GeekPolice Tech TutorialsLog in

 

Ask, keeps overpowering google on one site only cant stop it!

Share

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
Please check this site.

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
I went to the site and followed insructions. The address bar turned red once I clicked on " continue anyway,we recommend you dont continue " . I was able to proceed to the login page,however they said the password or acct number was wrong,but it isn,t wrong.The address bar remains red.. Is there anything else I can do? This hapened once before ,I phoned them and was told my pc must be going to an old cashed site of theres. Could this be? I never did figure it out cause I switched pc's shortly after that.

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
Please run AdwCleaner and delete those infections.

Download Combofix from any of the links below, and save it to your DESKTOP.
If your version of Windows defaults to you download folder you will need to copy it to your desktop.

Link 1
Link 2
Link 3

To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.

  • Close any open windows and double click ComboFix.exe to run it.

    You will see the following image:



Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:



As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.



Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
I'll post this in two parts
ComboFix 13-11-27.01 - myComputer 12/01/2013 10:42:07.2.2 - x64
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.4094.2414 [GMT -7:00]
Running from: c:\users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YTY4OSHC\ComboFix.exe
AV: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: ESET NOD32 Antivirus 7.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
SP: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: ESET NOD32 Antivirus 7.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\ydi.log
.
.
((((((((((((((((((((((((( Files Created from 2013-11-01 to 2013-12-01 )))))))))))))))))))))))))))))))
.
.
2013-12-01 18:33 . 2013-12-01 18:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-01 10:56 . 2013-12-01 10:56 -------- d-----w- c:\users\myComputer\AppData\Local\ESET
2013-11-29 03:43 . 2013-11-29 03:43 -------- d-----w- c:\program files\ESET
2013-11-29 00:47 . 2013-11-29 00:47 -------- d-----w- c:\users\myComputer\AppData\Roaming\AVG2014
2013-11-29 00:46 . 2013-11-29 00:46 -------- d-----w- c:\users\myComputer\AppData\Roaming\TuneUp Software
2013-11-29 00:45 . 2013-12-01 18:35 -------- d-----w- c:\programdata\AVG2014
2013-11-29 00:45 . 2013-11-29 00:45 -------- d-----w- C:\$AVG
2013-11-29 00:45 . 2013-11-29 00:45 -------- d-----w- c:\program files (x86)\AVG
2013-11-29 00:41 . 2013-12-01 17:10 -------- d-----w- c:\programdata\MFAData
2013-11-29 00:41 . 2013-11-29 03:00 -------- d-----w- c:\users\myComputer\AppData\Local\Avg2014
2013-11-29 00:41 . 2013-11-29 00:41 -------- d-----w- c:\users\myComputer\AppData\Local\MFAData
2013-11-28 03:55 . 2013-11-18 08:28 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{71ADEC8A-24EC-4322-8DCA-6FC540A33935}\mpengine.dll
2013-11-28 00:28 . 2013-11-28 00:28 -------- d-----w- c:\windows\ERUNT
2013-11-27 14:28 . 2013-11-27 14:28 -------- d-----w- c:\users\wangjihua
2013-11-27 06:27 . 2013-11-27 06:27 -------- d-----w- c:\users\myComputer\.android
2013-11-27 06:27 . 2013-11-27 14:28 -------- d-----w- c:\users\myComputer\AppData\Local\cache
2013-11-27 06:27 . 2013-11-27 14:29 -------- d-----w- c:\users\myComputer\AppData\Local\Mobogenie
2013-11-27 06:26 . 2013-11-27 14:29 -------- d-----w- c:\program files (x86)\Mobogenie
2013-11-27 05:49 . 2013-11-27 05:49 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-27 05:49 . 2013-11-27 05:49 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-11-26 22:09 . 2013-11-28 03:39 -------- d-----w- C:\AdwCleaner
2013-11-26 15:27 . 2013-11-27 22:53 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-11-26 15:27 . 2013-04-04 21:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-26 15:17 . 2013-11-26 15:17 -------- d-----w- c:\programdata\AVAST Software
2013-11-26 14:30 . 2013-11-27 00:23 -------- d-----w- c:\users\myComputer\AppData\Local\LogMeIn Rescue Applet
2013-11-26 06:45 . 2013-11-26 06:45 -------- d-----w- c:\programdata\HitmanPro
2013-11-26 03:11 . 2013-11-26 03:11 -------- d-----w- c:\programdata\Pure Networks
2013-11-14 10:03 . 2013-10-13 14:36 96768 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-14 10:03 . 2013-10-13 14:35 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-11-14 10:03 . 2013-10-13 09:25 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-11-14 10:03 . 2013-10-13 16:04 183024 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2013-11-14 10:03 . 2013-10-13 14:46 996352 ----a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-11-14 10:03 . 2013-10-13 14:44 305152 ----a-w- c:\program files\Internet Explorer\IEShims.dll
2013-11-14 10:03 . 2013-10-13 10:49 149744 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll
2013-11-14 10:03 . 2013-10-13 09:33 768512 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\vgx\VGX.dll
2013-11-14 10:03 . 2013-10-13 09:29 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-13 14:38 . 2013-10-11 04:23 462848 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-11-13 14:38 . 2013-10-11 04:23 781824 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-11-13 14:38 . 2013-10-11 02:07 596480 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2013-11-13 14:38 . 2013-10-03 15:02 1278976 ----a-w- c:\windows\system32\crypt32.dll
2013-11-13 14:38 . 2013-10-03 12:45 993792 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-11-13 14:38 . 2013-10-03 15:03 389632 ----a-w- c:\windows\system32\gdi32.dll
2013-11-13 14:38 . 2013-10-03 12:46 304128 ----a-w- c:\windows\SysWow64\gdi32.dll
2013-11-13 14:38 . 2013-09-04 02:31 404992 ----a-w- c:\windows\system32\drivers\afd.sys
2013-11-13 03:16 . 2013-11-13 03:16 -------- d-----w- c:\users\myComputer\AppData\Local\MaxiGet Download Manager
2013-11-13 03:16 . 2013-11-13 03:20 -------- d-----w- c:\users\myComputer\AppData\Local\Maxiget
2013-11-06 04:55 . 2013-11-06 04:55 150808 ----a-w- c:\windows\system32\drivers\avgdiska.sys
2013-11-05 04:52 . 2013-11-05 04:52 240920 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
2013-11-05 04:19 . 2013-11-05 04:19 -------- d-----w- c:\windows\Sun
2013-11-05 04:19 . 2013-11-26 05:30 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-11-05 04:18 . 2013-10-08 14:50 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-11-05 04:16 . 2013-11-05 04:19 -------- d-----w- c:\programdata\Oracle
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-14 10:01 . 2006-11-02 12:35 82896128 ----a-w- c:\windows\system32\mrt.exe
2013-11-11 12:50 . 2013-01-09 02:38 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-01 06:00 . 2013-11-01 06:00 212280 ----a-w- c:\windows\system32\drivers\avgldx64.sys
2013-11-01 05:49 . 2013-11-01 05:49 294712 ----a-w- c:\windows\system32\drivers\avgloga.sys
2013-10-25 05:25 . 2013-10-25 05:25 194872 ----a-w- c:\windows\system32\drivers\avgidsha.sys
2013-10-01 07:52 . 2013-10-01 07:52 123704 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
2013-09-17 22:17 . 2013-09-17 22:17 239320 ----a-w- c:\windows\system32\drivers\eamonm.sys
2013-09-17 22:17 . 2013-09-17 22:17 239296 ----a-w- c:\windows\system32\drivers\edevmon.sys
2013-09-17 22:17 . 2013-09-17 22:17 168256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2013-09-17 22:17 . 2013-09-17 22:17 157432 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2013-09-10 07:43 . 2013-09-10 07:43 31544 ----a-w- c:\windows\system32\drivers\avgrkx64.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
"ForceActiveDesktopOn"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\rjatydimofu.exe]
"debugger"=tasklist.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Browsing Protection]
2013-01-31 15:11 542632 ----a-w- c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx]
2010-04-02 18:18 1185112 ----a-w- c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-07-02 16:16 254336 ----a-w- c:\program files (x86)\Common Files\Java\Java Update\jusched.exe
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-27 05:49]
.
2013-12-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-09 03:16]
.
2013-12-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-09 03:16]
.
2013-12-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-929725188-2267044026-2474493764-1000Core.job
- c:\users\myComputer\AppData\Local\Google\Update\GoogleUpdate.exe [2013-09-21 00:38]
.
2013-12-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-929725188-2267044026-2474493764-1000UA.job
- c:\users\myComputer\AppData\Local\Google\Update\GoogleUpdate.exe [2013-09-21 00:38]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2013-09-12 5618456]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mSearch Page = hxxp://do-search.com/web/?type=ds&ts=1385533547&from=ild&uid=HitachiXHDP725016GLA380_GEM864RH27AR4E27AR4EX&q={searchTerms}
mLocal Page = c:\windows\SysWOW64\blank.htm
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
Toolbar-10 - (no file)
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
HKLM-Run-SBRegRebootCleaner - c:\program files (x86)\Ad-Aware Antivirus\SBRC.exe
AddRemove-Coupon Printer for Windows5.0.0.0 - c:\program files (x86)\Coupons\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET CLR Data]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET CLR Networking]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET CLR Networking 4.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET Data Provider for Oracle]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET Data Provider for SqlServer]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NETFramework]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ACPI]
"ImagePath"="system32\drivers\acpi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AdobeARMservice]
"ImagePath"="\"c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AdobeFlashPlayerUpdateSvc]
"ImagePath"="c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adp94xx]
"ImagePath"="\SystemRoot\system32\drivers\adp94xx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adpahci]
"ImagePath"="\SystemRoot\system32\drivers\adpahci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adpu160m]
"ImagePath"="\SystemRoot\system32\drivers\adpu160m.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adpu320]
"ImagePath"="\SystemRoot\system32\drivers\adpu320.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adsi]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AeLookupSvc]
"ServiceDll"="%SystemRoot%\System32\aelupsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AFD]
"ImagePath"="\SystemRoot\system32\drivers\afd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\agp440]
"ImagePath"="\SystemRoot\system32\drivers\agp440.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aic78xx]
"ImagePath"="\SystemRoot\system32\drivers\djsvs.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ALG]
"ImagePath"="%SystemRoot%\System32\alg.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aliide]
"ImagePath"="\SystemRoot\system32\drivers\aliide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AMD External Events Utility]
"ImagePath"="%SystemRoot%\system32\atiesrxx.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdide]
"ImagePath"="\SystemRoot\system32\drivers\amdide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AmdK8]
"ImagePath"="\SystemRoot\system32\drivers\amdk8.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdkmdag]
"ImagePath"="system32\DRIVERS\atikmdag.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdkmdap]
"ImagePath"="system32\DRIVERS\atikmpag.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Appinfo]
"ServiceDll"="%SystemRoot%\System32\appinfo.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AppMgmt]
"ServiceDll"="%SystemRoot%\System32\appmgmts.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\arc]
"ImagePath"="\SystemRoot\system32\drivers\arc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\arcsas]
"ImagePath"="\SystemRoot\system32\drivers\arcsas.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AsyncMac]
"ImagePath"="system32\DRIVERS\asyncmac.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\atapi]
"ImagePath"="system32\drivers\atapi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Atierecord]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AudioEndpointBuilder]
"ServiceDll"="%SystemRoot%\System32\Audiosrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AudioSrv]
"ServiceDll"="%SystemRoot%\System32\Audiosrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avg]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgdiska]
"ImagePath"="system32\DRIVERS\avgdiska.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSAgent]
"ImagePath"="\"c:\program files (x86)\AVG\AVG2014\avgidsagent.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSDriver]
"ImagePath"="system32\DRIVERS\avgidsdrivera.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSHA]
"ImagePath"="system32\DRIVERS\avgidsha.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgldx64]
"ImagePath"="system32\DRIVERS\avgldx64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgloga]
"ImagePath"="system32\DRIVERS\avgloga.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgmfx64]
"ImagePath"="system32\DRIVERS\avgmfx64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgrkx64]
"ImagePath"="system32\DRIVERS\avgrkx64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgtdia]
"ImagePath"="system32\DRIVERS\avgtdia.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avgwd]
"ImagePath"="\"c:\program files (x86)\AVG\AVG2014\avgwdsvc.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BattC]
"MofImagePath"="system32\drivers\battc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BFE]
"ServiceDll"="%SystemRoot%\System32\bfe.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BITS]
"ServiceDll"="%systemroot%\system32\qmgr.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\blbdrive]
"ImagePath"="\SystemRoot\system32\drivers\blbdrive.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bowser]
"ImagePath"="system32\DRIVERS\bowser.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrFiltLo]
"ImagePath"="\SystemRoot\system32\drivers\brfiltlo.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrFiltUp]
"ImagePath"="\SystemRoot\system32\drivers\brfiltup.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Browser]
"ServiceDll"="%SystemRoot%\System32\browser.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Brserid]
"ImagePath"="\SystemRoot\system32\drivers\brserid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrSerWdm]
"ImagePath"="\SystemRoot\system32\drivers\brserwdm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrUsbMdm]
"ImagePath"="\SystemRoot\system32\drivers\brusbmdm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrUsbSer]
"ImagePath"="\SystemRoot\system32\drivers\brusbser.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BTHMODEM]
"ImagePath"="\SystemRoot\system32\drivers\bthmodem.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BTHPORT]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\catchme]
"ImagePath"="\??\c:\combofix\catchme.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cdfs]
"ImagePath"="system32\DRIVERS\cdfs.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cdrom]
"ImagePath"="system32\DRIVERS\cdrom.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CertPropSvc]
"ServiceDll"="%SystemRoot%\System32\certprop.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\circlass]
"ImagePath"="\SystemRoot\system32\drivers\circlass.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CLFS]
"ImagePath"="System32\CLFS.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v2.0.50727_32]
"ImagePath"="%systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v2.0.50727_64]
"ImagePath"="%systemroot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v4.0.30319_32]
"ImagePath"="c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v4.0.30319_64]
"ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdide]
"ImagePath"="\SystemRoot\system32\drivers\cmdide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Compbatt]
"ImagePath"="\SystemRoot\system32\drivers\compbatt.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\COMSysApp]
"ImagePath"="%SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crcdisk]
"ImagePath"="system32\drivers\crcdisk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crypt32]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CryptSvc]
"ServiceDll"="%SystemRoot%\system32\cryptsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CSC]
"ImagePath"="system32\drivers\csc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CscService]
"ServiceDll"="%SystemRoot%\System32\cscsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DCLocator]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DcomLaunch]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DfsC]
"ImagePath"="System32\Drivers\dfsc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DFSR]
"ImagePath"="%SystemRoot%\system32\DFSR.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dhcp]
"ServiceDll"="%SystemRoot%\system32\dhcpcsvc.dll"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\disk]
"ImagePath"="system32\drivers\disk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache]
"ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\dot3svc]
"ServiceDll"="%SystemRoot%\System32\dot3svc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DPS]
"ServiceDll"="%SystemRoot%\system32\dps.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\drmkaud]
"ImagePath"="system32\drivers\drmkaud.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DXGKrnl]
"ImagePath"="\SystemRoot\System32\drivers\dxgkrnl.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\E1G60]
"ImagePath"="system32\DRIVERS\E1G6032E.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\eamonm]
"ImagePath"="system32\DRIVERS\eamonm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EapHost]
"ServiceDll"="%SystemRoot%\System32\eapsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ecache]
"ImagePath"="System32\drivers\ecache.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\edevmon]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ehdrv]
"ImagePath"="system32\DRIVERS\ehdrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ekrn]
"ImagePath"="\"c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\elxstor]
"ImagePath"="\SystemRoot\system32\drivers\elxstor.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EmdCache]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EMDMgmt]
"ServiceDll"="%systemroot%\system32\emdmgmt.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\epfwwfpr]
"ImagePath"="system32\DRIVERS\epfwwfpr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ErrDev]
"ImagePath"="\SystemRoot\system32\drivers\errdev.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ESENT]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog]
"ServiceDll"="%SystemRoot%\System32\wevtsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventSystem]
"ServiceDll"="%systemroot%\system32\es.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\exfat]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fastfat]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Fax]
"ImagePath"="%systemroot%\system32\fxssvc.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fdc]
"ImagePath"="system32\DRIVERS\fdc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fdPHost]
"ServiceDll"="%SystemRoot%\system32\fdPHost.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FDResPub]
"ServiceDll"="%SystemRoot%\system32\fdrespub.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FileInfo]
"ImagePath"="system32\drivers\fileinfo.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Filetrace]
"ImagePath"="system32\drivers\filetrace.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\flpydisk]
"ImagePath"="system32\DRIVERS\flpydisk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FltMgr]
"ImagePath"="system32\drivers\fltmgr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FontCache]
"ServiceDll"="%SystemRoot%\system32\FntCache.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FontCache3.0.0.0]
"ImagePath"="%systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Fs_Rec]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gagp30kx]
"ImagePath"="\SystemRoot\system32\drivers\gagp30kx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gfiark]
"ImagePath"="system32\drivers\gfiark.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gpsvc]
"ServiceDll"="%SystemRoot%\System32\gpsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gupdate]
"ImagePath"="\"c:\program files (x86)\Google\Update\GoogleUpdate.exe\" /svc"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gupdatem]
"ImagePath"="\"c:\program files (x86)\Google\Update\GoogleUpdate.exe\" /medsvc"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gusvc]
"ImagePath"="\"c:\program files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HdAudAddService]
"ImagePath"="system32\drivers\HdAudio.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HDAudBus]
"ImagePath"="system32\DRIVERS\HDAudBus.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HidBth]
"ImagePath"="\SystemRoot\system32\drivers\hidbth.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HidIr]
"ImagePath"="\SystemRoot\system32\drivers\hidir.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hidserv]
"ServiceDll"="%SystemRoot%\System32\hidserv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HidUsb]
"ImagePath"="system32\DRIVERS\hidusb.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hkmsvc]
"ServiceDLL"="%SystemRoot%\system32\kmsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HpCISSs]
"ImagePath"="\SystemRoot\system32\drivers\hpcisss.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HTTP]
"ImagePath"="system32\drivers\HTTP.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i2omp]
"ImagePath"="\SystemRoot\system32\drivers\i2omp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i8042prt]
"ImagePath"="system32\DRIVERS\i8042prt.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iaStorV]
"ImagePath"="\SystemRoot\system32\drivers\iastorv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IDriverT]
"ImagePath"="\"c:\program files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\idsvc]
"ImagePath"="\"%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iirsp]
"ImagePath"="\SystemRoot\system32\drivers\iirsp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IKEEXT]
"ServiceDll"="%SystemRoot%\System32\ikeext.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\inetaccs]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\intelide]
"ImagePath"="system32\drivers\intelide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\intelppm]
"ImagePath"="system32\DRIVERS\intelppm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPBusEnum]
"ServiceDll"="%SystemRoot%\system32\ipbusenum.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IpFilterDriver]
"ImagePath"="system32\DRIVERS\ipfltdrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iphlpsvc]
"ServiceDll"="%SystemRoot%\System32\iphlpsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IpInIp]
"ImagePath"="system32\DRIVERS\ipinip.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPMIDRV]
"ImagePath"="\SystemRoot\system32\drivers\ipmidrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPNAT]
"ImagePath"="system32\DRIVERS\ipnat.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IRENUM]
"ImagePath"="system32\drivers\irenum.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\isapnp]
"ImagePath"="\SystemRoot\system32\drivers\isapnp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iScsiPrt]
"ImagePath"="system32\DRIVERS\msiscsi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iteatapi]
"ImagePath"="\SystemRoot\system32\drivers\iteatapi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iteraid]
"ImagePath"="\SystemRoot\system32\drivers\iteraid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kbdclass]
"ImagePath"="system32\DRIVERS\kbdclass.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kbdhid]
"ImagePath"="system32\DRIVERS\kbdhid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KeyIso]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KSecDD]
"ImagePath"="System32\Drivers\ksecdd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ksthunk]
"ImagePath"="\SystemRoot\system32\drivers\ksthunk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KtmRm]
"ServiceDll"="%systemroot%\system32\msdtckrm.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanmanServer]
"ServiceDll"="%SystemRoot%\System32\srvsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanmanWorkstation]
"ServiceDll"="%SystemRoot%\System32\wkssvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldap]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lltdio]
"ImagePath"="system32\DRIVERS\lltdio.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lltdsvc]
"ServiceDll"="%SystemRoot%\System32\lltdsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lmhosts]
"ServiceDll"="%SystemRoot%\System32\lmhsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Lsa]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LSI_FC]
"ImagePath"="\SystemRoot\system32\drivers\lsi_fc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LSI_SAS]
"ImagePath"="\SystemRoot\system32\drivers\lsi_sas.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LSI_SCSI]
"ImagePath"="\SystemRoot\system32\drivers\lsi_scsi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\luafv]
"ImagePath"="\SystemRoot\system32\drivers\luafv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMProtector]
"ImagePath"="\??\c:\windows\system32\drivers\mbam.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMScheduler]
"ImagePath"="\"c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMService]
"ImagePath"="\"c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\megasas]
"ImagePath"="\SystemRoot\system32\drivers\megasas.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MegaSR]
"ImagePath"="\SystemRoot\system32\drivers\megasr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MMCSS]
"ServiceDll"="%SystemRoot%\system32\mmcss.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Modem]
"ImagePath"="system32\drivers\modem.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\monitor]
"ImagePath"="system32\DRIVERS\monitor.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mouclass]
"ImagePath"="system32\DRIVERS\mouclass.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mouhid]
"ImagePath"="system32\DRIVERS\mouhid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MountMgr]
"ImagePath"="System32\drivers\mountmgr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mpio]
"ImagePath"="\SystemRoot\system32\drivers\mpio.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mpsdrv]
"ImagePath"="System32\drivers\mpsdrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MpsSvc]
"ServiceDll"="%SystemRoot%\system32\mpssvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mraid35x]
"ImagePath"="\SystemRoot\system32\drivers\mraid35x.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MRxDAV]
"ImagePath"="\SystemRoot\system32\drivers\mrxdav.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mrxsmb]
"ImagePath"="system32\DRIVERS\mrxsmb.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mrxsmb10]
"ImagePath"="system32\DRIVERS\mrxsmb10.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mrxsmb20]
"ImagePath"="system32\DRIVERS\mrxsmb20.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msahci]
"ImagePath"="\SystemRoot\system32\drivers\msahci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msdsm]
"ImagePath"="\SystemRoot\system32\drivers\msdsm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC]
"ImagePath"="%SystemRoot%\System32\msdtc.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC Bridge 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC Bridge 4.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Msfs]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msisadrv]
"ImagePath"="system32\drivers\msisadrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSiSCSI]
"ServiceDll"="%systemroot%\system32\iscsiexe.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSKSSRV]
"ImagePath"="system32\drivers\MSKSSRV.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSPCLOCK]
"ImagePath"="system32\drivers\MSPCLOCK.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSPQM]
"ImagePath"="system32\drivers\MSPQM.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MsRPC]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSSCNTRS]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mssmbios]
"ImagePath"="system32\DRIVERS\mssmbios.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSTEE]
"ImagePath"="system32\drivers\MSTEE.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mup]
"ImagePath"="System32\Drivers\mup.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\napagent]
"ServiceDLL"="%SystemRoot%\system32\qagentRT.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NativeWifiP]
"ImagePath"="system32\DRIVERS\nwifi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NDIS]
"ImagePath"="system32\drivers\ndis.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NdisTapi]
"ImagePath"="system32\DRIVERS\ndistapi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ndisuio]
"ImagePath"="system32\DRIVERS\ndisuio.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NdisWan]
"ImagePath"="system32\DRIVERS\ndiswan.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NDProxy]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetBIOS]
"ImagePath"="system32\DRIVERS\netbios.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\netbt]
"ImagePath"="System32\DRIVERS\netbt.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Netlogon]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Netman]
"ServiceDll"="%SystemRoot%\System32\netman.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\netprofm]
"ServiceDll"="%SystemRoot%\System32\netprofm.dll"

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetTcpPortSharing]
"ImagePath"="\"%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nfrd960]
"ImagePath"="\SystemRoot\system32\drivers\nfrd960.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NlaSvc]
"ServiceDll"="%SystemRoot%\System32\nlasvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Npfs]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsi]
"ServiceDll"="%systemroot%\system32\nsisvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsiproxy]
"ImagePath"="system32\drivers\nsiproxy.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTDS]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ntfs]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Null]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nvraid]
"ImagePath"="\SystemRoot\system32\drivers\nvraid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nvstor]
"ImagePath"="\SystemRoot\system32\drivers\nvstor.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nv_agp]
"ImagePath"="\SystemRoot\system32\drivers\nv_agp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NwlnkFlt]
"ImagePath"="system32\DRIVERS\nwlnkflt.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NwlnkFwd]
"ImagePath"="system32\DRIVERS\nwlnkfwd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ohci1394]
"ImagePath"="\SystemRoot\system32\drivers\ohci1394.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\p2pimsvc]
"ServiceDll"="%SystemRoot%\system32\p2psvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\p2psvc]
"ServiceDll"="%SystemRoot%\system32\p2psvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Parport]
"ImagePath"="system32\DRIVERS\parport.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\partmgr]
"ImagePath"="System32\drivers\partmgr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PcaSvc]
"ServiceDll"="%SystemRoot%\System32\pcasvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pci]
"ImagePath"="system32\drivers\pci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pciide]
"ImagePath"="\SystemRoot\system32\drivers\pciide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pcmcia]
"ImagePath"="\SystemRoot\system32\drivers\pcmcia.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PEAUTH]
"ImagePath"="system32\drivers\peauth.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfDisk]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfHost]
"ImagePath"="%SystemRoot%\SysWow64\perfhost.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfNet]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfOS]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfProc]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ph3xIB64]
"ImagePath"="system32\DRIVERS\Ph3xIB64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pla]
"ServiceDll"="%systemroot%\system32\pla.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PlugPlay]
"ServiceDll"="%SystemRoot%\system32\umpnpmgr.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PNRPAutoReg]
"ServiceDll"="%SystemRoot%\system32\p2psvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PNRPsvc]
"ServiceDll"="%SystemRoot%\system32\p2psvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PolicyAgent]
"ServiceDll"="%SystemRoot%\System32\ipsecsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PortProxy]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PptpMiniport]
"ImagePath"="system32\DRIVERS\raspptp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Processor]
"ImagePath"="\SystemRoot\system32\drivers\processr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProfSvc]
"ServiceDll"="%systemroot%\system32\profsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProtectedStorage]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PSched]
"ImagePath"="system32\DRIVERS\pacer.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ql2300]
"ImagePath"="\SystemRoot\system32\drivers\ql2300.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ql40xx]
"ImagePath"="\SystemRoot\system32\drivers\ql40xx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\QWAVE]
"ServiceDll"="%windir%\system32\qwave.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\QWAVEdrv]
"ImagePath"="\SystemRoot\system32\drivers\qwavedrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasAcd]
"ImagePath"="System32\DRIVERS\rasacd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasAuto]
"ServiceDll"="%SystemRoot%\System32\rasauto.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Rasl2tp]
"ImagePath"="system32\DRIVERS\rasl2tp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasMan]
"ServiceDll"="%SystemRoot%\System32\rasmans.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasPppoe]
"ImagePath"="system32\DRIVERS\raspppoe.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasSstp]
"ImagePath"="system32\DRIVERS\rassstp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdbss]
"ImagePath"="system32\DRIVERS\rdbss.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPCDD]
"ImagePath"="System32\DRIVERS\RDPCDD.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPDD]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdpdr]
"ImagePath"="system32\DRIVERS\rdpdr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPENCDD]
"ImagePath"="system32\drivers\rdpencdd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPNP]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPWD]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess]
"ServiceDLL"="%SystemRoot%\System32\mprdim.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteRegistry]
"ServiceDll"="%SystemRoot%\system32\regsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcLocator]
"ImagePath"="%SystemRoot%\system32\locator.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcSs]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rspndr]
"ImagePath"="system32\DRIVERS\rspndr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SamSs]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sbp2port]
"ImagePath"="\SystemRoot\system32\drivers\sbp2port.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SCardSvr]
"ServiceDll"="%SystemRoot%\System32\SCardSvr.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Schedule]
"ServiceDll"="%systemroot%\system32\schedsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SCPolicySvc]
"ServiceDll"="%SystemRoot%\System32\certprop.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SDRSVC]
"ServiceDll"="%Systemroot%\System32\SDRSVC.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\secdrv]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\seclogon]
"ServiceDll"="%windir%\system32\seclogon.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SENS]
"ServiceDll"="%SystemRoot%\system32\sens.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Serenum]
"ImagePath"="system32\DRIVERS\serenum.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Serial]
"ImagePath"="system32\DRIVERS\serial.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sermouse]
"ImagePath"="\SystemRoot\system32\drivers\sermouse.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceModelEndpoint 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceModelOperation 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceModelService 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SessionEnv]
"ServiceDLL"="%SystemRoot%\system32\sessenv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sffdisk]
"ImagePath"="\SystemRoot\system32\drivers\sffdisk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sffp_mmc]
"ImagePath"="\SystemRoot\system32\drivers\sffp_mmc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sffp_sd]
"ImagePath"="\SystemRoot\system32\drivers\sffp_sd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sfloppy]
"ImagePath"="\SystemRoot\system32\drivers\sfloppy.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess]
"ServiceDll"="%SystemRoot%\System32\ipnathlp.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ShellHWDetection]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SiSRaid2]
"ImagePath"="\SystemRoot\system32\drivers\sisraid2.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SiSRaid4]
"ImagePath"="\SystemRoot\system32\drivers\sisraid4.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\slsvc]
"ImagePath"="%SystemRoot%\system32\SLsvc.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SLUINotify]
"ServiceDll"="%SystemRoot%\system32\SLUINotify.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Smb]
"ImagePath"="system32\DRIVERS\smb.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SMSvcHost 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SMSvcHost 4.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SNMPTRAP]
"ImagePath"="%SystemRoot%\System32\snmptrap.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\spldr]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Spooler]
"ImagePath"="%SystemRoot%\System32\spoolsv.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srv]
"ImagePath"="System32\DRIVERS\srv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srv2]
"ImagePath"="System32\DRIVERS\srv2.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srvnet]
"ImagePath"="System32\DRIVERS\srvnet.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SSDPSRV]
"ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SstpSvc]
"ServiceDll"="%SystemRoot%\system32\sstpsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\stisvc]
"ServiceDll"="%SystemRoot%\System32\wiaservc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\swenum]
"ImagePath"="system32\DRIVERS\swenum.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\swprv]
"ServiceDll"="%Systemroot%\System32\swprv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Symc8xx]
"ImagePath"="\SystemRoot\system32\drivers\symc8xx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sym_hi]
"ImagePath"="\SystemRoot\system32\drivers\sym_hi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sym_u3]
"ImagePath"="\SystemRoot\system32\drivers\sym_u3.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysMain]
"ServiceDll"="%systemroot%\system32\sysmain.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TabletInputService]
"ServiceDll"="%SystemRoot%\System32\TabSvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv]
"ServiceDll"="%SystemRoot%\System32\tapisrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TBS]
"ServiceDll"="%SystemRoot%\System32\tbssvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip]
"ImagePath"="System32\drivers\tcpip.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6]
"ImagePath"="system32\DRIVERS\tcpip.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tcpipreg]
"ImagePath"="System32\drivers\tcpipreg.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDPIPE]
"ImagePath"="system32\drivers\tdpipe.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDTCP]
"ImagePath"="system32\drivers\tdtcp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tdx]
"ImagePath"="system32\DRIVERS\tdx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TermDD]
"ImagePath"="system32\DRIVERS\termdd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TermService]
"ServiceDll"="%SystemRoot%\System32\termsrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Themes]
"ServiceDll"="%SystemRoot%\system32\shsvcs.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\THREADORDER]
"ServiceDll"="%SystemRoot%\system32\mmcss.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWks]
"ServiceDll"="%SystemRoot%\System32\trkwks.dll"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrustedInstaller]
"ImagePath"="%SystemRoot%\servicing\TrustedInstaller.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TSDDD]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tssecsrv]
"ImagePath"="System32\DRIVERS\tssecsrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tunmp]
"ImagePath"="system32\DRIVERS\tunmp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tunnel]
"ImagePath"="system32\DRIVERS\tunnel.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uagp35]
"ImagePath"="\SystemRoot\system32\drivers\uagp35.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\udfs]
"ImagePath"="system32\DRIVERS\udfs.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UGatherer]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UGTHRSVC]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UI0Detect]
"ImagePath"="%SystemRoot%\system32\UI0Detect.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uliagpkx]
"ImagePath"="\SystemRoot\system32\drivers\uliagpkx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uliahci]
"ImagePath"="\SystemRoot\system32\drivers\uliahci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UlSata]
"ImagePath"="\SystemRoot\system32\drivers\ulsata.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ulsata2]
"ImagePath"="\SystemRoot\system32\drivers\ulsata2.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\umbus]
"ImagePath"="system32\DRIVERS\umbus.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UmRdpService]
"ServiceDll"="%SystemRoot%\System32\umrdp.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\upnphost]
"ServiceDll"="%SystemRoot%\System32\upnphost.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usb]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbbus]
"ImagePath"="system32\DRIVERS\lgx64bus.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbccgp]
"ImagePath"="system32\DRIVERS\usbccgp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbcir]
"ImagePath"="\SystemRoot\system32\drivers\usbcir.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UsbDiag]
"ImagePath"="system32\DRIVERS\lgx64diag.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbehci]
"ImagePath"="system32\DRIVERS\usbehci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UsbGps]
"ImagePath"="system32\DRIVERS\lgx64gps.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbhub]
"ImagePath"="system32\DRIVERS\usbhub.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\USBModem]
"ImagePath"="system32\DRIVERS\lgx64modem.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbohci]
"ImagePath"="\SystemRoot\system32\drivers\usbohci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbprint]
"ImagePath"="system32\DRIVERS\usbprint.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbscan]
"ImagePath"="system32\DRIVERS\usbscan.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\USBSTOR]
"ImagePath"="system32\DRIVERS\USBSTOR.SYS"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbuhci]
"ImagePath"="system32\DRIVERS\usbuhci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UxSms]
"ServiceDll"="%SystemRoot%\System32\uxsms.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vds]
"ImagePath"="%SystemRoot%\System32\vds.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vga]
"ImagePath"="system32\DRIVERS\vgapnp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VgaSave]
"ImagePath"="\SystemRoot\System32\drivers\vga.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\viaide]
"ImagePath"="\SystemRoot\system32\drivers\viaide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\volmgr]
"ImagePath"="system32\drivers\volmgr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\volmgrx]
"ImagePath"="System32\drivers\volmgrx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\volsnap]
"ImagePath"="system32\drivers\volsnap.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vsmraid]
"ImagePath"="\SystemRoot\system32\drivers\vsmraid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS]
"ImagePath"="%systemroot%\system32\vssvc.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W32Time]
"ServiceDll"="%systemroot%\system32\w32time.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W3SVC]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WacomPen]
"ImagePath"="\SystemRoot\system32\drivers\wacompen.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wanarp]
"ImagePath"="system32\DRIVERS\wanarp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wanarpv6]
"ImagePath"="system32\DRIVERS\wanarp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wbengine]
"ImagePath"="\"%systemroot%\system32\wbengine.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wcncsvc]
"ServiceDll"="%SystemRoot%\System32\wcncsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WcsPlugInService]
"ServiceDll"="%SystemRoot%\System32\WcsPlugInService.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wd]
"ImagePath"="\SystemRoot\system32\drivers\wd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wdf01000]
"ImagePath"="system32\drivers\Wdf01000.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WdiServiceHost]
"ServiceDll"="%SystemRoot%\system32\wdi.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WdiSystemHost]
"ServiceDll"="%SystemRoot%\system32\wdi.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebClient]
"ServiceDll"="%SystemRoot%\System32\webclnt.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wecsvc]
"ServiceDll"="%SystemRoot%\system32\wecsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wercplsupport]
"ServiceDll"="%SystemRoot%\System32\wercplsupport.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WerSvc]
"ServiceDll"="%SystemRoot%\System32\WerSvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinDefend]
"ServiceDll"="%ProgramFiles%\Windows Defender\mpsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Windows Workflow Foundation 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinHttpAutoProxySvc]
"ServiceDll"="winhttp.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winmgmt]
"ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinRM]
"ServiceDll"="%SystemRoot%\system32\WsmSvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wlansvc]
"ServiceDll"="%SystemRoot%\System32\wlansvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiAcpi]
"ImagePath"="\SystemRoot\system32\drivers\wmiacpi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiApRpl]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wmiApSrv]
"ImagePath"="%systemroot%\system32\wbem\WmiApSrv.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WMPNetworkSvc]
"ImagePath"="\"%ProgramFiles%\Windows Media Player\wmpnetwk.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WPDBusEnum]
"ServiceDll"="%SystemRoot%\system32\wpdbusenum.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WpdUsb]
"ImagePath"="system32\DRIVERS\wpdusb.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WPFFontCache_v0400]
"ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ws2ifsl]
"ImagePath"="\SystemRoot\system32\drivers\ws2ifsl.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WSearch]
"ImagePath"="%systemroot%\system32\SearchIndexer.exe /Embedding"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WSearchIdxPi]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv]
"ServiceDll"="%systemroot%\system32\wuaueng.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WudfPf]
"ImagePath"="system32\drivers\WudfPf.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WUDFRd]
"ImagePath"="system32\DRIVERS\WUDFRd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wudfsvc]
"ServiceDll"="%SystemRoot%\System32\WUDFSvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\YahooAUService]
"ImagePath"="\"c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yksvc]
"ServiceDll"="%SystemRoot%\System32\ykx64mpcoinst.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yukonx64]
"ImagePath"="system32\DRIVERS\yk60x64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{07171AC2-0D2A-427d-BCE5-B6C2D6C7058B}]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{8E7FF6BA-8E5A-46B1-B8A4-EE49F9A0BFAE}]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-12-01 11:36:53
ComboFix-quarantined-files.txt 2013-12-01 18:36
.
Pre-Run: 89,275,867,136 bytes free
Post-Run: 90,324,500,480 bytes free
.
- - End Of File - - CA6DB3391309F7C4696CF27EA8632809
5C616939100B85E558DA92B899A0FC36

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
Malwarebytes' Anti-Rootkit

Please download Malwarebytes' Anti-Rootkit and save it to your desktop.

  • Be sure to print out and follow the instructions provided on that same page for performing a scan.
  • Caution: This is a beta version so also read the disclaimer and back up all your data before using.
  • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • If there are problems with Internet access, Windows Update, Windows Firewall or other system issues, run the fixdamage tool located in the folder Malwarebytes Anti-Rootkit was run from and reboot your computer.
  • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
  • Copy and paste the contents of these two log files in your next reply.

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
It said no bad stuff was found. Heres the log.
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1007

(c) Malwarebytes Corporation 2011-2012

OS version: 6.0.6002 Windows Vista Service Pack 2 x64

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, E:\ DRIVE_FIXED
CPU speed: 2.992000 GHz
Memory total: 4293210112, free: 2684821504

Downloaded database version: v2013.12.02.10
Downloaded database version: v2013.10.11.02
Initializing...
======================
------------ Kernel report ------------
12/02/2013 15:30:30
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\acpi.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\system32\drivers\intelide.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\msrpc.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\ecache.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\system32\drivers\crcdisk.sys
\SystemRoot\system32\DRIVERS\avgrkx64.sys
\SystemRoot\system32\DRIVERS\avgloga.sys
\SystemRoot\system32\DRIVERS\avgmfx64.sys
\SystemRoot\system32\DRIVERS\avgidsha.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\tunmp.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\atikmpag.sys
\SystemRoot\system32\DRIVERS\atikmdag.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\yk60x64.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\serial.sys
\SystemRoot\system32\DRIVERS\serenum.sys
\SystemRoot\system32\DRIVERS\parport.sys
\SystemRoot\system32\DRIVERS\i8042prt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\msiscsi.sys
\SystemRoot\system32\DRIVERS\storport.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\BdaSup.SYS
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\rdpdr.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\eamonm.sys
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\system32\DRIVERS\ehdrv.sys
C:\Program Files\ESET\ESET NOD32 Antivirus\em006_64.dat
C:\Program Files\ESET\ESET NOD32 Antivirus\em018_64.dat
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\smb.sys
\SystemRoot\system32\DRIVERS\avgtdia.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\avgldx64.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\avgidsdrivera.sys
\SystemRoot\system32\DRIVERS\avgdiska.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\??\C:\Windows\system32\drivers\mbam.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\drivers\spsys.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\drivers\mrxdav.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\SystemRoot\system32\DRIVERS\epfwwfpr.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\drivers\tcpipreg.sys
\??\C:\Windows\system32\Drivers\PROCEXP113.SYS
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR1
Upper Device Object: 0xfffffa80068bf060
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\0000006a\
Lower Device Object: 0xfffffa80068c0b20
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8004d28380
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\Ide\IdeDeviceP2T0L0-2\
Lower Device Object: 0xfffffa8004b8f940
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa8004d28380, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8004d27040, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8004d28380, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
DevicePointer: 0xfffffa8004b8ee40, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa8004b8f940, DeviceName: \Device\Ide\IdeDeviceP2T0L0-2\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: E9CE19C4

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 63 Numsec = 312576642
Partition file system is NTFS
Partition is bootable

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 160041885696 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-312561808-312581808)...
Done!
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xfffffa80068bf060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa80068c0650, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa80068bf060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
DevicePointer: 0xfffffa80068c0b20, DeviceName: \Device\0000006a\, DriverName: \Driver\USBSTOR\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 5BFEE727

Partition information:

Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 63 Numsec = 625137282

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 320072932864 bytes
Sector size: 512 bytes

Done!
Read File: File "c:\programdata\avg2014\chjw\104c15104c13d6.dat:f4905160-5df6-4f55-b30e-0b6a5d3b477c" is sparse (flags = 32768)
Read File: File "c:\windows\system32\config\systemprofile\appdata\local\avg2014\log\avg-b37e894e-f5d2-462d-9425-e10b2894856e.tmp" is compressed (flags = 1)
Read File: File "C:\Windows\System32\config\systemprofile\AppData\Local\Avg2014\log\avgcore.log.4" is compressed (flags = 1)
Scan finished
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\Bootstrap_0_0_63_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_r.mbam...
Removal finished

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
Second half .. ( and first part too.)
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1007

(c) Malwarebytes Corporation 2011-2012

OS version: 6.0.6002 Windows Vista Service Pack 2 x64

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, E:\ DRIVE_FIXED
CPU speed: 2.992000 GHz
Memory total: 4293210112, free: 2684821504

Downloaded database version: v2013.12.02.10
Downloaded database version: v2013.10.11.02
Initializing...
======================
------------ Kernel report ------------
12/02/2013 15:30:30
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\acpi.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\system32\drivers\intelide.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\msrpc.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\ecache.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\system32\drivers\crcdisk.sys
\SystemRoot\system32\DRIVERS\avgrkx64.sys
\SystemRoot\system32\DRIVERS\avgloga.sys
\SystemRoot\system32\DRIVERS\avgmfx64.sys
\SystemRoot\system32\DRIVERS\avgidsha.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\tunmp.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\atikmpag.sys
\SystemRoot\system32\DRIVERS\atikmdag.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\yk60x64.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\serial.sys
\SystemRoot\system32\DRIVERS\serenum.sys
\SystemRoot\system32\DRIVERS\parport.sys
\SystemRoot\system32\DRIVERS\i8042prt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\msiscsi.sys
\SystemRoot\system32\DRIVERS\storport.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\BdaSup.SYS
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\rdpdr.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\eamonm.sys
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\system32\DRIVERS\ehdrv.sys
C:\Program Files\ESET\ESET NOD32 Antivirus\em006_64.dat
C:\Program Files\ESET\ESET NOD32 Antivirus\em018_64.dat
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\smb.sys
\SystemRoot\system32\DRIVERS\avgtdia.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\avgldx64.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\avgidsdrivera.sys
\SystemRoot\system32\DRIVERS\avgdiska.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\??\C:\Windows\system32\drivers\mbam.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\drivers\spsys.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\drivers\mrxdav.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\SystemRoot\system32\DRIVERS\epfwwfpr.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\drivers\tcpipreg.sys
\??\C:\Windows\system32\Drivers\PROCEXP113.SYS
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR1
Upper Device Object: 0xfffffa80068bf060
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\0000006a\
Lower Device Object: 0xfffffa80068c0b20
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8004d28380
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\Ide\IdeDeviceP2T0L0-2\
Lower Device Object: 0xfffffa8004b8f940
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa8004d28380, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8004d27040, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8004d28380, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
DevicePointer: 0xfffffa8004b8ee40, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa8004b8f940, DeviceName: \Device\Ide\IdeDeviceP2T0L0-2\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: E9CE19C4

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 63 Numsec = 312576642
Partition file system is NTFS
Partition is bootable

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 160041885696 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-312561808-312581808)...
Done!
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xfffffa80068bf060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa80068c0650, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa80068bf060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
DevicePointer: 0xfffffa80068c0b20, DeviceName: \Device\0000006a\, DriverName: \Driver\USBSTOR\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 5BFEE727

Partition information:

Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 63 Numsec = 625137282

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 320072932864 bytes
Sector size: 512 bytes

Done!
Read File: File "c:\programdata\avg2014\chjw\104c15104c13d6.dat:f4905160-5df6-4f55-b30e-0b6a5d3b477c" is sparse (flags = 32768)
Read File: File "c:\windows\system32\config\systemprofile\appdata\local\avg2014\log\avg-b37e894e-f5d2-462d-9425-e10b2894856e.tmp" is compressed (flags = 1)
Read File: File "C:\Windows\System32\config\systemprofile\AppData\Local\Avg2014\log\avgcore.log.4" is compressed (flags = 1)
Scan finished
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\Bootstrap_0_0_63_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_r.mbam...
Removal finished
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1007

(c) Malwarebytes Corporation 2011-2012

OS version: 6.0.6002 Windows Vista Service Pack 2 x64

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, E:\ DRIVE_FIXED
CPU speed: 2.992000 GHz
Memory total: 4293210112, free: 2677116928

Downloaded database version: v2013.12.02.11
Downloaded database version: v2013.10.11.02
=======================================
Initializing...
------------ Kernel report ------------
12/02/2013 15:45:14
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\acpi.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\system32\drivers\intelide.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\msrpc.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\ecache.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\system32\drivers\crcdisk.sys
\SystemRoot\system32\DRIVERS\avgrkx64.sys
\SystemRoot\system32\DRIVERS\avgloga.sys
\SystemRoot\system32\DRIVERS\avgmfx64.sys
\SystemRoot\system32\DRIVERS\avgidsha.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\tunmp.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\atikmpag.sys
\SystemRoot\system32\DRIVERS\atikmdag.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\yk60x64.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\serial.sys
\SystemRoot\system32\DRIVERS\serenum.sys
\SystemRoot\system32\DRIVERS\parport.sys
\SystemRoot\system32\DRIVERS\i8042prt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\msiscsi.sys
\SystemRoot\system32\DRIVERS\storport.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\BdaSup.SYS
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\rdpdr.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\eamonm.sys
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\system32\DRIVERS\ehdrv.sys
C:\Program Files\ESET\ESET NOD32 Antivirus\em006_64.dat
C:\Program Files\ESET\ESET NOD32 Antivirus\em018_64.dat
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\smb.sys
\SystemRoot\system32\DRIVERS\avgtdia.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\avgldx64.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\avgidsdrivera.sys
\SystemRoot\system32\DRIVERS\avgdiska.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\??\C:\Windows\system32\drivers\mbam.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\drivers\spsys.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\drivers\mrxdav.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\SystemRoot\system32\DRIVERS\epfwwfpr.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\drivers\tcpipreg.sys
\??\C:\Windows\system32\Drivers\PROCEXP113.SYS
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR1
Upper Device Object: 0xfffffa80068bf060
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\0000006a\
Lower Device Object: 0xfffffa80068c0b20
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8004d28380
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\Ide\IdeDeviceP2T0L0-2\
Lower Device Object: 0xfffffa8004b8f940
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa8004d28380, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8004d27040, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8004d28380, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
DevicePointer: 0xfffffa8004b8ee40, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa8004b8f940, DeviceName: \Device\Ide\IdeDeviceP2T0L0-2\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: E9CE19C4

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 63 Numsec = 312576642
Partition file system is NTFS
Partition is bootable

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 160041885696 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-312561808-312581808)...
Done!
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xfffffa80068bf060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa80068c0650, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa80068bf060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
DevicePointer: 0xfffffa80068c0b20, DeviceName: \Device\0000006a\, DriverName: \Driver\USBSTOR\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 5BFEE727

Partition information:

Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 63 Numsec = 625137282

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 320072932864 bytes
Sector size: 512 bytes

Done!
Read File: File "c:\programdata\avg2014\chjw\104c15104c13d6.dat:f4905160-5df6-4f55-b30e-0b6a5d3b477c" is sparse (flags = 32768)
Read File: File "c:\windows\system32\config\systemprofile\appdata\local\avg2014\log\avg-b37e894e-f5d2-462d-9425-e10b2894856e.tmp" is compressed (flags = 1)
Read File: File "c:\windows\system32\config\systemprofile\appdata\local\avg2014\log\avg-b8c94a59-df5e-4724-969a-b77f2eb64716.tmp" is compressed (flags = 1)
Scan finished
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\Bootstrap_0_0_63_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_r.mbam...
Removal finished

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.

•Check
•Click the button.
•Accept any security warnings from your browser.

  • Leave the check mark next to Remove found threats.

•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
I did the scan with ESET OnlineScan as you said to , it did the scan and said no infected files found, so it did not show a log.

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
Another strange thing, I downloaded firefox and I am able to get to the asite with no problems. It is just explore that causes the problem.

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
How's your computer running now? Any other issues before we clean up?

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
No ,but my problem still exists. I can/y access that site in explore but in firefox I can. I am wondering why it hapened, and don't want it to do the same thing in firefox. This is the second time that this hapened on that same web site..

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
I just noticed in your ComboFix log that you have two AV's enabled; AVG AntiVirus Free Edition 2014 and ESET NOD32 Antivirus 7.0. You cannot have two AV's active on your computer. One will have to be disabled.

Please download and run MS Fix-it from here. Click on Internet Explorer.

descriptionRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
I tried to delete EST from my control panel but it says its got an error and I cant delete it,so I clicked on AVG to delete ,it said error also,but asked if I wanted to save the log, about 6 folders poped up .I opend the last one and this is what it shows
=== Verbose logging started: 11/28/2013 17:44:44 Build type: SHIP UNICODE 4.05.6002.00 Calling process: C:\Windows\SysWOW64\msiexec.exe ===
MSI (c) (A4:48) [17:44:44:237]: Resetting cached policy values
MSI (c) (A4:48) [17:44:44:237]: Machine policy value 'Debug' is 0
MSI (c) (A4:48) [17:44:44:237]: ******* RunEngine:
******* Product: C:\ProgramData\MFAData\pack\vc_red.msi
******* Action:
******* CommandLine: **********
MSI (c) (A4:48) [17:44:44:237]: Client-side and UI is none or basic: Running entire install on the server.
MSI (c) (A4:48) [17:44:44:237]: Grabbed execution mutex.
MSI (c) (A4:48) [17:44:44:237]: Cloaking enabled.
MSI (c) (A4:48) [17:44:44:237]: Attempting to enable all disabled privileges before calling Install on Server
MSI (c) (A4:48) [17:44:44:253]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (50:BC) [17:44:44:315]: Running installation inside multi-package transaction C:\ProgramData\MFAData\pack\vc_red.msi
MSI (s) (50:BC) [17:44:44:315]: Grabbed execution mutex.
MSI (s) (50:68) [17:44:44:315]: Resetting cached policy values
MSI (s) (50:68) [17:44:44:315]: Machine policy value 'Debug' is 0
MSI (s) (50:68) [17:44:44:315]: ******* RunEngine:
******* Product: C:\ProgramData\MFAData\pack\vc_red.msi
******* Action:
******* CommandLine: **********
MSI (s) (50:68) [17:44:44:315]: Machine policy value 'DisableUserInstalls' is 0
MSI (s) (50:68) [17:44:44:331]: SRSetRestorePoint skipped for this transaction.
MSI (s) (50:68) [17:44:44:347]: File will have security applied from OpCode.
MSI (s) (50:68) [17:44:44:362]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'C:\ProgramData\MFAData\pack\vc_red.msi' against software restriction policy
MSI (s) (50:68) [17:44:44:362]: SOFTWARE RESTRICTION POLICY: C:\ProgramData\MFAData\pack\vc_red.msi has a digital signature
MSI (s) (50:68) [17:44:44:456]: SOFTWARE RESTRICTION POLICY: C:\ProgramData\MFAData\pack\vc_red.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (50:68) [17:44:44:456]: End dialog not enabled
MSI (s) (50:68) [17:44:44:456]: Original package ==> C:\ProgramData\MFAData\pack\vc_red.msi
MSI (s) (50:68) [17:44:44:456]: Package we're running from ==> C:\Windows\Installer\48ae7a7.msi
MSI (s) (50:68) [17:44:44:456]: APPCOMPAT: looking for appcompat database entry with ProductCode '{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}'.
MSI (s) (50:68) [17:44:44:456]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (50:68) [17:44:44:659]: MSCOREE not loaded loading copy from system32
MSI (s) (50:68) [17:44:44:659]: Machine policy value 'TransformsSecure' is 0
MSI (s) (50:68) [17:44:44:659]: User policy value 'TransformsAtSource' is 0
MSI (s) (50:68) [17:44:44:659]: Note: 1: 2205 2: 3: MsiFileHash
MSI (s) (50:68) [17:44:44:659]: Machine policy value 'DisablePatch' is 0
MSI (s) (50:68) [17:44:44:659]: Machine policy value 'AllowLockdownPatch' is 0
MSI (s) (50:68) [17:44:44:659]: Machine policy value 'DisableLUAPatching' is 0
MSI (s) (50:68) [17:44:44:659]: Machine policy value 'DisableFlyWeightPatching' is 0
MSI (s) (50:68) [17:44:44:659]: APPCOMPAT: looking for appcompat database entry with ProductCode '{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}'.
MSI (s) (50:68) [17:44:44:659]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (50:68) [17:44:44:659]: Transforms are not secure.
MSI (s) (50:68) [17:44:44:659]: Note: 1: 2205 2: 3: Control
MSI (s) (50:68) [17:44:44:659]: PROPERTY CHANGE: Adding MsiLogFileLocation property. Its value is 'C:\Users\myComputer\AppData\Local\MFAData\logs\r86-20131129-004444.log'.
MSI (s) (50:68) [17:44:44:659]: Command Line: REBOOT=ReallySuppress CURRENTDIRECTORY=C:\Users\MYCOMP~1\AppData\Local\Temp\7zS4FCC.tmp CLIENTUILEVEL=3 CLIENTPROCESSID=676
MSI (s) (50:68) [17:44:44:659]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{8D9DE39A-DFAA-4F2F-95C8-B6B0EFEF1F27}'.
MSI (s) (50:68) [17:44:44:659]: Product Code passed to Engine.Initialize: ''
MSI (s) (50:68) [17:44:44:659]: Product Code from property table before transforms: '{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}'
MSI (s) (50:68) [17:44:44:659]: Product Code from property table after transforms: '{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}'
MSI (s) (50:68) [17:44:44:659]: Product not registered: beginning first-time install
MSI (s) (50:68) [17:44:44:659]: Product {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8} is not managed.
MSI (s) (50:68) [17:44:44:659]: MSI_LUA: Credential prompt not required, user is an admin
MSI (s) (50:68) [17:44:44:659]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.
MSI (s) (50:68) [17:44:44:659]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (50:68) [17:44:44:659]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (50:68) [17:44:44:659]: Adding new sources is allowed.
MSI (s) (50:68) [17:44:44:659]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.
MSI (s) (50:68) [17:44:44:659]: Package name extracted from package path: 'vc_red.msi'
MSI (s) (50:68) [17:44:44:659]: Package to be registered: 'vc_red.msi'
MSI (s) (50:68) [17:44:44:659]: Note: 1: 2205 2: 3: Error
MSI (s) (50:68) [17:44:44:659]: Note: 1: 2262 2: AdminProperties 3: -2147287038
MSI (s) (50:68) [17:44:44:659]: Machine policy value 'DisableMsi' is 0
MSI (s) (50:68) [17:44:44:659]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (50:68) [17:44:44:659]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (50:68) [17:44:44:659]: Product installation will be elevated because user is admin and product is being installed per-machine.
MSI (s) (50:68) [17:44:44:659]: Running product '{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}' with elevated privileges: Product is assigned.
MSI (s) (50:68) [17:44:44:659]: PROPERTY CHANGE: Adding REBOOT property. Its value is 'ReallySuppress'.
MSI (s) (50:68) [17:44:44:659]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'C:\Users\MYCOMP~1\AppData\Local\Temp\7zS4FCC.tmp'.
MSI (s) (50:68) [17:44:44:659]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.
MSI (s) (50:68) [17:44:44:659]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '676'.
MSI (s) (50:68) [17:44:44:659]: Machine policy value 'DisableAutomaticApplicationShutdown' is 0
MSI (s) (50:68) [17:44:44:659]: PROPERTY CHANGE: Adding MsiRestartManagerSessionKey property. Its value is '2cb4247e2a800c4aabc417990f819cce'.
MSI (s) (50:68) [17:44:44:659]: RESTART MANAGER: Session opened.
MSI (s) (50:68) [17:44:44:659]: TRANSFORMS property is now:
MSI (s) (50:68) [17:44:44:659]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '300'.
MSI (s) (50:68) [17:44:44:659]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\AppData\Roaming
MSI (s) (50:68) [17:44:44:659]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\Favorites
MSI (s) (50:68) [17:44:44:659]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\AppData\Roaming\Microsoft\Windows\Network Shortcuts
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\Documents
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\AppData\Roaming\Microsoft\Windows\Recent
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\AppData\Roaming\Microsoft\Windows\SendTo
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\AppData\Roaming\Microsoft\Windows\Templates
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\ProgramData
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\AppData\Local
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\Documents\pictures\Pictures
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\Users\Public\Desktop
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MSI (s) (50:68) [17:44:44:674]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
MSI (s) (50:68) [17:44:44:690]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\AppData\Roaming\Microsoft\Windows\Start Menu
MSI (s) (50:68) [17:44:44:690]: SHELL32::SHGetFolderPath returned: C:\Users\myComputer\Desktop
MSI (s) (50:68) [17:44:44:690]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Templates
MSI (s) (50:68) [17:44:44:690]: SHELL32::SHGetFolderPath returned: C:\Windows\Fonts
MSI (s) (50:68) [17:44:44:690]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16
MSI (s) (50:68) [17:44:44:690]: MSI_LUA: Setting MsiRunningElevated property to 1 because the install is already running elevated.
MSI (s) (50:68) [17:44:44:690]: PROPERTY CHANGE: Adding MsiRunningElevated property. Its value is '1'.
MSI (s) (50:68) [17:44:44:690]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
MSI (s) (50:68) [17:44:44:690]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (50:68) [17:44:44:690]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'myComputer'.
MSI (s) (50:68) [17:44:44:690]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (50:68) [17:44:44:690]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'C:\Windows\Installer\48ae7a7.msi'.
MSI (s) (50:68) [17:44:44:690]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'C:\ProgramData\MFAData\pack\vc_red.msi'.
MSI (s) (50:68) [17:44:44:690]: Machine policy value 'MsiDisableEmbeddedUI' is 0
MSI (s) (50:68) [17:44:44:690]: EEUI - Disabling MsiEmbeddedUI for service because it's not a quiet/basic install
MSI (s) (50:68) [17:44:44:690]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (50:68) [17:44:44:690]: Machine policy value 'DisableRollback' is 0
MSI (s) (50:68) [17:44:44:690]: User policy value 'DisableRollback' is 0
MSI (s) (50:68) [17:44:44:690]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.
=== Logging started: 11/28/2013 17:44:44 ===
MSI (s) (50:68) [17:44:44:690]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
MSI (s) (50:68) [17:44:44:690]: Doing action: INSTALL
MSI (s) (50:68) [17:44:44:690]: Note: 1: 2205 2: 3: ActionText
Action start 17:44:44: INSTALL.
MSI (s) (50:68) [17:44:44:690]: Running ExecuteSequence
MSI (s) (50:68) [17:44:44:690]: Doing action: WindowsFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1
MSI (s) (50:68) [17:44:44:690]: Note: 1: 2205 2: 3: ActionText
MSI (s) (50:68) [17:44:44:690]: PROPERTY CHANGE: Adding WindowsFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1 property. Its value is 'C:\Windows\'.
Action start 17:44:44: WindowsFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1.
MSI (s) (50:68) [17:44:44:690]: Doing action: SystemFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1
MSI (s) (50:68) [17:44:44:690]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:44: WindowsFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1. Return value 1.
MSI (s) (50:68) [17:44:44:690]: PROPERTY CHANGE: Adding SystemFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1 property. Its value is 'C:\Windows\SysWOW64\'.
Action start 17:44:44: SystemFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1.
MSI (s) (50:68) [17:44:44:690]: Doing action: ValidateProductID
MSI (s) (50:68) [17:44:44:690]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:44: SystemFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1. Return value 1.
Action start 17:44:44: ValidateProductID.
MSI (s) (50:68) [17:44:44:690]: Doing action: CA_WindowsFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1
MSI (s) (50:68) [17:44:44:690]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:44: ValidateProductID. Return value 1.
Action start 17:44:44: CA_WindowsFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1.
MSI (s) (50:68) [17:44:44:690]: Doing action: CA_SystemFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1
MSI (s) (50:68) [17:44:44:690]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:44: CA_WindowsFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1. Return value 1.
Action start 17:44:44: CA_SystemFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1.
MSI (s) (50:68) [17:44:44:690]: Doing action: CostInitialize
MSI (s) (50:68) [17:44:44:690]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:44: CA_SystemFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1. Return value 1.
MSI (s) (50:68) [17:44:44:721]: Machine policy value 'MaxPatchCacheSize' is 10
Action start 17:44:44: CostInitialize.
MSI (s) (50:68) [17:44:44:721]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'C:\'.
MSI (s) (50:68) [17:44:44:721]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Patch
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: __MsiPatchFileList
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2228 2: 3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId`
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Patch
MSI (s) (50:68) [17:44:44:721]: Doing action: FileCost
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:44: CostInitialize. Return value 1.
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: MsiAssembly
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Registry
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Registry
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Class
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Extension
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: TypeLib
Action start 17:44:44: FileCost.
MSI (s) (50:68) [17:44:44:721]: Doing action: CostFinalize
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:44: FileCost. Return value 1.
MSI (s) (50:68) [17:44:44:721]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.
MSI (s) (50:68) [17:44:44:721]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.
MSI (s) (50:68) [17:44:44:721]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.
MSI (s) (50:68) [17:44:44:721]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.
MSI (s) (50:68) [17:44:44:721]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Patch
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Condition
MSI (s) (50:68) [17:44:44:721]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'C:\'.
MSI (s) (50:68) [17:44:44:721]: Target path resolution complete. Dumping Directory table...
MSI (s) (50:68) [17:44:44:721]: Note: target paths subject to change (via custom actions or browsing)
MSI (s) (50:68) [17:44:44:721]: Dir (target): Key: TARGETDIR , Object: C:\
MSI (s) (50:68) [17:44:44:721]: Dir (target): Key: WindowsFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1 , Object: C:\Windows\
MSI (s) (50:68) [17:44:44:721]: Dir (target): Key: SystemFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1 , Object: C:\Windows\SysWOW64\
MSI (s) (50:68) [17:44:44:721]: PROPERTY CHANGE: Adding INSTALLLEVEL property. Its value is '1'.
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: MsiAssembly
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2228 2: 3: MsiAssembly 4: SELECT `MsiAssembly`.`Attributes`, `MsiAssembly`.`File_Application`, `MsiAssembly`.`File_Manifest`, `Component`.`KeyPath` FROM `MsiAssembly`, `Component` WHERE `MsiAssembly`.`Component_` = `Component`.`Component` AND `MsiAssembly`.`Component_` = ?
Action start 17:44:44: CostFinalize.
MSI (s) (50:68) [17:44:44:721]: Doing action: InstallValidate
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:44: CostFinalize. Return value 1.
MSI (s) (50:68) [17:44:44:721]: PROPERTY CHANGE: Deleting MsiRestartManagerSessionKey property. Its current value is '2cb4247e2a800c4aabc417990f819cce'.
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Dialog
MSI (s) (50:68) [17:44:44:721]: Feature: VCRedist32; Installed: Absent; Request: Local; Action: Local
MSI (s) (50:68) [17:44:44:721]: Component: C_CENTRAL_atl110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1; Installed: Absent; Request: Local; Action: Local
MSI (s) (50:68) [17:44:44:721]: Component: C_CENTRAL_msvcr110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1; Installed: Absent; Request: Local; Action: Local
MSI (s) (50:68) [17:44:44:721]: Component: C_CENTRAL_msvcp110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1; Installed: Absent; Request: Local; Action: Local
MSI (s) (50:68) [17:44:44:721]: Component: C_CENTRAL_vccorlib110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1; Installed: Absent; Request: Local; Action: Null
MSI (s) (50:68) [17:44:44:721]: Component: C_CENTRAL_mfc110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1; Installed: Absent; Request: Local; Action: Local
MSI (s) (50:68) [17:44:44:721]: Component: C_CENTRAL_mfc110u_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1; Installed: Absent; Request: Local; Action: Local
MSI (s) (50:68) [17:44:44:721]: Component: C_CENTRAL_mfcm110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1; Installed: Absent; Request: Local; Action: Local
MSI (s) (50:68) [17:44:44:721]: Component: C_CENTRAL_mfcm110u_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1; Installed: Absent; Request: Local; Action: Local
MSI (s) (50:68) [17:44:44:721]: Component: C_CENTRAL_vcomp110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1; Installed: Absent; Request: Local; Action: Local
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Registry
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: BindImage
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: ProgId
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: PublishComponent
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: SelfReg
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Extension
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Font
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Shortcut
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: Class
Action start 17:44:44: InstallValidate.
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: _RemoveFilePath
MSI (s) (50:68) [17:44:44:721]: Note: 1: 2205 2: 3: MsiFileHash
MSI (s) (50:68) [17:44:44:737]: PROPERTY CHANGE: Modifying CostingComplete property. Its current value is '0'. Its new value: '1'.
MSI (s) (50:68) [17:44:44:737]: Note: 1: 2205 2: 3: Registry
MSI (s) (50:68) [17:44:44:737]: Note: 1: 2205 2: 3: BindImage
MSI (s) (50:68) [17:44:44:737]: Note: 1: 2205 2: 3: ProgId
MSI (s) (50:68) [17:44:44:737]: Note: 1: 2205 2: 3: PublishComponent
MSI (s) (50:68) [17:44:44:737]: Note: 1: 2205 2: 3: SelfReg
MSI (s) (50:68) [17:44:44:737]: Note: 1: 2205 2: 3: Extension
MSI (s) (50:68) [17:44:44:737]: Note: 1: 2205 2: 3: Font
MSI (s) (50:68) [17:44:44:737]: Note: 1: 2205 2: 3: Shortcut
MSI (s) (50:68) [17:44:44:737]: Note: 1: 2205 2: 3: Class
MSI (s) (50:68) [17:44:44:737]: Note: 1: 2727 2:
MSI (s) (50:68) [17:44:44:737]: Note: 1: 2727 2:
MSI (s) (50:68) [17:44:44:737]: Doing action: InstallInitialize
MSI (s) (50:68) [17:44:44:737]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:44: InstallValidate. Return value 1.
MSI (s) (50:68) [17:44:44:737]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (50:68) [17:44:44:737]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (50:68) [17:44:44:737]: BeginTransaction: Locking Server
MSI (s) (50:68) [17:44:44:737]: SRSetRestorePoint skipped for this transaction.
MSI (s) (50:68) [17:44:44:737]: Server not locked: locking for product {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}
Action start 17:44:44: InstallInitialize.
MSI (s) (50:68) [17:44:45:361]: Doing action: ProcessComponents
MSI (s) (50:68) [17:44:45:361]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:45: InstallInitialize. Return value 1.
MSI (s) (50:68) [17:44:45:361]: Note: 1: 2205 2: 3: MsiPatchCertificate
MSI (s) (50:68) [17:44:45:361]: LUA patching is disabled: missing MsiPatchCertificate table
MSI (s) (50:68) [17:44:45:361]: Resolving source.
MSI (s) (50:68) [17:44:45:361]: Resolving source to launched-from source.
MSI (s) (50:68) [17:44:45:361]: Setting launched-from source as last-used.
MSI (s) (50:68) [17:44:45:361]: PROPERTY CHANGE: Adding SourceDir property. Its value is 'C:\ProgramData\MFAData\pack\'.
MSI (s) (50:68) [17:44:45:361]: PROPERTY CHANGE: Adding SOURCEDIR property. Its value is 'C:\ProgramData\MFAData\pack\'.
MSI (s) (50:68) [17:44:45:361]: PROPERTY CHANGE: Adding SourcedirProduct property. Its value is '{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}'.
MSI (s) (50:68) [17:44:45:361]: SOURCEDIR ==> C:\ProgramData\MFAData\pack\
MSI (s) (50:68) [17:44:45:361]: SOURCEDIR product ==> {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}
MSI (s) (50:68) [17:44:45:361]: Determining source type
MSI (s) (50:68) [17:44:45:361]: Source type from package 'vc_red.msi': 2
Action start 17:44:45: ProcessComponents.
MSI (s) (50:68) [17:44:45:361]: Source path resolution complete. Dumping Directory table...
MSI (s) (50:68) [17:44:45:361]: Dir (source): Key: TARGETDIR , Object: C:\ProgramData\MFAData\pack\ , LongSubPath: , ShortSubPath:
MSI (s) (50:68) [17:44:45:361]: Dir (source): Key: WindowsFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1 , Object: C:\ProgramData\MFAData\pack\ , LongSubPath: Win\ , ShortSubPath:
MSI (s) (50:68) [17:44:45:361]: Dir (source): Key: SystemFolder_x86_VC.D371D00B_69EC_3F8E_A622_74710A89ADC1 , Object: C:\ProgramData\MFAData\pack\ , LongSubPath: Win\System\ , ShortSubPath:
MSI (s) (50:68) [17:44:45:361]: Note: 1: 2205 2: 3: ActionText
MSI (s) (50:68) [17:44:45:361]: Note: 1: 2205 2: 3: ActionText
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: ActionText
MSI (s) (50:68) [17:44:45:392]: Doing action: UnpublishFeatures
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:45: ProcessComponents. Return value 1.
Action start 17:44:45: UnpublishFeatures.
MSI (s) (50:68) [17:44:45:392]: Doing action: RemoveFiles
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:45: UnpublishFeatures. Return value 1.
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: RemoveFile
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: RemoveFile
Action start 17:44:45: RemoveFiles.
MSI (s) (50:68) [17:44:45:392]: Doing action: InstallFiles
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:45: RemoveFiles. Return value 0.
Action start 17:44:45: InstallFiles.
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: Patch
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2228 2: 3: Patch 4: SELECT `Patch`.`File_`, `Patch`.`Header`, `Patch`.`Attributes`, `Patch`.`Sequence`, `Patch`.`StreamRef_` FROM `Patch` WHERE `Patch`.`File_` = ? AND `Patch`.`#_MsiActive`=? ORDER BY `Patch`.`Sequence`
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: Error
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1302
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: MsiSFCBypass
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2228 2: 3: MsiSFCBypass 4: SELECT `File_` FROM `MsiSFCBypass` WHERE `File_` = ?
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2228 2: 3: MsiPatchHeaders 4: SELECT `Header` FROM `MsiPatchHeaders` WHERE `StreamRef` = ?
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: MsiDigitalSignature
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (50:68) [17:44:45:392]: Doing action: RegisterUser
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:45: InstallFiles. Return value 1.
Action start 17:44:45: RegisterUser.
MSI (s) (50:68) [17:44:45:392]: Doing action: RegisterProduct
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:45: RegisterUser. Return value 1.
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: Error
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1302
MSI (s) (50:68) [17:44:45:392]: Note: 1: 2205 2: 3: MsiDigitalSignature
Action start 17:44:45: RegisterProduct.
MSI (s) (50:68) [17:44:45:407]: PROPERTY CHANGE: Adding ProductToBeRegistered property. Its value is '1'.
MSI (s) (50:68) [17:44:45:407]: Doing action: PublishFeatures
MSI (s) (50:68) [17:44:45:407]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:45: RegisterProduct. Return value 1.
Action start 17:44:45: PublishFeatures.
MSI (s) (50:68) [17:44:45:407]: Doing action: PublishProduct
MSI (s) (50:68) [17:44:45:407]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:45: PublishFeatures. Return value 1.
MSI (s) (50:68) [17:44:45:407]: Note: 1: 2205 2: 3: Icon
MSI (s) (50:68) [17:44:45:407]: Note: 1: 2228 2: 3: Icon 4: SELECT `Name`, `Data` FROM `Icon`
Action start 17:44:45: PublishProduct.
MSI (s) (50:68) [17:44:45:407]: Doing action: InstallFinalize
MSI (s) (50:68) [17:44:45:407]: Note: 1: 2205 2: 3: ActionText
Action ended 17:44:45: PublishProduct. Return value 1.
MSI (s) (50:68) [17:44:45:407]: Running Script: C:\Windows\Installer\MSIEBAD.tmp
MSI (s) (50:68) [17:44:45:407]: PROPERTY CHANGE: Adding UpdateStarted property. Its value is '1'.
MSI (s) (50:68) [17:44:45:407]: Machine policy value 'DisableRollback' is 0
MSI (s) (50:68) [17:44:45:439]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (50:68) [17:44:45:439]: Executing op: Header(Signature=1397708873,Version=405,Timestamp=1132236183,LangId=1033,Platform=0,ScriptType=1,ScriptMajorVersion=21,ScriptMinorVersion=4,ScriptAttributes=1)
Action start 17:44:45: InstallFinalize.
MSI (s) (50:68) [17:44:45:439]: Executing op: ProductInfo(ProductKey={98EFF19A-30AB-4E4B-B943-F06B1C63EBF8},ProductName=Visual Studio 2012 x86 Redistributables,PackageName=vc_red.msi,Language=1033,Version=234881024,Assignment=1,ObsoleteArg=0,,,PackageCode={8D9DE39A-DFAA-4F2F-95C8-B6B0EFEF1F27},,,InstanceType=0,LUASetting=0,RemoteURTInstalls=0,ProductDeploymentFlags=3)
MSI (s) (50:68) [17:44:45:439]: Executing op: DialogInfo(Type=0,Argument=1033)
MSI (s) (50:68) [17:44:45:439]: Executing op: DialogInfo(Type=1,Argument=Visual Studio 2012 x86 Redistributables)
MSI (s) (50:68) [17:44:45:439]: Executing op: RollbackInfo(,RollbackAction=Rollback,RollbackDescription=Rolling back action:,RollbackTemplate=[1],CleanupAction=RollbackCleanup,CleanupDescription=Removing backup files,CleanupTemplate=File: [1])
MSI (s) (50:68) [17:44:45:439]: Executing op: SetBaseline(Baseline=0,)
MSI (s) (50:68) [17:44:45:439]: Executing op: SetBaseline(Baseline=1,)
MSI (s) (50:68) [17:44:45:439]: Executing op: ActionStart(Name=ProcessComponents,Description=Updating component registration,)
MSI (s) (50:68) [17:44:45:439]: Executing op: ProgressTotal(Total=9,Type=1,ByteEquivalent=24000)
MSI (s) (50:68) [17:44:45:439]: Executing op: ComponentRegister(ComponentId={DDE261C6-A53D-45E5-8EFB-3F300CB58E68},KeyPath=C:\Windows\SysWOW64\atl110.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (50:68) [17:44:45:439]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\atl110.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:439]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\atl110.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:439]: Executing op: ComponentRegister(ComponentId={F5CBD6DC-5C9C-430E-83A7-179BA49988CD},KeyPath=C:\Windows\SysWOW64\msvcr110.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (50:68) [17:44:45:454]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\msvcr110.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:454]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\msvcr110.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:454]: Executing op: ComponentRegister(ComponentId={0E7F74F7-0943-4AFE-AA5D-5DAE3B49A19F},KeyPath=C:\Windows\SysWOW64\msvcp110.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (50:68) [17:44:45:454]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\msvcp110.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:454]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\msvcp110.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:454]: Executing op: ComponentRegister(ComponentId={1981D1A7-C996-4E04-957B-58FB178962C6},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (50:68) [17:44:45:454]: Executing op: ComponentRegister(ComponentId={4EC905D9-BAE5-46F2-8C09-F2990D8C59C8},KeyPath=C:\Windows\SysWOW64\mfc110.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (50:68) [17:44:45:454]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\mfc110.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:454]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\mfc110.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:454]: Executing op: ComponentRegister(ComponentId={C11871C7-C4D6-4623-A78F-94BB58760BE5},KeyPath=C:\Windows\SysWOW64\mfc110u.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (50:68) [17:44:45:454]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\mfc110u.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:454]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\mfc110u.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:454]: Executing op: ComponentRegister(ComponentId={B8D7967A-2B5D-4B54-8EAB-F2629AC300A1},KeyPath=C:\Windows\SysWOW64\mfcm110.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (50:68) [17:44:45:454]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\mfcm110.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:454]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\mfcm110.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:454]: Executing op: ComponentRegister(ComponentId={43ADE158-0CFD-423D-A80C-0F430B2F9623},KeyPath=C:\Windows\SysWOW64\mfcm110u.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (50:68) [17:44:45:454]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\mfcm110u.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:454]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\mfcm110u.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:470]: Executing op: ComponentRegister(ComponentId={B7711DFE-D1DD-4998-AACD-A04E293E47E6},KeyPath=C:\Windows\SysWOW64\vcomp110.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (50:68) [17:44:45:470]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\vcomp110.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:470]: WIN64DUALFOLDERS: 'C:\Windows\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\vcomp110.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (50:68) [17:44:45:470]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0,)
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTick()
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (50:68) [17:44:45:470]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0,)
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTick()
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (50:68) [17:44:45:470]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0,)
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTick()
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (50:68) [17:44:45:470]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0,)
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTick()
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (50:68) [17:44:45:470]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0,)
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTick()
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (50:68) [17:44:45:470]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0,)
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTick()
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (50:68) [17:44:45:470]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0,)
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTick()
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (50:68) [17:44:45:470]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0,)
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTick()
MSI (s) (50:68) [17:44:45:470]: Executing op: ActionStart(Name=InstallFiles,Description=Copying new files,Template=File: [1], Directory: [9], Size: [6])
MSI (s) (50:68) [17:44:45:470]: Executing op: ProgressTotal(Total=10768528,Type=0,ByteEquivalent=1)
MSI (s) (50:68) [17:44:45:470]: Executing op: SetTargetFolder(Folder=C:\Windows\SysWOW64\)
MSI (s) (50:68) [17:44:45:470]: Executing op: SetSourceFolder(Folder=1\Win\System\)
MSI (s) (50:68) [17:44:45:470]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,MediaCabinet=1\vc_red.cab,BytesPerTick=32768,CopierType=1,,,SignatureRequired=0,,,IsFirstPhysicalMedia=1)
MSI (s) (50:68) [17:44:45:470]: Executing op: FileCopy(SourceName=atl110.dll,SourceCabKey=F_CENTRAL_atl110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1,DestName=atl110.dll,Attributes=512,FileSize=168920,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,Version=11.0.51106.1,Language=1033,InstallMode=58982400,,,,,,,)
MSI (s) (50:68) [17:44:45:470]: File: C:\Windows\SysWOW64\atl110.dll; To be installed; Won't patch; No existing file
MSI (s) (50:68) [17:44:45:470]: Source for file 'F_CENTRAL_atl110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1' is compressed
MSI (s) (50:68) [17:44:45:470]: Note: 1: 2318 2: C:\Windows\SysWOW64\atl110.dll
MSI (s) (50:68) [17:44:45:470]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:470]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:470]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:470]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:470]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:470]: Executing op: FileCopy(SourceName=mfc110.dll,SourceCabKey=F_CENTRAL_mfc110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1,DestName=mfc110.dll,Attributes=512,FileSize=4421080,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,Version=11.0.51106.1,Language=1033,InstallMode=58982400,,,,,,,)
MSI (s) (50:68) [17:44:45:470]: File: C:\Windows\SysWOW64\mfc110.dll; To be installed; Won't patch; No existing file
MSI (s) (50:68) [17:44:45:470]: Source for file 'F_CENTRAL_mfc110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1' is compressed
MSI (s) (50:68) [17:44:45:470]: Note: 1: 2318 2: C:\Windows\SysWOW64\mfc110.dll
MSI (s) (50:68) [17:44:45:470]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:470]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:470]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:470]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:485]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:501]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Executing op: FileCopy(SourceName=mfc110u.dll,SourceCabKey=F_CENTRAL_mfc110u_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1,DestName=mfc110u.dll,Attributes=512,FileSize=4456904,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,Version=11.0.51106.1,Language=1033,InstallMode=58982400,,,,,,,)
MSI (s) (50:68) [17:44:45:517]: File: C:\Windows\SysWOW64\mfc110u.dll; To be installed; Won't patch; No existing file
MSI (s) (50:68) [17:44:45:517]: Source for file 'F_CENTRAL_mfc110u_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1' is compressed
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2318 2: C:\Windows\SysWOW64\mfc110u.dll
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:517]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:532]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Executing op: FileCopy(SourceName=mfcm110.dll,SourceCabKey=F_CENTRAL_mfcm110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1,DestName=mfcm110.dll,Attributes=512,FileSize=92616,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,Version=11.0.51106.1,Language=1033,InstallMode=58982400,,,,,,,)
MSI (s) (50:68) [17:44:45:548]: File: C:\Windows\SysWOW64\mfcm110.dll; To be installed; Won't patch; No existing file
MSI (s) (50:68) [17:44:45:548]: Source for file 'F_CENTRAL_mfcm110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1' is compressed
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2318 2: C:\Windows\SysWOW64\mfcm110.dll
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Executing op: FileCopy(SourceName=mfcm110u.dll,SourceCabKey=F_CENTRAL_mfcm110u_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1,DestName=mfcm110u.dll,Attributes=512,FileSize=92624,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,Version=11.0.51106.1,Language=1033,InstallMode=58982400,,,,,,,)
MSI (s) (50:68) [17:44:45:548]: File: C:\Windows\SysWOW64\mfcm110u.dll; To be installed; Won't patch; No existing file
MSI (s) (50:68) [17:44:45:548]: Source for file 'F_CENTRAL_mfcm110u_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1' is compressed
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2318 2: C:\Windows\SysWOW64\mfcm110u.dll
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:548]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Executing op: FileCopy(SourceName=msvcp110.dll,SourceCabKey=F_CENTRAL_msvcp110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1,DestName=msvcp110.dll,Attributes=512,FileSize=535008,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,Version=11.0.51106.1,Language=1033,InstallMode=58982400,,,,,,,)
MSI (s) (50:68) [17:44:45:563]: File: C:\Windows\SysWOW64\msvcp110.dll; To be installed; Won't patch; No existing file
MSI (s) (50:68) [17:44:45:563]: Source for file 'F_CENTRAL_msvcp110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1' is compressed
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2318 2: C:\Windows\SysWOW64\msvcp110.dll
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Executing op: FileCopy(SourceName=msvcr110.dll,SourceCabKey=F_CENTRAL_msvcr110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1,DestName=msvcr110.dll,Attributes=512,FileSize=875472,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,Version=11.0.51106.1,Language=1033,InstallMode=58982400,,,,,,,)
MSI (s) (50:68) [17:44:45:563]: File: C:\Windows\SysWOW64\msvcr110.dll; To be installed; Won't patch; No existing file
MSI (s) (50:68) [17:44:45:563]: Source for file 'F_CENTRAL_msvcr110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1' is compressed
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2318 2: C:\Windows\SysWOW64\msvcr110.dll
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:563]: Executing op: FileCopy(SourceName=vcomp110.dll,SourceCabKey=F_CENTRAL_vcomp110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1,DestName=vcomp110.dll,Attributes=512,FileSize=125904,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,Version=11.0.51106.1,Language=1033,InstallMode=58982400,,,,,,,)
MSI (s) (50:68) [17:44:45:563]: File: C:\Windows\SysWOW64\vcomp110.dll; To be installed; Won't patch; No existing file
MSI (s) (50:68) [17:44:45:563]: Source for file 'F_CENTRAL_vcomp110_x86.D371D00B_69EC_3F8E_A622_74710A89ADC1' is compressed
MSI (s) (50:68) [17:44:45:563]: Note: 1: 2318 2: C:\Windows\SysWOW64\vcomp110.dll
MSI (s) (50:68) [17:44:45:579]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:579]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:579]: Note: 1: 2360
MSI (s) (50:68) [17:44:45:579]: Executing op: CacheSizeFlush(,)
MSI (s) (50:68) [17:44:45:579]: Executing op: ActionStart(Name=RegisterProduct,Description=Registering product,Template=[1])
MSI (s) (50:68) [17:44:45:579]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,MediaCabinet=1\vc_red.cab,BytesPerTick=0,CopierType=1,,,SignatureRequired=0,,,IsFirstPhysicalMedia=1)
MSI (s) (50:68) [17:44:45:579]: Executing op: DatabaseCopy(DatabasePath=C:\Windows\Installer\48ae7a7.msi,ProductCode={98EFF19A-30AB-4E4B-B943-F06B1C63EBF8},,,)
MSI (s) (50:68) [17:44:45:579]: Note: 1: 1402 2: UNKNOWN\Products\A91FFE89BA03B4E49B340FB6C136BE8F\InstallProperties 3: 2
MSI (s) (50:68) [17:44:45:751]: Executing op: ProductRegister(UpgradeCode={3960B201-E810-438B-A8E7-09E05F0F83AC},VersionString=14.0.0.1,,,,InstallSource=C:\ProgramData\MFAData\pack\,Publisher=AVG Technologies CZ, s.r.o.,,,,,,,,,,,,EstimatedSize=10512,)
MSI (s) (50:68) [17:44:46:187]: Executing op: ProductCPDisplayInfoRegister()
MSI (s) (50:68) [17:44:46:203]: Executing op: ActionStart(Name=PublishFeatures,Description=Publishing Product Features,Template=Feature: [1])
MSI (s) (50:68) [17:44:46:203]: Executing op: FeaturePublish(Feature=VCRedist32,,Absent=2,Component=gs^Bp2GSO=xN.S32QI[IHys~wsGuV9[~ypYhly'kx[(a'i.e+@8EN&aCpvA[85o4++dH)A46QkyGk`ihucCCAW17m=Jb]PY5ODIi741(g(s.V=ZHQ@e999]ru&cJdPLu5@cY0mG!!Lh[SCwh9]jW@9*]{V9r}3M.nNLzcewY`?6s%?Ai[y!s)
MSI (s) (50:68) [17:44:46:203]: Executing op: ActionStart(Name=PublishProduct,Description=Publishing product information,)
MSI (s) (50:68) [17:44:46:203]: Executing op: CleanupConfigData()
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A91FFE89BA03B4E49B340FB6C136BE8F\Patches 3: 2
MSI (s) (50:68) [17:44:46:203]: Executing op: RegisterPatchOrder(Continue=0,SequenceType=1,Remove=0)
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: UNKNOWN\Products\A91FFE89BA03B4E49B340FB6C136BE8F\Patches 3: 2
MSI (s) (50:68) [17:44:46:203]: Executing op: ProductPublish(PackageKey={8D9DE39A-DFAA-4F2F-95C8-B6B0EFEF1F27})
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: UNKNOWN\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F 3: 2
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: UNKNOWN\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F 3: 2
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: UNKNOWN\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F 3: 2
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: UNKNOWN\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F 3: 2
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: UNKNOWN\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F 3: 2
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: UNKNOWN\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F 3: 2
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: UNKNOWN\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F 3: 2
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: UNKNOWN\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F 3: 2
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: UNKNOWN\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F 3: 2
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: UNKNOWN\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F 3: 2
MSI (s) (50:68) [17:44:46:203]: Note: 1: 1402 2: UNKNOWN\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F 3: 2
MSI (s) (50:68) [17:44:46:219]: Executing op: UpgradeCodePublish(UpgradeCode={3960B201-E810-438B-A8E7-09E05F0F83AC})
MSI (s) (50:68) [17:44:46:219]: Executing op: SourceListPublish(,,,,NumberOfDisks=1)
MSI (s) (50:68) [17:44:46:219]: Note: 1: 1402 2: UNKNOWN\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F\SourceList 3: 2
MSI (s) (50:68) [17:44:46:219]: Executing op: ProductPublishClient(,,)
MSI (s) (50:68) [17:44:46:219]: Executing op: SourceListRegisterLastUsed(SourceProduct={98EFF19A-30AB-4E4B-B943-F06B1C63EBF8},LastUsedSource=C:\ProgramData\MFAData\pack\)
MSI (s) (50:68) [17:44:46:219]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (50:68) [17:44:46:219]: Specifed source is already in a list.
MSI (s) (50:68) [17:44:46:219]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (50:68) [17:44:46:219]: Machine policy value 'DisableBrowse' is 0
MSI (s) (50:68) [17:44:46:219]: Machine policy value 'AllowLockdownBrowse' is 0
MSI (s) (50:68) [17:44:46:219]: Adding new sources is allowed.
MSI (s) (50:68) [17:44:46:219]: Set LastUsedSource to: C:\ProgramData\MFAData\pack\.
MSI (s) (50:68) [17:44:46:219]: Set LastUsedType to: n.
MSI (s) (50:68) [17:44:46:219]: Set LastUsedIndex to: 1.
MSI (s) (50:68) [17:44:46:234]: Executing op: End(Checksum=0,ProgressTotalHDWord=0,ProgressTotalLDWord=11090128)
MSI (s) (50:68) [17:44:46:234]: User policy value 'DisableRollback' is 0
MSI (s) (50:68) [17:44:46:234]: Machine policy value 'DisableRollback' is 0
MSI (s) (50:68) [17:44:46:234]: No System Restore sequence number for this installation.
MSI (s) (50:68) [17:44:46:234]: Unlocking Server
MSI (s) (50:68) [17:44:46:281]: PROPERTY CHANGE: Deleting UpdateStarted property. Its current value is '1'.
Action ended 17:44:46: InstallFinalize. Return value 1.
Action ended 17:44:46: INSTALL. Return value 1.
MSI (s) (50:68) [17:44:46:281]: Note: 1: 1707
MSI (s) (50:68) [17:44:46:281]: Note: 1: 2205 2: 3: Error
MSI (s) (50:68) [17:44:46:281]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1707
MSI (s) (50:68) [17:44:46:281]: Note: 1: 2205 2: 3: Error
MSI (s) (50:68) [17:44:46:281]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1709
MSI (s) (50:68) [17:44:46:281]: Product: Visual Studio 2012 x86 Redistributables -- Installation completed successfully.

MSI (s) (50:68) [17:44:46:281]: Windows Installer installed the product. Product Name: Visual Studio 2012 x86 Redistributables. Product Version: 14.0.0.1. Product Language: 1033. Installation success or error status: 0.

MSI (s) (50:68) [17:44:46:281]: Deferring clean up of packages/files, if any exist
MSI (s) (50:68) [17:44:46:281]: MainEngineThread is returning 0
MSI (s) (50:BC) [17:44:46:281]: RESTART MANAGER: Session closed.
MSI (s) (50:BC) [17:44:46:281]: No System Restore sequence number for this installation.
=== Logging stopped: 11/28/2013 17:44:46 ===
MSI (s) (50:BC) [17:44:46:281]: User policy value 'DisableRollback' is 0
MSI (s) (50:BC) [17:44:46:281]: Machine policy value 'DisableRollback' is 0
MSI (s) (50:BC) [17:44:46:281]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (50:BC) [17:44:46:281]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (50:BC) [17:44:46:281]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (50:BC) [17:44:46:281]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1
MSI (s) (50:BC) [17:44:46:281]: Restoring environment variables
MSI (c) (A4:48) [17:44:46:281]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1
MSI (c) (A4:48) [17:44:46:281]: MainEngineThread is returning 0
=== Verbose logging stopped: 11/28/2013 17:44:46 ===

Permissions in this forum:
You cannot reply to topics in this forum