CD1D0604 . 859648 . . [6.0.6002.18449] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6002.18449_none_fbf56d33404850e7\kernel32.dll
[7] 2011-04-12 . BBB3D68596C6B6E8A7ECAFDB2962E89B . 860672 . . [6.0.6002.22625] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6002.22625_none_fc90aa945959509a\kernel32.dll
[7] 2011-04-12 . 6EBBE14BE54877C386C63FFED52D391D . 857600 . . [6.0.6001.18631] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18631_none_fa11c701432117f3\kernel32.dll
[7] 2011-04-12 . 35FC1E7929DA4828B9CC73DC84B42E6F . 860160 . . [6.0.6001.22898] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.22898_none_fa6188305c690deb\kernel32.dll
[7] 2009-04-11 . A5830F679B5B38AE9700A72087178745 . 858112 . . [6.0.6002.18005] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6002.18005_none_fc1ca423402b872b\kernel32.dll
[7] 2009-02-13 . D4902D1DC60CB71197EFE4474A582841 . 855552 . . [6.0.6001.18215] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18215_none_fa2b6069430d50d1\kernel32.dll
[7] 2009-02-13 . 1B5BE39A927C36B3162ADA23B6CA001E . 858112 . . [6.0.6001.22376] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.22376_none_fa751df65c5ab198\kernel32.dll
[7] 2009-02-13 . 444A00544B4EDFEDD8FCCD281EDE3ED4 . 840704 . . [6.0.6000.16820] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.16820_none_f835506545f35d1e\kernel32.dll
[7] 2009-02-13 . 4118366CDDA655F8AEDB20CD03DEBAE9 . 841216 . . [6.0.6000.21010] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.21010_none_f8c9953e5f091439\kernel32.dll
[7] 2008-01-21 . 799EEDF377F3B72DB30192AD9FD3C7F3 . 855552 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18000_none_fa312b174309bbdf\kernel32.dll
.
[7] 2006-11-02 . 24F90AEFEBE601D427CB4511E74CDCB6 . 22016 . . [6.0.6000.16386] .. c:\windows\SysWOW64\linkinfo.dll
[7] 2006-11-02 . 24F90AEFEBE601D427CB4511E74CDCB6 . 22016 . . [6.0.6000.16386] .. c:\windows\winsxs\x86_microsoft-windows-linkinfo_31bf3856ad364e35_6.0.6001.18000_none_3865321ca55411b2\linkinfo.dll
.
[7] 2013-06-04 . 25D23247F95873C7322BE6B5E9A0DB93 . 23552 . . [6.0.6002.23132] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.23132_none_1297ecbb5d9f1d02\lpk.dll
[7] 2012-12-16 . 1AFE3E0E4FBAE0FA540CBCEEC5E39D1F . 23552 . . [6.0.6002.23004] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.23004_none_12ba5b2d5d84feb6\lpk.dll
[7] 2011-02-16 . F9AA0406BA33BC029536E04D6066C03A . 23552 . . [6.0.6002.22589] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22589_none_1268fd855dc13513\lpk.dll
[7] 2011-02-16 . 789CD968872EFA074339E0CFB70EB6B2 . 23552 . . [6.0.6001.22854] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22854_none_109df9ef60870d69\lpk.dll
[7] 2009-10-19 . 77F2AB938BFBAB43EC1B91D11BBA2EEE . 24064 . . [6.0.6000.16939] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16939_none_0e48b8304a2e2ee3\lpk.dll
[7] 2009-10-19 . 08992A029F43690B4340BF6B2F7BCE5B . 24064 . . [6.0.6000.21142] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21142_none_0ec05b2b635a6c7f\lpk.dll
[7] 2009-10-19 . D669A9A4C894708388ADF96BBEAD3787 . 23552 . . [6.0.6001.22544] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22544_none_10a8c429607efa03\lpk.dll
[7] 2009-10-19 . 7EC16AB95B707BE43A938E20D096240E . 23552 . . [6.0.6002.22247] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22247_none_129236ef5da29b2c\lpk.dll
[7] 2009-04-11 . DF37346EA13082E3E1B423B54014E641 . 23552 . . [6.0.6002.18005] .. c:\windows\SysWOW64\lpk.dll
[7] 2009-04-11 . DF37346EA13082E3E1B423B54014E641 . 23552 . . [6.0.6002.18005] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18005_none_1231d75a44665bc9\lpk.dll
[7] 2009-04-11 . DF37346EA13082E3E1B423B54014E641 . 23552 . . [6.0.6002.18005] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18124_none_121b391e4477777b\lpk.dll
[7] 2009-04-11 . DF37346EA13082E3E1B423B54014E641 . 23552 . . [6.0.6002.18005] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18405_none_1231def244665065\lpk.dll
[7] 2009-04-11 . DF37346EA13082E3E1B423B54014E641 . 23552 . . [6.0.6002.18005] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18755_none_11fbd508448ed38f\lpk.dll
[7] 2009-04-11 . DF37346EA13082E3E1B423B54014E641 . 23552 . . [6.0.6002.18005] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18861_none_11ed05da449a874b\lpk.dll
[7] 2008-01-21 . 6FC8AC168B7E9BF46A0DB29E58CB60D2 . 23552 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18000_none_10465e4e4744907d\lpk.dll
[7] 2008-01-21 . 6FC8AC168B7E9BF46A0DB29E58CB60D2 . 23552 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18344_none_101f257847615d12\lpk.dll
[7] 2008-01-21 . 6FC8AC168B7E9BF46A0DB29E58CB60D2 . 23552 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18599_none_0fee1b1a478561c8\lpk.dll
.
[7] 2013-10-13 . AC986A1AD35CDBF07B0E5D1AC9D527B5 . 12344832 . . [9.00.8112.16421] .. c:\windows\SysWOW64\mshtml.dll
[7] 2013-10-13 . AC986A1AD35CDBF07B0E5D1AC9D527B5 . 12344832 . . [9.00.8112.16520] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16520_none_d3354f28600ea4fe\mshtml.dll
[7] 2013-10-13 . F111B63E90F9A36B8CF4894B43EFC641 . 12344832 . . [9.00.8112.20631] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20631_none_d3b51c5179337a10\mshtml.dll
[7] 2013-09-22 . 41DAD6EDAE3F02B7D527FA9B4B4EA022 . 12336640 . . [9.00.8112.20625] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20625_none_d3c3ed657927c37b\mshtml.dll
[7] 2013-09-22 . F46A58EC9183CB2B24326A41CDDE1FAE . 12336128 . . [9.00.8112.16514] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16514_none_d344203c6002ee69\mshtml.dll
[7] 2013-07-31 . 6DB41C70A74B420A0ADC55A9862DDAD9 . 12335104 . . [9.00.8112.16506] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16506_none_d350f0bc5ff90526\mshtml.dll
[7] 2013-07-31 . DCC51F3466767C3B418E23F5A467D6E5 . 12335616 . . [9.00.8112.20617] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20617_none_d3d0bde5791dda38\mshtml.dll
[7] 2013-07-25 . 0E2B5CB2193B6B0057F7D8B3FE02777E . 12334080 . . [9.00.8112.20613] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20613_none_d3ccbcbd792174dc\mshtml.dll
[7] 2013-07-25 . 7161E761E81356C8EF6383CB1AE41B8D . 12334080 . . [9.00.8112.16502] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16502_none_d34cef945ffc9fca\mshtml.dll
[7] 2013-05-29 . 4ACB8A0EA4A1BEAA4FA92680BB71C542 . 12335104 . . [9.00.8112.20606] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20606_none_d3da8d877916a4f0\mshtml.dll
[7] 2013-05-29 . 7BD6A6DFA75B665FA8F21BB21E59EC11 . 12333568 . . [9.00.8112.16496] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16496_none_d2ef9f8a60420378\mshtml.dll
[7] 2013-05-16 . A6F5B25905CD01AE714990E02C7205A5 . 12329984 . . [9.00.8112.16490] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16490_none_d2e99dce60476b6e\mshtml.dll
[7] 2013-05-16 . 097654708FE5F07278A1E36D9F78CA94 . 12330496 . . [9.00.8112.20600] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20600_none_d3d48bcb791c0ce6\mshtml.dll
[7] 2013-05-05 . 1152DE9D7FE16EC92A12165D1CBE8406 . 12325888 . . [9.00.8112.20594] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20594_none_d3773bc179617094\mshtml.dll
[7] 2013-05-05 . 26F30066B9FA78C97A0E92803D496211 . 12324864 . . [9.00.8112.16484] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16484_none_d2f86ee2603bb4d9\mshtml.dll
[7] 2013-04-04 . 79B0D843B26BEA808EA89BA2D8A026F2 . 12324864 . . [9.00.8112.16483] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16483_none_d2f76e98603c9b82\mshtml.dll
[7] 2013-04-04 . 4EBF337D1F52EA9202072348BA41CA95 . 12325376 . . [9.00.8112.20593] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20593_none_d3763b777962573d\mshtml.dll
[7] 2013-02-22 . 474D43D76E2A33FEE21C6F4BB7C4A3B7 . 12324864 . . [9.00.8112.20586] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20586_none_d3840c4179578751\mshtml.dll
[7] 2013-02-22 . 658EBC74BD38D16805648C4775F7FA82 . 12324352 . . [9.00.8112.16476] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16476_none_d3053f626031cb96\mshtml.dll
[7] 2013-02-02 . 88C27474E61271B49677F22CEE76FB3E . 12322304 . . [9.00.8112.20580] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20580_none_d37e0a85795cef47\mshtml.dll
[7] 2013-02-02 . 263963D93A3CA8F685EFA5966F1E6581 . 12321792 . . [9.00.8112.16470] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16470_none_d2ff3da66037338c\mshtml.dll
[7] 2013-01-08 . C97434C851C4821BD92D2831FDF1ECBE . 12321280 . . [9.00.8112.16464] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16464_none_d30e0eba602b7cf7\mshtml.dll
[7] 2013-01-08 . B6AD225B3BCC07332FBB2C2824315534 . 12322304 . . [9.00.8112.20573] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20573_none_d38bdb4f79521f5b\mshtml.dll
[7] 2012-11-14 . 07F649CD36F266BBE33B814FA678AA43 . 12320256 . . [9.00.8112.16457] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16457_none_d31bdf846020ad0b\mshtml.dll
[7] 2012-11-14 . 8021EF27048F9ECE5286EA8C8EED23B8 . 12321280 . . [9.00.8112.20565] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20565_none_d398abcf79483618\mshtml.dll
[7] 2012-10-03 . A831FFEF2C5244600373A426576B0604 . 12320768 . . [9.00.8112.16455] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16455_none_d319def060227a5d\mshtml.dll
[7] 2012-10-03 . BCDB83DDE29DD2EF57C71904F11B9554 . 12321280 . . [9.00.8112.20562] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20562_none_d395aaf1794aea13\mshtml.dll
[7] 2012-08-24 . 975D1EA99A0FE8104B72440995B3C20B . 12319744 . . [9.00.8112.20557] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20557_none_d3a57c4f793e4cd5\mshtml.dll
[7] 2012-08-24 . BB197F54A8F69EEA8356B7F70E6D3A20 . 12319744 . . [9.00.8112.16450] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16450_none_d314dd7e6026fbaa\mshtml.dll
[7] 2012-06-28 . 525F42376AA8D997B638145415244162 . 12317184 . . [9.00.8112.16448] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16448_none_d327afba6017aa71\mshtml.dll
[7] 2012-06-27 . 435BAC247A54B03D02F02DFA57B1AA43 . 12317184 . . [9.00.8112.20554] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20554_none_d3a27b71794100d0\mshtml.dll
[7] 2012-06-02 . 6820A9E91AFF7CB3A510360D8CCD9BDD . 12314624 . . [9.00.8112.16447] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16447_none_d326af706018911a\mshtml.dll
[7] 2012-06-02 . 1ABF770552EA9D4FE90F654468FAF4CE . 12314624 . . [9.00.8112.20553] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20553_none_d3a17b277941e779\mshtml.dll
[7] 2012-05-17 . 9FB58F71104107D44540AF1195F7A14D . 12314624 . . [9.00.8112.16446] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16446_none_d325af26601977c3\mshtml.dll
[7] 2012-05-17 . 761D9111F5A2619CB5060661D36FBFFF . 12314624 . . [9.00.8112.20551] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20551_none_d39f7a937943b4cb\mshtml.dll
[7] 2012-05-16 . 497C9C3DB953A60EC4F43A097E15F75E . 12282368 . . [9.00.8112.16441] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16441_none_d320adb4601df910\mshtml.dll
[7] 2012-02-28 . 6DA8DB32B2597B16AEC318FF4C951970 . 3618304 . . [7.00.6002.18591] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.18591_none_14c944b21f97ce48\mshtml.dll
[7] 2012-02-28 . 9829E580E9A19CDF28C79399B9E1A4F5 . 3619328 . . [7.00.6002.22805] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.22805_none_15b835bd3868d243\mshtml.dll
[7] 2012-02-28 . F82BF2CB075B49E9FAB5FF213C45C020 . 12281856 . . [9.00.8112.16443] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.16443_none_d322ae48601c2bbe\mshtml.dll
[7] 2012-02-28 . B9E083B14B1994F1255983F2DF31C7DF . 12281856 . . [9.00.8112.20548] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.1.8112.20548_none_d3b14c8579354a3b\mshtml.dll
[7] 2011-04-21 . C062788870AF39AFBC3B5645E1381559 . 3610112 . . [7.00.6002.18457] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.18457_none_14fa84381f71f967\mshtml.dll
[7] 2011-04-21 . 78484C24A46297C628115F6D0E4D0A17 . 3611136 . . [7.00.6002.22629] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.22629_none_15a6934138757533\mshtml.dll
[7] 2011-04-21 . D6C2CEACB1EE184EA0C1D6BD594B398F . 3593728 . . [7.00.6001.18639] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18639_none_132bb0d62239a1e8\mshtml.dll
[7] 2011-04-21 . 8E33539FB60AA8C146CFC9BB0565880D . 3595264 . . [7.00.6001.22905] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22905_none_13d1c0093b4282d1\mshtml.dll
[7] 2009-05-12 . 676692EDC2E1DBD89EFCB617A1E75F7D . 3594752 . . [7.00.6000.16809] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16809_none_1165da5c24fac888\mshtml.dll
[7] 2009-05-12 . AD9E78847641E519FE50A9C27E49AD27 . 3596288 . . [7.00.6000.20996] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.20996_none_118b26fd3e6417c6\mshtml.dll
[7] 2009-05-12 . E161281A8E8937ED94299A6B465D7BCE . 3580416 . . [7.00.6001.18203] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18203_none_134617462226c16f\mshtml.dll
[7] 2009-05-12 . 8FA6CFFC665D1D9D99126CFA8D8DEAB7 . 3580928 . . [7.00.6001.22355] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22355_none_139ba5093b6b1f9c\mshtml.dll
[7] 2009-05-12 . 863FBEECA377800B2AFA4F8E972BEBC0 . 3593216 . . [7.00.6000.16788] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16788_none_110e58cc253c9192\mshtml.dll
[7] 2009-05-12 . 616EA8D014AF07FB1DC97B7432794AA6 . 3594752 . . [7.00.6000.20973] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.20973_none_119dc5f73e5693df\mshtml.dll
[7] 2009-05-12 . 8ECFDD5549AD28191D8594C80D4001E8 . 3578880 . . [7.00.6001.18183] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18183_none_12ef96002267a3d0\mshtml.dll
[7] 2009-05-12 . 20348C5C94D7D4A0D9AA12FBAA698514 . 3579392 . . [7.00.6001.22328] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22328_none_13bf15ab3b5017ce\mshtml.dll
[7] 2009-05-12 . 8B03B6121C4A55BF48B56BFAF962F879 . 3593216 . . [7.00.6000.16764] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16764_none_111ff77c252ff454\mshtml.dll
[7] 2009-05-12 . CF807C36C2E1984104D173B9DE1BCBCD . 3595264 . . [7.00.6000.20937] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.20937_none_11cd06cf3e328977\mshtml.dll
[7] 2009-05-12 . B1AE727959358E4FE72D7FE6DC6736E8 . 3578880 . . [7.00.6001.18157] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18157_none_131406ec224bb559\mshtml.dll
[7] 2009-05-12 . 6D4AAAAAEB494F78610AE792EC6B3E77 . 3579392 . . [7.00.6001.22288] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22288_none_137e343d3b80c24d\mshtml.dll
[7] 2009-05-12 . 713D3D802424C56F28A3AC21F843D9E4 . 3593216 . . [7.00.6000.16757] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16757_none_112dc84625252468\mshtml.dll
[7] 2009-05-12 . 34311116C0A994BD82D7732D0950999C . 3594752 . . [7.00.6000.20927] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.20927_none_11d7d6bb3e2a6d86\mshtml.dll
[7] 2009-05-12 . 3E3D3E24BD1F862CD1A772C0DAD3F134 . 3578880 . . [7.00.6001.18148] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18148_none_131fd7222242b2bf\mshtml.dll
[7] 2009-05-12 . 56942EB5D17DFA38CA0B2B234BB578A3 . 3579392 . . [7.00.6001.22278] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22278_none_138904293b78a65c\mshtml.dll
[7] 2009-05-12 . B964D58A6698C8FCA93447ADBDE18820 . 3592192 . . [7.00.6000.16711] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16711_none_1153063a250a1c9a\mshtml.dll
[7] 2009-05-12 . 1D73575D8A0F368CD8FE3212E8928743 . 3594240 . . [7.00.6000.20868] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.20868_none_11ad956f3e49f97a\mshtml.dll
[7] 2009-05-12 . 2B59221D1B9D9FB1D202A21AFE8E410A . 3578368 . . [7.00.6001.18099] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18099_none_12eac5ea226a5aa4\mshtml.dll
[7] 2009-05-12 . 256E9D588ACB7F104123947297A9302A . 3578880 . . [7.00.6001.22212] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22212_none_13c3e1f53b4d66ac\mshtml.dll
[7] 2009-05-12 . 13A0AA60B35A6A13152A759536C10203 . 3591680 . . [7.00.6000.16681] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16681_none_110754e02542e30a\mshtml.dll
[7] 2009-05-12 . 38EC352C600EB037FE02749F8C170B6B . 3593728 . . [7.00.6000.20823] .. c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.20823_none_11d3d3ad3e2e0b03\mshtml.dll
.
[7] 2011-12-14 . 17AF64D727545F2804F6E6D998327E3F . 680448 . . [7.0.6002.18551] .. c:\windows\SysWOW64\msvcrt.dll
[7] 2011-12-14 . 17AF64D727545F2804F6E6D998327E3F . 680448 . . [7.0.6002.18551] .. c:\windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.0.6002.18551_none_d306a7e69c340115\msvcrt.dll
[7] 2011-12-14 . A807F65718C263442F0C3613F9BFD267 . 680448 . . [7.0.6002.22755] .. c:\windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.0.6002.22755_none_d39447bfb54e0362\msvcrt.dll
[7] 2009-04-11 . F5E991236960137B1F5449C5E5DF4656 . 679936 . . [7.0.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.0.6002.18005_none_d340af2c9c07e8f9\msvcrt.dll
[7] 2008-01-21 . 04CBEAA089B6A752B3EB660BEE8C4964 . 680448 . . [7.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.0.6001.18000_none_d15536209ee61dad\msvcrt.dll
.
[7] 2009-04-11 . 8617350C9B590B63E620881092751BCB . 223232 . . [6.0.6000.16386] .. c:\windows\SysWOW64\mswsock.dll
[7] 2009-04-11 . 8617350C9B590B63E620881092751BCB . 223232 . . [6.0.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.0.6002.18005_none_ba3ed0122a6d89da\mswsock.dll
[7] 2008-01-21 . 89FD0595EEA4E505CABEFCF7008F2612 . 223232 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.0.6001.18000_none_b85357062d4bbe8e\mswsock.dll
.
[7] 2009-04-11 . 95DAECF0FB120A7B5DA679CC54E37DDE . 592896 . . [6.0.6001.18000] .. c:\windows\SysWOW64\netlogon.dll
[7] 2009-04-11 . 95DAECF0FB120A7B5DA679CC54E37DDE . 592896 . . [6.0.6002.18005] .. c:\windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[7] 2008-01-21 . A8EFC0B6E75B789F7FD3BA5025D4E37F . 592384 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
.
[7] 2009-04-11 . 9A7F4B2EDACD11444D048AA19CBB26AF . 98816 . . [6.0.6001.18000] .. c:\windows\SysWOW64\powrprof.dll
[7] 2009-04-11 . 9A7F4B2EDACD11444D048AA19CBB26AF . 98816 . . [6.0.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-userpowermanagement_31bf3856ad364e35_6.0.6002.18005_none_a505176cf9fa2abd\powrprof.dll
[7] 2008-01-21 . 51832219A52C3535BF4771C375E63F9B . 97280 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-userpowermanagement_31bf3856ad364e35_6.0.6001.18000_none_a3199e60fcd85f71\powrprof.dll
.
[7] 2009-04-11 . 8FC182167381E9915651267044105EE1 . 177152 . . [6.0.6000.16386] .. c:\windows\SysWOW64\scecli.dll
[7] 2009-04-11 . 8FC182167381E9915651267044105EE1 . 177152 . . [6.0.6002.18005] .. c:\windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[7] 2008-01-21 . 28B84EB538F7E8A0FE8B9299D591E0B9 . 177152 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
.
[7] 2006-11-02 . F4E1AA5D59C849A4AB47E895DC76B9C8 . 4608 . . [6.0.6000.16386] .. c:\windows\SysWOW64\sfc.dll
[7] 2006-11-02 . F4E1AA5D59C849A4AB47E895DC76B9C8 . 4608 . . [6.0.6000.16386] .. c:\windows\winsxs\x86_microsoft-windows-sfc_31bf3856ad364e35_6.0.6001.18000_none_a735c34c5c31a578\sfc.dll
.
[7] 2008-01-21 . 3794B461C45882E06856F282EEF025AF . 21504 . . [6.0.6000.16386] .. c:\windows\SysWOW64\svchost.exe
[7] 2008-01-21 . 3794B461C45882E06856F282EEF025AF . 21504 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
.
[7] 2009-04-11 . D7673E4B38CE21EE54C59EEEB65E2483 . 242688 . . [6.0.6000.16386] .. c:\windows\SysWOW64\tapisrv.dll
[7] 2009-04-11 . D7673E4B38CE21EE54C59EEEB65E2483 . 242688 . . [6.0.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-tapiservice_31bf3856ad364e35_6.0.6002.18005_none_e52851e7e21463cb\tapisrv.dll
[7] 2008-01-21 . 680916BB09EE0F3A6ACA7C274B0D633F . 242688 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-tapiservice_31bf3856ad364e35_6.0.6001.18000_none_e33cd8dbe4f2987f\tapisrv.dll
.
[7] 2009-04-11 . D29FDB5DEDBDC1BD882164DC6DC4DD53 . 648704 . . [6.0.6001.18000] .. c:\windows\SysWOW64\user32.dll
[7] 2009-04-11 . D29FDB5DEDBDC1BD882164DC6DC4DD53 . 648704 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_35972b23573c7daf\user32.dll
[7] 2008-01-21 . 3D691030DBD3BD75DE1501BE54F0D425 . 648192 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll
.
[7] 2008-01-21 . 0E135526E9785D085BCD9AEDE6FBCBF9 . 25088 . . [6.0.6000.16386] .. c:\windows\SysWOW64\userinit.exe
[7] 2008-01-21 . 0E135526E9785D085BCD9AEDE6FBCBF9 . 25088 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
.
[7] 2013-10-13 . C36E38AD3C7FAFF0E30C4CBCB28CE7FB . 1129472 . . [9.00.8112.16421] .. c:\windows\SysWOW64\wininet.dll
[7] 2013-10-13 . C36E38AD3C7FAFF0E30C4CBCB28CE7FB . 1129472 . . [9.00.8112.16520] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16520_none_c1db3009dfb83bc8\wininet.dll
[7] 2013-10-13 . F1771715A3DC3DB14BD374F63507878D . 1130496 . . [9.00.8112.20631] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20631_none_c25afd32f8dd10da\wininet.dll
[7] 2013-09-22 . 508484580EA124FB03C41C58D4A63BE1 . 1130496 . . [9.00.8112.20625] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20625_none_c269ce46f8d15a45\wininet.dll
[7] 2013-09-22 . C8ADAA6948993D839D14524847EA5B75 . 1129472 . . [9.00.8112.16514] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16514_none_c1ea011ddfac8533\wininet.dll
[7] 2013-07-31 . 21A5424935A32080A58DD40F2712212C . 1129472 . . [9.00.8112.16506] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16506_none_c1f6d19ddfa29bf0\wininet.dll
[7] 2013-07-31 . 99991FC7D1430A61F27B48AC3D43B028 . 1129984 . . [9.00.8112.20617] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20617_none_c2769ec6f8c77102\wininet.dll
[7] 2013-07-25 . EFA69C15A411D9794131CBCF6B59EA08 . 1129984 . . [9.00.8112.20613] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20613_none_c2729d9ef8cb0ba6\wininet.dll
[7] 2013-07-25 . 6839F14A2507D9273BD13565DD880377 . 1129472 . . [9.00.8112.16502] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16502_none_c1f2d075dfa63694\wininet.dll
[7] 2013-05-29 . 745410A5E043E8F880C932007034F8B6 . 1129984 . . [9.00.8112.20606] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20606_none_c2806e68f8c03bba\wininet.dll
[7] 2013-05-29 . EA952A5C277CABCBA69EA806146BB984 . 1129472 . . [9.00.8112.16496] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16496_none_c195806bdfeb9a42\wininet.dll
[7] 2013-05-16 . 6A25377A76479A0C0BF3DB6FC42FE09A . 1129472 . . [9.00.8112.16490] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16490_none_c18f7eafdff10238\wininet.dll
[7] 2013-05-16 . CC25EA1287613DC45D25A26037B4DBDD . 1129984 . . [9.00.8112.20600] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20600_none_c27a6cacf8c5a3b0\wininet.dll
[7] 2013-04-04 . 2C96B3921B4CDE10DBAED5AAD760DB67 . 1129472 . . [9.00.8112.16483] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16483_none_c19d4f79dfe6324c\wininet.dll
[7] 2013-04-04 . 28B2DD8DBAEE306290A74ED03DB3768F . 1129984 . . [9.00.8112.20593] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20593_none_c21c1c58f90bee07\wininet.dll
[7] 2013-02-22 . C5B6468422DB1C8AA36C32CBB0197E5E . 1129472 . . [9.00.8112.16476] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16476_none_c1ab2043dfdb6260\wininet.dll
[7] 2013-02-22 . 490E24D5E427DFA55B1C1182F0DB861C . 1129984 . . [9.00.8112.20586] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20586_none_c229ed22f9011e1b\wininet.dll
[7] 2013-02-02 . 1284D72C04B553ED5382EA14303D66DB . 1129472 . . [9.00.8112.20580] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20580_none_c223eb66f9068611\wininet.dll
[7] 2013-02-02 . 03728C624D05C2F157BBD46F6B7F6EA0 . 1129472 . . [9.00.8112.16470] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16470_none_c1a51e87dfe0ca56\wininet.dll
[7] 2013-01-08 . B49B56B64F57699A1A663D2CF7D0A56F . 1129472 . . [9.00.8112.16464] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16464_none_c1b3ef9bdfd513c1\wininet.dll
[7] 2013-01-08 . 16C45E6881449C6330567E51C13920FA . 1129472 . . [9.00.8112.20573] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20573_none_c231bc30f8fbb625\wininet.dll
[7] 2012-11-14 . 7FA3A810F383588D46220967DE8B64FF . 1129472 . . [9.00.8112.16457] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16457_none_c1c1c065dfca43d5\wininet.dll
[7] 2012-11-14 . 0635D714351F842D43EA184E75C4A3FF . 1129472 . . [9.00.8112.20565] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20565_none_c23e8cb0f8f1cce2\wininet.dll
[7] 2012-10-03 . ED223944D96ED3B4922B8434AEAA94DA . 1129472 . . [9.00.8112.16455] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16455_none_c1bfbfd1dfcc1127\wininet.dll
[7] 2012-10-03 . 3A7F37F14E9603A28E98D00115F022DD . 1129472 . . [9.00.8112.20562] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20562_none_c23b8bd2f8f480dd\wininet.dll
[7] 2012-08-24 . 2895E29EFCFC0B1BCF8AEE1A0C67913C . 1129472 . . [9.00.8112.20557] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20557_none_c24b5d30f8e7e39f\wininet.dll
[7] 2012-08-24 . 5553611E2F9EA6F613079177F1233068 . 1129472 . . [9.00.8112.16450] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16450_none_c1babe5fdfd09274\wininet.dll
[7] 2012-06-28 . 975129E360241BE751BE93D9E0AC7409 . 1129472 . . [9.00.8112.16448] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16448_none_c1cd909bdfc1413b\wininet.dll
[7] 2012-06-27 . 015A57A7749B28593E52D80DD60CF90A . 1129472 . . [9.00.8112.20554] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20554_none_c2485c52f8ea979a\wininet.dll
[7] 2012-06-02 . 8E87270C4704CF2951E1E7820D6C8A2B . 1129472 . . [9.00.8112.16447] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16447_none_c1cc9051dfc227e4\wininet.dll
[7] 2012-06-02 . E430161A632F9A8FE512DE0CA5685559 . 1129472 . . [9.00.8112.20553] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20553_none_c2475c08f8eb7e43\wininet.dll
[7] 2012-05-17 . 1C191A4F0960F21B5D58C8A65BAF5427 . 1129472 . . [9.00.8112.16446] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16446_none_c1cb9007dfc30e8d\wininet.dll
[7] 2012-05-17 . 43BAC67996D8765A5F1B3A4EA6231E21 . 1129472 . . [9.00.8112.20551] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20551_none_c2455b74f8ed4b95\wininet.dll
[7] 2012-05-16 . 1D94FA7C81D2FFE494AF094619BA706F . 1127424 . . [9.00.8112.16441] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16441_none_c1c68e95dfc78fda\wininet.dll
[7] 2012-02-28 . 07AEE972DE88F8780EA1474DB2CABBE3 . 834048 . . [7.00.6002.18591] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18591_none_036f25939f416512\wininet.dll
[7] 2012-02-28 . 11D6F5BC10D5B10CC157F016AC8BAF8C . 842240 . . [7.00.6002.22805] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22805_none_045e169eb812690d\wininet.dll
[7] 2012-02-28 . 44465367256D1C72B58F5ABAA19E7016 . 1127424 . . [9.00.8112.16443] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.16443_none_c1c88f29dfc5c288\wininet.dll
[7] 2012-02-28 . 11A34DCA08EB2A586246F2D6C2A81D58 . 1127424 . . [9.00.8112.20548] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.1.8112.20548_none_c2572d66f8dee105\wininet.dll
[7] 2011-04-21 . 17413EF7D95632D892B4C914CD7E66F9 . 834048 . . [7.00.6002.18457] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18457_none_03a065199f1b9031\wininet.dll
[7] 2011-04-21 . 3790936B00FBA6EC2053C3E81B42AFCE . 842240 . . [7.00.6002.22629] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22629_none_044c7422b81f0bfd\wininet.dll
[7] 2011-04-21 . DA5A72211661C7F162B332FEA4F09A69 . 833024 . . [7.00.6001.18639] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18639_none_01d191b7a1e338b2\wininet.dll
[7] 2011-04-21 . D53D34CA16BE45211F7A13532D181A1A . 841728 . . [7.00.6001.22905] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22905_none_0277a0eabaec199b\wininet.dll
[7] 2009-05-12 . FF35D495AC08549154D1D96990513CD9 . 826368 . . [7.00.6000.16809] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16809_none_000bbb3da4a45f52\wininet.dll
[7] 2009-05-12 . 65647F41CEC0C8EEC9DF5BC1168EC76C . 827904 . . [7.00.6000.20996] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20996_none_003107debe0dae90\wininet.dll
[7] 2009-05-12 . FB79A2AA5E92653B9A394FE26D799BF8 . 827392 . . [7.00.6001.18203] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18203_none_01ebf827a1d05839\wininet.dll
[7] 2009-05-12 . 6A986C2CD30633447DAB21A4852E40D6 . 827904 . . [7.00.6001.22355] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22355_none_024185eabb14b666\wininet.dll
[7] 2009-05-12 . F18C1B151A0B18C35BF0919A9BA0FA0F . 826368 . . [7.00.6000.16764] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16764_none_ffc5d85da4d98b1e\wininet.dll
[7] 2009-05-12 . 622FE627D15DD920238A993021F0A4D1 . 827904 . . [7.00.6000.20937] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20937_none_0072e7b0bddc2041\wininet.dll
[7] 2009-05-12 . 8F89FFECF6989DD7D9ECCEC6D95D7419 . 827392 . . [7.00.6001.18157] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18157_none_01b9e7cda1f54c23\wininet.dll
[7] 2009-05-12 . 4944C9FFE8903A276590D4215F74B937 . 827904 . . [7.00.6001.22288] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22288_none_0224151ebb2a5917\wininet.dll
[7] 2009-05-12 . 8BF7D225505A4ADA25D9444E91811CEA . 826368 . . [7.00.6000.16757] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16757_none_ffd3a927a4cebb32\wininet.dll
[7] 2009-05-12 . C85EF7DE97ABBF00B16AD11EDFEAC637 . 827904 . . [7.00.6000.20927] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20927_none_007db79cbdd40450\wininet.dll
[7] 2009-05-12 . C373C19F10601C1AFE7E40907AE48694 . 827392 . . [7.00.6001.18148] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18148_none_01c5b803a1ec4989\wininet.dll
[7] 2009-05-12 . 6B2591CDCEFEB8451594288426677CBB . 827904 . . [7.00.6001.22278] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22278_none_022ee50abb223d26\wininet.dll
[7] 2009-05-12 . E74D932CA7B3DA8CDB7A5F11F5A03ABC . 826368 . . [7.00.6000.16711] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16711_none_fff8e71ba4b3b364\wininet.dll
[7] 2009-05-12 . AE7150C0696C656D02FDD48259F4EFF5 . 827904 . . [7.00.6000.20868] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20868_none_00537650bdf39044\wininet.dll
[7] 2009-05-12 . 618A51B5FB9DD5810960F6044C0E9289 . 827392 . . [7.00.6001.18099] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18099_none_0190a6cba213f16e\wininet.dll
[7] 2009-05-12 . EDF59D63DDBC8BE0BB4836EFFFC04BDC . 827904 . . [7.00.6001.22212] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22212_none_0269c2d6baf6fd76\wininet.dll
[7] 2009-05-12 . 9191790BF02A8D759EC2B4E4FA868407 . 826368 . . [7.00.6000.16681] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16681_none_ffad35c1a4ec79d4\wininet.dll
[7] 2009-05-12 . F40594128A6BFDA6C3F0900796895078 . 827392 . . [7.00.6000.20823] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20823_none_0079b48ebdd7a1cd\wininet.dll
[7] 2009-05-12 . 44FD3968AD885026D94450832A78DE8A . 826880 . . [7.00.6001.18063] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18063_none_01ab14d3a2010591\wininet.dll
[7] 2009-05-12 . A86218059C228E7691A13E4CB63C4CDF . 826880 . . [7.00.6001.22167] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22167_none_0238b2c6bb1b0ab7\wininet.dll
[7] 2009-05-12 . DAEED2799D4D19F955C3E90B22A1E91E . 826368 . . [7.00.6000.16643] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16643_none_ffda7605a4ca3cbe\wininet.dll
[7] 2009-05-12 . F7FF1E0D443788D6AE4CBCA593530099 . 827392 . . [7.00.6000.20777] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20777_none_0047a434bdfc95b7\wininet.dll
[7] 2009-05-12 . 482BCCBF1FCBB3378100FF97081438C1 . 826880 . . [7.00.6001.18023] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18023_none_01d65483a1e095cd\wininet.dll
[7] 2009-05-12 . 4E962B645608E6EDB7D31B75921D07FA . 826880 . . [7.00.6001.22120] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22120_none_025cf070bb00e992\wininet.dll
[7] 2009-04-11 . 8777B44511D8BCCF47B5A7CBDC02DE11 . 828416 . . [7.00.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18005_none_03d46c899ef4dd32\wininet.dll
[7] 2008-01-21 . 455D715A840579BDC1CF8E5C1DA76849 . 825856 . . [7.00.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18000_none_01e8f37da1d311e6\wininet.dll
.
[7] 2008-01-21 . B304D47D5744BA20FCB99FB8B2C07B0B . 179200 . . [6.0.6000.16386] .. c:\windows\SysWOW64\ws2_32.dll
[7] 2008-01-21 . B304D47D5744BA20FCB99FB8B2C07B0B . 179200 . . [6.0.6000.16386] .. c:\windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6001.18000_none_f2b7b0c2ce5605c4\ws2_32.dll
[7] 2008-01-21 . B304D47D5744BA20FCB99FB8B2C07B0B . 179200 . . [6.0.6000.16386] .. c:\windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6002.18005_none_f4a329cecb77d110\ws2_32.dll
.
[7] 2006-11-02 . 17C0671BF57057108A6D949510EE42C8 . 4608 . . [6.0.6000.16386] .. c:\windows\SysWOW64\ws2help.dll
[7] 2006-11-02 . 17C0671BF57057108A6D949510EE42C8 . 4608 . . [6.0.6000.16386] .. c:\windows\winsxs\wow64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6001.18000_none_6af84843e4192e9a\ws2help.dll
.
[7] 2009-05-12 . 50514057C28A74BAC2BD04B7B990D615 . 3087360 . . [6.0.6000.16771] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_aba256ac352b2919\explorer.exe
[7] 2009-05-12 . 72B9990E45C25AA3C75C4FB50A9D6CE0 . 3086848 . . [6.0.6000.20947] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_ac5266dd4e2b0a41\explorer.exe
[7] 2009-05-12 . BBD8E74F23D7605CB0CDB57A1B25D826 . 3080704 . . [6.0.6001.18164] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_ad96661c3246ea1e\explorer.exe
[7] 2009-05-12 . E404A65EF890140410E9F3D405841C95 . 3081216 . . [6.0.6001.22298] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_ae03944b4b794317\explorer.exe
[7] 2009-04-11 . 6B08E54A451B3F95E4109DBA7E594270 . 3079168 . . [6.0.6000.16386] .. c:\windows\explorer.exe
[7] 2009-04-11 . 6B08E54A451B3F95E4109DBA7E594270 . 3079168 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_afbebba22f3bab41\explorer.exe
[7] 2008-01-21 . F6D765FB6B457542D954682F50C26E4F . 3080704 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_add342963219dff5\explorer.exe
.
[7] 2008-01-21 . 5DFBCE56E689D90AE9E2FB278F80058E . 134656 . . [6.0.6000.16386] .. c:\windows\regedit.exe
[7] 2008-01-21 . 5DFBCE56E689D90AE9E2FB278F80058E . 161792 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.0.6001.18000_none_504d50e8943617cd\regedit.exe
.
[7] 2010-06-28 . 7C6F74A11FCF5745B36CB8085B7DE3FB . 1316864 . . [6.0.6002.22433] .. c:\windows\winsxs\x86_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6002.22433_none_ae70528d08aae434\ole32.dll
[7] 2010-06-28 . 9586E7CB2255A8B097A7E4538202585E . 1316864 . . [6.0.6000.16386] .. c:\windows\SysWOW64\ole32.dll
[7] 2010-06-28 . 9586E7CB2255A8B097A7E4538202585E . 1316864 . . [6.0.6000.16386] .. c:\windows\winsxs\x86_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6002.18277_none_adbf7553efaa1c63\ole32.dll
[7] 2010-06-28 . 64A319477AF21806B8A17E8A3A3FF8BC . 1315840 . . [6.0.6001.22720] .. c:\windows\winsxs\x86_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6001.22720_none_ac91afb30b7f271a\ole32.dll
[7] 2010-06-28 . AA406846DD60E3A4536DBAAB4037B685 . 1315840 . . [6.0.6001.18498] .. c:\windows\winsxs\x86_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6001.18498_none_abc461f7f2931b51\ole32.dll
[7] 2009-04-11 . C50A0AB19094BC362FBA69E105EBCCFD . 1316864 . . [6.0.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6002.18005_none_ae092067ef732bd0\ole32.dll
[7] 2008-01-21 . 3B634E4BE373D6D987EBF906B43FAAB3 . 1315328 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6001.18000_none_ac1da75bf2516084\ole32.dll
.
[7] 2010-04-16 . E609A492AD596187CEA24E8418FF082F . 502784 . . [1.0626.6002.22384] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.0.6002.22384_none_af1813076efd8bc3\usp10.dll
[7] 2010-04-16 . 80FFF14F1757B9AF8BE9D314FC1AE88B . 502272 . . [1.0626.6002.18244] .. c:\windows\SysWOW64\usp10.dll
[7] 2010-04-16 . 80FFF14F1757B9AF8BE9D314FC1AE88B . 502272 . . [1.0626.6002.18244] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.0.6002.18244_none_aeb9b5ec55bf7c35\usp10.dll
[7] 2010-04-16 . 8CB1162DD3586683D71BCB303C1FF54F . 502272 . . [1.0626.6001.22672] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.0.6001.22672_none_ad3a707771d0e800\usp10.dll
[7] 2010-04-16 . A23E4692716C25E5AEA300ED74E73A1C . 501760 . . [1.0626.6001.18461] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.0.6001.18461_none_acbaa16858ac15c7\usp10.dll
[7] 2009-04-11 . 5A8E28037289FCCBF7AD3FC57DF7048F . 502272 . . [1.0626.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.0.6002.18005_none_aee5f21a559e2b7a\usp10.dll
[7] 2008-01-21 . 3122DAF86B33ED8AC4662D07593025D7 . 501760 . . [1.0626.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.0.6001.18000_none_acfa790e587c602e\usp10.dll
.
[7] 2006-11-02 . 919CC2A0476D5A6A4C935D4B88E29912 . 4608 . . [6.0.6000.16386] .. c:\windows\SysWOW64\ksuser.dll
[7] 2006-11-02 . 919CC2A0476D5A6A4C935D4B88E29912 . 4608 . . [6.0.6000.16386] .. c:\windows\winsxs\x86_microsoft-windows-d..tshow-kernelsupport_31bf3856ad364e35_6.0.6001.18000_none_e8019c5c974c4491\ksuser.dll
.
[7] 2006-11-02 . 22BFD03DF51065A9ED8D17F8FB72296B . 8704 . . [6.0.6000.16386] .. c:\windows\SysWOW64\ctfmon.exe
[7] 2006-11-02 . 22BFD03DF51065A9ED8D17F8FB72296B . 8704 . . [6.0.6000.16386] .. c:\windows\winsxs\x86_microsoft-windows-t..cesframework-ctfmon_31bf3856ad364e35_6.0.6000.16386_none_9af9cad793a67953\ctfmon.exe
.
[7] 2009-07-10 . 1E3FDB80E40A3CE645F229DFBDFB7694 . 247808 . . [6.0.6001.18287] .. c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18287_none_cce0e39c1d282219\shsvcs.dll
[7] 2009-07-10 . 94285A002D2826D2FD1C0806455136E9 . 245760 . . [6.0.6000.16883] .. c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6000.16883_none_caf6a3ce20052bcc\shsvcs.dll
[7] 2009-07-10 . 6898575E052CE7CB1CB87622EF187CDA . 245760 . . [6.0.6000.21081] .. c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6000.21081_none_cb7e18273924cc2a\shsvcs.dll
[7] 2009-07-10 . 6669714ACE90E9BB4E8C1D550C67B160 . 247808 . . [6.0.6001.22467] .. c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.22467_none_cd80222536358728\shsvcs.dll
[7] 2009-07-10 . F0942394F642F5CE3D9A86474FA293FA . 247808 . . [6.0.6002.22169] .. c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.22169_none_cf6894a1335a0efa\shsvcs.dll
[7] 2009-07-10 . C7230FBEE14437716701C15BE02C27B8 . 247808 . . [6.0.6000.16386] .. c:\windows\SysWOW64\shsvcs.dll
[7] 2009-07-10 . C7230FBEE14437716701C15BE02C27B8 . 247808 . . [6.0.6002.18063] .. c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.18063_none_ced8f61a1a41d726\shsvcs.dll
[7] 2009-04-11 . C818C44C201898399BF999BB6B35D4E3 . 247296 . . [6.0.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.18005_none_cf1bd6361a0f622e\shsvcs.dll
[7] 2008-01-21 . 27F10F348E508243F6254846F8370D0D . 247296 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18000_none_cd305d2a1ced96e2\shsvcs.dll
.
[7] 2006-11-02 . 2EC53B5A351C4D443896DBAD117F7E82 . 4608 . . [6.0.6000.16386] .. c:\windows\SysWOW64\msimg32.dll
[7] 2006-11-02 . 2EC53B5A351C4D443896DBAD117F7E82 . 4608 . . [6.0.6000.16386] .. c:\windows\winsxs\x86_microsoft-windows-gdi-painting_31bf3856ad364e35_6.0.6001.18000_none_776bd81b1c0c11c1\msimg32.dll
.
[7] 2006-11-02 . 7F15B4953378C8B5161D65C26D5FED4D . 11776 . . [6.0.6000.16386] .. c:\windows\SysWOW64\cngaudit.dll
[7] 2006-11-02 . 7F15B4953378C8B5161D65C26D5FED4D . 11776 . . [6.0.6000.16386] .. c:\windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
.
[7] 2008-01-21 . 101BA3EA053480BB5D957EF37C06B5ED . 96768 . . [6.0.6000.16386] .. c:\windows\SysWOW64\wininit.exe
[7] 2008-01-21 . 101BA3EA053480BB5D957EF37C06B5ED . 96768 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
.
[7] 2008-01-21 . 7A5F8218325F00396DAEA2F985FA0ECB . 18944 . . [6.0.6001.18000] .. c:\windows\SysWOW64\ias.dll
[7] 2008-01-21 . 7A5F8218325F00396DAEA2F985FA0ECB . 18944 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-n..ion_service_runtime_31bf3856ad364e35_6.0.6001.18000_none_f900daa442864318\ias.dll
[7] 2008-01-21 . 7A5F8218325F00396DAEA2F985FA0ECB . 18944 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-n..ion_service_runtime_31bf3856ad364e35_6.0.6002.18005_none_faec53b03fa80e64\ias.dll
.
[7] 2010-08-31 16:49 . 5E9F187AC6BADB58C21C4E3A18DD1F62 . 954288 . . [4.1.6151] .. c:\windows\winsxs\x86_microsoft-windows-mfc40u_31bf3856ad364e35_6.0.6002.22478_none_f53f7ef86c05abb0\mfc40u.dll
[7] 2010-08-31 15:46 . 2A64FE405579BB073FBABD68AF1468E7 . 954288 . . [4.1.6140] .. c:\windows\SysWOW64\mfc40u.dll
[7] 2010-08-31 15:46 . 2A64FE405579BB073FBABD68AF1468E7 . 954288 . . [4.1.6151] .. c:\windows\winsxs\x86_microsoft-windows-mfc40u_31bf3856ad364e35_6.0.6002.18305_none_f4fe90c352b1fc4a\mfc40u.dll
[7] 2010-08-31 15:41 . 13D0F7769927B74782CB59D8CCEF9E10 . 954288 . . [4.1.6151] .. c:\windows\winsxs\x86_microsoft-windows-mfc40u_31bf3856ad364e35_6.0.6001.18523_none_f3007c89559daf33\mfc40u.dll
[7] 2010-08-31 15:17 . 1C1486BB262DF6DFD298110BC495906E . 954288 . . [4.1.6151] .. c:\windows\winsxs\x86_microsoft-windows-mfc40u_31bf3856ad364e35_6.0.6001.22754_none_f36aabc06ed2b94e\mfc40u.dll
[7] 2006-11-02 09:46 . BA8639F9EB0F74F2946DE6DE1AF4691F . 924944 . . [4.1.6140] .. c:\windows\winsxs\x86_microsoft-windows-mfc40u_31bf3856ad364e35_6.0.6000.16386_none_f0dc500958a528b5\mfc40u.dll
.
[7] 2008-01-21 . 68308183F4AE0BE7BF8ECD07CB297999 . 259072 . . [6.0.6000.16386] .. c:\windows\SysWOW64\upnphost.dll
[7] 2008-01-21 . 68308183F4AE0BE7BF8ECD07CB297999 . 259072 . . [6.0.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-upnpdevicehost_31bf3856ad364e35_6.0.6001.18000_none_285b7a4b21423100\upnphost.dll
.
[7] 2009-04-11 . 84B8827562B005C118CADBA0F25DB2C6 . 444416 . . [6.0.6000.16386] .. c:\windows\SysWOW64\dsound.dll
[7] 2009-04-11 . 84B8827562B005C118CADBA0F25DB2C6 . 444416 . . [6.0.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-audio-dsound_31bf3856ad364e35_6.0.6002.18005_none_5a8737643f04aa4c\dsound.dll
[7] 2008-01-21 . 8A7B8DA5CA558D2DE47086BB23556543 . 444416 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-audio-dsound_31bf3856ad364e35_6.0.6001.18000_none_589bbe5841e2df00\dsound.dll
.
[7] 2009-04-11 . 8AAEEE8E59A70F37579993D118A34EE0 . 1788416 . . [6.0.6002.18005] .. c:\windows\SysWOW64\d3d9.dll
[7] 2009-04-11 . 8AAEEE8E59A70F37579993D118A34EE0 . 1788416 . . [6.0.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-directx-direct3d9_31bf3856ad364e35_6.0.6002.18005_none_c438e5b15de80145\d3d9.dll
[7] 2008-01-21 . FAB8F08EC64A54917C07BDB6DC811C95 . 1788928 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-directx-direct3d9_31bf3856ad364e35_6.0.6001.18000_none_c24d6ca560c635f9\d3d9.dll
.
[7] 2008-01-21 . FA2A3AFADC4FB47DBC234A4E57F92CDB . 522752 . . [6.0.6000.16386] .. c:\windows\SysWOW64\ddraw.dll
[7] 2008-01-21 . FA2A3AFADC4FB47DBC234A4E57F92CDB . 522752 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-directx-directdraw_31bf3856ad364e35_6.0.6001.18000_none_0505a2ecc0013ebd\ddraw.dll
.
[7] 2009-04-11 06:28 . A944A73CEC5921B871542FE5CC5E03E4 . 88576 . . [6.0.6002.18005] .. c:\windows\SysWOW64\olepro32.dll
[7] 2009-04-11 06:28 . A944A73CEC5921B871542FE5CC5E03E4 . 88576 . . [6.0.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-ole-automation-legacy_31bf3856ad364e35_6.0.6002.18005_none_3bff339efed611ca\olepro32.dll
[7] 2008-01-21 02:48 . AE70AE6F0760793D4893C3735EEC7292 . 88576 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-ole-automation-legacy_31bf3856ad364e35_6.0.6001.18000_none_3a13ba9301b4467e\olepro32.dll
.
[7] 2006-11-02 . BA7C3E9DD6B1A632124C8659E8014028 . 39424 . . [6.0.6000.16386] .. c:\windows\SysWOW64\perfctrs.dll
[7] 2006-11-02 . BA7C3E9DD6B1A632124C8659E8014028 . 39424 . . [6.0.6000.16386] .. c:\windows\winsxs\x86_microsoft-windows-p..ormancebasecounters_31bf3856ad364e35_6.0.6001.18000_none_31733dc35d19d298\perfctrs.dll
[7] 2006-11-02 . BA7C3E9DD6B1A632124C8659E8014028 . 39424 . . [6.0.6000.16386] .. c:\windows\winsxs\x86_microsoft-windows-p..ormancebasecounters_31bf3856ad364e35_6.0.6002.18005_none_335eb6cf5a3b9de4\perfctrs.dll
.
[7] 2009-04-11 . 69827805A221C21450BA22F4326A2EE3 . 20480 . . [6.0.6002.18005] .. c:\windows\SysWOW64\version.dll
[7] 2009-04-11 . 69827805A221C21450BA22F4326A2EE3 . 20480 . . [6.0.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-version_31bf3856ad364e35_6.0.6002.18005_none_16e9c83b4e078740\version.dll
[7] 2008-01-21 . 187D588F7A1A45DE48B8540401A90850 . 20480 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-version_31bf3856ad364e35_6.0.6001.18000_none_14fe4f2f50e5bbf4\version.dll
.
[7] 2013-10-13 . 06085B62BC7E0C8E2605CEA38774D956 . 757488 . . [9.00.8112.16520] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16520_none_bf1bdebbd86924e7\iexplore.exe
[7] 2013-10-13 . 2D64E29ADB5DEB40446796A9C42417E3 . 757488 . . [9.00.8112.20631] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20631_none_bf9babe4f18df9f9\iexplore.exe
[7] 2013-09-22 . F87E95A127E83277B9AE500D7A18C998 . 757400 . . [9.00.8112.20625] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20625_none_bfaa7cf8f1824364\iexplore.exe
[7] 2013-09-22 . 45BDA923BE52906D1460BCB13AC2AB7A . 757400 . . [9.00.8112.16514] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16514_none_bf2aafcfd85d6e52\iexplore.exe
[7] 2013-07-31 . AA9CBDCD4675A48755DDA3A73BE3E283 . 757400 . . [9.00.8112.16506] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16506_none_bf37804fd853850f\iexplore.exe
[7] 2013-07-31 . 10C1F2EC48D524AE10229AACD37B172A . 757400 . . [9.00.8112.20617] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20617_none_bfb74d78f1785a21\iexplore.exe
[7] 2013-07-25 . 139C8953AC56A9E559C7DEF07BC45ED7 . 757400 . . [9.00.8112.20613] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20613_none_bfb34c50f17bf4c5\iexplore.exe
[7] 2013-07-25 . 57EC630DBD5F0713E77CB3540AB80A8E . 757400 . . [9.00.8112.16502] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16502_none_bf337f27d8571fb3\iexplore.exe
[7] 2013-05-29 . 33E62E4EFC2ACA8EC63A8926F26D3889 . 757400 . . [9.00.8112.20606] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20606_none_bfc11d1af17124d9\iexplore.exe
[7] 2013-05-29 . EE12BA876C4190532A4085994BA9B616 . 757400 . . [9.00.8112.16496] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16496_none_bed62f1dd89c8361\iexplore.exe
[7] 2013-05-16 . 67EE46FD4D3B56531C5DD1BDC149275A . 757400 . . [9.00.8112.16490] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16490_none_bed02d61d8a1eb57\iexplore.exe
[7] 2013-05-16 . A8732CEDB2C0EE7AFC08F867A47BB3EC . 757400 . . [9.00.8112.20600] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20600_none_bfbb1b5ef1768ccf\iexplore.exe
[7] 2013-04-04 . 3F00BE80B9CEA20B7FE7363D15EDDB94 . 757360 . . [9.00.8112.16483] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16483_none_beddfe2bd8971b6b\iexplore.exe
[7] 2013-04-04 . C036AB1ED8BAC04FE4A349BA263077BB . 757360 . . [9.00.8112.20593] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20593_none_bf5ccb0af1bcd726\iexplore.exe
[7] 2013-02-22 . 4145E2B5663F6FACC08EFDB17B658BB2 . 757360 . . [9.00.8112.20586] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20586_none_bf6a9bd4f1b2073a\iexplore.exe
[7] 2013-02-22 . 32732CEDE2A1106B736EF3D84054EE04 . 757376 . . [9.00.8112.16476] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16476_none_beebcef5d88c4b7f\iexplore.exe
[7] 2013-02-02 . DDE5A0DFAF7C6370FB36402D7A746ED3 . 757296 . . [9.00.8112.16470] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16470_none_bee5cd39d891b375\iexplore.exe
[7] 2013-02-02 . A285E1965C115031DA02B777EE9D7689 . 757280 . . [9.00.8112.20580] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20580_none_bf649a18f1b76f30\iexplore.exe
[7] 2013-01-08 . 698EB1E5F8C66344D97C00B5699E871D . 757280 . . [9.00.8112.16464] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16464_none_bef49e4dd885fce0\iexplore.exe
[7] 2013-01-08 . F05982E56ABD835AA8DF260EEC873E5B . 757280 . . [9.00.8112.20573] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20573_none_bf726ae2f1ac9f44\iexplore.exe
[7] 2012-11-14 . 0D286C0FE561D1A7EB30E83A0FF305B2 . 757296 . . [9.00.8112.16457] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16457_none_bf026f17d87b2cf4\iexplore.exe
[7] 2012-11-14 . F691418EE9A6344AEB5C1B0518FBF8AE . 757280 . . [9.00.8112.20565] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20565_none_bf7f3b62f1a2b601\iexplore.exe
[7] 2012-10-03 . 96A360002311ECE53952AF2F5B4CD64E . 748680 . . [9.00.8112.16455] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16455_none_bf006e83d87cfa46\iexplore.exe
[7] 2012-10-03 . 7FC9E840B32E9DFBFBBA92BA5E9B97C2 . 748680 . . [9.00.8112.20562] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20562_none_bf7c3a84f1a569fc\iexplore.exe
[7] 2012-08-24 . 62188720CE27B982B4285C03163C9FB3 . 748680 . . [9.00.8112.20557] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20557_none_bf8c0be2f198ccbe\iexplore.exe
[7] 2012-08-24 . 22CC6CDBA678790046693654C3B212E4 . 748680 . . [9.00.8112.16450] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16450_none_befb6d11d8817b93\iexplore.exe
[7] 2012-06-28 . 32F1A71CC1943BD537DA1516E0CB6AF3 . 748664 . . [9.00.8112.16448] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16448_none_bf0e3f4dd8722a5a\iexplore.exe
[7] 2012-06-27 . 4B649ED3CDC17707898E4948AAB72528 . 748664 . . [9.00.8112.20554] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20554_none_bf890b04f19b80b9\iexplore.exe
[7] 2012-06-02 . 34B01BBD8F00B6B9C9248DC4F1E3CD01 . 748664 . . [9.00.8112.16447] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16447_none_bf0d3f03d8731103\iexplore.exe
[7] 2012-06-02 . BE967C74B89577B78FB57C061E12B04C . 748664 . . [9.00.8112.20553] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20553_none_bf880abaf19c6762\iexplore.exe
[7] 2012-05-17 . 0129BB16161C2FD9A6B19111AB047198 . 748664 . . [9.00.8112.16446] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16446_none_bf0c3eb9d873f7ac\iexplore.exe
[7] 2012-05-17 . 268982F1FD671A077C6A2AF41E351436 . 748664 . . [9.00.8112.20551] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20551_none_bf860a26f19e34b4\iexplore.exe
[7] 2012-05-16 . 904E13BA41AF2E353A32CF351CA53639 . 748336 . . [9.00.8112.16421] .. c:\windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16421_none_bf1cdd1fd8684117\iexplore.exe
[7] 2011-04-21 . 77B9A891222FB46B13E414B99E1AF842 . 634648 . . [7.00.6001.18639] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18639_none_95bde41906ccdac6\iexplore.exe
[7] 2011-04-21 . 6C93AC7C0A8718E2A1543DB1B1B3B19F . 634648 . . [7.00.6001.22905] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22905_none_9663f34c1fd5bbaf\iexplore.exe
[7] 2009-05-12 . 0844F5B9CB3BB85A917D347EF1565B6C . 634024 . . [7.00.6000.16809] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16809_none_93f80d9f098e0166\iexplore.exe
[7] 2009-05-12 . F0B1CA517977BA2FF6DA33F1B966C488 . 634024 . . [7.00.6000.20996] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20996_none_941d5a4022f750a4\iexplore.exe
[7] 2009-05-12 . D762642A109433EEDCD332B0A9511137 . 634024 . . [7.00.6000.16764] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16764_none_93b22abf09c32d32\iexplore.exe
[7] 2009-05-12 . 4CBA2F58668F2D5F3259CBE73E227F25 . 634024 . . [7.00.6000.20937] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20937_none_945f3a1222c5c255\iexplore.exe
[7] 2009-05-12 . 19403B64906C9EAC627E3C10847B0FDA . 633632 . . [7.00.6000.16757] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16757_none_93bffb8909b85d46\iexplore.exe
[7] 2009-05-12 . 6655B851D9EEF7C83395EE52D551B448 . 633632 . . [7.00.6000.20927] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20927_none_946a09fe22bda664\iexplore.exe
[7] 2009-05-12 . 157F8DE991396C536820D7FA5C8DCF7D . 625664 . . [7.00.6000.16711] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16711_none_93e5397d099d5578\iexplore.exe
[7] 2009-05-12 . 4DBD95312B1C96C5285D38F1D748CD4D . 625664 . . [7.00.6000.20868] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20868_none_943fc8b222dd3258\iexplore.exe
[7] 2009-05-12 . 07ED775D6DB4BFA96D7CFB09EB228418 . 625664 . . [7.00.6000.16681] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16681_none_9399882309d61be8\iexplore.exe
[7] 2009-05-12 . 9F1427F203CA078005C9943800929640 . 625664 . . [7.00.6000.20823] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20823_none_946606f022c143e1\iexplore.exe
[7] 2009-05-12 . 9437CA21CD48C9B6BFD6F5AC0143D251 . 625664 . . [7.00.6000.16643] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16643_none_93c6c86709b3ded2\iexplore.exe
[7] 2009-05-12 . 182CAF7403705ACCB51211A761080B8F . 625664 . . [7.00.6000.20777] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20777_none_9433f69622e637cb\iexplore.exe
[7] 2009-04-11 . 2C5168C856455CC43C4B4E1CC1920001 . 636080 . . [7.00.6002.18005] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_97c0beeb03de7f46\iexplore.exe
[7] 2008-01-21 . 5B92133D3E7FB2644677686305E29E81 . 625664 . . [7.00.6001.18000] .. c:\windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_95d545df06bcb3fa\iexplore.exe
.
.
[7] 2009-04-11 . 83199EF88D691E730B80666E29F90D58 . 17408 . . [6.0.6000.16386] .. c:\windows\SysWOW64\midimap.dll
[7] 2009-04-11 . 83199EF88D691E730B80666E29F90D58 . 17408 . . [6.0.6002.18005] .. c:\windows\winsxs\x86_microsoft-windows-audio-mmecore-other_31bf3856ad364e35_6.0.6002.18005_none_8ee941100db1acf2\midimap.dll
[7] 2008-01-21 . D7F1F6C72276A15579D5761098018891 . 17408 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-audio-mmecore-other_31bf3856ad364e35_6.0.6001.18000_none_8cfdc804108fe1a6\midimap.dll
.
[7] 2006-11-02 . A7D525E5C0D91C8C1D84C6BCD25AD77D . 10240 . . [6.0.6000.16386] .. c:\windows\SysWOW64\rasadhlp.dll
[7] 2006-11-02 . A7D525E5C0D91C8C1D84C6BCD25AD77D . 10240 . . [6.0.6000.16386] .. c:\windows\winsxs\wow64_microsoft-windows-rasautodial_31bf3856ad364e35_6.0.6001.18000_none_764d448c52115294\rasadhlp.dll
.
[7] 2008-01-21 . 22CFAEB9172F5F198048401485CD0571 . 9216 . . [6.0.6000.16386] .. c:\windows\SysWOW64\WSHTCPIP.DLL
[7] 2008-01-21 . 22CFAEB9172F5F198048401485CD0571 . 9216 . . [6.0.6001.18000] .. c:\windows\winsxs\x86_microsoft-windows-winsock-helper-tcpip_31bf3856ad364e35_6.0.6001.18000_none_cbb305c23187855a\WSHTCPIP.DLL
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-01-28 61440]
"HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-12-04 75016]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"UpdatePDIRShortCut"="c:\program files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"UpdatePSTShortCut"="c:\program files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" [2009-02-02 210216]
"TSMAgent"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2009-04-10 1328424]
"CLMLServer for HP TouchSmart"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2009-04-10 185640]
"DVDAgent"="c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2009-03-19 1148200]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-06 224616]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-03-06 4767304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
Themes
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-10 17:16]
.
2013-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-14 17:37]
.
2013-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-14 17:37]
.
2013-11-01 c:\windows\Tasks\PCDRScheduledMaintenance.job
- c:\program files\PC-Doctor for Windows\pcdr5cuiw32.exe [2009-02-02 18:59]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 22:32    133840    ----a-w-    c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2008-08-19 333344]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-12-07 5889816]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Pavilion&pf=cndt
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Pavilion&pf=cndt
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
FF - ProfilePath - c:\users\James\AppData\Roaming\Mozilla\Firefox\Profiles\txg0x96c.default-1386298911882\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
SafeBoot-mbamchameleon
SafeBoot-WudfPf
SafeBoot-WudfRd
Toolbar-10 - (no file)
AddRemove-AIM - c:\users\James\AppData\Local\AOL\AIM\uninstall.exe
AddRemove-Gamers Unite! Snag Bar - c:\users\James\AppData\Roaming\Gamers Unite! Snag Bar\uninstall.exe
AddRemove-Google Chrome - c:\users\James\AppData\Local\Google\Chrome\Application\31.0.1650.57\Installer\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCDSRVC{F36B3A4C-F95654BD-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{1E61ED7C-7CB8-49D6-B9E9-AB4C880C8414}"=hex:51,66,7a,6c,4c,1d,38,12,12,ee,72,
   1a,8a,32,b8,0c,c6,ff,e8,0c,8d,52,c0,00
"{8E5E2654-AD2D-48BF-AC2D-D17F00898D06}"=hex:51,66,7a,6c,4c,1d,38,12,3a,25,4d,
   8a,1f,e3,d1,0d,d3,3b,92,3f,05,d7,c9,12
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
   72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
   aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd,
   d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
   df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7}"=hex:51,66,7a,6c,4c,1d,38,12,19,c7,a0,
   e8,38,54,d3,01,c4,41,3b,b9,ea,bd,0b,b3
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:c0,ff,30,ff,41,59,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,38,4a,19,45,ed,4a,5c,41,ad,88,e9,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,38,4a,19,45,ed,4a,5c,41,ad,88,e9,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
Completion time: 2013-12-07  22:10:29
ComboFix-quarantined-files.txt  2013-12-08 03:10
.
Pre-Run: 596,366,614,528 bytes free
Post-Run: 626,711,564,288 bytes free
.
- - End Of File - - 24F7FE0E4F40BB11F5257A325D3025BF
81CD5EC01DB0CE57EDD853F82462EF27
 



#10 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:12:04 PM

Posted 07 December 2013 - 10:58 PM


Hello totalsiege

Yes go back into normal mode

At this time I would like you to run this script for me and it is a good time to check out the computer to see if there is anything else that needs to be addressed.

:Run CFScript:

Please start by opening Notepad and copy/paste the text in the box into the window:

ClearJavaCache::


 
Save it to your desktop as CFScript.txt

Referring to the picture above, drag CFScript.txt into ComboFix.exe
CFScriptB-4.gif
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"
  • In your next post I need the following
    • report from Combofix
    • let me know of any problems you may have had
    • How is the computer doing now after running the script?
Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#11 totalsiege

totalsiege
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:04 AM

Posted 08 December 2013 - 12:34 AM

When I tried going to normal mode it was very slow and programs were missing also trying to do almost anything I would get an error(The system could not find the environment option that was entered.). This is an example of it from the event viewer. Programs that had a admin icon on the button were unresponsive. No error they just wouldn't work. I have attached the combofix log.

 

Log Name:      System
Source:        Service Control Manager
Date:          12/7/2013 10:58:32 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      James-PC
Description:
The Application Information service terminated with the following error:
The system could not find the environment option that was entered.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908D1-A6D7-4695-8E1E-26931D2012F4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2013-12-08T03:58:32.000Z" />
    <EventRecordID>343457</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>System</Channel>
    <Computer>James-PC</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Application Information</Data>

ComboFix 13-12-07.01 - James 12/07/2013  23:34:49.1.4 - x64 NETWORK
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.8190.7093 [GMT -5:00]
Running from: c:\users\James\Desktop\ComboFix.exe
Command switches used :: c:\users\James\Desktop\CFscript.txt
AV: avast! Internet Security *Enabled/Outdated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Enabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Enabled/Outdated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((   Files Created from 2013-11-08 to 2013-12-08  )))))))))))))))))))))))))))))))
.
.
2013-12-08 04:45 . 2013-12-08 04:45    --------    d-----w-    c:\users\James\AppData\Local\temp
2013-12-08 04:45 . 2013-12-08 04:45    --------    d-----w-    c:\users\Default\AppData\Local\temp
2013-12-08 04:15 . 2013-12-08 04:15    --------    d-----w-    c:\users\James\WPDNSE
2013-12-08 03:19 . 2013-12-08 03:19    --------    d-----w-    c:\users\James\plugtmp-2
2013-12-08 01:30 . 2013-12-08 02:32    --------    d-----w-    c:\program files\3
2013-12-07 23:42 . 2013-12-07 23:42    --------    d-----w-    c:\program files (x86)\FileASSASSIN
2013-12-07 17:32 . 2013-12-07 18:16    --------    d-----w-    C:\AdwCleaner
2013-12-07 01:23 . 2013-12-07 01:23    --------    d-----w-    c:\users\James\Deployment
2013-12-07 01:19 . 2013-12-07 03:26    --------    d-----w-    c:\users\James\plugtmp-1
2013-12-07 00:48 . 2013-12-07 00:48    --------    d-----w-    c:\program files\CCleaner
2013-12-06 04:13 . 2013-12-06 04:13    --------    d-----w-    c:\users\James\Skype
2013-12-06 04:12 . 2013-12-06 04:12    --------    d-----w-    c:\users\James\MWTrace
2013-12-06 04:10 . 2013-12-06 04:10    --------    d-----w-    c:\windows\SysWow64\_avast_
2013-12-06 04:10 . 2013-12-08 03:43    --------    d-----w-    c:\windows\system32\_avast_
2013-12-06 04:07 . 2013-12-06 04:07    --------    d-----w-    c:\users\James\plugtmp
2013-12-06 04:07 . 2013-12-08 03:19    --------    d---a-w-    c:\users\James\acro_rd_dir
2013-12-06 01:44 . 2013-12-08 00:04    --------    d-----w-    c:\programdata\Malwarebytes' Anti-Malware (portable)
2013-12-06 01:43 . 2013-12-06 01:43    91352    ----a-w-    c:\windows\system32\drivers\mbamchameleon.sys
2013-12-06 01:32 . 2013-12-06 01:32    --------    d-----w-    c:\users\James\AppData\Roaming\Malwarebytes
2013-12-06 01:32 . 2013-12-06 01:32    --------    d-----w-    c:\programdata\Malwarebytes
2013-12-06 01:32 . 2013-12-06 01:32    --------    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
2013-12-06 01:32 . 2013-04-04 19:50    25928    ----a-w-    c:\windows\system32\drivers\mbam.sys
2013-12-06 01:27 . 2013-12-06 01:27    --------    d-----w-    c:\users\James\Low
2013-12-05 02:17 . 2013-12-06 04:02    --------    d-----w-    C:\sfzone_profile
2013-12-04 12:06 . 2013-11-08 03:12    10285968    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{B50E1DE8-7EB6-4210-BEE4-1E9513332C25}\mpengine.dll
2013-12-04 08:44 . 2013-12-04 11:39    --------    d-----w-    c:\users\Guest
2013-12-03 11:00 . 2013-12-03 11:00    --------    d-----w-    C:\sh4ldr
2013-12-03 11:00 . 2013-12-03 11:00    --------    d-----w-    c:\program files\Enigma Software Group
2013-12-03 10:59 . 2013-12-03 11:00    --------    d-----w-    c:\windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
2013-12-03 05:24 . 2013-12-03 05:24    --------    d-----w-    c:\users\James\AppData\Local\VS Revo Group
2013-12-03 05:24 . 2013-12-03 05:24    --------    d-----w-    c:\program files\VS Revo Group
2013-12-03 01:50 . 2013-12-03 01:50    --------    d-----w-    c:\program files (x86)\VS Revo Group
2013-11-30 20:37 . 2013-11-30 20:53    --------    d-----w-    c:\users\James\AppData\Local\cache
2013-11-30 20:37 . 2013-12-08 02:56    --------    d-----w-    c:\users\James\AppData\Local\Mobogenie
2013-11-29 06:56 . 2013-11-29 06:56    --------    d-----w-    c:\users\James\AppData\Local\LogMeIn
2013-11-29 06:56 . 2013-11-29 06:56    --------    d-----w-    c:\programdata\LogMeIn
2013-11-28 19:43 . 2013-11-28 19:43    --------    d-----w-    c:\users\James\AppData\Local\LogMeIn Rescue
2013-11-28 19:41 . 2013-12-04 11:35    --------    d-----w-    c:\program files (x86)\LogMeIn Rescue Technician Console
2013-11-14 08:01 . 2013-10-13 15:09    10926080    ----a-w-    c:\windows\system32\ieframe.dll
2013-11-13 11:45 . 2013-10-11 04:23    462848    ----a-w-    c:\windows\system32\IKEEXT.DLL
2013-11-13 11:45 . 2013-10-11 04:23    781824    ----a-w-    c:\windows\system32\FWPUCLNT.DLL
2013-11-13 11:45 . 2013-10-11 02:07    596480    ----a-w-    c:\windows\SysWow64\FWPUCLNT.DLL
2013-11-13 11:45 . 2013-10-03 15:02    1278976    ----a-w-    c:\windows\system32\crypt32.dll
2013-11-13 11:45 . 2013-10-03 12:45    993792    ----a-w-    c:\windows\SysWow64\crypt32.dll
2013-11-13 11:45 . 2013-10-03 15:03    389632    ----a-w-    c:\windows\system32\gdi32.dll
2013-11-13 11:45 . 2013-10-03 12:46    304128    ----a-w-    c:\windows\SysWow64\gdi32.dll
2013-11-13 11:45 . 2013-09-04 02:31    404992    ----a-w-    c:\windows\system32\drivers\afd.sys
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-11 10:50 . 2012-05-10 05:56    267936    ------w-    c:\windows\system32\MpSigStub.exe
2013-10-09 17:16 . 2012-05-10 11:37    71048    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-09 17:16 . 2012-05-10 11:37    692616    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-01-28 61440]
"HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-12-04 75016]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"UpdatePDIRShortCut"="c:\program files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"UpdatePSTShortCut"="c:\program files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" [2009-02-02 210216]
"TSMAgent"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2009-04-10 1328424]
"CLMLServer for HP TouchSmart"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2009-04-10 185640]
"DVDAgent"="c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2009-03-19 1148200]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-06 224616]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-03-06 4767304]
"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
"masqform.exe"="c:\program files (x86)\PureEdge\Viewer 6.5\masqform.exe" [2005-07-04 643072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2013-04-04 532040]
"Malwarebytes Anti-Malware (cleanup)"="c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll" [2013-04-04 1127496]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ECACHE
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
Themes
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-10 17:16]
.
2013-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-14 17:37]
.
2013-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-14 17:37]
.
2013-11-01 c:\windows\Tasks\PCDRScheduledMaintenance.job
- c:\program files\PC-Doctor for Windows\pcdr5cuiw32.exe [2009-02-02 18:59]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 22:32    133840    ----a-w-    c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2008-08-19 333344]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-12-07 5889816]
"HP Remote Software"="c:\program files\Hewlett-Packard\HP Remote\HP REMOTE V1.0.5.exe" [2009-02-06 172032]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Pavilion&pf=cndt
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Pavilion&pf=cndt
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
FF - ProfilePath - c:\users\James\AppData\Roaming\Mozilla\Firefox\Profiles\txg0x96c.default-1386298911882\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
Wow6432Node-HKLM-RunOnce-(A0) - c:\users\James\Desktop\mbar\mbar.exe
HKLM-Run-SmartMenu - c:\program files (x86)\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCDSRVC{F36B3A4C-F95654BD-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{1E61ED7C-7CB8-49D6-B9E9-AB4C880C8414}"=hex:51,66,7a,6c,4c,1d,38,12,12,ee,72,
   1a,8a,32,b8,0c,c6,ff,e8,0c,8d,52,c0,00
"{8E5E2654-AD2D-48BF-AC2D-D17F00898D06}"=hex:51,66,7a,6c,4c,1d,38,12,3a,25,4d,
   8a,1f,e3,d1,0d,d3,3b,92,3f,05,d7,c9,12
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
   72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
   aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd,
   d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
   df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7}"=hex:51,66,7a,6c,4c,1d,38,12,19,c7,a0,
   e8,38,54,d3,01,c4,41,3b,b9,ea,bd,0b,b3
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:c0,ff,30,ff,41,59,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,38,4a,19,45,ed,4a,5c,41,ad,88,e9,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,38,4a,19,45,ed,4a,5c,41,ad,88,e9,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
Completion time: 2013-12-07  23:47:07
ComboFix-quarantined-files.txt  2013-12-08 04:47
ComboFix2.txt  2013-12-08 03:10
.
Pre-Run: 627,549,097,984 bytes free
Post-Run: 627,442,069,504 bytes free
.
- - End Of File - - 5EB388B0D05A133DE3AE1D5AEFF9A6F1
81CD5EC01DB0CE57EDD853F82462EF27
 

 

    <Data Name="param2">%%203</Data>
  </EventData>
</Event>



#12 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:12:04 PM

Posted 08 December 2013 - 01:00 AM




Download Windows Repair (all in one) from here.

Install the program then run



Go to step 3 and allow it to run SFC
waio%20step3.JPG


On the start repairs tab click start
waiostart%20rep.JPG

Select the following items and tick restart system when finished

Reset Registry Permissions
Reset File Permissions
Register System Files
Repair WMI
Repair Windows Firewall
Repair Internet Explorer
Repair Hosts File
Remove Policies Set By Infections
Repair Missing Start menu Icons
Repair Icons
Repair Winsock & DNS Cache
Remove Temp Files
Repair Proxy Settings
Unhide Non System Files
Repair Windows Updates
Set windows Services To Default
Repair MSI (windows Installer)
Repair File Associations
Repair windows Safe mode

After that come back and tell me if that has made a difference.

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#13 totalsiege

totalsiege
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:04 AM

Posted 10 December 2013 - 12:11 AM

I ran it in safemode and fixed some things when I tried to go to normal in hopes of fixing the rest. The program failed to access regedit so it could not make any fixes. I was able to get a restore point to work though and followed the previous steps again and everything seems to be working fine for the most part.

 

I had blocked all in/out connections in avast because there were many duplicates didn't know which were safe. Any tips on how to make sure everything is actually removed and to make avast work correctly again would be helpful. Currently using malwarebytes anti malware and malware anti exploit with windows firewall and have avast disabled. Thanks for the help.



#14 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:12:04 PM

Posted 10 December 2013 - 01:43 AM


Hello totalsiege

Uninstall avast and then run their removal tool - http://www.avast.com/en-us/uninstall-utility

Then reinstall and see if it works correctly.

At this time I would like you to run this script for me and it is a good time to check out the computer to see if there is anything else that needs to be addressed.

:Run CFScript:

Please start by opening Notepad and copy/paste the text in the box into the window:

ClearJavaCache::


 
Save it to your desktop as CFScript.txt

Referring to the picture above, drag CFScript.txt into ComboFix.exe
CFScriptB-4.gif
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"
  • In your next post I need the following
    • report from Combofix
    • let me know of any problems you may have had
    • How is the computer doing now after running the script?
Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#15 totalsiege

totalsiege
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:04 AM

Posted 10 December 2013 - 03:26 AM

Not sure if everything is gone. It might be gone and I don't want it getting re installed by me using something installed by whatever it is.
 
 
ComboFix 13-12-08.01 - James 12/10/2013   2:54.1.4 - x64
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.8190.5835 [GMT -5:00]
Running from: c:\users\James\Desktop\ComboFix.exe
Command switches used :: c:\users\James\Desktop\CFScript.txt
AV: avast! Internet Security *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Internet Security *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Internet Security *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((   Files Created from 2013-11-10 to 2013-12-10  )))))))))))))))))))))))))))))))
.
.
2013-12-10 08:06 . 2013-12-10 08:06 -------- d-----w- c:\users\James\AppData\Local\temp
2013-12-10 08:06 . 2013-12-10 08:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-10 07:39 . 2013-12-10 07:39 -------- d-----w- c:\users\James\AppData\Roaming\AVAST Software
2013-12-10 07:36 . 2013-12-10 07:37 -------- d-----w- c:\windows\LastGood
2013-12-10 07:32 . 2013-12-10 07:32 -------- d-----w- c:\program files\AVAST Software
2013-12-10 06:51 . 2013-12-10 06:51 -------- d-----w- c:\users\James\AppData\Local\CrashDumps
2013-12-09 23:11 . 2013-12-09 23:11 -------- d-----w- c:\users\James\AppData\Roaming\LolClient
2013-12-09 06:06 . 2010-04-06 08:34 345984 ----a-w- c:\windows\system32\drivers\netio.sys
2013-12-09 06:06 . 2013-12-09 06:06 -------- d-----w- c:\users\James\AppData\Local\DoNotTrackPlus
2013-12-09 06:05 . 2013-12-09 06:12 -------- d-----w- c:\users\James\AppData\Roaming\24x7 Help
2013-12-09 06:04 . 2013-12-09 06:04 -------- d-----w- c:\users\James\AppData\Roaming\PCFixSpeed
2013-12-09 06:04 . 2013-12-09 06:04 -------- d-----w- c:\programdata\PCFixSpeed
2013-12-09 06:04 . 2013-12-09 06:04 -------- d-----w- c:\programdata\CheckPoint
2013-12-09 05:19 . 2013-12-09 06:18 -------- d-----w- c:\program files\Malwarebytes Anti-Exploit
2013-12-09 05:19 . 2013-07-16 09:41 743248 ----a-w- c:\windows\SysWow64\msvcp100d.dll
2013-12-09 05:19 . 2013-07-16 09:41 1858896 ----a-w- c:\windows\system32\msvcr100d.dll
2013-12-09 05:19 . 2013-07-16 09:41 1498960 ----a-w- c:\windows\SysWow64\msvcr100d.dll
2013-12-09 05:19 . 2013-07-16 09:41 1014096 ----a-w- c:\windows\system32\msvcp100d.dll
2013-12-09 03:04 . 2013-12-09 03:04 -------- d-----w- c:\users\James\AppData\Roaming\Hewlett-Packard
2013-12-09 02:58 . 2013-12-09 03:03 -------- d-----w- c:\windows\system32\catroot2
2013-12-09 02:47 . 2013-12-10 07:02 -------- d-----w- c:\windows\system32\wbem\repository
2013-12-09 02:47 . 2013-12-09 02:47 -------- d-----w- c:\windows\SysWow64\wbem\Performance
2013-12-09 01:50 . 2013-12-09 01:50 -------- d-----w- c:\program files (x86)\Tweaking.com
2013-12-08 23:21 . 2013-12-08 23:21 -------- d-----w- c:\users\James\AppData\Roaming\Malwarebytes
2013-12-08 23:21 . 2013-12-08 23:21 -------- d-----w- c:\programdata\Malwarebytes
2013-12-08 23:21 . 2013-12-08 23:21 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-12-08 23:21 . 2013-04-04 19:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-08 23:15 . 2013-10-14 07:12 10280728 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FEF8D344-F0AE-4898-936D-2BB89C4FE7DD}\mpengine.dll
2013-12-08 23:14 . 2013-12-08 23:14 -------- d-----w- c:\windows\ERUNT
2013-12-08 07:52 . 2013-12-08 07:52 -------- d-----w- c:\users\James\WPDNSE
2013-12-08 07:20 . 2013-12-08 07:27 -------- d-----w- c:\users\James\plugtmp
2013-12-08 07:20 . 2013-12-08 07:27 -------- d---a-w- c:\users\James\acro_rd_dir
2013-12-08 07:20 . 2013-12-08 07:20 -------- d-----w- c:\users\James\AppData\Roaming\Macromedia(16211)
2013-12-08 07:20 . 2013-12-08 07:20 -------- d-----w- c:\users\James\AppData\Local\Macromedia
2013-12-08 07:04 . 2013-12-08 07:04 -------- d-----w- c:\users\James\AppData\Roaming\ATI
2013-12-08 07:04 . 2013-12-08 07:04 -------- d-----w- c:\users\James\AppData\Local\ATI
2013-12-08 07:04 . 2013-12-08 07:04 -------- d-----w- c:\users\James\AppData\Local\Logitech
2013-12-08 07:04 . 2013-12-08 07:04 -------- d-----w- c:\users\James\AppData\Local\Apps(16202)
2013-12-08 07:04 . 2013-12-08 07:04 -------- d-----w- c:\users\James\Documents(16216)
2013-12-08 07:04 . 2013-12-08 07:04 -------- d-----w- c:\users\James\AppData\Roaming\PureEdge(16214)
2013-12-08 07:04 . 2013-12-08 07:04 -------- d-----w- c:\users\James\AppData\Roaming\Adobe(16210)
2013-12-08 07:03 . 2013-12-08 07:03 -------- d-----w- c:\users\James\AppData\Local\VirtualStore
2013-12-08 07:03 . 2013-12-08 07:03 -------- d-----w- c:\users\James\AppData\Local\Hewlett-Packard(16203)
2013-12-08 07:03 . 2013-12-08 07:03 -------- d-----w- c:\users\James\MWTrace
2013-12-08 07:03 . 2013-12-08 07:03 -------- d-----r- c:\users\James\Favorites(16217)
2013-12-08 07:00 . 2013-12-08 07:04 -------- d-----r- c:\users\James\Desktop(16215)
2013-12-08 06:18 . 2013-12-08 06:18 -------- d-----w- C:\RegBackup
2013-12-08 06:09 . 2013-12-08 06:09 -------- d-----w- c:\program files (x86)\7-Zip
2013-12-08 04:53 . 2013-12-08 07:38 -------- d-----w- c:\users\James\mozilla-temp-files
2013-12-08 01:30 . 2013-12-08 02:32 -------- d-----w- c:\program files\3
2013-12-07 23:42 . 2013-12-07 23:42 -------- d-----w- c:\program files (x86)\FileASSASSIN
2013-12-07 17:32 . 2013-12-09 03:59 -------- d-----w- C:\AdwCleaner
2013-12-06 04:10 . 2013-12-08 07:48 -------- d-----w- c:\windows\SysWow64\_avast_
2013-12-06 01:44 . 2013-12-08 00:04 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2013-12-05 02:17 . 2013-12-06 04:02 -------- d-----w- C:\sfzone_profile
2013-12-04 08:44 . 2013-12-04 11:39 -------- d-----w- c:\users\Guest
2013-12-03 11:00 . 2013-12-03 11:00 -------- d-----w- C:\sh4ldr
2013-12-03 11:00 . 2013-12-03 11:00 -------- d-----w- c:\program files\Enigma Software Group
2013-12-03 10:59 . 2013-12-03 11:00 -------- d-----w- c:\windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
2013-12-03 05:24 . 2013-12-03 05:24 -------- d-----w- c:\program files\VS Revo Group
2013-12-03 01:50 . 2013-12-03 01:50 -------- d-----w- c:\program files (x86)\VS Revo Group
2013-11-29 06:56 . 2013-11-29 06:56 -------- d-----w- c:\programdata\LogMeIn
2013-11-14 08:01 . 2013-10-13 15:09 10926080 ----a-w- c:\windows\system32\ieframe.dll
2013-11-13 11:45 . 2013-10-11 04:23 462848 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-11-13 11:45 . 2013-10-11 04:23 781824 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-11-13 11:45 . 2013-10-11 02:07 596480 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2013-11-13 11:45 . 2013-10-03 15:02 1278976 ----a-w- c:\windows\system32\crypt32.dll
2013-11-13 11:45 . 2013-10-03 12:45 993792 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-11-13 11:45 . 2013-10-03 15:03 389632 ----a-w- c:\windows\system32\gdi32.dll
2013-11-13 11:45 . 2013-10-03 12:46 304128 ----a-w- c:\windows\SysWow64\gdi32.dll
2013-11-13 11:45 . 2013-09-04 02:31 404992 ----a-w- c:\windows\system32\drivers\afd.sys
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-09 17:16 . 2012-05-10 11:37 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-09 17:16 . 2012-05-10 11:37 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
"HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-04-04 1644088]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-10-02 20472992]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2013-10-09 1813928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-01-28 61440]
"HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-12-04 75016]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"UpdatePDIRShortCut"="c:\program files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"UpdatePSTShortCut"="c:\program files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" [2009-02-02 210216]
"TSMAgent"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2009-04-10 1328424]
"CLMLServer for HP TouchSmart"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2009-04-10 185640]
"DVDAgent"="c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2009-03-19 1148200]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-06 224616]
"masqform.exe"="c:\program files (x86)\PureEdge\Viewer 6.5\masqform.exe" [2005-07-04 643072]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-10 3568312]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware (cleanup)"="c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll" [2013-04-04 1127496]
.
c:\users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ASWKBD
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
Themes
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-10 17:16]
.
2013-12-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-14 17:37]
.
2013-12-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-14 17:37]
.
2013-12-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2913837339-2283795315-3485834564-1000Core.job
- c:\users\James\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-09 09:42]
.
2013-12-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2913837339-2283795315-3485834564-1000UA.job
- c:\users\James\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-09 09:42]
.
2013-12-10 c:\windows\Tasks\Malwarebytes Anti-Exploit.job
- c:\program files\Malwarebytes Anti-Exploit\mbae-loader.exe [2013-12-09 14:48]
.
2013-11-01 c:\windows\Tasks\PCDRScheduledMaintenance.job
- c:\program files\PC-Doctor for Windows\pcdr5cuiw32.exe [2009-02-02 18:59]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-12-10 07:35 326944 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Remote Software"="c:\program files\Hewlett-Packard\HP Remote\HP REMOTE V1.0.5.exe" [2009-02-06 172032]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2008-08-19 333344]
"SmartMenu"="c:\program files (x86)\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [BU]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-12-07 5889816]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
FF - ProfilePath - c:\users\James\AppData\Roaming\Mozilla\Firefox\Profiles\r6ep47ez.default-1386563585531\
FF - prefs.js: browser.search.selectedEngine - 
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-12-06 15:59; firefox@browsesmart.net; c:\users\James\AppData\Roaming\Mozilla\Firefox\Profiles\r6ep47ez.default-1386563585531\extensions\firefox@browsesmart.net.xpi
FF - ExtSQL: 2013-12-08 11:45; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - ExtSQL: 2013-12-08 11:45; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2013-12-08 11:46; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - ExtSQL: 2013-12-10 00:51; ffxtlbr@zonealarm.com; c:\users\James\AppData\Roaming\Mozilla\Firefox\Profiles\r6ep47ez.default-1386563585531\extensions\ffxtlbr@zonealarm.com
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
Wow6432Node-HKLM-Run-20131121 - c:\program files\AVAST Software\Avast\setup\emupdate\d524004b-85f9-4a5d-bf76-1934b415fd61.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files (x86)\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCDSRVC{F36B3A4C-F95654BD-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{1E61ED7C-7CB8-49D6-B9E9-AB4C880C8414}"=hex:51,66,7a,6c,4c,1d,38,12,12,ee,72,
   1a,8a,32,b8,0c,c6,ff,e8,0c,8d,52,c0,00
"{8E5E2654-AD2D-48BF-AC2D-D17F00898D06}"=hex:51,66,7a,6c,4c,1d,38,12,3a,25,4d,
   8a,1f,e3,d1,0d,d3,3b,92,3f,05,d7,c9,12
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
   72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
   aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd,
   d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
   df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7}"=hex:51,66,7a,6c,4c,1d,38,12,19,c7,a0,
   e8,38,54,d3,01,c4,41,3b,b9,ea,bd,0b,b3
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:c0,ff,30,ff,41,59,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,38,4a,19,45,ed,4a,5c,41,ad,88,e9,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,38,4a,19,45,ed,4a,5c,41,ad,88,e9,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
Completion time: 2013-12-10  03:09:17
ComboFix-quarantined-files.txt  2013-12-10 08:09
ComboFix2.txt  2013-12-09 00:55
ComboFix3.txt  2013-12-08 04:47
ComboFix4.txt  2013-12-08 03:10
.
Pre-Run: 624,306,782,208 bytes free
Post-Run: 623,313,592,320 bytes free
.
- - End Of File - - DD2B1C638B6FB1E7988ED37428125B7F
81CD5EC01DB0CE57EDD853F82462EF27





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users