Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

can't stop processes


  • Please log in to reply
19 replies to this topic

#1 garyflater

garyflater

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Winnipeg, Canada
  • Local time:10:51 PM

Posted 06 March 2016 - 01:15 AM

shot of task manager. A friend said I had some bad stuff. He did a check through command prompt, and was not allowed to see everything. Said to run malwarebytes in safe mode. Fount some pups but nothing else. screenshot taken after this.

Attached Files


Edited by hamluis, 06 March 2016 - 09:08 AM.
Moved from Win 7 to Am I Infected - Hamluis.

.....let us not lose heart in running the race.....


BC AdBot (Login to Remove)

 


#2 dc3

dc3

    Bleeping Treehugger


  • Members
  • 30,397 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:09:51 PM

Posted 06 March 2016 - 10:41 AM

What command did your friend run from the command prompt?
 
Please post the Malwarebytes log.
 
To find your Malwarebytes log,download mbam-check.exe from here and save it to your desktop.
 
To open the log double click on mbam-check.exe on your desktop.  Copy and paste the log in your topic.
 

Emsisoft Emergency Kit
 
Please download Emsisoft Emergency Kit and save it to your desktop. Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop. Leave all settings as they are and click the Extract button at the bottom. A folder named EEK will be created in the root of the drive (usually c:\).

  •  
  • After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
  • The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates. Please click Yes so that it downloads the latest database updates.
  • When update is complete, click Malware Scan. When asked if you want the scanner to scan for Potentially Unwanted Programs, click Yes. Emsisoft Emergency Kit will start scanning.
  • When the scan is completed click Quarantine selected objects. Note:  This option is only available if malicious objects were detected during the scan.  If this is the case select Delete selected.
  • When the threats have been quarantined, click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
  • Please save the log in Notepad on your desktop and post the contents in your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.

================

Please run AdwCleaner
 
Please download AdwCleaner and install it.
 
When AdwCleaner opens you will see an image like the one below.
 
adwcleaner11_zps48314883.png
 
Click on Scan to start the scan.
 
Once the search is complete a list of the pending items will be displayed.  If you see any which you do not want removed, remove the check mark next to it.
 
If there are no malicious programs are found you will receive the following message.
 
adwcleaner%20111_zpsiduqrrrp.png
 
Click on Clean to remove the selected items.  If you have any questions about any items in the list please copy and paste the list in your topic so we can review it.  
 
You will receive a message telling you that all programs will be closed so that the infections can be removed.  Click on OK.  The computer will be restarted to complete the cleaning process.
 
When the cleaning process is complete a log of what was removed will be presented.  Please copy and the paste this log in your topic.
 
=================
 

Please run the ESET OnlineScan

This scan takes quite a long time to run, so be prepared to allow this to run till it is completed.

***Please note. If you run this scan using Internet Explorer you won't need to download the Eset Smartinstaller.***

ESET Online Scanner

  • Click here to download the installer for ESET Online Scanner and save it to your Desktop.
  • Disable all your antivirus and antimalware software - see how to do that here.
  • Right click on esetsmartinstaller_enu.exe and select Run as Administrator.
  • Place a checkmark in YES, I accept the Terms of Use, then click Start. Wait for ESET Online Scanner to load its components.
  • Select Enable detection of potentially unwanted applications.
  • Click Advanced Settings, then place a checkmark in the following:
    • Remove found threats
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Click Start to begin scanning.
  • ESET Online Scanner will start downloading signatures and scan. Please be patient, as this scan can take quite some time.
  • When the scan is done, click List threats (only available if ESET Online Scanner found something).
  • Click Export, then save the file to your desktop.
  • Click Back, then Finish to exit ESET Online Scanner.

Edited by dc3, 06 March 2016 - 10:42 AM.

Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

 

 

 

 


#3 garyflater

garyflater
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Winnipeg, Canada
  • Local time:10:51 PM

Posted 06 March 2016 - 04:36 PM

Here is the log.  Trying to get a hold of my friend

 

 

mbam-check result log version:     2.3.2.0
========================================

User Account type:                 Administrator
DomainComputer:                    No
OS:                                Windows 7 Service Pack 1 Service Pack 1 64 bit Operating System
Current Version and Build:         6.1.7601
Malwarebytes Anti-Malware:         2.2.0.1024
Installed On:                      2016/03/05
Malware Database:                  2016.03.06.03
Rootkit Database:                  2016.02.27.01
Remediation Database:              2016.03.05.01
IP Database:                       2016.03.03.01
Domain Database:                   2016.03.06.01
License:                           Trial
Malware Protection:                4 (The service is running.)
Malicious Website Protection:      4 (The service is running.)
Chameleon:                         0 <--CAN NOT OPEN SC_HANDLE, SERVICE IS NOT RUNNING FOR: MBAMChameleon
Log Created:                       2016/03/06 15:34:18

User Information for Local System:
===========================================
User Account: Beautiful People
    Account Level: Guest
User Account: happy
    Account Level: Limited User
User Account: HomeGroupUser$
    Account Level: Guest
User Account: Mother Theresa
    Account Level: Admin
User Account: user
    Account Level: Admin
Total # of user entries: 5

UAC Settings:
===================
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
    DWORD    1    Status: ON
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
    DWORD    5    Status: ON

AntiVirus Information:
===================
AntiVirus Software Installed:    "avast! Antivirus"

FireWall Information:
===================
NO 3rd Party Firewall Software Installed

AntiSpyware Information:
===================
AntiSpyware Software Installed:    "Windows Defender"
AntiSpyware Software Installed:    "avast! Antivirus"

Machine Information
===============================================
Machine ID:    970f5928dd034e70b958560980da057be94d8e27
Installation Token:    qCzAvo1xPrFYYZerf7J41457237469
System has been up for:     6.35639 Hours
Current Date:    2016-Mar-06 21:34:20.167600
Date Booted:    2016-Mar-06 15:34:20.167600

Detection and Protection Settings
===============================================
Use Advanced Heuristics Engine (Shuriken):            true
Scan for rootkits:                                    false
Scan within archives:                                 true
PUP (Potentially Unwanted Program) detections:        Treat Detections as Malware
PUM (Potentially Unwanted Modification) detections:   Treat Detections as Malware

Compatibility Flag Settings:
=================================





Malwarebytes Anti-Malware Shell Extension Block Check:
======================================================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked:

MBAM Startup Entries:
=====================
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

Malwarebytes Anti-Malware Service and Driver Status:
=======================================================

--------------Driver File Info:--------------
C:\Windows\system32\drivers\mbam.sys
File Size:     25816 BYTES    FileVersion: 0.1.16.0    MD5: [cfbc6c6d8a492697cabd1d353ee64933]
C:\Windows\system32\drivers\mwac.sys
File Size:     63704 BYTES    FileVersion: 1.0.6.0    MD5: [d61070cfad43038dc56aead9bfe9ce2a]
C:\Windows\system32\drivers\mbamswissarmy.sys
File Size:    192216 BYTES    FileVersion: 0.3.0.4    MD5: [78488af2ab2111d67b3c4044707a519b]
C:\Windows\system32\drivers\mbamchameleon.sys
File Size:    109272 BYTES    FileVersion: 1.1.21.0    MD5: [47701eca633574e122687693b5c5d35c]

--------------MBAMProtector:--------------
Type:                   2
State:                  4 (The service is running.) (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE:        0
SERVICE_EXIT_CODE:      0
CHECKPOINT:             0
WAIT_HINT:              0


--------------MBAMService:--------------
Type:                   16
State:                  4 (The service is running.)
WIN32_EXIT_CODE:        0
SERVICE_EXIT_CODE:      0
CHECKPOINT:             0
WAIT_HINT:              0


--------------MBAMScheduler:--------------
Type:                   16
State:                  4 (The service is running.)
WIN32_EXIT_CODE:        0
SERVICE_EXIT_CODE:      0
CHECKPOINT:             0
WAIT_HINT:              0


--------------MBAMChameleon:--------------
Type:                   N/A
State:                  0 <--CAN NOT OPEN SC_HANDLE, SERVICE IS NOT RUNNING FOR: MBAMChameleon
WIN32_EXIT_CODE:        N/A
SERVICE_EXIT_CODE:      N/A
CHECKPOINT:             N/A
WAIT_HINT:              N/A


--------------MBAMWebAccessControl:--------------
Type:                   2
State:                  4 (The service is running.) (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE:        0
SERVICE_EXIT_CODE:      0
CHECKPOINT:             0
WAIT_HINT:              0


Required Dependencies:
======================

--------------BFE:--------------
Type:                   32
State:                  4 (The service is running.)
WIN32_EXIT_CODE:        0
SERVICE_EXIT_CODE:      0
CHECKPOINT:             0
WAIT_HINT:              0


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE
    DisplayName                   REG_SZ        @%SystemRoot%\system32\bfe.dll,-1001
    Group                         REG_SZ        NetworkProvider
    ImagePath                     REG_EXPAND_SZ    %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
    Description                   REG_SZ        @%SystemRoot%\system32\bfe.dll,-1002
    ObjectName                    REG_SZ        NT AUTHORITY\LocalService
    ErrorControl                  REG_DWORD        1
    Start                         REG_DWORD        2
    Type                          REG_DWORD        32
    DependOnService               REG_MULTI_SZ    RpcSs

    ServiceSidType                REG_DWORD        3
    RequiredPrivileges            REG_MULTI_SZ    SeAuditPrivilege

    FailureActions                REG_BINARY    Binary Data

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE\Parameters
    ServiceDll                    REG_EXPAND_SZ    %SystemRoot%\System32\bfe.dll
    ServiceDllUnloadOnStop        REG_DWORD        1
    ServiceMain                   REG_SZ        BfeServiceMain

--------------fltmgr:--------------
Type:                   2
State:                  4 (The service is running.) (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE:        0
SERVICE_EXIT_CODE:      0
CHECKPOINT:             0
WAIT_HINT:              0


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\FltMgr
    AttachWhenLoaded              REG_DWORD        1
    DisplayName                   REG_SZ        @%SystemRoot%\system32\drivers\fltmgr.sys,-10001
    Group                         REG_SZ        FSFilter Infrastructure
    ImagePath                     REG_EXPAND_SZ    system32\drivers\fltmgr.sys
    Description                   REG_SZ        @%SystemRoot%\system32\drivers\fltmgr.sys,-10000
    ErrorControl                  REG_DWORD        3
    Start                         REG_DWORD        0
    Tag                           REG_DWORD        1
    Type                          REG_DWORD        2
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\FltMgr\Enum
    0                             REG_SZ        Root\LEGACY_FLTMGR\0000
    Count                         REG_DWORD        1
    NextInstance                  REG_DWORD        1


C:\Windows\system32\drivers\fltmgr.sys
File Size: 289664    BYTES    FileVersion: 6.1.7601.17514    MD5: [da6b67270fd9db3697b20fce94950741]
C:\Windows\SysWOW64\olepro32.dll
File Size: 90112     BYTES    FileVersion: 6.1.7601.17514    MD5: [703ffd301ab900b047337c5d40fd6f96]


MBAM Registry Settings and License Info:
========================================
--------------Settings:--------------
Advanced:
    AutomaticQuarantine:                                       true
    AutostartProtection:                                       true
    LimitedMode:                                               false
    StartSilentMode:                                           false
    StartupDelay:                                              -15
ApplicationState:
    First-Run-After-Installation:                              false
General:
    DaysUntilNotifyExpiration:                                 5
    Language:                                                  en
    RightClickAccess:                                          false
    SilentErrors:                                              false
Logging:
    ExportLog:                                                 true
Marketing:
    LastPostScanMarketingIndex:                                1
Notification:
ProtectionTray:
    DisplayMilliseconds:                                       3000
ScanHistory:
    Duration_Complete:                                         135417
    Duration_Driver:                                           0
    Duration_Filesystem:                                       33
    Duration_Heuristics:                                       374739
    Duration_Loading:                                          0
    Duration_MasterBootRecord:                                 0
    Duration_Memory:                                           40000
    Duration_PreScan:                                          22194
    Duration_Registry:                                         40556
    Duration_Sector:                                           0
    Duration_Startup:                                          5607
    ItemCount_Complete:                                        362516
    ItemCount_Driver:                                          0
    ItemCount_Filesystem:                                      41887
    ItemCount_Heuristics:                                      11598
    ItemCount_Loading:                                         0
    ItemCount_MasterBootRecord:                                0
    ItemCount_Memory:                                          2797
    ItemCount_PreScan:                                         0
    ItemCount_Registry:                                        595
    ItemCount_Sector:                                          0
    ItemCount_Startup:                                         224
    LastRemovalRequiredDOR:                                    false
    LastScanDateEpoch:                                         1457240509125
    LastScanType:                                              1 (Threat Scan)
    QuarantineCompletedCount:                                  24
Update:
    LastUpdate:                                                2016-03-06T20:13:25
    NotifyInstallReady:                                        true
    NotifyOutdatedDatabase:                                    3
    ProxyPassword:                                              
    ProxyPort:                                                 0
    ProxyServer:                                                
    ProxyUsername:                                              
    UseProxy:                                                  false
    UseProxyAuthentication:                                    false
    CheckProgramUpdates:                          true
--------------Account:--------------
  Account Status:                                              Trial
  Expiration Time:                                             2016/03/20 04:11:10
  Activation Time:                                             2016/03/05 22:11:22
  Trial Used:                                                  true
--------------Access Policies:--------------

Scheduler Queue:
================

tasks:
    8967837e-6b83-431a-bcc2-06182ea2a9aa:                       
      parameters:                                               
        AutoDelete:                                            false
        CheckForUpdatesBeforeScanStart:                        true
        ProcessLaunchedFromScheduler:                          true
        ScanConfig:                                             
          ExportLog:                                           true
          FileSystemOption:                                    true
          Quarantine:                                          Prompt
          RebootSystemWhenMalwareDetected:                     false
          ScanArchives:                                        true
          ScanExtra:                                           true
          ScanHeuristic:                                       true
          ScanMemoryObjects:                                   true
          ScanPUM:                                             Treat Detections as Malware
          ScanPUP:                                             Treat Detections as Malware
          ScanRegistry:                                        true
          ScanRootkits:                                        false
          ScanSource:                                          1
          ScanStartup:                                         true
          ScanTargets:                                          
          ScanType:                                            1 (Threat Scan)
          Silent:                                              true
        StartTaskFromSystemAccount:                            false
        TaskType:                                              0
      triggers:                                                 
        0c262ae9-bc36-4421-9903-14b66d83bf94:                   
          dateinterval:                                        1:0:0 (Days:Months:Years)
          lastscheduled:                                       Sun, 06 Mar 2016 09:14:03.436114 -0600
          lasttriggered:                                       Sun, 06 Mar 2016 09:14:03.436114 -0600
          nextscheduled:                                       Mon, 07 Mar 2016 02:11:12 -0600
          recovery:                                            23:00:00 (Hours:Minutes:Seconds)
          start:                                               Sun, 06 Mar 2016 02:21:49 -0600
          timeinterval:                                        00:00:00 (Hours:Minutes:Seconds)
          type:                                                Daily
          uuid:                                                0c262ae9-bc36-4421-9903-14b66d83bf94
      type:                                                    scan
      uuid:                                                    8967837e-6b83-431a-bcc2-06182ea2a9aa
    cf3bbdb1-dc1f-4ec8-bf8d-f18bb4f668d9:                       
      parameters:                                               
        NotifyWhenUpdateCompletes:                             false
        TaskType:                                              3
      triggers:                                                 
        e55074a1-c0b3-44b8-8e23-a7ea9c46e79e:                   
          dateinterval:                                        0:0:0 (Days:Months:Years)
          lastscheduled:                                       Sun, 06 Mar 2016 15:28:41.743654 -0600
          lasttriggered:                                       Sun, 06 Mar 2016 15:28:41.743654 -0600
          nextscheduled:                                       Sun, 06 Mar 2016 16:13:29.715637 -0600
          recovery:                                            00:00:00 (Hours:Minutes:Seconds)
          start:                                               Sat, 05 Mar 2016 22:17:09.715637 -0600
          timeinterval:                                        01:00:00 (Hours:Minutes:Seconds)
          type:                                                Hourly
          uuid:                                                e55074a1-c0b3-44b8-8e23-a7ea9c46e79e
      type:                                                    update
      uuid:                                                    cf3bbdb1-dc1f-4ec8-bf8d-f18bb4f668d9

Pending File Rename Operations:
================================
If any Malwarebytes Anti-Malware items are listed below, the user must reboot to complete a Malwarebytes Anti-Malware upgrade installation.
Pending File Rename Operations:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\
    PendingFileRenameOperations    REG_MULTI_SZ    \??\C:\Users\user\AppData\Local\Temp\~nsu.tmp\Au_.exe



MBAMProtector Registry Values:
==============================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector
    Type                          REG_DWORD        2
    Start                         REG_DWORD        3
    ErrorControl                  REG_DWORD        1
    ImagePath                     REG_EXPAND_SZ    \??\C:\Windows\system32\drivers\mbam.sys
    Group                         REG_SZ        FSFilter Anti-Virus
    DependOnService               REG_MULTI_SZ    FltMgr

    WOW64                         REG_DWORD        1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector\Instances
    DefaultInstance               REG_SZ        MBAMProtector Instance
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector\Instances\MBAMProtector Instance
    Altitude                      REG_SZ        328800
    Flags                         REG_DWORD        0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector\Parameters
    PassThruFile                  REG_SZ        mbampt.exe
    ProductPath                   REG_SZ        C:\Program Files (x86)\Malwarebytes Anti-Malware
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector\Enum
    0                             REG_SZ        Root\LEGACY_MBAMPROTECTOR\0000
    Count                         REG_DWORD        1
    NextInstance                  REG_DWORD        1

MBAMService Registry Values:
============================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMService
    Type                          REG_DWORD        16
    Start                         REG_DWORD        2
    ErrorControl                  REG_DWORD        1
    ImagePath                     REG_EXPAND_SZ    "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
    DependOnService               REG_MULTI_SZ    MBAMProtector

    WOW64                         REG_DWORD        1
    ObjectName                    REG_SZ        LocalSystem
    Description                   REG_SZ        Malwarebytes Anti-Malware service
    DelayedAutostart              REG_DWORD        0

MBAMScheduler Registry Values:
==============================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMScheduler
    Type                          REG_DWORD        16
    Start                         REG_DWORD        2
    ErrorControl                  REG_DWORD        1
    ImagePath                     REG_EXPAND_SZ    "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
    WOW64                         REG_DWORD        1
    ObjectName                    REG_SZ        LocalSystem
    Description                   REG_SZ        Malwarebytes Anti-Malware scheduler

Terminal Services Status for (null) entries in PM logs and GetUserToken errors:
===============================================================================

--------------TERMService:--------------
Type:                   32
State:                  4 (The service is running.)
WIN32_EXIT_CODE:        0
SERVICE_EXIT_CODE:      0
CHECKPOINT:             0
WAIT_HINT:              0


TermService Start is set to: 2 (Automatic Startup)

Proxy Status: No proxy is Set

LAN Settings:
=============

only 'Automatically detect settings' is selected

SystemPartition:
================

HKEY_LOCAL_MACHINE\SYSTEM\Setup\
    SystemPartition    REG_SZ        \Device\HarddiskVolume1

Balloon Tips Status:
====================

Enabled

Time Format Settings:
=====================

Should be:
        h:mm:ss tt
        AM
        PM
        :

Currently:
REG_SZ        h:mm:ss tt
REG_SZ        AM
REG_SZ        PM
REG_SZ        :

Language and Regional Settings:
===============================

ACP:     Language is English (United States)
MACCP:     Language is English (United States)
OEMCP:     Language is English (United States)

Startup Folders for Error_Expanding_Variables Check:
====================================================

All Users Startup Folder Exists.
Current User's Startup Folder Exists.


Context Menu Entries:
=====================
















List of MBAM Related Directories:
=================================

C:\Program Files (x86)\Malwarebytes Anti-Malware\
7z.dll                                      File Size: 920888    BYTES    FileVersion:  9.20.0.0       MD5: [0bce989cf27fdce498305a041d1eba95]
changes.txt                                 File Size: 1301      BYTES    FileVersion:  N/A            MD5: [b535a0821de0464a9927c996f7e957d8]
cloud-enumeration.dll                       File Size: 286008    BYTES    FileVersion:  1.0.1.0        MD5: [9fdabf510e37b06c24aaac53d402633e]
cloud.dll                                   File Size: 351544    BYTES    FileVersion:  1.0.1.0        MD5: [020f7775a0f0bedfbbc2d87cac34e452]
license.rtf                                 File Size: 270257    BYTES    FileVersion:  N/A            MD5: [4bac855abf62066aa03591d904a26558]
master.conf                                 File Size: 1258      BYTES    FileVersion:  N/A            MD5: [9702ca5e82d3756c6d8af34a2ababaea]
mbam.dll                                    File Size: 608568    BYTES    FileVersion:  1.0.40.0       MD5: [9f597ef193ba422303888cdd34e33456]
mbam.exe                                    File Size: 9832760   BYTES    FileVersion:  2.3.125.0      MD5: [babbbdef9dbb5e012ee5210fcb47c33b]
mbamcore.dll                                File Size: 2126648   BYTES    FileVersion:  1.3.24.0       MD5: [9507addeb1f70f4abf50a9835cd2f8cb]
mbamdor.exe                                 File Size: 54072     BYTES    FileVersion:  1.0.2.0        MD5: [9cee13ddcf207923a1849a8371e714e9]
mbamext.dll                                 File Size: 310584    BYTES    FileVersion:  3.0.7.0        MD5: [9c96d44764f8b8bdb09e6ad6ad68d494]
mbampt.exe                                  File Size: 39736     BYTES    FileVersion:  1.0.57.0       MD5: [edd398e736e3efd188dfa86ca4f28527]
mbamresearch.exe                            File Size: 1947960   BYTES    FileVersion:  1.1.1.0        MD5: [f4fe7e8cbf51aa07cfb947dbef07e1af]
mbamscheduler.exe                           File Size: 1513784   BYTES    FileVersion:  3.1.6.0        MD5: [ab176b9e59c0435499d83047d84edd59]
mbamservice.exe                             File Size: 1135416   BYTES    FileVersion:  3.2.19.0       MD5: [40c126cb15fab7d6c66490dca9c1aed2]
mbamsrv.dll                                 File Size: 3861816   BYTES    FileVersion:  2.1.9.0        MD5: [8853bc829caee0b5c4952e97156c9fc5]
msvcp100.dll                                File Size: 421688    BYTES    FileVersion:  10.0.40219.325 MD5: [955743f613f744c184383e09c1d2b16d]
msvcr100.dll                                File Size: 774456    BYTES    FileVersion:  10.0.40219.325 MD5: [f7659c545773f2d21f0335f58a7f20cd]
Qt5Core.dll                                 File Size: 4645688   BYTES    FileVersion:  5.4.1.0        MD5: [0187e57536d48f33acb8d9789c7ff3fc]
Qt5Gui.dll                                  File Size: 4639032   BYTES    FileVersion:  5.4.1.0        MD5: [8eb68983624868507f33b8da78507f7c]
Qt5Network.dll                              File Size: 672056    BYTES    FileVersion:  5.4.1.0        MD5: [21f2b555c0a904232f00c480219a35a8]
Qt5Widgets.dll                              File Size: 4473656   BYTES    FileVersion:  5.4.1.0        MD5: [c14017b307fb9a222ce12f7ba6c7a9c8]
unins000.dat                                File Size: 34685     BYTES    FileVersion:  N/A            MD5: [9f82fb0e4be2f7454643d9d354e28dd9]
unins000.exe                                File Size: 720085    BYTES    FileVersion:  51.52.0.0      MD5: [f1505d347325c77e3eeef418495e1f57]

C:\Program Files (x86)\Malwarebytes Anti-Malware\\Chameleon

C:\Program Files (x86)\Malwarebytes Anti-Malware\\Chameleon\Windows
chameleon.chm                               File Size: 235882    BYTES    FileVersion:  N/A            MD5: [c4190b71f037714aa77aba294434ba5b]
firefox.com                                 File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]
firefox.exe                                 File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]
firefox.pif                                 File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]
firefox.scr                                 File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]
iexplore.exe                                File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]
mbam-chameleon.com                          File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]
mbam-chameleon.exe                          File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]
mbam-chameleon.pif                          File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]
mbam-chameleon.scr                          File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]
mbam-killer.exe                             File Size: 1503544   BYTES    FileVersion:  3.0.15.0       MD5: [f604a8e64d02412be1d4b94c6f294b14]
rundll32.exe                                File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]
svchost.exe                                 File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]
windows.exe                                 File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]
winlogon.exe                                File Size: 893752    BYTES    FileVersion:  3.1.27.0       MD5: [e9a75e4b409a01e52055ce7cca7ff925]

C:\Program Files (x86)\Malwarebytes Anti-Malware\\imageformats
qgif.dll                                    File Size: 28472     BYTES    FileVersion:  5.4.1.0        MD5: [98abe94698324f6326781e492e774bd3]

C:\Program Files (x86)\Malwarebytes Anti-Malware\\Languages
lang_ar.qm                                  File Size: 87404     BYTES    FileVersion:  N/A            MD5: [269d3107ca72a75fe154ce4ff718af50]
lang_bg.qm                                  File Size: 133911    BYTES    FileVersion:  N/A            MD5: [376ad1e4ad206bc32da09b12b564ecc4]
lang_ca.qm                                  File Size: 92634     BYTES    FileVersion:  N/A            MD5: [2d35f58b0c2db44ad2717f4a4526a085]
lang_cs.qm                                  File Size: 105193    BYTES    FileVersion:  N/A            MD5: [2c191de828d5e05fd7afa27ee1245023]
lang_da.qm                                  File Size: 88039     BYTES    FileVersion:  N/A            MD5: [f8a4941d5d388160d252832a77ab584f]
lang_de.qm                                  File Size: 139276    BYTES    FileVersion:  N/A            MD5: [b55f37281f0fcadfae67aecf0bf4cca5]
lang_el.qm                                  File Size: 126897    BYTES    FileVersion:  N/A            MD5: [bd671253e071bac626beea63393abcda]
lang_en.qm                                  File Size: 3081      BYTES    FileVersion:  N/A            MD5: [e2790b3cd9fdd9d3e266e9623fe477af]
lang_es.qm                                  File Size: 138468    BYTES    FileVersion:  N/A            MD5: [cc4f3aab63d933d5964e2bba62df4277]
lang_et.qm                                  File Size: 107794    BYTES    FileVersion:  N/A            MD5: [aa4845cd64b20377cea0ebc66eed4a42]
lang_fi.qm                                  File Size: 130793    BYTES    FileVersion:  N/A            MD5: [00653d1fb2f790817aef991025c176aa]
lang_fr.qm                                  File Size: 141996    BYTES    FileVersion:  N/A            MD5: [e06db8ef6b826b75ec5859913651ed44]
lang_he.qm                                  File Size: 98928     BYTES    FileVersion:  N/A            MD5: [2954e902664f2e129f8a8d8238e90552]
lang_hu.qm                                  File Size: 132359    BYTES    FileVersion:  N/A            MD5: [6bf3b8c78fd393ef2811a19742518b9a]
lang_id.qm                                  File Size: 129135    BYTES    FileVersion:  N/A            MD5: [6be058072a90897595c6f097a3caa797]
lang_it.qm                                  File Size: 134154    BYTES    FileVersion:  N/A            MD5: [183990148beec433023688db65a7bf2e]
lang_ja.qm                                  File Size: 73762     BYTES    FileVersion:  N/A            MD5: [f6bfd643cb92fa760ae6ec64344ee7e1]
lang_ko.qm                                  File Size: 85731     BYTES    FileVersion:  N/A            MD5: [53b5a94eb309d69993a5bc3cd43a85e4]
lang_lt.qm                                  File Size: 90799     BYTES    FileVersion:  N/A            MD5: [eecd8edca1fb068ad3bd88aa711bdae2]
lang_lv.qm                                  File Size: 90659     BYTES    FileVersion:  N/A            MD5: [683950904e725821740217824df440ff]
lang_nl.qm                                  File Size: 133514    BYTES    FileVersion:  N/A            MD5: [442a6cf7e07e6f676d8b5ae41637549c]
lang_no.qm                                  File Size: 129833    BYTES    FileVersion:  N/A            MD5: [8949e21e367e5a32ca9f36d8d22c9771]
lang_pl.qm                                  File Size: 133827    BYTES    FileVersion:  N/A            MD5: [48379f4ac164adfc8d448bf53c8e2df8]
lang_pt_BR.qm                               File Size: 136918    BYTES    FileVersion:  N/A            MD5: [b1ea2002cf5362b24ca0a026f448e3f1]
lang_pt_PT.qm                               File Size: 136982    BYTES    FileVersion:  N/A            MD5: [5e23b66cb6d8d9894b991cc8f33658af]
lang_ro.qm                                  File Size: 90458     BYTES    FileVersion:  N/A            MD5: [bcf524020255c4f7a6fdbae8df2bfe81]
lang_ru.qm                                  File Size: 137874    BYTES    FileVersion:  N/A            MD5: [5e28394fbd12f21301e2b7e1a9dbac94]
lang_sk.qm                                  File Size: 131080    BYTES    FileVersion:  N/A            MD5: [68e0e95e7131d101188a57e3a413dee5]
lang_sl.qm                                  File Size: 107631    BYTES    FileVersion:  N/A            MD5: [83755001a3f1bd527d0b4b7a77d0b37d]
lang_sv.qm                                  File Size: 129135    BYTES    FileVersion:  N/A            MD5: [b3c38242beb63f895fabcc14bbc6807a]
lang_tr.qm                                  File Size: 88838     BYTES    FileVersion:  N/A            MD5: [1e4a3c0dcd7074ad4a3971ce67762cda]
lang_vi.qm                                  File Size: 133386    BYTES    FileVersion:  N/A            MD5: [586de19c023986bf884ad56fc29c8f5e]
lang_zh_TW.qm                               File Size: 87797     BYTES    FileVersion:  N/A            MD5: [e120a014cf077bdcbcdcbf98c3438188]

C:\Program Files (x86)\Malwarebytes Anti-Malware\\platforms
qwindows.dll                                File Size: 928568    BYTES    FileVersion:  5.4.1.0        MD5: [1dadf33fdeaabb550384beaef851313b]

C:\Program Files (x86)\Malwarebytes Anti-Malware\\Plugins
fixdamage.exe                               File Size: 822584    BYTES    FileVersion:  1.4.0.1001     MD5: [16fd048f3362bf6fd2050ef22b85dba8]

C:\Users\user\AppData\Roaming\Malwarebytes\Malwarebytes Anti-Malware

C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware
actions.ref                                 File Size: 5135      BYTES    FileVersion:  N/A            MD5: [e68dd74ad6cbe0d6cc891c79ce9c3d8c]
akadomains.ref                              File Size: 92        BYTES    FileVersion:  N/A            MD5: [73d5774cbd8df165274a0691ae264808]
akaips.ref                                  File Size: 92        BYTES    FileVersion:  N/A            MD5: [2a6869d1f91f0a0b87b1d27bd30ccc5c]
domains.ref                                 File Size: 444301    BYTES    FileVersion:  N/A            MD5: [7e7b9294aca913bb5bef77c6203ba299]
exclusions.dat                              File Size: 0         BYTES    FileVersion:  N/A            MD5: [d41d8cd98f00b204e9800998ecf8427e]
ips.ref                                     File Size: 139230    BYTES    FileVersion:  N/A            MD5: [2c27850092c85baff47a4285a9288168]
rules.ref                                   File Size: 10224213  BYTES    FileVersion:  N/A            MD5: [d55f4d46507389a1c633d8988c6bc5da]
swissarmy.ref                               File Size: 27858     BYTES    FileVersion:  N/A            MD5: [7a43716023deca3ca8c81758272c3be2]

C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration
build.conf                                  File Size: 4594      BYTES    FileVersion:  N/A            MD5: [eb03e264d8c262fa8724e7423e78f0cc]
database.conf                               File Size: 4         BYTES    FileVersion:  N/A            MD5: [2261e7eca4cd0615a97263c0ad5045c2]
gatekeeper.conf                             File Size: 4         BYTES    FileVersion:  N/A            MD5: [2261e7eca4cd0615a97263c0ad5045c2]
license.conf                                File Size: 1534      BYTES    FileVersion:  N/A            MD5: [6ed9cd95857dfa6224265cc5a6b83828]
manifest.conf                               File Size: 3402      BYTES    FileVersion:  N/A            MD5: [1bcd9bf2b3169bc178bc856a36ed59e4]
marketing.conf                              File Size: 7288      BYTES    FileVersion:  N/A            MD5: [7fb08c35a4364722324c8df694fba07a]
net.conf                                    File Size: 7199      BYTES    FileVersion:  N/A            MD5: [f296534ef35523d360ea97f9af8a9463]
notifications.conf                          File Size: 4         BYTES    FileVersion:  N/A            MD5: [2261e7eca4cd0615a97263c0ad5045c2]
scheduler.conf                              File Size: 2160      BYTES    FileVersion:  N/A            MD5: [449f6536dcbcf9ef32f36ae96bcc8b21]
settings.conf                               File Size: 2120      BYTES    FileVersion:  N/A            MD5: [200ab00b2682fc0c196270dbffe55653]
statistics.conf                             File Size: 513       BYTES    FileVersion:  N/A            MD5: [5b12507488c8cc6ba1b0fad3d196d79a]

C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore
build.conf                                  File Size: 4178      BYTES    FileVersion:  N/A            MD5: [6759bfb0d20758e828f322cb432d8acb]
database.conf                               File Size: 4         BYTES    FileVersion:  N/A            MD5: [2261e7eca4cd0615a97263c0ad5045c2]
gatekeeper.conf                             File Size: 4         BYTES    FileVersion:  N/A            MD5: [2261e7eca4cd0615a97263c0ad5045c2]
license.conf                                File Size: 23        BYTES    FileVersion:  N/A            MD5: [0ec01df616b565180556881d8042255b]
manifest.conf                               File Size: 3184      BYTES    FileVersion:  N/A            MD5: [f9da45921ee39ca76afc39467ebc8e0a]
marketing.conf                              File Size: 6944      BYTES    FileVersion:  N/A            MD5: [c2133abde83f47a94e64d581e20b29cd]
net.conf                                    File Size: 6402      BYTES    FileVersion:  N/A            MD5: [859eb83405ed41b02f5a960bfb4ab573]
notifications.conf                          File Size: 4         BYTES    FileVersion:  N/A            MD5: [2261e7eca4cd0615a97263c0ad5045c2]
scheduler.conf                              File Size: 4         BYTES    FileVersion:  N/A            MD5: [2261e7eca4cd0615a97263c0ad5045c2]
settings.conf                               File Size: 1725      BYTES    FileVersion:  N/A            MD5: [5454026126dac24f6e96eeb0c64123d3]
statistics.conf                             File Size: 4         BYTES    FileVersion:  N/A            MD5: [2261e7eca4cd0615a97263c0ad5045c2]

C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs
mbam-log-2016-03-05 (23-01-49).xml          File Size: 12256     BYTES    FileVersion:  N/A            MD5: [1d680a9db337349f323dcabd003af7b0]
protection-log-2016-03-05.xml               File Size: 12444     BYTES    FileVersion:  N/A            MD5: [94c7a202217232534e348b1c881bab2e]
protection-log-2016-03-06.xml               File Size: 9963      BYTES    FileVersion:  N/A            MD5: [f74045e32cc644f81050d4bbb07df1c9]

C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Quarantine
0623359427.data                             File Size: 739       BYTES    FileVersion:  N/A            MD5: [81b72c58067fa6cc32eac6327cb0865b]
0623359427.quar                             File Size: 3526      BYTES    FileVersion:  N/A            MD5: [39864721f145a3cc37c1cd7be78eb6eb]
1259736005.data                             File Size: 698       BYTES    FileVersion:  N/A            MD5: [040d02ad46740914f44543fcf5fe76e9]
1259736005.quar                             File Size: 620       BYTES    FileVersion:  N/A            MD5: [6fbba37f1a54c6dbe0777bbde3fdc4e1]
1330431953.data                             File Size: 731       BYTES    FileVersion:  N/A            MD5: [d9bf7dbff669e4227df464ed9aa60502]
1330431953.quar                             File Size: 922       BYTES    FileVersion:  N/A            MD5: [de631cec9f5f9906d8d387f0fc364d1f]
1716808155.data                             File Size: 743       BYTES    FileVersion:  N/A            MD5: [3e7f71de78a9ad773e09ffae0d48ffec]
1716808155.quar                             File Size: 994       BYTES    FileVersion:  N/A            MD5: [7ec3c5a7fc84488c6e75bb2f14291210]
1875665876.quar                             File Size: 0         BYTES    FileVersion:  N/A            MD5: [d41d8cd98f00b204e9800998ecf8427e]
2269127605.data                             File Size: 739       BYTES    FileVersion:  N/A            MD5: [12bce02583d937b0eb698dc9f25fde56]
2269127605.quar                             File Size: 788       BYTES    FileVersion:  N/A            MD5: [08860a48ae4b70d1063a3f081b4d1fcd]
2636942398.data                             File Size: 731       BYTES    FileVersion:  N/A            MD5: [990135def2074fbfa8cdc51d594c139e]
2636942398.quar                             File Size: 908       BYTES    FileVersion:  N/A            MD5: [6d2a3c2156d2083ddafdaf376fb35df9]
3070957845.data                             File Size: 741       BYTES    FileVersion:  N/A            MD5: [fd3a65d5cede7d8bf5d0c9152f865460]
3070957845.quar                             File Size: 1802      BYTES    FileVersion:  N/A            MD5: [7cd6586e439db2be163bcb60416351c7]
3907057049.data                             File Size: 743       BYTES    FileVersion:  N/A            MD5: [eaaa6f2bce00e717a895838ccfc1ede8]
3907057049.quar                             File Size: 1222      BYTES    FileVersion:  N/A            MD5: [6bd26e03c135859d2a8013b8e77c7b02]
4148651422.data                             File Size: 743       BYTES    FileVersion:  N/A            MD5: [034d2b6e8483d393a0e252d632d7f135]
4148651422.quar                             File Size: 2189969   BYTES    FileVersion:  N/A            MD5: [f050d5a3b12729a10682cce0241b3885]
4820064406.data                             File Size: 743       BYTES    FileVersion:  N/A            MD5: [9b15e22a2d3160b1f4390590cb5e1d36]
4820064406.quar                             File Size: 994       BYTES    FileVersion:  N/A            MD5: [1aba7b3a81ab5eae217319b7ee27b939]
5169965672.data                             File Size: 739       BYTES    FileVersion:  N/A            MD5: [4c05b37b380fe865243245496d6a0aaa]
5169965672.quar                             File Size: 788       BYTES    FileVersion:  N/A            MD5: [86595e9ce92c7ab336c3315f9ae1957e]
5295145207.data                             File Size: 743       BYTES    FileVersion:  N/A            MD5: [2950d1715d59bff6cf128be37b2a651e]
5295145207.quar                             File Size: 1222      BYTES    FileVersion:  N/A            MD5: [d28400cff146d371be2d65f6d14acc62]
6262932032.data                             File Size: 700       BYTES    FileVersion:  N/A            MD5: [1e1a18e68f6e47353ca0b3b616a822e3]
6262932032.quar                             File Size: 594       BYTES    FileVersion:  N/A            MD5: [095e651e618e47f9830f8dc1a51c39fd]
6377204841.quar                             File Size: 0         BYTES    FileVersion:  N/A            MD5: [d41d8cd98f00b204e9800998ecf8427e]
6604540486.quar                             File Size: 0         BYTES    FileVersion:  N/A            MD5: [d41d8cd98f00b204e9800998ecf8427e]
7413740959.data                             File Size: 742       BYTES    FileVersion:  N/A            MD5: [7b949c44f5e2b67f27a2c4f13f4b8dd6]
7413740959.quar                             File Size: 193632    BYTES    FileVersion:  N/A            MD5: [ce45195d9adee6d4aa079cf679a50262]
8216120234.data                             File Size: 709       BYTES    FileVersion:  N/A            MD5: [dcf96e4943ced5c6ebb656e204741654]
8216120234.quar                             File Size: 1050600   BYTES    FileVersion:  N/A            MD5: [0daa0c2b9e0e3caee5ed2bf17d2b2090]
8613177373.data                             File Size: 698       BYTES    FileVersion:  N/A            MD5: [78b1e8b744c7260c7bd541696f9a9280]
8613177373.quar                             File Size: 690       BYTES    FileVersion:  N/A            MD5: [d154a81708368e6feab2f39c2eec6452]
8829625626.data                             File Size: 739       BYTES    FileVersion:  N/A            MD5: [8b05925662ee5e1db0c8dadd212124b5]
8829625626.quar                             File Size: 3526      BYTES    FileVersion:  N/A            MD5: [95805648894a623700cf4f6dc5dcc60a]
9373562672.data                             File Size: 741       BYTES    FileVersion:  N/A            MD5: [289f1fd3d66a72dfd54c676aee20840f]
9373562672.quar                             File Size: 1802      BYTES    FileVersion:  N/A            MD5: [e3feb430eb4b05efb07acb2938042061]
9458514336.quar                             File Size: 0         BYTES    FileVersion:  N/A            MD5: [d41d8cd98f00b204e9800998ecf8427e]
9500841199.data                             File Size: 737       BYTES    FileVersion:  N/A            MD5: [80f9c78a18c5ac12b1372a98028f09b1]
9500841199.quar                             File Size: 1050600   BYTES    FileVersion:  N/A            MD5: [058a1c488fcec6acb3cff48a06f139b4]
9910250803.data                             File Size: 729       BYTES    FileVersion:  N/A            MD5: [aa10680224988915f104942d82d40e25]
9910250803.quar                             File Size: 1658      BYTES    FileVersion:  N/A            MD5: [f37a8a5125de7c2cab5fec96350ed855]

Malware Exclusions:
===================
Web Exclusions:
================
Quarantined Items:
===================
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146}
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\CLASSES\OCComSDK.ComSDK
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\CLASSES\INTERFACE\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\CLASSES\INTERFACE\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{1112F282-7099-4624-A439-DB29D6551552}
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: File, Location: C:\Users\user\AppData\Local\Temp\HYD5571.tmp.1457226127\HTA\install.1457226127.zip
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\CLASSES\OCComSDK.ComSDK.1
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: File, Location: C:\Users\user\AppData\Local\Temp\HYD5571.tmp.1457226127\HTA\3rdparty\OCComSDK.dll
Vendor: PUP.Optional.BundleInstaller, Date: 2016/03/06 05:01:49, Type: File, Location: C:\Users\user\Downloads\FreeScreencast.exe
Vendor: PUP.Optional.ConduitTB.Gen, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\WOW6432NODE\Conduit
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146}
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{1112F282-7099-4624-A439-DB29D6551552}
Vendor: PUP.Optional.BundleInstaller, Date: 2016/03/06 05:01:49, Type: File, Location: C:\Users\user\AppData\Roaming\New Version Available\FreeScreencast.exe
Vendor: PUP.Optional.OpenCandy, Date: 2016/03/06 05:01:49, Type: Registry Key, Location: HKLM\SOFTWARE\CLASSES\TYPELIB\{1112F282-7099-4624-A439-DB29D6551552}
===============================================================
END OF FILE

 


.....let us not lose heart in running the race.....


#4 garyflater

garyflater
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Winnipeg, Canada
  • Local time:10:51 PM

Posted 06 March 2016 - 05:02 PM

emisoft log

Emsisoft Emergency Kit - Version 11.0
Last update: 3/6/2016 3:48:44 PM
User account: MOTHERTHERESA\user

Scan settings:

Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files

Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off

Scan start:    3/6/2016 3:54:27 PM
C:\Users\user\AppData\Roaming\speedypc software     detected: Application.AppInstall (A)
C:\ProgramData\speedypc software     detected: Application.AppInstall (A)
Key: HKEY_USERS\S-1-5-21-3585230462-2918350490-1616340752-1000\SOFTWARE\SPEEDYPC SOFTWARE     detected: Application.InstallAd (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SPEEDYPC SOFTWARE     detected: Application.InstallAd (A)
C:\Users\user\Downloads\SlimCleaner-setup.exe     detected: Application.Win32.InstallClean (A)

Scanned    71685
Found    5

Scan end:    3/6/2016 3:58:28 PM
Scan time:    0:04:01

C:\Users\user\Downloads\SlimCleaner-setup.exe     Application.Win32.InstallClean (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SPEEDYPC SOFTWARE     Application.InstallAd (A)
Key: HKEY_USERS\S-1-5-21-3585230462-2918350490-1616340752-1000\SOFTWARE\SPEEDYPC SOFTWARE     Application.InstallAd (A)

Quarantined    3
 


.....let us not lose heart in running the race.....


#5 garyflater

garyflater
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Winnipeg, Canada
  • Local time:10:51 PM

Posted 06 March 2016 - 05:14 PM

adaware log

 

# AdwCleaner v5.100 - Logfile created 06/03/2016 at 16:06:54
# Updated 06/03/2016 by Xplode
# Database : 2016-03-06.3 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : user - MOTHERTHERESA
# Running from : C:\Users\user\Downloads\AdwCleaner.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[#] Folder Deleted : C:\ProgramData\mntemp
[-] Folder Deleted : C:\ProgramData\speedypc software
[-] Folder Deleted : C:\users\user\AppData\Local\slimware utilities inc
[-] Folder Deleted : C:\users\user\AppData\Roaming\speedypc software

***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\SlimWare Utilities Inc
[-] Key Deleted : [x64] HKLM\SOFTWARE\SlimWare Utilities Inc

***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

*************************

C:\Program Files (x86)\AdwCleaner\AdwCleaner[C1].txt - [1063 bytes] - [06/03/2016 16:06:54]
C:\Program Files (x86)\AdwCleaner\AdwCleaner[S1].txt - [1133 bytes] - [06/03/2016 16:04:32]

########## EOF - C:\Program Files (x86)\AdwCleaner\AdwCleaner[C1].txt - [1249 bytes] ##########
 


Edited by garyflater, 06 March 2016 - 05:17 PM.

.....let us not lose heart in running the race.....


#6 garyflater

garyflater
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Winnipeg, Canada
  • Local time:10:51 PM

Posted 06 March 2016 - 06:08 PM

the command prompt my friend used was  Netstat -b


.....let us not lose heart in running the race.....


#7 garyflater

garyflater
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Winnipeg, Canada
  • Local time:10:51 PM

Posted 06 March 2016 - 06:28 PM

Eset

 

C:\Users\user\AppData\Local\Temp\g1Aos0UJ.exe.part    a variant of Win32/InstallCore.ACY.gen potentially unwanted application    cleaned by deleting
 


.....let us not lose heart in running the race.....


#8 dc3

dc3

    Bleeping Treehugger


  • Members
  • 30,397 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:09:51 PM

Posted 07 March 2016 - 09:43 AM

All I'm seeing are PUPs, nothing malicious.

 

 
 
Please run System File Checker
 
The sfc /scannow command scans all protected system files and replaces corrupted and incorrect versions with correct Microsoft versions.
 
Click on the Start orb rsz_1rsz_1rsz_start_orb_zpshjewtibd.png and then type cmd in the Search programs and files box.
 
In the pane above the search box Programs will appear with cmd below it, right click on cmd and select Run as administrator.
 
If you are prompted for an administrator password or for a confirmation, enter the password, or click Allow.
 
This will open the Elevated Command Prompt, it will look similar to the image below.
 
command%20prompt%20w8_zpsxjmewau9.png
 
Copy and paste sfc /scannow in the command prompt, then press Enter to start the scan.  
 
If the scan finds no integrity  problems the scan will stop.  Type in exit, then press Enter to stop the scan.
 
When the scan is finished and if intergrity issues are found, please do the following.
 
Click on the Start orb rsz_1rsz_1rsz_start_orb_zpshjewtibd.png then copy and paste the following in the Search programs and files box.
 
findstr /c:"[SR]" %windir%\logs\cbs\cbs.log >"%userprofile%\Desktop\sfcdetails.txt"
 
This will place a new icon on the desktop titled sfcdetails.  Double click on this icon to  
the CBS log, copy and paste the log in your topic.
 
If this fails to place the icon on your desktop run the command from the Command Prompt.  Use the instructions I provided at the start of this tutorial.
 
This log may be very large, if you have problems posting it try breaking it into smaller parts.  When you copy these parts you will highlight the section you are going to copy.  If you leave that section highlighted it will give you a quick reference for where you left off.
 
 

Please download and install Speccy to provide us with information about your computer.  Clicking on this link will automatically initiate the download. 
 
When Speccy opens you will see a screen similar to the one below.
 
speccy9_zps2d9cdedc.png
 
Click on File which is outlined in red in the screen above, and then click on Publish Snapshot.
 
The following screen will appear, click on Yes.
 
speccy7_zpsfa02105f.png
 
The following screen will appear, click on Copy to Clipboard.
 
speccy3_zps1791b093.png
 
In your next post right click inside the Reply to Topic box, then click on Paste.  This will load a link to the Speccy log.
 
 

Please download MiniToolBox to your desktop.
 
Right-click on MiniToolBox.exe and select Run as Administrator.
 
You will see an image like the one below.
 
minitoolbox_zps7byuwkla.png
 
Click on the following checkboxes only:
 
• List last 10 Event Viewer log
• List Installed Programs
• List Users, Partitions and Memory size.
• List Minidump Files
 
Click on Go to start the scan.  Once it is finished highlight the text, then copy it and paste it in your topic.

Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

 

 

 

 


#9 garyflater

garyflater
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Winnipeg, Canada
  • Local time:10:51 PM

Posted 07 March 2016 - 04:50 PM

First Half of Log

 

 

Name    Description    Status      Startup Type    Log On As
ActiveX Installer (AxInstSV)    Provides User Account Control validation for the installation of ActiveX controls from the Internet and enables management of ActiveX control installation based on Group Policy settings. This service is started on demand and if disabled the installation of ActiveX controls will behave according to default browser settings.        Manual    Local System
Adaptive Brightness    Monitors ambient light sensors to detect changes in ambient light and adjust the display brightness.  If this service is stopped or disabled, the display brightness will not adapt to lighting conditions.        Manual    Local Service
Adobe Acrobat Update Service    Adobe Acrobat Updater keeps your Adobe software up to date.        Manual    Local System
Application Experience    Processes application compatibility cache requests for applications as they are launched    Started    Manual    Local System
Application Identity    Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced.        Manual    Local Service
Application Information    Facilitates the running of interactive applications with additional administrative privileges.  If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.    Started    Manual    Local System
Application Layer Gateway Service    Provides support for 3rd party protocol plug-ins for Internet Connection Sharing        Manual    Local Service
Application Management    Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local System
ASP.NET State Service    Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start.        Disabled    Network Service
Avast Antivirus    Manages and implements Avast antivirus services for this computer. This includes the real-time shields, the virus chest and the scheduler.    Started    Automatic    Local System
Background Intelligent Transfer Service    Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information.        Manual    Local System
Base Filtering Engine    The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictable behavior in IPsec management and firewall applications.    Started    Automatic    Local Service
BitLocker Drive Encryption Service    BDESVC hosts the BitLocker Drive Encryption service. BitLocker Drive Encryption provides secure startup for the operating system, as well as full volume encryption for OS, fixed or removable volumes. This service allows BitLocker to prompt users for various actions related to their volumes when mounted, and unlocks volumes automatically without user interaction. Additionally, it stores recovery information to Active Directory, if available, and, if necessary, ensures the most recent recovery certificates are used.  Stopping or disabling the service would prevent users from leveraging this functionality.        Manual    Local System
Block Level Backup Engine Service    The WBENGINE service is used by Windows Backup to perform backup and recovery operations. If this service is stopped by a user, it may cause the currently running backup or recovery operation to fail. Disabling this service may disable backup and recovery operations using Windows Backup on this computer.        Manual    Local System
Bluetooth Support Service    The Bluetooth service supports discovery and association of remote Bluetooth devices.  Stopping or disabling this service may cause already installed Bluetooth devices to fail to operate properly and prevent new devices from being discovered or associated.        Manual    Local Service
BranchCache    This service caches network content from peers on the local subnet.        Manual    Network Service
Certificate Propagation    Copies user certificates and root certificates from smart cards into the current user's certificate store, detects when a smart card is inserted into a smart card reader, and, if needed, installs the smart card Plug and Play minidriver.        Manual    Local System
CNG Key Isolation    The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common Criteria requirements.    Started    Manual    Local System
COM+ Event System    Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.    Started    Automatic    Local Service
COM+ System Application    Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local System
Computer Browser    Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start.    Started    Manual    Local System
Credential Manager    Provides secure storage and retrieval of credentials to users, applications and security service packages.    Started    Manual    Local System
Cryptographic Services    Provides four management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; Automatic Root Certificate Update Service, which retrieves root certificates from Windows Update and enable scenarios such as SSL; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.    Started    Automatic    Network Service
DCOM Server Process Launcher    The DCOMLAUNCH service launches COM and DCOM servers in response to object activation requests. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the DCOMLAUNCH service running.    Started    Automatic    Local System
Desktop Window Manager Session Manager    Provides Desktop Window Manager startup and maintenance services    Started    Automatic    Local System
DHCP Client    Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start.    Started    Automatic    Local Service
Diagnostic Policy Service    The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components.  If this service is stopped, diagnostics will no longer function.        Manual    Local Service
Diagnostic Service Host    The Diagnostic Service Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local Service context.  If this service is stopped, any diagnostics that depend on it will no longer function.        Manual    Local Service
Diagnostic System Host    The Diagnostic System Host is used by the Diagnostic Policy Service to host diagnostics that need to run in a Local System context.  If this service is stopped, any diagnostics that depend on it will no longer function.        Manual    Local System
Disk Defragmenter    Provides Disk Defragmentation Capabilities.        Manual    Local System
Distributed Link Tracking Client    Maintains links between NTFS files within a computer or across computers in a network.        Manual    Local System
Distributed Transaction Coordinator    Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will fail. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Network Service
DNS Client    The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start.    Started    Automatic    Network Service
Encrypting File System (EFS)    Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files.        Manual    Local System
Extensible Authentication Protocol    The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP).  EAP also provides application programming interfaces (APIs) that are used by network access clients, including wireless and VPN clients, during the authentication process.  If you disable this service, this computer is prevented from accessing networks that require EAP authentication.    Started    Manual    Local System
Fax    Enables you to send and receive faxes, utilizing fax resources available on this computer or on the network.        Manual    Network Service
Function Discovery Provider Host    The FDPHOST service hosts the Function Discovery (FD) network discovery providers. These FD providers supply network discovery services for the Simple Services Discovery Protocol (SSDP) and Web Services – Discovery (WS-D) protocol. Stopping or disabling the FDPHOST service will disable network discovery for these protocols when using FD. When this service is unavailable, network services using FD and relying on these discovery protocols will be unable to find network devices or resources.    Started    Manual    Local Service
Function Discovery Resource Publication    Publishes this computer and resources attached to this computer so they can be discovered over the network.  If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network.    Started    Manual    Local Service
Group Policy Client    The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is stopped or disabled, the settings will not be applied and applications and components will not be manageable through Group Policy. Any components or applications that depend on the Group Policy component might not be functional if the service is stopped or disabled.        Manual    Local System
Health Key and Certificate Management    Provides X.509 certificate and key management services for the Network Access Protection Agent (NAPAgent). Enforcement technologies that use X.509 certificates may not function properly without this service        Manual    Local System
HomeGroup Listener    Makes local computer changes associated with configuration and maintenance of the homegroup-joined computer. If this service is stopped or disabled, your computer will not work properly in a homegroup and your homegroup might not work properly. It is recommended that you keep this service running.    Started    Manual    Local System
HomeGroup Provider    Performs networking tasks associated with configuration and maintenance of homegroups. If this service is stopped or disabled, your computer will be unable to detect other homegroups and your homegroup might not work properly. It is recommended that you keep this service running.    Started    Manual    Local Service
HP Support Solutions Framework Service    This service allows for the detection of HP products and enables identification of support solutions for detected products.    Starting    Automatic (Delayed Start)    Local System
Human Interface Device Access    Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local System
HyperW7 Service            Automatic    Local System
IKE and AuthIP IPsec Keying Modules    The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running.        Manual    Local System
Intel® Content Protection HECI Service    Intel® Content Protection HECI Service - enables communication with the Content Protection FW        Manual    Local System
Intel® Integrated Clock Controller Service - Intel® ICCS    Intel® Integrated Clock Controller Service - Intel® ICCS        Manual    Local System
Intel® PROSet/Wireless Event Log    Manages the event trace messages for all the Intel® PROSet/Wireless Software components.    Started    Automatic    Local System
Intel® PROSet/Wireless Registry Service    Provides registry access to all Intel® PROSet/Wireless Software components    Started    Automatic    Local System
Intel® PROSet/Wireless Zero Configuration Service    Manages the zero configuration service for all the Intel® PROSet/Wireless Software components.    Started    Automatic    Local System
Interactive Services Detection    Enables user notification of user input for interactive services, which enables access to dialogs created by interactive services when they appear. If this service is stopped, notifications of new interactive service dialogs will no longer function and there might not be access to interactive service dialogs. If this service is disabled, both notifications of and access to new interactive service dialogs will no longer function.        Manual    Local System
Internet Connection Sharing (ICS)    Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.        Disabled    Local System
Internet Explorer ETW Collector Service    ETW Collector Service for Internet Explorer. When running, this service collects real time ETW events and processes them.        Manual    Local System
IP Helper    Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer.    Started    Automatic    Local System
IPsec Policy Agent    Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection.  This service enforces IPsec policies created through the IP Security Policies snap-in or the command-line tool "netsh ipsec".  If you stop this service, you may experience network connectivity issues if your policy requires that connections use IPsec.  Also,remote management of Windows Firewall is not available when this service is stopped.        Manual    Network Service
KtmRm for Distributed Transaction Coordinator    Coordinates transactions between the Distributed Transaction Coordinator (MSDTC) and the Kernel Transaction Manager (KTM). If it is not needed, it is recommended that this service remain stopped. If it is needed, both MSDTC and KTM will start this service automatically. If this service is disabled, any MSDTC transaction interacting with a Kernel Resource Manager will fail and any services that explicitly depend on it will fail to start.        Manual    Network Service
Lenovo Hotkey Client Loader        Started    Automatic    Local System
Lenovo Microphone Mute        Started    Automatic    Local System
Lenovo PM Service        Started    Automatic    Local System
Link-Layer Topology Discovery Mapper    Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device.  If this service is disabled, the Network Map will not function properly.        Manual    Local Service
Media Center Extender Service    Allows Media Center Extenders to locate and connect to the computer.        Disabled    Local Service
Microsoft .NET Framework NGEN v2.0.50727_X64    Microsoft .NET Framework NGEN        Disabled    Local System
Microsoft .NET Framework NGEN v2.0.50727_X86    Microsoft .NET Framework NGEN        Disabled    Local System
Microsoft .NET Framework NGEN v4.0.30319_X64    Microsoft .NET Framework NGEN        Automatic (Delayed Start)    Local System
Microsoft .NET Framework NGEN v4.0.30319_X86    Microsoft .NET Framework NGEN        Automatic (Delayed Start)    Local System
Microsoft iSCSI Initiator Service    Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local System
Microsoft Software Shadow Copy Provider    Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local System
Mozilla Maintenance Service    The Mozilla Maintenance Service ensures that you have the latest and most secure version of Mozilla Firefox on your computer. Keeping Firefox up to date is very important for your online security, and Mozilla strongly recommends that you keep this service enabled.        Manual    Local System
Multimedia Class Scheduler    Enables relative prioritization of work based on system-wide task priorities. This is intended mainly for multimedia applications.  If this service is stopped, individual tasks resort to their default priority.    Started    Automatic    Local System
Net.Msmq Listener Adapter    Receives activation requests over the net.msmq and msmq.formatname protocols and passes them to the Windows Process Activation Service.        Disabled    Network Service
Net.Pipe Listener Adapter    Receives activation requests over the net.pipe protocol and passes them to the Windows Process Activation Service.        Disabled    Local Service
Net.Tcp Listener Adapter    Receives activation requests over the net.tcp protocol and passes them to the Windows Process Activation Service.        Disabled    Local Service
Net.Tcp Port Sharing Service    Provides ability to share TCP ports over the net.tcp protocol.        Disabled    Local Service
Netlogon    Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local System
Network Access Protection Agent    The Network Access Protection (NAP) agent service collects and manages health information for client computers on a network. Information collected by NAP agent is used to make sure that the client computer has the required software and settings. If a client computer is not compliant with health policy, it can be provided with restricted network access until its configuration is updated. Depending on the configuration of health policy, client computers might be automatically updated so that users quickly regain full network access without having to manually update their computer.        Manual    Network Service
Network Connections    Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.    Started    Manual    Local System
Network List Service    Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change.    Started    Manual    Local Service
Network Location Awareness    Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.    Started    Automatic    Network Service
Network Store Interface Service    This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to start.    Started    Automatic    Local Service
Office 64 Source Engine    Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.        Manual    Local System
Office Software Protection Platform    Enables the download, installation, and enforcement of digital licenses for Microsoft Office applications. These applications require this service for proper operation. It is strongly recommended that you keep this service enabled.        Manual    Network Service
Offline Files    The Offline Files service performs maintenance activities on the Offline Files cache, responds to user logon and logoff events, implements the internals of the public API, and dispatches interesting events to those interested in Offline Files activities and changes in cache state.        Manual    Local System
On Screen Display        Started    Automatic    Local System
Parental Controls    This service is a stub for Windows Parental Control functionality that existed in Vista. It is provided for backward compatibility only.        Manual    Local Service
 


.....let us not lose heart in running the race.....


#10 garyflater

garyflater
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Winnipeg, Canada
  • Local time:10:51 PM

Posted 07 March 2016 - 04:51 PM

Second Half

 

 

Peer Name Resolution Protocol    Enables serverless peer name resolution over the Internet using the Peer Name Resolution Protocol (PNRP). If disabled, some peer-to-peer and collaborative applications, such as Remote Assistance, may not function.    Started    Manual    Local Service
Peer Networking Grouping    Enables multi-party communication using Peer-to-Peer Grouping.  If disabled, some applications, such as HomeGroup, may not function.    Started    Manual    Local Service
Peer Networking Identity Manager    Provides identity services for the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services.  If disabled, the Peer Name Resolution Protocol (PNRP) and Peer-to-Peer Grouping services may not function, and some applications, such as HomeGroup and Remote Assistance, may not function correctly.    Started    Manual    Local Service
Performance Counter DLL Host    Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs.        Manual    Local Service
Performance Logs & Alerts    Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local Service
Plug and Play    Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.    Started    Automatic    Local System
PnP-X IP Bus Enumerator    The PnP-X bus enumerator service manages the virtual network bus. It discovers network connected devices using the SSDP/WS discovery protocols and gives them presence in PnP. If this service is stopped or disabled, presence of NCD devices will not be maintained in PnP. All pnpx based scenarios will stop functioning.        Manual    Local System
PNRP Machine Name Publication Service    This service publishes a machine name using the Peer Name Resolution Protocol.  Configuration is managed via the netsh context 'p2p pnrp peer'         Manual    Local Service
Portable Device Enumerator Service    Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices.    Started    Manual    Local System
Power    Manages power policy and power policy notification delivery.    Started    Automatic    Local System
Print Spooler    Loads files to memory for later printing    Started    Automatic    Local System
Problem Reports and Solutions Control Panel Support    This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports and Solutions control panel.        Manual    Local System
Program Compatibility Assistant Service    This service provides support for the Program Compatibility Assistant (PCA).  PCA monitors programs installed and run by the user and detects known compatibility problems. If this service is stopped, PCA will not function properly.    Started    Automatic    Local System
Protected Storage    Provides protected storage for sensitive data, such as passwords, to prevent access by unauthorized services, processes, or users.        Manual    Local System
Quality Windows Audio Video Experience    Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. It provides mechanisms for admission control, run time monitoring and enforcement, application feedback, and traffic prioritization.        Manual    Local Service
Remote Access Auto Connection Manager    Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.        Manual    Local System
Remote Access Connection Manager    Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local System
Remote Desktop Configuration    Remote Desktop Configuration service (RDCS) is responsible for all Remote Desktop Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, RD themes, and RD certificates.        Manual    Local System
Remote Desktop Services    Allows users to connect interactively to a remote computer. Remote Desktop and Remote Desktop Session Host Server depend on this service.  To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item.        Manual    Network Service
Remote Desktop Services UserMode Port Redirector    Allows the redirection of Printers/Drives/Ports for RDP connections        Manual    Local System
Remote Procedure Call (RPC)    The RPCSS service is the Service Control Manager for COM and DCOM servers. It performs object activations requests, object exporter resolutions and distributed garbage collection for COM and DCOM servers. If this service is stopped or disabled, programs using COM or DCOM will not function properly. It is strongly recommended that you have the RPCSS service running    Started    Manual    Network Service
Remote Procedure Call (RPC) Locator    In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database. In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility.        Manual    Network Service
Remote Registry    Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local Service
Routing and Remote Access    Offers routing services to businesses in local area and wide area network environments.        Disabled    Local System
RPC Endpoint Mapper    Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly.    Started    Automatic    Network Service
Secondary Logon    Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local System
Secure Socket Tunneling Protocol Service    Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers.        Manual    Local Service
Security Accounts Manager    The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests.  Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to fail to start correctly. This service should not be disabled.    Started    Manual    Local System
Security Center    The WSCSVC (Windows Security Center) service monitors and reports security health settings on the computer.  The health settings include firewall (on/off), antivirus (on/off/out of date), antispyware (on/off/out of date), Windows Update (automatically/manually download and install updates), User Account Control (on/off), and Internet settings (recommended/not recommended). The service provides COM APIs for independent software vendors to register and record the state of their products to the Security Center service.  The Action Center (AC) UI uses the service to provide systray alerts and a graphical view of the security health states in the AC control panel.  Network Access Protection (NAP) uses the service to report the security health states of clients to the NAP Network Policy Server to make network quarantine decisions.  The service also has a public API that allows external consumers to programmatically retrieve the aggregated security health state of the system.    Started    Automatic (Delayed Start)    Local Service
Server    Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.    Started    Manual    Local System
Shell Hardware Detection    Provides notifications for AutoPlay hardware events.    Started    Automatic    Local System
Smart Card    Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local Service
Smart Card Removal Policy    Allows the system to be configured to lock the user desktop upon smart card removal.        Manual    Local System
SNMP Trap    Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local Service
Software Protection    Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a notification mode. It is strongly recommended that you not disable the Software Protection service.        Automatic (Delayed Start)    Network Service
SPP Notification Service    Provides Software Licensing activation and notification        Manual    Local Service
SSDP Discovery    Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any services that explicitly depend on it will fail to start.    Started    Manual    Local Service
Storage Service    Enforces group policy for storage devices        Manual    Local System
Superfetch    Maintains and improves system performance over time.    Started    Automatic    Local System
System Event Notification Service    Monitors system events and notifies subscribers to COM+ Event System of these events.    Started    Automatic    Local System
Tablet PC Input Service    Enables Tablet PC pen and ink functionality        Manual    Local System
Task Scheduler    Enables a user to configure and schedule automated tasks on this computer. The service also hosts multiple Windows system-critical tasks. If this service is stopped or disabled, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.    Started    Automatic    Local System
TCP/IP NetBIOS Helper    Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.    Started    Manual    Local Service
Telephony    Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service.        Manual    Network Service
Themes    Provides user experience theme management.    Started    Automatic    Local System
Thread Ordering Server    Provides ordered execution for a group of threads within a specific period of time.        Manual    Local Service
TPM Base Services    Enables access to the Trusted Platform Module (TPM), which provides hardware-based cryptographic services to system components and applications.  If this service is stopped or disabled, applications will be unable to use keys protected by the TPM.        Manual    Local Service
UPnP Device Host    Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start.    Started    Manual    Local Service
User Profile Service    This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully logon or logoff, applications may have problems getting to users' data, and components registered to receive profile event notifications will not receive them.    Started    Automatic    Local System
Virtual Disk    Provides management services for disks, volumes, file systems, and storage arrays.        Manual    Local System
Volume Shadow Copy    Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local System
WebClient    Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local Service
Windows Audio    Manages audio for Windows-based programs.  If this service is stopped, audio devices and effects will not function properly.  If this service is disabled, any services that explicitly depend on it will fail to start    Started    Automatic    Local Service
Windows Audio Endpoint Builder    Manages audio devices for the Windows Audio service.  If this service is stopped, audio devices and effects will not function properly.  If this service is disabled, any services that explicitly depend on it will fail to start    Started    Automatic    Local System
Windows Backup    Provides Windows Backup and Restore capabilities.        Manual    Local System
Windows Biometric Service    The Windows biometric service gives client applications the ability to capture, compare, manipulate, and store biometric data without gaining direct access to any biometric hardware or samples. The service is hosted in a privileged SVCHOST process.    Started    Automatic    Local System
Windows CardSpace    Securely enables the creation, management, and disclosure of digital identities.        Manual    Local System
Windows Color System    The WcsPlugInService service hosts third-party Windows Color System color device model and gamut map model plug-in modules. These plug-in modules are vendor-specific extensions to the Windows Color System baseline color device and gamut map models. Stopping or disabling the WcsPlugInService service will disable this extensibility feature, and the Windows Color System will use its baseline model processing rather than the vendor's desired processing. This might result in inaccurate color rendering.        Manual    Local Service
Windows Connect Now - Config Registrar    WCNCSVC hosts the Windows Connect Now Configuration which is Microsoft's Implementation of Wi-Fi Protected Setup (WPS) protocol. This is used to configure Wireless LAN settings for an Access Point (AP) or a Wi-Fi Device. The service is started programmatically as needed.        Manual    Local Service
Windows Defender    Protection against spyware and potentially unwanted software        Manual    Local System
Windows Driver Foundation - User-mode Driver Framework    Creates and manages user-mode driver processes. This service cannot be stopped.    Started    Manual    Local System
Windows Error Reporting Service    Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results of diagnostic services and repairs might not be displayed.        Manual    Local System
Windows Event Collector    This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stopped or disabled event subscriptions cannot be created and forwarded events cannot be accepted.        Manual    Network Service
Windows Event Log    This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability of the system.    Started    Automatic    Local Service
Windows Firewall    Windows Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network.    Started    Automatic    Local Service
Windows Font Cache Service    Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance.    Started    Manual    Local Service
Windows Image Acquisition (WIA)    Provides image acquisition services for scanners and cameras    Started    Automatic    Local Service
Windows Installer    Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local System
Windows Management Instrumentation    Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.    Started    Automatic    Local System
Windows Media Center Receiver Service    Windows Media Center Service for TV and FM broadcast reception        Manual    Network Service
Windows Media Center Scheduler Service    Starts and stops recording of TV programs within Windows Media Center        Manual    Network Service
Windows Media Player Network Sharing Service    Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play    Started    Manual    Network Service
Windows Modules Installer    Enables installation, modification, and removal of Windows updates and optional components. If this service is disabled, install or uninstall of Windows updates might fail for this computer.        Manual    Local System
Windows Presentation Foundation Font Cache 3.0.0.0    Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications.        Manual    Local Service
Windows Remote Management (WS-Management)    Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Management requests and processes them. The WinRM Service needs to be configured with a listener using winrm.cmd command line tool or through Group Policy in order for it to listen over the network. The WinRM service provides access to WMI data and enables event collection. Event collection and subscription to events require that the service is running. WinRM messages use HTTP and HTTPS as transports. The WinRM service does not depend on IIS but is preconfigured to share a port with IIS on the same machine.  The WinRM service reserves the /wsman URL prefix. To prevent conflicts with IIS, administrators should ensure that any websites hosted on IIS do not use the /wsman URL prefix.        Manual    Network Service
Windows Search    Provides content indexing, property caching, and search results for files, e-mail, and other content.    Started    Automatic (Delayed Start)    Local System
Windows Time    Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.        Manual    Local Service
Windows Update    Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WUA) API.        Automatic (Delayed Start)    Local System
WinHTTP Web Proxy Auto-Discovery Service    WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its implementation of the Web Proxy Auto-Discovery (WPAD) protocol.    Started    Manual    Local Service
Wired AutoConfig    The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.        Manual    Local System
Wireless PAN DHCP Server            Manual    Local System
WLAN AutoConfig    The WLANSVC service provides the logic required to configure, discover, connect to, and disconnect from a wireless local area network (WLAN) as defined by IEEE 802.11 standards. It also contains the logic to turn your computer into a software access point so that other devices or computers can connect to your computer wirelessly using a WLAN adapter that can support this. Stopping or disabling the WLANSVC service will make all WLAN adapters on your computer inaccessible from the Windows networking UI. It is strongly recommended that you have the WLANSVC service running if your computer has a WLAN adapter.    Started    Automatic    Local System
WMI Performance Adapter    Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated.        Manual    Local System
Workstation    Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.    Started    Manual    Network Service
WWAN AutoConfig    This service manages mobile broadband (GSM & CDMA) data card/embedded module adapters and connections by auto-configuring the networks. It is strongly recommended that this service be kept running for best user experience of mobile broadband devices.        Manual    Local Service
 


.....let us not lose heart in running the race.....


#11 garyflater

garyflater
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Winnipeg, Canada
  • Local time:10:51 PM

Posted 07 March 2016 - 05:16 PM

speccy

 

http://speccy.piriform.com/results/riLl4ql8o73fCcgVE57ZHj2

 

Mini tool box closed after scan and did not generate a log file. Tried multilpe times

with same result


.....let us not lose heart in running the race.....


#12 dc3

dc3

    Bleeping Treehugger


  • Members
  • 30,397 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:09:51 PM

Posted 08 March 2016 - 09:03 AM

What you posted for the CBS Log does not resemble a CBS Log.

 

Please do the following to produce the CBS Log.

 

Click on the Start orb rsz_1rsz_1rsz_start_orb_zpshjewtibd.png, when the Start Menu opens click on Computer.  If there are more than one partition click on the C: drive.

 

Click on Windows, then Logs, then CBS.  

 

The log is stamped for time and date.  Click on the log with the date when you ran the sfc /scannow.  Copy and paste this in your topic.


Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

 

 

 

 


#13 garyflater

garyflater
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Winnipeg, Canada
  • Local time:10:51 PM

Posted 08 March 2016 - 03:37 PM

the file consists of every thing that day. Evening included. there are 960051 lines

 

did another just now  

 

 

First half

 

 

SI    0000045c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:20, Info                  CSI    0000045d [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:21, Info                  CSI    0000045f [SR] Verify complete
2016-03-08 14:18:21, Info                  CSI    00000460 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:21, Info                  CSI    00000461 [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:23, Info                  CSI    00000463 [SR] Verify complete
2016-03-08 14:18:23, Info                  CSI    00000464 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:23, Info                  CSI    00000465 [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:24, Info                  CSI    00000467 [SR] Verify complete
2016-03-08 14:18:24, Info                  CSI    00000468 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:24, Info                  CSI    00000469 [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:26, Info                  CSI    0000046b [SR] Verify complete
2016-03-08 14:18:26, Info                  CSI    0000046c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:26, Info                  CSI    0000046d [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:28, Info                  CSI    0000046f [SR] Verify complete
2016-03-08 14:18:28, Info                  CSI    00000470 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:28, Info                  CSI    00000471 [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:30, Info                  CSI    00000473 [SR] Verify complete
2016-03-08 14:18:30, Info                  CSI    00000474 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:30, Info                  CSI    00000475 [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:32, Info                  CSI    00000477 [SR] Verify complete
2016-03-08 14:18:32, Info                  CSI    00000478 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:32, Info                  CSI    00000479 [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:33, Info                  CSI    0000047b [SR] Verify complete
2016-03-08 14:18:33, Info                  CSI    0000047c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:33, Info                  CSI    0000047d [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:35, Info                  CSI    0000047f [SR] Verify complete
2016-03-08 14:18:35, Info                  CSI    00000480 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:35, Info                  CSI    00000481 [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:38, Info                  CSI    00000483 [SR] Verify complete
2016-03-08 14:18:38, Info                  CSI    00000484 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:38, Info                  CSI    00000485 [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:41, Info                  CSI    00000487 [SR] Verify complete
2016-03-08 14:18:41, Info                  CSI    00000488 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:41, Info                  CSI    00000489 [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:44, Info                  CSI    0000048b [SR] Verify complete
2016-03-08 14:18:44, Info                  CSI    0000048c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:44, Info                  CSI    0000048d [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:47, Info                  CSI    0000048f [SR] Verify complete
2016-03-08 14:18:47, Info                  CSI    00000490 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:47, Info                  CSI    00000491 [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:49, Info                  CSI    00000493 [SR] Verify complete
2016-03-08 14:18:49, Info                  CSI    00000494 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:49, Info                  CSI    00000495 [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:51, Info                  CSI    00000497 [SR] Verify complete
2016-03-08 14:18:51, Info                  CSI    00000498 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:51, Info                  CSI    00000499 [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:53, Info                  CSI    0000049b [SR] Verify complete
2016-03-08 14:18:53, Info                  CSI    0000049c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:53, Info                  CSI    0000049d [SR] Beginning Verify and Repair transaction
2016-03-08 14:18:58, Info                  CSI    0000049f [SR] Verify complete
2016-03-08 14:18:58, Info                  CSI    000004a0 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:18:58, Info                  CSI    000004a1 [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:01, Info                  CSI    000004a3 [SR] Verify complete
2016-03-08 14:19:02, Info                  CSI    000004a4 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:02, Info                  CSI    000004a5 [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:04, Info                  CSI    000004a7 [SR] Verify complete
2016-03-08 14:19:04, Info                  CSI    000004a8 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:04, Info                  CSI    000004a9 [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:07, Info                  CSI    000004ab [SR] Verify complete
2016-03-08 14:19:08, Info                  CSI    000004ac [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:08, Info                  CSI    000004ad [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:14, Info                  CSI    000004b1 [SR] Verify complete
2016-03-08 14:19:14, Info                  CSI    000004b2 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:14, Info                  CSI    000004b3 [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:19, Info                  CSI    000004b8 [SR] Verify complete
2016-03-08 14:19:19, Info                  CSI    000004b9 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:19, Info                  CSI    000004ba [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:23, Info                  CSI    000004bd [SR] Verify complete
2016-03-08 14:19:23, Info                  CSI    000004be [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:23, Info                  CSI    000004bf [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:27, Info                  CSI    000004c1 [SR] Verify complete
2016-03-08 14:19:27, Info                  CSI    000004c2 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:27, Info                  CSI    000004c3 [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:32, Info                  CSI    000004c8 [SR] Verify complete
2016-03-08 14:19:32, Info                  CSI    000004c9 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:32, Info                  CSI    000004ca [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:38, Info                  CSI    000004ec [SR] Verify complete
2016-03-08 14:19:39, Info                  CSI    000004ed [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:39, Info                  CSI    000004ee [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:44, Info                  CSI    000004f0 [SR] Verify complete
2016-03-08 14:19:44, Info                  CSI    000004f1 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:44, Info                  CSI    000004f2 [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:49, Info                  CSI    000004f4 [SR] Verify complete
2016-03-08 14:19:49, Info                  CSI    000004f5 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:49, Info                  CSI    000004f6 [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:53, Info                  CSI    000004f8 [SR] Verify complete
2016-03-08 14:19:53, Info                  CSI    000004f9 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:53, Info                  CSI    000004fa [SR] Beginning Verify and Repair transaction
2016-03-08 14:19:59, Info                  CSI    000004fc [SR] Verify complete
2016-03-08 14:19:59, Info                  CSI    000004fd [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:19:59, Info                  CSI    000004fe [SR] Beginning Verify and Repair transaction
2016-03-08 14:20:03, Info                  CSI    00000500 [SR] Verify complete
2016-03-08 14:20:03, Info                  CSI    00000501 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:20:03, Info                  CSI    00000502 [SR] Beginning Verify and Repair transaction
2016-03-08 14:20:09, Info                  CSI    00000504 [SR] Verify complete
2016-03-08 14:20:10, Info                  CSI    00000505 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:20:10, Info                  CSI    00000506 [SR] Beginning Verify and Repair transaction
2016-03-08 14:20:18, Info                  CSI    00000529 [SR] Verify complete
2016-03-08 14:20:18, Info                  CSI    0000052a [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:20:18, Info                  CSI    0000052b [SR] Beginning Verify and Repair transaction
2016-03-08 14:20:25, Info                  CSI    0000052d [SR] Verify complete
2016-03-08 14:20:25, Info                  CSI    0000052e [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:20:25, Info                  CSI    0000052f [SR] Beginning Verify and Repair transaction
2016-03-08 14:20:36, Info                  CSI    00000531 [SR] Verify complete
2016-03-08 14:20:36, Info                  CSI    00000532 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:20:36, Info                  CSI    00000533 [SR] Beginning Verify and Repair transaction
2016-03-08 14:20:45, Info                  CSI    00000537 [SR] Verify complete
2016-03-08 14:20:45, Info                  CSI    00000538 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:20:45, Info                  CSI    00000539 [SR] Beginning Verify and Repair transaction
2016-03-08 14:20:48, Info                  CSI    0000053b [SR] Verify complete
2016-03-08 14:20:48, Info                  CSI    0000053c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:20:48, Info                  CSI    0000053d [SR] Beginning Verify and Repair transaction
2016-03-08 14:20:49, Info                  CSI    0000053f [SR] Verify complete
2016-03-08 14:20:49, Info                  CSI    00000540 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:20:49, Info                  CSI    00000541 [SR] Beginning Verify and Repair transaction
2016-03-08 14:20:52, Info                  CSI    00000543 [SR] Verify complete
2016-03-08 14:20:52, Info                  CSI    00000544 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:20:52, Info                  CSI    00000545 [SR] Beginning Verify and Repair transaction
2016-03-08 14:20:59, Info                  CSI    00000558 [SR] Verify complete
2016-03-08 14:20:59, Info                  CSI    00000559 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:20:59, Info                  CSI    0000055a [SR] Beginning Verify and Repair transaction
2016-03-08 14:21:01, Info                  CSI    0000055c [SR] Verify complete
2016-03-08 14:21:01, Info                  CSI    0000055d [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:21:01, Info                  CSI    0000055e [SR] Beginning Verify and Repair transaction
2016-03-08 14:21:04, Info                  CSI    00000560 [SR] Verify complete
2016-03-08 14:21:04, Info                  CSI    00000561 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:21:04, Info                  CSI    00000562 [SR] Beginning Verify and Repair transaction
2016-03-08 14:21:06, Info                  CSI    00000564 [SR] Verify complete
2016-03-08 14:21:06, Info                  CSI    00000565 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:21:06, Info                  CSI    00000566 [SR] Beginning Verify and Repair transaction
2016-03-08 14:21:10, Info                  CSI    00000569 [SR] Verify complete
2016-03-08 14:21:10, Info                  CSI    0000056a [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:21:10, Info                  CSI    0000056b [SR] Beginning Verify and Repair transaction
2016-03-08 14:21:18, Info                  CSI    0000056e [SR] Verify complete
2016-03-08 14:21:18, Info                  CSI    0000056f [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:21:18, Info                  CSI    00000570 [SR] Beginning Verify and Repair transaction
2016-03-08 14:21:20, Info                  CSI    00000572 [SR] Verify complete
2016-03-08 14:21:21, Info                  CSI    00000573 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:21:21, Info                  CSI    00000574 [SR] Beginning Verify and Repair transaction
2016-03-08 14:21:23, Info                  CSI    00000576 [SR] Verify complete
2016-03-08 14:21:23, Info                  CSI    00000577 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:21:23, Info                  CSI    00000578 [SR] Beginning Verify and Repair transaction
2016-03-08 14:21:28, Info                  CSI    0000057a [SR] Verify complete
2016-03-08 14:21:28, Info                  CSI    0000057b [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:21:28, Info                  CSI    0000057c [SR] Beginning Verify and Repair transaction
2016-03-08 14:21:33, Info                  CSI    0000057e [SR] Verify complete
2016-03-08 14:21:33, Info                  CSI    0000057f [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:21:33, Info                  CSI    00000580 [SR] Beginning Verify and Repair transaction
2016-03-08 14:21:39, Info                  CSI    00000582 [SR] Verify complete
2016-03-08 14:21:39, Info                  CSI    00000583 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:21:39, Info                  CSI    00000584 [SR] Beginning Verify and Repair transaction
2016-03-08 14:21:48, Info                  CSI    0000058e [SR] Verify complete
2016-03-08 14:21:48, Info                  CSI    0000058f [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:21:48, Info                  CSI    00000590 [SR] Beginning Verify and Repair transaction
2016-03-08 14:21:55, Info                  CSI    000005a0 [SR] Verify complete
2016-03-08 14:21:56, Info                  CSI    000005a1 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:21:56, Info                  CSI    000005a2 [SR] Beginning Verify and Repair transaction
2016-03-08 14:22:01, Info                  CSI    000005a4 [SR] Verify complete
2016-03-08 14:22:02, Info                  CSI    000005a5 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:22:02, Info                  CSI    000005a6 [SR] Beginning Verify and Repair transaction
2016-03-08 14:22:20, Info                  CSI    000005a8 [SR] Verify complete
2016-03-08 14:22:20, Info                  CSI    000005a9 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:22:20, Info                  CSI    000005aa [SR] Beginning Verify and Repair transaction
2016-03-08 14:22:33, Info                  CSI    000005ad [SR] Verify complete
2016-03-08 14:22:33, Info                  CSI    000005ae [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:22:33, Info                  CSI    000005af [SR] Beginning Verify and Repair transaction
2016-03-08 14:22:41, Info                  CSI    000005b1 [SR] Verify complete
2016-03-08 14:22:41, Info                  CSI    000005b2 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:22:41, Info                  CSI    000005b3 [SR] Beginning Verify and Repair transaction
2016-03-08 14:22:45, Info                  CSI    000005b5 [SR] Verify complete
2016-03-08 14:22:46, Info                  CSI    000005b6 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:22:46, Info                  CSI    000005b7 [SR] Beginning Verify and Repair transaction
2016-03-08 14:22:52, Info                  CSI    000005b9 [SR] Verify complete
2016-03-08 14:22:52, Info                  CSI    000005ba [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:22:52, Info                  CSI    000005bb [SR] Beginning Verify and Repair transaction
2016-03-08 14:22:56, Info                  CSI    000005bd [SR] Verify complete
2016-03-08 14:22:56, Info                  CSI    000005be [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:22:56, Info                  CSI    000005bf [SR] Beginning Verify and Repair transaction
2016-03-08 14:23:02, Info                  CSI    000005c3 [SR] Verify complete
2016-03-08 14:23:02, Info                  CSI    000005c4 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:23:02, Info                  CSI    000005c5 [SR] Beginning Verify and Repair transaction
2016-03-08 14:23:09, Info                  CSI    000005c7 [SR] Cannot repair member file [l:34{17}]"windeploy.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:09, Info                  CSI    000005c9 [SR] Cannot repair member file [l:32{16}]"WinLGDep.dll.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:09, Info                  CSI    000005cb [SR] Cannot repair member file [l:26{13}]"audit.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:09, Info                  CSI    000005cd [SR] Cannot repair member file [l:26{13}]"setup.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:09, Info                  CSI    000005cf [SR] Cannot repair member file [l:32{16}]"W32UIRes.dll.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:09, Info                  CSI    000005d1 [SR] Cannot repair member file [l:30{15}]"oobeldr.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:11, Info                  CSI    000005d3 [SR] Cannot repair member file [l:34{17}]"windeploy.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:11, Info                  CSI    000005d4 [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:23:11, Info                  CSI    000005d6 [SR] Cannot repair member file [l:32{16}]"WinLGDep.dll.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:11, Info                  CSI    000005d7 [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:23:11, Info                  CSI    000005d9 [SR] Cannot repair member file [l:26{13}]"audit.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:11, Info                  CSI    000005da [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:23:11, Info                  CSI    000005dc [SR] Cannot repair member file [l:26{13}]"setup.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:11, Info                  CSI    000005dd [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:23:11, Info                  CSI    000005df [SR] Cannot repair member file [l:32{16}]"W32UIRes.dll.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:11, Info                  CSI    000005e0 [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:23:11, Info                  CSI    000005e2 [SR] Cannot repair member file [l:30{15}]"oobeldr.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:11, Info                  CSI    000005e3 [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:23:11, Info                  CSI    000005e6 [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\System32\oobe\en-US"\[l:34{17}]"windeploy.exe.mui"; source file in store is also corrupted
2016-03-08 14:23:11, Info                  CSI    000005e9 [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\System32\oobe\en-US"\[l:32{16}]"WinLGDep.dll.mui"; source file in store is also corrupted
2016-03-08 14:23:11, Info                  CSI    000005ec [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\System32\oobe\en-US"\[l:26{13}]"audit.exe.mui"; source file in store is also corrupted
2016-03-08 14:23:11, Info                  CSI    000005ef [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\System32\oobe\en-US"\[l:26{13}]"setup.exe.mui"; source file in store is also corrupted
2016-03-08 14:23:11, Info                  CSI    000005f2 [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\System32\oobe\en-US"\[l:32{16}]"W32UIRes.dll.mui"; source file in store is also corrupted
2016-03-08 14:23:11, Info                  CSI    000005f5 [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\System32\oobe\en-US"\[l:30{15}]"oobeldr.exe.mui"; source file in store is also corrupted
2016-03-08 14:23:15, Info                  CSI    000005f7 [SR] Verify complete
2016-03-08 14:23:15, Info                  CSI    000005f8 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:23:15, Info                  CSI    000005f9 [SR] Beginning Verify and Repair transaction
2016-03-08 14:23:19, Info                  CSI    000005fb [SR] Cannot repair member file [l:24{12}]"spwizimg.dll" of Microsoft-Windows-Setup-Navigation-Wizard-Framework, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:20, Info                  CSI    000005fd [SR] Cannot repair member file [l:24{12}]"spwizimg.dll" of Microsoft-Windows-Setup-Navigation-Wizard-Framework, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:20, Info                  CSI    000005fe [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
2016-03-08 14:23:20, Info                  CSI    00000601 [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:24{12}]"spwizimg.dll"; source file in store is also corrupted
2016-03-08 14:23:21, Info                  CSI    00000604 [SR] Verify complete
2016-03-08 14:23:21, Info                  CSI    00000605 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:23:21, Info                  CSI    00000606 [SR] Beginning Verify and Repair transaction
2016-03-08 14:23:27, Info                  CSI    00000609 [SR] Verify complete
2016-03-08 14:23:27, Info                  CSI    0000060a [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:23:27, Info                  CSI    0000060b [SR] Beginning Verify and Repair transaction
2016-03-08 14:23:32, Info                  CSI    0000060d [SR] Verify complete
2016-03-08 14:23:33, Info                  CSI    0000060e [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:23:33, Info                  CSI    0000060f [SR] Beginning Verify and Repair transaction
2016-03-08 14:23:34, Info                  CSI    00000611 [SR] Cannot repair member file [l:24{12}]"W32UIRes.dll" of Microsoft-Windows-Setup-Component, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:40, Info                  CSI    00000613 [SR] Cannot repair member file [l:24{12}]"W32UIRes.dll" of Microsoft-Windows-Setup-Component, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:23:40, Info                  CSI    00000614 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
2016-03-08 14:23:40, Info                  CSI    00000617 [SR] Could not reproject corrupted file [ml:520{260},l:56{28}]"\??\C:\Windows\System32\oobe"\[l:24{12}]"W32UIRes.dll"; source file in store is also corrupted
2016-03-08 14:23:42, Info                  CSI    0000061a [SR] Verify complete
2016-03-08 14:23:42, Info                  CSI    0000061b [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:23:42, Info                  CSI    0000061c [SR] Beginning Verify and Repair transaction
2016-03-08 14:23:47, Info                  CSI    0000061e [SR] Verify complete
2016-03-08 14:23:48, Info                  CSI    0000061f [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:23:48, Info                  CSI    00000620 [SR] Beginning Verify and Repair transaction
2016-03-08 14:23:53, Info                  CSI    00000622 [SR] Verify complete
2016-03-08 14:23:53, Info                  CSI    00000623 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:23:53, Info                  CSI    00000624 [SR] Beginning Verify and Repair transaction
2016-03-08 14:23:58, Info                  CSI    00000626 [SR] Verify complete
2016-03-08 14:23:58, Info                  CSI    00000627 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:23:58, Info                  CSI    00000628 [SR] Beginning Verify and Repair transaction
2016-03-08 14:24:04, Info                  CSI    0000062b [SR] Verify complete
2016-03-08 14:24:04, Info                  CSI    0000062c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:24:04, Info                  CSI    0000062d [SR] Beginning Verify and Repair transaction
2016-03-08 14:24:11, Info                  CSI    0000062f [SR] Verify complete
2016-03-08 14:24:12, Info                  CSI    00000630 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:24:12, Info                  CSI    00000631 [SR] Beginning Verify and Repair transaction
2016-03-08 14:24:15, Info                  CSI    00000633 [SR] Verify complete
2016-03-08 14:24:16, Info                  CSI    00000634 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:24:16, Info                  CSI    00000635 [SR] Beginning Verify and Repair transaction
2016-03-08 14:24:21, Info                  CSI    00000638 [SR] Verify complete
2016-03-08 14:24:21, Info                  CSI    00000639 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:24:21, Info                  CSI    0000063a [SR] Beginning Verify and Repair transaction
2016-03-08 14:24:27, Info                  CSI    0000063c [SR] Verify complete
2016-03-08 14:24:27, Info                  CSI    0000063d [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:24:27, Info                  CSI    0000063e [SR] Beginning Verify and Repair transaction
2016-03-08 14:24:33, Info                  CSI    00000642 [SR] Verify complete
2016-03-08 14:24:33, Info                  CSI    00000643 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:24:33, Info                  CSI    00000644 [SR] Beginning Verify and Repair transaction
2016-03-08 14:24:38, Info                  CSI    00000646 [SR] Verify complete
2016-03-08 14:24:39, Info                  CSI    00000647 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:24:39, Info                  CSI    00000648 [SR] Beginning Verify and Repair transaction
2016-03-08 14:24:45, Info                  CSI    0000064b [SR] Verify complete
2016-03-08 14:24:45, Info                  CSI    0000064c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:24:45, Info                  CSI    0000064d [SR] Beginning Verify and Repair transaction
2016-03-08 14:24:49, Info                  CSI    0000064f [SR] Verify complete
2016-03-08 14:24:49, Info                  CSI    00000650 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:24:49, Info                  CSI    00000651 [SR] Beginning Verify and Repair transaction
2016-03-08 14:24:50, Info                  CSI    00000653 [SR] Verify complete
2016-03-08 14:24:50, Info                  CSI    00000654 [SR] Verifying 100 (0x0000000000000064) components

.....let us not lose heart in running the race.....


#14 garyflater

garyflater
  • Topic Starter

  • Members
  • 39 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Winnipeg, Canada
  • Local time:10:51 PM

Posted 08 March 2016 - 03:38 PM

second half

 

2016-03-08 14:24:50, Info                  CSI    00000655 [SR] Beginning Verify and Repair transaction
2016-03-08 14:24:55, Info                  CSI    00000657 [SR] Verify complete
2016-03-08 14:24:55, Info                  CSI    00000658 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:24:55, Info                  CSI    00000659 [SR] Beginning Verify and Repair transaction
2016-03-08 14:25:01, Info                  CSI    0000065b [SR] Verify complete
2016-03-08 14:25:01, Info                  CSI    0000065c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:25:01, Info                  CSI    0000065d [SR] Beginning Verify and Repair transaction
2016-03-08 14:25:08, Info                  CSI    0000065f [SR] Verify complete
2016-03-08 14:25:08, Info                  CSI    00000660 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:25:08, Info                  CSI    00000661 [SR] Beginning Verify and Repair transaction
2016-03-08 14:25:12, Info                  CSI    00000663 [SR] Verify complete
2016-03-08 14:25:12, Info                  CSI    00000664 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:25:12, Info                  CSI    00000665 [SR] Beginning Verify and Repair transaction
2016-03-08 14:25:17, Info                  CSI    00000667 [SR] Verify complete
2016-03-08 14:25:17, Info                  CSI    00000668 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:25:17, Info                  CSI    00000669 [SR] Beginning Verify and Repair transaction
2016-03-08 14:25:29, Info                  CSI    0000066b [SR] Verify complete
2016-03-08 14:25:29, Info                  CSI    0000066c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:25:29, Info                  CSI    0000066d [SR] Beginning Verify and Repair transaction
2016-03-08 14:25:50, Info                  CSI    0000066f [SR] Verify complete
2016-03-08 14:25:50, Info                  CSI    00000670 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:25:50, Info                  CSI    00000671 [SR] Beginning Verify and Repair transaction
2016-03-08 14:25:59, Info                  CSI    00000673 [SR] Verify complete
2016-03-08 14:25:59, Info                  CSI    00000674 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:25:59, Info                  CSI    00000675 [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:05, Info                  CSI    00000677 [SR] Verify complete
2016-03-08 14:26:06, Info                  CSI    00000678 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:06, Info                  CSI    00000679 [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:07, Info                  CSI    0000067b [SR] Verify complete
2016-03-08 14:26:08, Info                  CSI    0000067c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:08, Info                  CSI    0000067d [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:12, Info                  CSI    0000067f [SR] Verify complete
2016-03-08 14:26:12, Info                  CSI    00000680 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:12, Info                  CSI    00000681 [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:17, Info                  CSI    00000683 [SR] Verify complete
2016-03-08 14:26:17, Info                  CSI    00000684 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:17, Info                  CSI    00000685 [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:19, Info                  CSI    00000687 [SR] Verify complete
2016-03-08 14:26:20, Info                  CSI    00000688 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:20, Info                  CSI    00000689 [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:21, Info                  CSI    0000068b [SR] Verify complete
2016-03-08 14:26:21, Info                  CSI    0000068c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:21, Info                  CSI    0000068d [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:25, Info                  CSI    00000695 [SR] Verify complete
2016-03-08 14:26:26, Info                  CSI    00000696 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:26, Info                  CSI    00000697 [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:30, Info                  CSI    00000699 [SR] Verify complete
2016-03-08 14:26:30, Info                  CSI    0000069a [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:30, Info                  CSI    0000069b [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:34, Info                  CSI    0000069d [SR] Verify complete
2016-03-08 14:26:35, Info                  CSI    0000069e [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:35, Info                  CSI    0000069f [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:38, Info                  CSI    000006a1 [SR] Verify complete
2016-03-08 14:26:38, Info                  CSI    000006a2 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:38, Info                  CSI    000006a3 [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:43, Info                  CSI    000006a5 [SR] Verify complete
2016-03-08 14:26:43, Info                  CSI    000006a6 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:43, Info                  CSI    000006a7 [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:49, Info                  CSI    000006aa [SR] Verify complete
2016-03-08 14:26:49, Info                  CSI    000006ab [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:49, Info                  CSI    000006ac [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:54, Info                  CSI    000006ae [SR] Verify complete
2016-03-08 14:26:54, Info                  CSI    000006af [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:54, Info                  CSI    000006b0 [SR] Beginning Verify and Repair transaction
2016-03-08 14:26:56, Info                  CSI    000006b2 [SR] Verify complete
2016-03-08 14:26:56, Info                  CSI    000006b3 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:26:56, Info                  CSI    000006b4 [SR] Beginning Verify and Repair transaction
2016-03-08 14:27:01, Info                  CSI    000006b6 [SR] Verify complete
2016-03-08 14:27:01, Info                  CSI    000006b7 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:27:01, Info                  CSI    000006b8 [SR] Beginning Verify and Repair transaction
2016-03-08 14:27:11, Info                  CSI    000006bd [SR] Verify complete
2016-03-08 14:27:12, Info                  CSI    000006be [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:27:12, Info                  CSI    000006bf [SR] Beginning Verify and Repair transaction
2016-03-08 14:27:20, Info                  CSI    000006c4 [SR] Verify complete
2016-03-08 14:27:20, Info                  CSI    000006c5 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:27:20, Info                  CSI    000006c6 [SR] Beginning Verify and Repair transaction
2016-03-08 14:27:31, Info                  CSI    000006c9 [SR] Verify complete
2016-03-08 14:27:31, Info                  CSI    000006ca [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:27:31, Info                  CSI    000006cb [SR] Beginning Verify and Repair transaction
2016-03-08 14:27:37, Info                  CSI    000006d6 [SR] Verify complete
2016-03-08 14:27:37, Info                  CSI    000006d7 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:27:37, Info                  CSI    000006d8 [SR] Beginning Verify and Repair transaction
2016-03-08 14:27:45, Info                  CSI    000006de [SR] Verify complete
2016-03-08 14:27:45, Info                  CSI    000006df [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:27:45, Info                  CSI    000006e0 [SR] Beginning Verify and Repair transaction
2016-03-08 14:27:50, Info                  CSI    000006e2 [SR] Verify complete
2016-03-08 14:27:50, Info                  CSI    000006e3 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:27:50, Info                  CSI    000006e4 [SR] Beginning Verify and Repair transaction
2016-03-08 14:27:57, Info                  CSI    000006e8 [SR] Verify complete
2016-03-08 14:27:57, Info                  CSI    000006e9 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:27:57, Info                  CSI    000006ea [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:00, Info                  CSI    000006ec [SR] Verify complete
2016-03-08 14:28:01, Info                  CSI    000006ed [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:01, Info                  CSI    000006ee [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:07, Info                  CSI    00000713 [SR] Verify complete
2016-03-08 14:28:08, Info                  CSI    00000714 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:08, Info                  CSI    00000715 [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:12, Info                  CSI    00000717 [SR] Verify complete
2016-03-08 14:28:12, Info                  CSI    00000718 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:12, Info                  CSI    00000719 [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:17, Info                  CSI    0000071b [SR] Verify complete
2016-03-08 14:28:17, Info                  CSI    0000071c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:17, Info                  CSI    0000071d [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:21, Info                  CSI    0000071f [SR] Verify complete
2016-03-08 14:28:22, Info                  CSI    00000720 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:22, Info                  CSI    00000721 [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:26, Info                  CSI    0000072f [SR] Verify complete
2016-03-08 14:28:26, Info                  CSI    00000730 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:26, Info                  CSI    00000731 [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:35, Info                  CSI    00000733 [SR] Verify complete
2016-03-08 14:28:35, Info                  CSI    00000734 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:35, Info                  CSI    00000735 [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:41, Info                  CSI    00000743 [SR] Verify complete
2016-03-08 14:28:41, Info                  CSI    00000744 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:41, Info                  CSI    00000745 [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:42, Info                  CSI    00000747 [SR] Verify complete
2016-03-08 14:28:42, Info                  CSI    00000748 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:42, Info                  CSI    00000749 [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:45, Info                  CSI    0000074b [SR] Verify complete
2016-03-08 14:28:45, Info                  CSI    0000074c [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:45, Info                  CSI    0000074d [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:50, Info                  CSI    00000750 [SR] Verify complete
2016-03-08 14:28:50, Info                  CSI    00000751 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:50, Info                  CSI    00000752 [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:53, Info                  CSI    00000754 [SR] Verify complete
2016-03-08 14:28:53, Info                  CSI    00000755 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:53, Info                  CSI    00000756 [SR] Beginning Verify and Repair transaction
2016-03-08 14:28:59, Info                  CSI    00000758 [SR] Verify complete
2016-03-08 14:28:59, Info                  CSI    00000759 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:28:59, Info                  CSI    0000075a [SR] Beginning Verify and Repair transaction
2016-03-08 14:29:04, Info                  CSI    0000075c [SR] Verify complete
2016-03-08 14:29:04, Info                  CSI    0000075d [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:29:04, Info                  CSI    0000075e [SR] Beginning Verify and Repair transaction
2016-03-08 14:29:11, Info                  CSI    00000766 [SR] Verify complete
2016-03-08 14:29:11, Info                  CSI    00000767 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:29:11, Info                  CSI    00000768 [SR] Beginning Verify and Repair transaction
2016-03-08 14:29:17, Info                  CSI    0000077c [SR] Verify complete
2016-03-08 14:29:17, Info                  CSI    0000077d [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:29:17, Info                  CSI    0000077e [SR] Beginning Verify and Repair transaction
2016-03-08 14:29:26, Info                  CSI    00000780 [SR] Cannot repair member file [l:30{15}]"notepad.exe.mui" of Microsoft-Windows-notepad.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:29:26, Info                  CSI    00000782 [SR] Cannot repair member file [l:30{15}]"notepad.exe.mui" of Microsoft-Windows-notepad.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:29:26, Info                  CSI    00000783 [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:29:26, Info                  CSI    00000786 [SR] Could not reproject corrupted file [ml:60{30},l:58{29}]"\??\C:\Windows\SysWOW64\en-US"\[l:30{15}]"notepad.exe.mui"; source file in store is also corrupted
2016-03-08 14:29:31, Info                  CSI    00000788 [SR] Verify complete
2016-03-08 14:29:32, Info                  CSI    00000789 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:29:32, Info                  CSI    0000078a [SR] Beginning Verify and Repair transaction
2016-03-08 14:29:39, Info                  CSI    0000078c [SR] Verify complete
2016-03-08 14:29:40, Info                  CSI    0000078d [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:29:40, Info                  CSI    0000078e [SR] Beginning Verify and Repair transaction
2016-03-08 14:29:44, Info                  CSI    00000790 [SR] Verify complete
2016-03-08 14:29:44, Info                  CSI    00000791 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:29:44, Info                  CSI    00000792 [SR] Beginning Verify and Repair transaction
2016-03-08 14:29:48, Info                  CSI    00000796 [SR] Verify complete
2016-03-08 14:29:49, Info                  CSI    00000797 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:29:49, Info                  CSI    00000798 [SR] Beginning Verify and Repair transaction
2016-03-08 14:29:52, Info                  CSI    0000079a [SR] Verify complete
2016-03-08 14:29:52, Info                  CSI    0000079b [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:29:52, Info                  CSI    0000079c [SR] Beginning Verify and Repair transaction
2016-03-08 14:29:57, Info                  CSI    0000079e [SR] Verify complete
2016-03-08 14:29:58, Info                  CSI    0000079f [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:29:58, Info                  CSI    000007a0 [SR] Beginning Verify and Repair transaction
2016-03-08 14:30:02, Info                  CSI    000007a2 [SR] Verify complete
2016-03-08 14:30:02, Info                  CSI    000007a3 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:30:02, Info                  CSI    000007a4 [SR] Beginning Verify and Repair transaction
2016-03-08 14:30:07, Info                  CSI    000007a7 [SR] Verify complete
2016-03-08 14:30:07, Info                  CSI    000007a8 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:30:07, Info                  CSI    000007a9 [SR] Beginning Verify and Repair transaction
2016-03-08 14:30:12, Info                  CSI    000007ab [SR] Verify complete
2016-03-08 14:30:12, Info                  CSI    000007ac [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:30:12, Info                  CSI    000007ad [SR] Beginning Verify and Repair transaction
2016-03-08 14:30:16, Info                  CSI    000007af [SR] Verify complete
2016-03-08 14:30:17, Info                  CSI    000007b0 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:30:17, Info                  CSI    000007b1 [SR] Beginning Verify and Repair transaction
2016-03-08 14:30:24, Info                  CSI    000007b3 [SR] Verify complete
2016-03-08 14:30:24, Info                  CSI    000007b4 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:30:24, Info                  CSI    000007b5 [SR] Beginning Verify and Repair transaction
2016-03-08 14:30:30, Info                  CSI    000007b8 [SR] Verify complete
2016-03-08 14:30:30, Info                  CSI    000007b9 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:30:30, Info                  CSI    000007ba [SR] Beginning Verify and Repair transaction
2016-03-08 14:30:38, Info                  CSI    000007bc [SR] Verify complete
2016-03-08 14:30:38, Info                  CSI    000007bd [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:30:38, Info                  CSI    000007be [SR] Beginning Verify and Repair transaction
2016-03-08 14:30:43, Info                  CSI    000007c0 [SR] Verify complete
2016-03-08 14:30:43, Info                  CSI    000007c1 [SR] Verifying 100 (0x0000000000000064) components
2016-03-08 14:30:43, Info                  CSI    000007c2 [SR] Beginning Verify and Repair transaction
2016-03-08 14:30:48, Info                  CSI    000007c4 [SR] Verify complete
2016-03-08 14:30:49, Info                  CSI    000007c5 [SR] Verifying 64 (0x0000000000000040) components
2016-03-08 14:30:49, Info                  CSI    000007c6 [SR] Beginning Verify and Repair transaction
2016-03-08 14:30:51, Info                  CSI    000007c8 [SR] Verify complete
2016-03-08 14:30:51, Info                  CSI    000007c9 [SR] Repairing 4 components
2016-03-08 14:30:51, Info                  CSI    000007ca [SR] Beginning Verify and Repair transaction
2016-03-08 14:30:51, Info                  CSI    000007cc [SR] Cannot repair member file [l:34{17}]"windeploy.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:51, Info                  CSI    000007ce [SR] Cannot repair member file [l:32{16}]"WinLGDep.dll.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:51, Info                  CSI    000007d0 [SR] Cannot repair member file [l:26{13}]"audit.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:51, Info                  CSI    000007d2 [SR] Cannot repair member file [l:26{13}]"setup.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:51, Info                  CSI    000007d4 [SR] Cannot repair member file [l:32{16}]"W32UIRes.dll.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:51, Info                  CSI    000007d6 [SR] Cannot repair member file [l:30{15}]"oobeldr.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    000007d8 [SR] Cannot repair member file [l:24{12}]"spwizimg.dll" of Microsoft-Windows-Setup-Navigation-Wizard-Framework, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    000007da [SR] Cannot repair member file [l:24{12}]"W32UIRes.dll" of Microsoft-Windows-Setup-Component, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    000007dc [SR] Cannot repair member file [l:30{15}]"notepad.exe.mui" of Microsoft-Windows-notepad.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    000007de [SR] Cannot repair member file [l:34{17}]"windeploy.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    000007df [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:30:52, Info                  CSI    000007e1 [SR] Cannot repair member file [l:32{16}]"WinLGDep.dll.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    000007e2 [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:30:52, Info                  CSI    000007e4 [SR] Cannot repair member file [l:26{13}]"audit.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    000007e5 [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:30:52, Info                  CSI    000007e7 [SR] Cannot repair member file [l:26{13}]"setup.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    000007e8 [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:30:52, Info                  CSI    000007ea [SR] Cannot repair member file [l:32{16}]"W32UIRes.dll.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    000007eb [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:30:52, Info                  CSI    000007ed [SR] Cannot repair member file [l:30{15}]"oobeldr.exe.mui" of Microsoft-Windows-Setup-Component.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    000007ee [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:30:52, Info                  CSI    000007f1 [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\System32\oobe\en-US"\[l:34{17}]"windeploy.exe.mui"; source file in store is also corrupted
2016-03-08 14:30:52, Info                  CSI    000007f4 [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\System32\oobe\en-US"\[l:32{16}]"WinLGDep.dll.mui"; source file in store is also corrupted
2016-03-08 14:30:52, Info                  CSI    000007f7 [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\System32\oobe\en-US"\[l:26{13}]"audit.exe.mui"; source file in store is also corrupted
2016-03-08 14:30:52, Info                  CSI    000007fa [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\System32\oobe\en-US"\[l:26{13}]"setup.exe.mui"; source file in store is also corrupted
2016-03-08 14:30:52, Info                  CSI    000007fd [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\System32\oobe\en-US"\[l:32{16}]"W32UIRes.dll.mui"; source file in store is also corrupted
2016-03-08 14:30:52, Info                  CSI    00000800 [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\System32\oobe\en-US"\[l:30{15}]"oobeldr.exe.mui"; source file in store is also corrupted
2016-03-08 14:30:52, Info                  CSI    00000802 [SR] Cannot repair member file [l:24{12}]"spwizimg.dll" of Microsoft-Windows-Setup-Navigation-Wizard-Framework, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    00000803 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
2016-03-08 14:30:52, Info                  CSI    00000806 [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:24{12}]"spwizimg.dll"; source file in store is also corrupted
2016-03-08 14:30:52, Info                  CSI    00000808 [SR] Cannot repair member file [l:30{15}]"notepad.exe.mui" of Microsoft-Windows-notepad.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    00000809 [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack"
2016-03-08 14:30:52, Info                  CSI    0000080c [SR] Could not reproject corrupted file [ml:60{30},l:58{29}]"\??\C:\Windows\SysWOW64\en-US"\[l:30{15}]"notepad.exe.mui"; source file in store is also corrupted
2016-03-08 14:30:52, Info                  CSI    0000080e [SR] Cannot repair member file [l:24{12}]"W32UIRes.dll" of Microsoft-Windows-Setup-Component, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2016-03-08 14:30:52, Info                  CSI    0000080f [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
2016-03-08 14:30:53, Info                  CSI    00000812 [SR] Could not reproject corrupted file [ml:520{260},l:56{28}]"\??\C:\Windows\System32\oobe"\[l:24{12}]"W32UIRes.dll"; source file in store is also corrupted
2016-03-08 14:30:53, Info                  CSI    00000814 [SR] Repair complete
2016-03-08 14:30:53, Info                  CSI    00000815 [SR] Committing transaction
2016-03-08 14:30:53, Info                  CSI    00000819 [SR] Verify and Repair Transaction completed. All files and registry keys listed in this transaction  have been successfully repaired

.....let us not lose heart in running the race.....


#15 dc3

dc3

    Bleeping Treehugger


  • Members
  • 30,397 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:09:51 PM

Posted 08 March 2016 - 03:48 PM

I would suggest running the Microsoft Fix it here.


Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

 

 

 

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users