|
Plagegeister aller Art und deren Bekämpfung: Bundeskriminalamt TrojanerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
11.09.2014, 08:32 | #46 |
/// TB-Ausbilder | Bundeskriminalamt Trojaner Starte noch einmal FRST.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
11.09.2014, 16:43 | #47 |
| Bundeskriminalamt Trojaner Frist.txt
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 07-09-2014 Ran by user (administrator) on USER-PC on 11-09-2014 17:37:41 Running from C:\Users\user\Desktop\Trojanercheck Platform: Microsoft Windows 7 Home Premium (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (SEC) C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe () C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Program Files\Samsung\Samsung Update Plus\SUPNotifier.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_12_0_0_70_ActiveX.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7711264 2009-08-19] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1541416 2009-07-15] (Synaptics Incorporated) HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems Incorporated) HKLM\...\Run: [UCam_Menu] => C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-14] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [164656 2014-08-27] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-771618654-3341757510-301361698-1000\...\MountPoints2: {7059c972-c02c-11de-a172-806e6f6e6963} - E:\setup\rsrc\Autorun.exe Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN SearchScopes: HKCU - DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\3.0.40624.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.3 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: PDF Architect 2 -> C:\Program Files\PDF Architect 2\np-previewer.dll (pdfforge GmbH) Chrome: ======= ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-08-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-14] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1021520 2014-08-14] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [160048 2014-08-27] (Avira Operations GmbH & Co. KG) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45272 2005-10-14] (Microsoft Corporation) R2 OberonGameConsoleService; C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe [44312 2009-08-13] () S3 PDF Architect 2; C:\Program Files\PDF Architect 2\ws.exe [1771560 2014-06-26] (pdfforge GmbH) S3 pdfforge CrashHandler; C:\Program Files\PDF Architect 2\crash-handler-ws.exe [861736 2014-06-26] (pdfforge GmbH) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\windows\System32\DRIVERS\avgntflt.sys [97648 2014-07-04] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\windows\System32\DRIVERS\avipbb.sys [136216 2014-06-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-09] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\windows\System32\DRIVERS\avnetflt.sys [35848 2014-07-24] (Avira Operations GmbH & Co. KG) R1 ssmdrv; C:\windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-09] (Avira GmbH) S3 cleanhlp; \??\C:\EEK\bin\cleanhlp32.sys [X] S3 MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-10 21:03 - 2014-09-10 21:03 - 00000743 _____ () C:\Users\user\Desktop\Start Emsisoft Emergency Kit.lnk 2014-09-10 15:45 - 2014-09-05 03:42 - 00444416 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-09-10 15:45 - 2014-09-05 03:38 - 00303104 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-09-08 17:14 - 2014-09-08 17:14 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-09-07 14:27 - 2014-09-07 14:29 - 00005639 _____ () C:\Users\user\Desktop\Rote Grütze.txt 2014-09-07 12:58 - 2014-09-11 17:37 - 00000000 ____D () C:\FRST 2014-09-06 08:42 - 2014-09-06 08:42 - 00000689 _____ () C:\Users\user\Desktop\updatefix.bat 2014-09-05 13:48 - 2014-09-05 13:50 - 00000000 ____D () C:\windows\SoftwareDistribution.old 2014-09-05 12:55 - 2014-09-05 12:55 - 00000207 _____ () C:\windows\tweaking.com-regbackup-USER-PC-Microsoft-Windows-7-Home-Premium-(32-bit).dat 2014-09-05 12:55 - 2014-09-05 12:55 - 00000000 ____D () C:\RegBackup 2014-09-05 12:20 - 2014-09-05 12:20 - 07489465 _____ () C:\Users\user\Downloads\tweaking.com_windows_repair_aio[1].zip 2014-09-05 09:04 - 2014-09-05 09:05 - 231030439 _____ () C:\Users\user\Downloads\Windows6.1-KB947821-v33-x86 (2).msu 2014-09-04 21:29 - 2014-09-04 21:30 - 00000720 _____ () C:\DelFix.txt 2014-09-04 21:28 - 2014-09-04 21:28 - 00000000 _____ () C:\Users\user\Desktop\Neues Textdokument.txt 2014-09-04 20:55 - 2014-09-04 20:58 - 563934504 _____ (Microsoft Corporation) C:\Users\user\Downloads\windows6.1-KB976932-X86.exe 2014-09-04 20:21 - 2014-09-04 20:23 - 231030439 _____ () C:\Users\user\Downloads\Windows6.1-KB947821-v33-x86 (1).msu 2014-09-04 20:17 - 2014-09-04 20:17 - 00002278 _____ () C:\Users\user\AppData\Local\recently-used.xbel 2014-09-04 19:28 - 2014-09-04 19:28 - 00000000 ____D () C:\windows\system32\EventProviders 2014-09-04 17:57 - 2014-09-04 17:57 - 00000000 ____D () C:\windows\CheckSur 2014-09-04 17:53 - 2014-09-04 17:54 - 231030439 _____ () C:\Users\user\Downloads\Windows6.1-KB947821-v33-x86.msu 2014-09-03 17:12 - 2014-09-03 17:12 - 00000000 ____D () C:\Program Files\ESET 2014-09-03 11:49 - 2014-09-03 11:49 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-09-03 11:43 - 2014-09-04 21:29 - 00000000 ____D () C:\windows\ERUNT 2014-09-02 19:27 - 2014-09-11 17:37 - 00000000 ____D () C:\Users\user\Desktop\Trojanercheck 2014-09-02 16:15 - 2014-09-02 16:15 - 00000000 ____D () C:\windows\pss 2014-09-02 13:41 - 2014-09-02 13:41 - 00000000 ____D () C:\windows\PIF 2014-08-26 19:41 - 2014-08-26 19:41 - 00000000 ____D () C:\ProgramData\Arcade Lab 2014-08-15 10:16 - 2014-09-08 17:14 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-14 18:09 - 2014-08-14 18:09 - 00000000 ____D () C:\Users\user\Documents\PDF Architect 2 2014-08-14 18:09 - 2014-08-14 18:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2 2014-08-14 18:09 - 2014-08-14 18:09 - 00000000 ____D () C:\Program Files\PDF Architect 2 2014-08-14 18:08 - 2014-08-14 18:10 - 00000000 ____D () C:\Program Files\PDFCreator 2014-08-14 18:08 - 2014-08-14 18:08 - 00000000 ____D () C:\ProgramData\PDF Architect 2 2014-08-14 18:08 - 2014-08-14 18:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator 2014-08-14 18:08 - 2014-04-25 17:44 - 00662288 _____ (Microsoft Corporation) C:\windows\system32\MSCOMCT2.OCX 2014-08-14 18:08 - 2014-04-25 17:44 - 00137000 _____ (Microsoft Corporation) C:\windows\system32\MSMAPI32.OCX 2014-08-14 18:08 - 2014-04-25 17:44 - 00095416 _____ (pdfforge GmbH) C:\windows\system32\pdfcmon.dll 2014-08-14 18:08 - 2014-04-25 17:44 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\MSMPIDE.DLL 2014-08-14 18:08 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\windows\system32\VB6DE.DLL 2014-08-14 18:08 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\windows\system32\MSCMCDE.DLL 2014-08-14 18:08 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\windows\system32\MSCC2DE.DLL 2014-08-13 17:06 - 2014-08-13 17:06 - 00000000 ___RD () C:\Users\user\AppData\Roaming\Brother ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-11 17:37 - 2014-09-07 12:58 - 00000000 ____D () C:\FRST 2014-09-11 17:37 - 2014-09-02 19:27 - 00000000 ____D () C:\Users\user\Desktop\Trojanercheck 2014-09-11 17:27 - 2009-07-14 06:34 - 00020400 _____ () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-11 17:27 - 2009-07-14 06:34 - 00020400 _____ () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-11 17:14 - 2009-09-22 07:23 - 01319823 _____ () C:\windows\WindowsUpdate.log 2014-09-11 17:14 - 2009-07-26 22:06 - 01759924 _____ () C:\windows\system32\PerfStringBackup.INI 2014-09-11 17:09 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-09-11 17:09 - 2009-07-14 06:39 - 00061967 _____ () C:\windows\setupact.log 2014-09-10 21:03 - 2014-09-10 21:03 - 00000743 _____ () C:\Users\user\Desktop\Start Emsisoft Emergency Kit.lnk 2014-09-10 20:55 - 2014-06-25 20:55 - 00000000 ____D () C:\windows\system32\MRT 2014-09-10 20:52 - 2014-06-25 20:55 - 98758480 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-09-10 17:16 - 2009-09-22 07:48 - 00750666 _____ () C:\windows\PFRO.log 2014-09-10 16:19 - 2014-07-09 19:05 - 00000000 ___SD () C:\windows\system32\CompatTel 2014-09-08 17:14 - 2014-09-08 17:14 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-09-08 17:14 - 2014-08-15 10:16 - 00000000 ____D () C:\ProgramData\Package Cache 2014-09-08 17:14 - 2014-01-05 15:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-09-08 17:14 - 2014-01-05 15:07 - 00000000 ____D () C:\Program Files\Avira 2014-09-07 14:29 - 2014-09-07 14:27 - 00005639 _____ () C:\Users\user\Desktop\Rote Grütze.txt 2014-09-06 08:42 - 2014-09-06 08:42 - 00000689 _____ () C:\Users\user\Desktop\updatefix.bat 2014-09-05 13:50 - 2014-09-05 13:48 - 00000000 ____D () C:\windows\SoftwareDistribution.old 2014-09-05 13:48 - 2009-12-05 20:11 - 00109280 _____ () C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT 2014-09-05 13:44 - 2009-07-14 06:33 - 00412776 _____ () C:\windows\system32\FNTCACHE.DAT 2014-09-05 12:55 - 2014-09-05 12:55 - 00000207 _____ () C:\windows\tweaking.com-regbackup-USER-PC-Microsoft-Windows-7-Home-Premium-(32-bit).dat 2014-09-05 12:55 - 2014-09-05 12:55 - 00000000 ____D () C:\RegBackup 2014-09-05 12:20 - 2014-09-05 12:20 - 07489465 _____ () C:\Users\user\Downloads\tweaking.com_windows_repair_aio[1].zip 2014-09-05 09:05 - 2014-09-05 09:04 - 231030439 _____ () C:\Users\user\Downloads\Windows6.1-KB947821-v33-x86 (2).msu 2014-09-05 03:42 - 2014-09-10 15:45 - 00444416 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-09-05 03:38 - 2014-09-10 15:45 - 00303104 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-09-04 21:30 - 2014-09-04 21:29 - 00000720 _____ () C:\DelFix.txt 2014-09-04 21:29 - 2014-09-03 11:43 - 00000000 ____D () C:\windows\ERUNT 2014-09-04 21:28 - 2014-09-04 21:28 - 00000000 _____ () C:\Users\user\Desktop\Neues Textdokument.txt 2014-09-04 20:58 - 2014-09-04 20:55 - 563934504 _____ (Microsoft Corporation) C:\Users\user\Downloads\windows6.1-KB976932-X86.exe 2014-09-04 20:23 - 2014-09-04 20:21 - 231030439 _____ () C:\Users\user\Downloads\Windows6.1-KB947821-v33-x86 (1).msu 2014-09-04 20:17 - 2014-09-04 20:17 - 00002278 _____ () C:\Users\user\AppData\Local\recently-used.xbel 2014-09-04 19:28 - 2014-09-04 19:28 - 00000000 ____D () C:\windows\system32\EventProviders 2014-09-04 17:57 - 2014-09-04 17:57 - 00000000 ____D () C:\windows\CheckSur 2014-09-04 17:54 - 2014-09-04 17:53 - 231030439 _____ () C:\Users\user\Downloads\Windows6.1-KB947821-v33-x86.msu 2014-09-03 17:12 - 2014-09-03 17:12 - 00000000 ____D () C:\Program Files\ESET 2014-09-03 12:05 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\twain_32 2014-09-03 11:49 - 2014-09-03 11:49 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-09-02 17:16 - 2014-01-14 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Purplehills 2014-09-02 16:15 - 2014-09-02 16:15 - 00000000 ____D () C:\windows\pss 2014-09-02 13:41 - 2014-09-02 13:41 - 00000000 ____D () C:\windows\PIF 2014-09-01 12:36 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\NDF 2014-08-29 19:46 - 2014-01-14 10:56 - 00000000 ____D () C:\Users\user\Documents\2014 2014-08-26 19:41 - 2014-08-26 19:41 - 00000000 ____D () C:\ProgramData\Arcade Lab 2014-08-23 16:14 - 2014-02-04 21:59 - 00000000 ____D () C:\Users\user\Documents\gothic3 2014-08-15 10:16 - 2014-01-05 15:07 - 00000000 ____D () C:\ProgramData\Avira 2014-08-14 18:10 - 2014-08-14 18:08 - 00000000 ____D () C:\Program Files\PDFCreator 2014-08-14 18:09 - 2014-08-14 18:09 - 00000000 ____D () C:\Users\user\Documents\PDF Architect 2 2014-08-14 18:09 - 2014-08-14 18:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2 2014-08-14 18:09 - 2014-08-14 18:09 - 00000000 ____D () C:\Program Files\PDF Architect 2 2014-08-14 18:08 - 2014-08-14 18:08 - 00000000 ____D () C:\ProgramData\PDF Architect 2 2014-08-14 18:08 - 2014-08-14 18:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator 2014-08-13 17:07 - 2014-01-21 09:23 - 00000432 _____ () C:\windows\BRWMARK.INI 2014-08-13 17:06 - 2014-08-13 17:06 - 00000000 ___RD () C:\Users\user\AppData\Roaming\Brother Some content of TEMP: ==================== C:\Users\user\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\windows\explorer.exe => File is digitally signed C:\windows\system32\winlogon.exe => File is digitally signed C:\windows\system32\wininit.exe => File is digitally signed C:\windows\system32\svchost.exe => File is digitally signed C:\windows\system32\services.exe => File is digitally signed C:\windows\system32\User32.dll => File is digitally signed C:\windows\system32\userinit.exe => File is digitally signed C:\windows\system32\rpcss.dll => File is digitally signed C:\windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-09-06 09:38 ==================== End Of Log ============================ Shortcut.txt Code:
ATTFilter Users shortcut scan result (x86) Version: 07-09-2014 Ran by user at 2014-09-11 17:38:13 Running from C:\Users\user\Desktop\Trojanercheck Boot Mode: Normal ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk -> C:\Windows\Installer\{AC76BA86-7AD7-1031-7B44-A91000000001}\SC_Reader.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk -> C:\Windows\ehome\ehshell.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk -> C:\Windows\System32\WindowsAnytimeUpgradeUI.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk -> C:\Program Files\DVD Maker\DVDMaker.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live\Windows Live Call.lnk -> C:\Program Files\Windows Live\Messenger\wlcstart.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live\Windows Live Family Safety.lnk -> C:\Windows\Installer\{994223F3-A99B-4DDD-9E1D-0190A17C6860}\fssicon.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live\Windows Live Fotogalerie.lnk -> C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live\Windows Live Mail.lnk -> C:\Program Files\Windows Live\Mail\wlmail.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live\Windows Live Messenger .lnk -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live\Windows Live Movie Maker.lnk -> C:\Program Files\Windows Live\Photo Gallery\MovieMaker.Exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live\Windows Live Writer.lnk -> C:\Program Files\Windows Live\Writer\WindowsLiveWriter.exe (Microsoft Corp.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Casual Games\Game Pack.lnk -> C:\Program Files\Samsung Casual Games\GameConsole\GamePack.exe (Oberon Media) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Casual Games\Go-Go Gourmet\Go-Go Gourmet.lnk -> C:\Program Files\Samsung Casual Games\Go-Go Gourmet\Launch.exe (Oberon Media Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Casual Games\Go-Go Gourmet\Uninstall.lnk -> C:\Program Files\Samsung Casual Games\Go-Go Gourmet\Uninstall.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Casual Games\Farm Frenzy 2\Farm Frenzy 2.lnk -> C:\Program Files\Samsung Casual Games\Farm Frenzy 2\Launch.exe (Oberon Media Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Casual Games\Farm Frenzy 2\Uninstall.lnk -> C:\Program Files\Samsung Casual Games\Farm Frenzy 2\Uninstall.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Casual Games\Elf Bowling Hawaiian Vacation\Elf Bowling Hawaiian Vacation.lnk -> C:\Program Files\Samsung Casual Games\Elf Bowling Hawaiian Vacation\Launch.exe (Oberon Media Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Casual Games\Elf Bowling Hawaiian Vacation\Uninstall.lnk -> C:\Program Files\Samsung Casual Games\Elf Bowling Hawaiian Vacation\Uninstall.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Casual Games\Dairy Dash\Dairy Dash.lnk -> C:\Program Files\Samsung Casual Games\Dairy Dash\Launch.exe (Oberon Media Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Casual Games\Dairy Dash\Uninstall.lnk -> C:\Program Files\Samsung Casual Games\Dairy Dash\Uninstall.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Casual Games\Alice Greenfingers\Alice Greenfingers.lnk -> C:\Program Files\Samsung Casual Games\Alice Greenfingers\Launch.exe (Oberon Media Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Casual Games\Alice Greenfingers\Uninstall.lnk -> C:\Program Files\Samsung Casual Games\Alice Greenfingers\Uninstall.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\User Guide\User Guide.lnk -> C:\Program Files\Samsung\SamsungManual\RunManual.exe (Samsung Electronics) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Samsung Update Plus\Samsung Update Plus Help.lnk -> C:\Program Files\Samsung\Samsung Update Plus\SUPHelp.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Samsung Update Plus\Samsung Update Plus.lnk -> C:\Program Files\Samsung\Samsung Update Plus\SupClientApp.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Samsung Support Center\Samsung Support Center.lnk -> C:\Program Files\Samsung\Samsung Support Center\SSCMain.exe (SAMSUNG Electronics) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Samsung Recovery Solution 4\Samsung Recovery Solution 4.lnk -> C:\Program Files\Samsung\Samsung Recovery Solution 4\Manager1.exe (SEC) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Easy Network Manager\Easy Network Manager Help.lnk -> C:\Program Files\Samsung\Easy Network Manager\HelpLaunch.exe (Samsung Electronics) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Easy Network Manager\Easy Network Manager.lnk -> C:\Program Files\Samsung\Easy Network Manager\ENM.exe (Samsung Electronics Co. Ltd) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Easy Display Manager\Easy Display Manager Option.lnk -> C:\Program Files\Samsung\Easy Display Manager\HotKeyOption.exe (Samsung Electronics Co., Ltd.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Easy Display Manager\Easy Display Manager.lnk -> C:\Program Files\Samsung\Easy Display Manager\DMLauncher_Vista.exe (SAMSUNG Electronics) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Battery Life Extender\BatteryLifeExtender.lnk -> C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe (Samsung Electronics. Co. Ltd.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Historie.lnk -> C:\Program Files\PDFCreator\History.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\PDFCreator Hilfe.lnk -> C:\Program Files\PDFCreator\PDFCreator_german.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\PDFCreator im Internet.lnk -> C:\Program Files\PDFCreator\PDFCreator.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\PDFCreator.lnk -> C:\Program Files\PDFCreator\PDFCreator.exe (pdfforge GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Translation Tool.lnk -> C:\Program Files\PDFCreator\languages\TransTool.exe (pdfforge hxxp://www.pdfforge.org/) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Unterstütze PDFCreator.lnk -> C:\Program Files\PDFCreator\Unterstütze PDFCreator.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Licenses\AFPL License.lnk -> C:\Program Files\PDFCreator\AFPL License.txt (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Licenses\FairPlay License.lnk -> C:\Program Files\PDFCreator\FairPlay License.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Licenses\GPL License.lnk -> C:\Program Files\PDFCreator\GNU License.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Images2PDF\Images2PDF.lnk -> C:\Program Files\PDFCreator\Images2PDF\Images2PDF.exe (pdfforge GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2\PDF Architect 2.lnk -> C:\Program Files\PDF Architect 2\PDF Architect 2.exe (pdfforge GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mount&Blade\Mount&Blade.lnk -> D:\Spiele\Mount&Blade\mount&blade.exe ( Taleworlds Entertainment) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mount&Blade\Uninstall.lnk -> D:\Spiele\Mount&Blade\uninstall.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2005\Konfigurationstools\Fehler- und Verwendungsberichterstellung von SQL Server.lnk -> C:\Program Files\Microsoft SQL Server\90\Shared\SqlWtsn.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2005\Konfigurationstools\SQL Server-Oberflächenkonfiguration.lnk -> C:\Program Files\Microsoft SQL Server\90\Shared\SqlSAC.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office - 60 Day Trial.lnk -> C:\Program Files\Microsoft Office Suite Activation Assistant\OAA.exe (Digital River Inc. ) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Access 2007.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\accicons.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Excel 2007.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\xlicons.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Groove 2007.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\GrooveIcon.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office InfoPath 2007.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\inficon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office OneNote 2007.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\joticon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Outlook 2007.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\outicon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office PowerPoint 2007.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pptico.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pubs.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Word 2007.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\wordicon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Digitales Zertifikat für VBA-Projekte.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Clip Organizer.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\cagicon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2007 Spracheinstellungen.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Picture Manager.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\oisicon.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office-Diagnose.lnk -> C:\Windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk -> C:\Windows\System32\recdisc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk -> C:\Windows\System32\msra.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrampsAIO 4.0.3\GrampsAIO 4.0.3-console.lnk -> C:\Program Files\GrampsAIO-4.0.3\bin\gramps.exe (www.gramps-project.org) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrampsAIO 4.0.3\GrampsAIO 4.0.3-debug.lnk -> C:\Program Files\GrampsAIO-4.0.3\bin\grampsd.exe (www.gramps-project.org) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrampsAIO 4.0.3\GrampsAIO 4.0.3.lnk -> C:\Program Files\GrampsAIO-4.0.3\bin\grampsw.exe (www.gramps-project.org) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic III\Deep Silver Webseite.lnk -> C:\Program Files\Gothic III\copublisher.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic III\Gothic III deinstallieren.lnk -> C:\Program Files\InstallShield Installation Information\{02B244A2-7F6A-42E8-A36F-8C385D7A1625}\setup.exe (InstallShield Software Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic III\Gothic III liesmich.lnk -> C:\Program Files\Gothic III\Readme.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic III\Gothic III online registrieren.lnk -> C:\Program Files\Gothic III\register.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic III\Gothic III starten.lnk -> C:\Program Files\Gothic III\Gothic3.exe (Pluto 13 GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic III\Gothic III Webseite.lnk -> C:\Program Files\Gothic III\site.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic III\JoWooD Productions Webseite.lnk -> C:\Program Files\Gothic III\publisher.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cadvilla professional 4\cadvilla professional 4.lnk -> C:\Program Files\cadvilla professional 4\Program\CACAD.exe (Creative Amadeo GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cadvilla professional 4\cadvilla Tutorials.lnk -> C:\Program Files\cadvilla professional 4\tutorial.exe (mirabyte GmbH & Co. KG) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cadvilla professional 4\Hilfe\cadvilla professional 4.lnk -> C:\Program Files\cadvilla professional 4\Program\cadvilla.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cadvilla professional 4\Handbücher\Handbuch 3D-Konverter.lnk -> C:\Program Files\cadvilla professional 4\Manuals\3DKonverter.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cadvilla professional 4\Handbücher\Handbuch cadvilla professional 4.lnk -> C:\Program Files\cadvilla professional 4\Manuals\manual.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cadvilla professional 4\Handbücher\Handbuch DXF-Import.lnk -> C:\Program Files\cadvilla professional 4\Manuals\DXFImport.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cadvilla professional 4\Handbücher\Handbuch Fensterkonstruktion.lnk -> C:\Program Files\cadvilla professional 4\Manuals\OpeningConstruction.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cadvilla professional 4\Handbücher\Handbuch Massenermittlung.lnk -> C:\Program Files\cadvilla professional 4\Manuals\Quantities.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cadvilla professional 4\Handbücher\Handbuch Planzusammenstellung.lnk -> C:\Program Files\cadvilla professional 4\Manuals\Planzusammenstellung.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cadvilla professional 4\Handbücher\Tastaturbelegung.lnk -> C:\Program Files\cadvilla professional 4\Manuals\ShortCuts.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Avira Free Antivirus Hilfe.lnk -> C:\Program Files\Avira\AntiVir Desktop\avwin.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Avira Free Antivirus starten.lnk -> C:\Program Files\Avira\AntiVir Desktop\avcenter.exe (Avira Operations GmbH & Co. KG) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Avira im Internet.lnk -> C:\Program Files\Avira\AntiVir Desktop\weblink.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyPC Client\AnyPC deinstallieren.lnk -> C:\Program Files\InstallShield Installation Information\{1AFA1FEF-8CF9-4A51-AC46-64FAA7F3D9E2}\Setup.exe (InstallShield Software Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyPC Client\AnyPC.lnk -> C:\Program Files\AnyPC Client\APStart.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyPC Client\Erstellen einer AnyPC-Server-Installationsdatei.lnk -> C:\Program Files\AnyPC Client\SetupMaker.exe (Doctorsoft) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk -> C:\Windows\System32\displayswitch.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk -> C:\Windows\System32\SoundRecorder.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk -> C:\Windows\System32\mobsync.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk -> C:\Program Files\Windows Journal\Journal.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\Windows\System32\rstrui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk -> C:\Windows\System32\migwiz\PostMig.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk -> C:\Windows\System32\migwiz\migwiz.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{DADC8F83-AFB8-4255-8036-052238A18A8A}\PlayTasks\0\Play.lnk -> C:\Program Files\Samsung Casual Games\Alice Greenfingers\Launch.exe (Oberon Media Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{D58C7682-084C-45CC-A1CF-EA7051A963A0}\PlayTasks\0\Play.lnk -> C:\Program Files\Samsung Casual Games\Go-Go Gourmet\Launch.exe (Oberon Media Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{72897716-6367-488F-98F0-12B17DBFBDD7}\PlayTasks\1\Call of Duty(R) - World at War(TM) - Mehrspieler.lnk -> C:\Program Files\Activision\Call of Duty - World at War\CoDWaWmp.exe (Activision Blizzard, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{72897716-6367-488F-98F0-12B17DBFBDD7}\PlayTasks\0\Call of Duty(R) - World at War(TM) Einzelspieler - Koop.lnk -> C:\Program Files\Activision\Call of Duty - World at War\CoDWaW.exe (Activision Blizzard, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{6282B6D7-8324-4F43-AF35-8ED766468E9C}\PlayTasks\0\Play.lnk -> C:\Program Files\Samsung Casual Games\Farm Frenzy 2\Launch.exe (Oberon Media Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{299C23BE-883D-4038-ACB4-4C8FCF07DC5A}\PlayTasks\0\Play.lnk -> C:\Program Files\Samsung Casual Games\Dairy Dash\Launch.exe (Oberon Media Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{07E7878E-762D-46D5-B8B8-7632A8DA579B}\PlayTasks\0\Play.lnk -> C:\Program Files\Samsung Casual Games\Elf Bowling Hawaiian Vacation\Launch.exe (Oberon Media Inc.) Shortcut: C:\Users\Default\Desktop\CyberLink YouCam.lnk -> C:\Program Files\CyberLink\YouCam\YouCam.exe (CyberLink Corp.) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\CyberLink YouCam.lnk -> C:\Program Files\CyberLink\YouCam\YouCam.exe (CyberLink Corp.) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\Readme.lnk -> C:\Program Files\CyberLink\YouCam\Language\YouCamDEU.htm () Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\YouCam Hilfe.lnk -> C:\Program Files\CyberLink\YouCam\Language\YouCamDeu.chm () Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Public\Desktop\Adobe Reader 9.lnk -> C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) Shortcut: C:\Users\Public\Desktop\AnyPC.lnk -> C:\Program Files\AnyPC Client\APStart.exe () Shortcut: C:\Users\Public\Desktop\Easy Network Manager.lnk -> C:\Program Files\Samsung\Easy Network Manager\ENM.exe (Samsung Electronics Co. Ltd) Shortcut: C:\Users\Public\Desktop\Game Pack.lnk -> C:\Program Files\Samsung Casual Games\GameConsole\GamePack.exe (Oberon Media) Shortcut: C:\Users\Public\Desktop\Gothic III.lnk -> C:\Program Files\Gothic III\Gothic3.exe (Pluto 13 GmbH) Shortcut: C:\Users\Public\Desktop\Microsoft Office - 60 Day Trial.lnk -> C:\Program Files\Microsoft Office Suite Activation Assistant\OAA.exe (Digital River Inc. ) Shortcut: C:\Users\Public\Desktop\Samsung Recovery Solution 4.lnk -> C:\Program Files\Samsung\Samsung Recovery Solution 4\Manager1.exe (SEC) Shortcut: C:\Users\Public\Desktop\Samsung Support Center.lnk -> C:\Program Files\Samsung\Samsung Support Center\SSCMain.exe (SAMSUNG Electronics) Shortcut: C:\Users\Public\Desktop\Samsung Update Plus.lnk -> C:\Program Files\Samsung\Samsung Update Plus\SupClientApp.exe () Shortcut: C:\Users\Public\Desktop\User Guide.lnk -> C:\Program Files\Samsung\SamsungManual\RunManual.exe (Samsung Electronics) Shortcut: C:\Users\UpdatusUser\Desktop\CyberLink YouCam.lnk -> C:\Program Files\CyberLink\YouCam\YouCam.exe (CyberLink Corp.) Shortcut: C:\Users\UpdatusUser\Desktop\Mount&Blade.lnk -> D:\Spiele\Mount&Blade\mount&blade.exe ( Taleworlds Entertainment) Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\CyberLink YouCam.lnk -> C:\Program Files\CyberLink\YouCam\YouCam.exe (CyberLink Corp.) Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\Readme.lnk -> C:\Program Files\CyberLink\YouCam\Language\YouCamDEU.htm () Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\YouCam Hilfe.lnk -> C:\Program Files\CyberLink\YouCam\Language\YouCamDeu.chm () Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation) Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\user\Links\Desktop.lnk -> C:\Users\user\Desktop () Shortcut: C:\Users\user\Links\Downloads.lnk -> C:\Users\user\Downloads () Shortcut: C:\Users\user\Desktop\CyberLink YouCam.lnk -> C:\Program Files\CyberLink\YouCam\YouCam.exe (CyberLink Corp.) Shortcut: C:\Users\user\Desktop\Mount&Blade.lnk -> D:\Spiele\Mount&Blade\mount&blade.exe ( Taleworlds Entertainment) Shortcut: C:\Users\user\Desktop\Start Emsisoft Emergency Kit.lnk -> C:\EEK\bin\a2emergencykit.exe (No File) Shortcut: C:\Users\user\Desktop\Gramps\GrampsAIO 4.0.3-console.lnk -> C:\Program Files\GrampsAIO-4.0.3\bin\gramps.exe (www.gramps-project.org) Shortcut: C:\Users\user\Desktop\Gramps\GrampsAIO 4.0.3-debug.lnk -> C:\Program Files\GrampsAIO-4.0.3\bin\grampsd.exe (www.gramps-project.org) Shortcut: C:\Users\user\Desktop\Gramps\GrampsAIO 4.0.3.lnk -> C:\Program Files\GrampsAIO-4.0.3\bin\grampsw.exe (www.gramps-project.org) Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\CyberLink YouCam.lnk -> C:\Program Files\CyberLink\YouCam\YouCam.exe (CyberLink Corp.) Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\Readme.lnk -> C:\Program Files\CyberLink\YouCam\Language\YouCamDEU.htm () Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\YouCam Hilfe.lnk -> C:\Program Files\CyberLink\YouCam\Language\YouCamDeu.chm () Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation) Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer\{DADC8F83-AFB8-4255-8036-052238A18A8A}\PlayTasks\0\Play.lnk -> C:\Program Files\Samsung Casual Games\Alice Greenfingers\Launch.exe (Oberon Media Inc.) Shortcut: C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer\{72897716-6367-488F-98F0-12B17DBFBDD7}\PlayTasks\1\Call of Duty(R) - World at War(TM) - Mehrspieler.lnk -> C:\Program Files\Activision\Call of Duty - World at War\CoDWaWmp.exe (Activision Blizzard, Inc.) Shortcut: C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer\{72897716-6367-488F-98F0-12B17DBFBDD7}\PlayTasks\0\Call of Duty(R) - World at War(TM) Einzelspieler - Koop.lnk -> C:\Program Files\Activision\Call of Duty - World at War\CoDWaW.exe (Activision Blizzard, Inc.) Shortcut: C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer\{1CCDAE49-A8C0-4524-AA17-07BCF836569F}\PlayTasks\0\Spielen.lnk -> C:\Program Files\Gothic III\Gothic3.exe (Pluto 13 GmbH) Shortcut: C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer\{07E7878E-762D-46D5-B8B8-7632A8DA579B}\PlayTasks\0\Play.lnk -> C:\Program Files\Samsung Casual Games\Elf Bowling Hawaiian Vacation\Launch.exe (Oberon Media Inc.) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk -> C:\Windows\System32\wuapp.exe (Microsoft Corporation) -> startmenu ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) -> /showgadgets ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Images2PDF\Images2PDF Console Application.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /k "C:\Program Files\PDFCreator\Images2PDF\Images2PDFC.exe" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2\Uninstall or Modify PDF Architect 2.lnk -> C:\ProgramData\PDF Architect 2\Installation\PDFArchitect2Installer.exe (© pdfforge GmbH.) -> /uninstall ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2005\Konfigurationstools\SQL Server-Konfigurations-Manager.lnk -> C:\Windows\System32\mmc.exe (Microsoft Corporation) -> /32 "C:\windows\system32\SQLServerManager.msc" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.BackupAndRestore ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\My Avira\Avira.lnk -> C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) -> /showMiniGui ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) -> -NoExit -ImportSystemModules ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) -> /open ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\Online Registrierung.lnk -> C:\Program Files\CyberLink\YouCam\OLRSubmission\OLRSubmission.exe () -> /LANG:DEU ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\YouCam deinstallieren.lnk -> C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe (Macrovision Corporation ) -> -l0x000407 /z-uninstall ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Public\Desktop\Avira.lnk -> C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) -> /showMiniGui ShortcutWithArgument: C:\Users\Public\Desktop\Browserwahl.lnk -> C:\Windows\System32\browserchoice.exe (Microsoft Corporation) -> /launch ShortcutWithArgument: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\Online Registrierung.lnk -> C:\Program Files\CyberLink\YouCam\OLRSubmission\OLRSubmission.exe () -> /LANG:DEU ShortcutWithArgument: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\YouCam deinstallieren.lnk -> C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe (Macrovision Corporation ) -> -l0x000407 /z-uninstall ShortcutWithArgument: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter ShortcutWithArgument: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) -> /tsr ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\Online Registrierung.lnk -> C:\Program Files\CyberLink\YouCam\OLRSubmission\OLRSubmission.exe () -> /LANG:DEU ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\YouCam deinstallieren.lnk -> C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe (Macrovision Corporation ) -> -l0x000407 /z-uninstall ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -extoff ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cadvilla professional 4\Support.url -> hxxp://www.cadvilla.com/support InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cadvilla professional 4\Hilfe\Online-Tutorial.url -> hxxp://www.cadvilla.com/de/tutorial InternetURL: C:\Users\user\Favorites\Cottage Lake House Plan 5572 - 4 Bedrooms and 3 Baths The House Designers.url -> hxxp://www.thehousedesigners.com/plan/cottage-lake-5572/ InternetURL: C:\Users\user\Favorites\Galleries of Timber Houses - Timber Home Living.url -> hxxp://www.timberhomeliving.com/category/timber-home-galleries/ InternetURL: C:\Users\user\Favorites\http--www.kotte-zeller.de-5-11-Tactical-Umhaengetasche-Rush-Moab-6-schwarz.htmwebsale8=kotte-zeller-shop&pi=122207&ci=017019.url -> hxxp://www.kotte-zeller.de/5-11-Tactical-Umhaengetasche-Rush-Moab-6-schwarz.htm?websale8=kotte-zeller-shop&pi=122207&ci=017019 InternetURL: C:\Users\user\Favorites\Tipp Kolumbien – Elfenbeinküste WM 2014 Prognose Fussball Wetten.url -> hxxp://www.fussball-wetten.com/wm-2014-tipps/tipp-kolumbien-elfenbeinkueste-wm-2014-prognose/ InternetURL: C:\Users\user\Favorites\Windows Live\Windows Live Gallery.url -> hxxp://go.microsoft.com/fwlink/?LinkId=70742 InternetURL: C:\Users\user\Favorites\Windows Live\Windows Live Ideas.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72700 InternetURL: C:\Users\user\Favorites\Windows Live\Windows Live Mail.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72681 InternetURL: C:\Users\user\Favorites\Windows Live\Windows Live Spaces.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72682 InternetURL: C:\Users\user\Favorites\Urlaub\Reisen zu Piratenpreisen!.url -> hxxp://www.urlaubspiraten.de/ InternetURL: C:\Users\user\Favorites\Urlaub\Urlaubsguru » Reise Schnäppchen Blog für Urlaub, Flüge und Hotels.url -> hxxp://www.urlaubsguru.de/ InternetURL: C:\Users\user\Favorites\MSN-Websites\MSN Auto.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72680 InternetURL: C:\Users\user\Favorites\MSN-Websites\MSN Fernsehen.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72659 InternetURL: C:\Users\user\Favorites\MSN-Websites\MSN Money.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72640 InternetURL: C:\Users\user\Favorites\MSN-Websites\MSN Nachrichten.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72636 InternetURL: C:\Users\user\Favorites\MSN-Websites\MSN Sport.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72635 InternetURL: C:\Users\user\Favorites\MSN-Websites\MSN.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72630 InternetURL: C:\Users\user\Favorites\Microsoft-Websites\IE-Site auf Microsoft.com.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72186 InternetURL: C:\Users\user\Favorites\Microsoft-Websites\Microsoft Deutschland GmbH.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72520 InternetURL: C:\Users\user\Favorites\Microsoft-Websites\Microsoft Store.url -> hxxp://go.microsoft.com/fwlink/?linkid=140813 InternetURL: C:\Users\user\Favorites\Microsoft-Websites\Microsoft Windows - Start.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72629 InternetURL: C:\Users\user\Favorites\Microsoft-Websites\Microsoft zu Hause.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72406 InternetURL: C:\Users\user\Favorites\Microsoft-Websites\Microsoft.com durchsuchen.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72893 InternetURL: C:\Users\user\Favorites\Microsoft-Websites\Site für IE Add-Ons.url -> hxxp://go.microsoft.com/fwlink/?LinkId=50893 InternetURL: C:\Users\user\Favorites\Links\Vorgeschlagene Sites.url -> https://ieonline.microsoft.com/#ieslice InternetURL: C:\Users\user\Favorites\Links\Web Slice-Katalog.url -> hxxp://go.microsoft.com/fwlink/?LinkId=121315 ==================== End of log ============================= |
12.09.2014, 07:51 | #48 |
/// TB-Ausbilder | Bundeskriminalamt Trojaner Mal schauen ob wir noch Infos zu diesem einen Fund bekommen:
__________________Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter file: C:\Users\Public\Desktop\Game Pack.lnk Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ |
12.09.2014, 08:42 | #49 |
| Bundeskriminalamt Trojaner Hi, das Game Pack Shortcut war schon von Anfang an auf dem Laptop. Dachte ich zumindest ... Hier das Log Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-09-2014 Ran by user at 2014-09-12 09:41:14 Run:4 Running from C:\Users\user\Desktop\Trojanercheck Boot Mode: Normal ============================================== Content of fixlist: ***************** file: C:\Users\Public\Desktop\Game Pack.lnk ***************** ========================= file: C:\Users\Public\Desktop\Game Pack.lnk ======================== MD5: 989F6FAA3DE31A1218D428F96B457AC7 Creation and modification date: 2009-12-05 20:07 - 2009-12-05 20:07 Size: 0002121 Attributes: ----A Company Name: Internal Name: Original Name: Product Name: Description: File Version: Product Version: Copyright: ====== End Of File: ====== ==== End of Fixlog ==== |
12.09.2014, 11:15 | #50 |
/// TB-Ausbilder | Bundeskriminalamt Trojaner Ok, die Datei scheint ne Falschmeldung zu sein. Wir hatten ja noch das Problem der SP1 Installation, richtig ? Hast du schon versucht, das Update herunterzuladen und manuell zu installieren ? Download Windows 7 und Windows Server 2008 R2 Service Pack 1 (KB976932) from Official Microsoft Download Center Falls nein, mal testen und berichten, was passiert.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
12.09.2014, 11:57 | #51 |
| Bundeskriminalamt Trojaner ja hatte ich schon. Da kam diese Assembly Fehlermeldung, ich starte es noch einmal neu... hab die Datei windwos6.1-KB976932-X86.exe gespeichert. Er startet auch "Computer wird vorbereitet".... (12:34 Uhr) Klick auf "Installieren" mit Häkchen für den Computer Neustart (12:35 Uhr) der grüne Balken schreitet voran bis ca. zur Hälfte da bleibt er stehen bis zum Abbruch (12:56 Uhr) "Installation war nich terfolgreich die referenziert Assembly konnte nicht gefunden werden." Details: "Fehler: ERROR_SXS_ASSEMBL_MISSING(0x80073701) |
12.09.2014, 12:17 | #52 |
/// TB-Ausbilder | Bundeskriminalamt Trojaner Kannst du mir die Datei c:\windows\Logs\CBS\CBS.log von deinem Rechner hochladen ?
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
12.09.2014, 13:53 | #53 |
| Bundeskriminalamt Trojaner sieht schlecht aus. Da scheint zuviel drin zu sein. Ich splitte das mal.... 11.09.2014 - Teil 1: Code:
ATTFilter 2014-09-11 00:18:52, Info CBS Starting TrustedInstaller initialization. 2014-09-11 00:18:52, Info CBS Loaded Servicing Stack v6.1.7601.17592 with Core: C:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_0b0e4b4025cf4049\cbscore.dll 2014-09-11 00:18:53, Info CSI 00000001@2014/9/10:22:18:53.969 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x583ade79 @0x6a685d7d @0x6a66205a @0xfa1c99 @0xfa1236 @0x77aa75a8) 2014-09-11 00:18:53, Info CSI 00000002@2014/9/10:22:18:53.969 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x583ade79 @0x6a6c7183 @0x6a6c4013 @0xfa1c99 @0xfa1236 @0x77aa75a8) 2014-09-11 00:18:53, Info CSI 00000003@2014/9/10:22:18:53.969 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x583ade79 @0x712c4bc8 @0x712c54a6 @0xfa1327 @0xfa1245 @0x77aa75a8) 2014-09-11 00:18:53, Info CBS Ending TrustedInstaller initialization. 2014-09-11 00:18:53, Info CBS Starting the TrustedInstaller main loop. 2014-09-11 00:18:53, Info CBS TrustedInstaller service starts successfully. 2014-09-11 00:18:53, Info CBS SQM: Initializing online with Windows opt-in: False 2014-09-11 00:18:53, Info CBS SQM: Cleaning up report files older than 10 days. 2014-09-11 00:18:53, Info CBS SQM: Requesting upload of all unsent reports. 2014-09-11 00:18:53, Info CBS SQM: Failed to start upload with file pattern: C:\windows\servicing\sqm\*_std.sqm, flags: 0x2 [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 00:18:53, Info CBS SQM: Failed to start standard sample upload. [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 00:18:53, Info CBS SQM: Failed to start upload with file pattern: C:\windows\servicing\sqm\*_all.sqm, flags: 0x6 [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 00:18:53, Info CBS SQM: Failed to start always sample upload. [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 00:18:53, Info CBS SQM: Warning: Failed to upload all unsent reports. [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 00:18:53, Info CBS No startup processing required, TrustedInstaller service was not set as autostart, or else a reboot is still pending. 2014-09-11 00:18:53, Info CBS NonStart: Checking to ensure startup processing was not required. 2014-09-11 00:18:53, Info CSI 00000004 IAdvancedInstallerAwareStore_ResolvePendingTransactions (call 1) (flags = 00000004, progress = NULL, phase = 0, pdwDisposition = @0xd0f9e0 2014-09-11 00:18:53, Info CSI 00000005 Creating NT transaction (seq 1), objectname [6]"(null)" 2014-09-11 00:18:53, Info CSI 00000006 Created NT transaction (seq 1) result 0x00000000, handle @0x1d8 2014-09-11 00:18:53, Info CSI 00000007@2014/9/10:22:18:53.984 CSI perf trace: CSIPERF:TXCOMMIT;710 2014-09-11 00:18:53, Info CBS NonStart: Success, startup processing not required as expected. 2014-09-11 00:18:53, Info CBS Startup processing thread terminated normally 2014-09-11 00:18:54, Info CBS Loading offline registry hive: SOFTWARE, into registry key '{bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/System32/config/SOFTWARE' from path '\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\windows\System32\config\SOFTWARE'. 2014-09-11 00:18:54, Info CBS Loading offline registry hive: SYSTEM, into registry key '{bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/System32/config/SYSTEM' from path '\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\windows\System32\config\SYSTEM'. 2014-09-11 00:18:54, Info CBS Loading offline registry hive: SECURITY, into registry key '{bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/System32/config/SECURITY' from path '\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\windows\System32\config\SECURITY'. 2014-09-11 00:18:54, Info CBS Loading offline registry hive: SAM, into registry key '{bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/System32/config/SAM' from path '\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\windows\System32\config\SAM'. 2014-09-11 00:18:54, Info CBS Loading offline registry hive: COMPONENTS, into registry key '{bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/System32/config/COMPONENTS' from path '\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\windows\System32\config\COMPONENTS'. 2014-09-11 00:18:54, Info CBS Loading offline registry hive: DEFAULT, into registry key '{bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/System32/config/DEFAULT' from path '\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\windows\System32\config\DEFAULT'. 2014-09-11 00:18:54, Info CBS Loading offline registry hive: ntuser.dat, into registry key '{bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/Users/default/ntuser.dat' from path '\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\Users\default\ntuser.dat'. 2014-09-11 00:18:54, Info CBS Loading offline registry hive: schema.dat, into registry key '{bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/system32/smi/store/Machine/schema.dat' from path '\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\windows\system32\smi\store\Machine\schema.dat'. 2014-09-11 00:18:54, Info CBS Offline image is: read-only 2014-09-11 00:18:54, Info CBS Disabling manifest caching, because the image is not writeable. 2014-09-11 00:18:54, Info CSI 00000008 CSI Store 2694480 (0x00291d50) initialized 2014-09-11 00:18:54, Info CBS Session: 4852_17984824 initialized by client SPP. 2014-09-11 00:19:03, Info CBS Archived backup log: C:\windows\Logs\CBS\CbsPersist_20140910221852.cab. 2014-09-11 00:19:25, Info CBS Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/System32/config/SOFTWARE 2014-09-11 00:19:25, Info CBS Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/System32/config/SYSTEM 2014-09-11 00:19:25, Info CBS Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/System32/config/SECURITY 2014-09-11 00:19:25, Info CBS Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/System32/config/SAM 2014-09-11 00:19:25, Info CBS Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/System32/config/COMPONENTS 2014-09-11 00:19:25, Info CBS Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/System32/config/DEFAULT 2014-09-11 00:19:25, Info CBS Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/Users/default/ntuser.dat 2014-09-11 00:19:25, Info CBS Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy3/windows/system32/smi/store/Machine/schema.dat 2014-09-11 00:29:26, Info CBS Reboot mark refs incremented to: 1 2014-09-11 00:29:26, Info CBS Scavenge: Starts 2014-09-11 00:29:26, Info CSI 00000009 CSI Store 2221488 (0x0021e5b0) initialized 2014-09-11 00:29:26, Info CSI 0000000a@2014/9/10:22:29:26.316 CSI Transaction @0x220828 initialized for deployment engine {d16d444c-56d8-11d5-882d-0080c847b195} with flags 00000002 and client id [10]"TI6.0_0:0/" 2014-09-11 00:29:26, Info CBS Scavenge: Begin CSI Store 2014-09-11 00:29:26, Info CSI 0000000b Performing 1 operations; 1 are not lock/unlock and follow: Scavenge (8): flags: 00000017 2014-09-11 00:29:26, Info CSI 0000000c Store coherency cookie matches last scavenge cookie, skipping scavenge. 2014-09-11 00:29:26, Info CSI 0000000d ICSITransaction::Commit calling IStorePendingTransaction::Apply - coldpatching=FALSE applyflags=7 2014-09-11 00:29:26, Info CSI 0000000e Creating NT transaction (seq 2), objectname [6]"(null)" 2014-09-11 00:29:26, Info CSI 0000000f Created NT transaction (seq 2) result 0x00000000, handle @0x214 2014-09-11 00:29:26, Info CSI 00000010@2014/9/10:22:29:26.612 CSI perf trace: CSIPERF:TXCOMMIT;21987 2014-09-11 00:29:26, Info CBS Scavenge: Completed, disposition: 0X1 2014-09-11 00:29:26, Info CSI 00000011@2014/9/10:22:29:26.612 CSI Transaction @0x220828 destroyed 2014-09-11 00:29:26, Info CBS Reboot mark refs: 0 2014-09-11 00:29:26, Info CBS Idle processing thread terminated normally 2014-09-11 00:29:26, Info CBS Ending the TrustedInstaller main loop. 2014-09-11 00:29:26, Info CBS Starting TrustedInstaller finalization. 2014-09-11 00:29:26, Info CBS Ending TrustedInstaller finalization. 2014-09-11 00:40:21, Info CBS Starting TrustedInstaller initialization. 2014-09-11 00:40:21, Info CBS Loaded Servicing Stack v6.1.7601.17592 with Core: C:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_0b0e4b4025cf4049\cbscore.dll 2014-09-11 00:40:22, Info CSI 00000001@2014/9/10:22:40:22.531 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x5724de79 @0x6a685d7d @0x6a66205a @0xa31c99 @0xa31236 @0x77aa75a8) 2014-09-11 00:40:22, Info CSI 00000002@2014/9/10:22:40:22.547 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x5724de79 @0x6a6c7183 @0x6a6c4013 @0xa31c99 @0xa31236 @0x77aa75a8) 2014-09-11 00:40:22, Info CSI 00000003@2014/9/10:22:40:22.547 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x5724de79 @0x6f5e4bc8 @0x6f5e54a6 @0xa31327 @0xa31245 @0x77aa75a8) 2014-09-11 00:40:22, Info CBS Ending TrustedInstaller initialization. 2014-09-11 00:40:22, Info CBS Starting the TrustedInstaller main loop. 2014-09-11 00:40:22, Info CBS TrustedInstaller service starts successfully. 2014-09-11 00:40:22, Info CBS SQM: Initializing online with Windows opt-in: False 2014-09-11 00:40:22, Info CBS SQM: Cleaning up report files older than 10 days. 2014-09-11 00:40:22, Info CBS SQM: Requesting upload of all unsent reports. 2014-09-11 00:40:22, Info CBS SQM: Failed to start upload with file pattern: C:\windows\servicing\sqm\*_std.sqm, flags: 0x2 [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 00:40:22, Info CBS SQM: Failed to start standard sample upload. [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 00:40:22, Info CBS SQM: Failed to start upload with file pattern: C:\windows\servicing\sqm\*_all.sqm, flags: 0x6 [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 00:40:22, Info CBS SQM: Failed to start always sample upload. [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 00:40:22, Info CBS SQM: Warning: Failed to upload all unsent reports. [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 00:40:22, Info CBS No startup processing required, TrustedInstaller service was not set as autostart, or else a reboot is still pending. 2014-09-11 00:40:22, Info CBS NonStart: Checking to ensure startup processing was not required. 2014-09-11 00:40:22, Info CSI 00000004 IAdvancedInstallerAwareStore_ResolvePendingTransactions (call 1) (flags = 00000004, progress = NULL, phase = 0, pdwDisposition = @0xa2fa74 2014-09-11 00:40:22, Info CSI 00000005 Creating NT transaction (seq 1), objectname [6]"(null)" 2014-09-11 00:40:22, Info CSI 00000006 Created NT transaction (seq 1) result 0x00000000, handle @0x1c0 2014-09-11 00:40:22, Info CSI 00000007@2014/9/10:22:40:22.562 CSI perf trace: CSIPERF:TXCOMMIT;936 2014-09-11 00:40:22, Info CBS NonStart: Success, startup processing not required as expected. 2014-09-11 00:40:22, Info CBS Startup processing thread terminated normally 2014-09-11 00:40:22, Info CSI 00000008 CSI Store 2352528 (0x0023e590) initialized 2014-09-11 00:40:22, Info CBS Session: 30395720_887565687 initialized by client WinMgmt. 2014-09-11 00:40:36, Info CBS Session: 30395720_887565687 finalized. Reboot required: no [HRESULT = 0x00000000 - S_OK] 2014-09-11 00:50:36, Info CBS Reboot mark refs incremented to: 1 2014-09-11 00:50:36, Info CBS Scavenge: Starts 2014-09-11 00:50:36, Info CSI 00000009@2014/9/10:22:50:36.735 CSI Transaction @0x2a30768 initialized for deployment engine {d16d444c-56d8-11d5-882d-0080c847b195} with flags 00000002 and client id [10]"TI6.0_0:0/" 2014-09-11 00:50:36, Info CBS Scavenge: Begin CSI Store 2014-09-11 00:50:36, Info CSI 0000000a Performing 1 operations; 1 are not lock/unlock and follow: Scavenge (8): flags: 00000017 2014-09-11 00:50:36, Info CSI 0000000b Store coherency cookie matches last scavenge cookie, skipping scavenge. 2014-09-11 00:50:36, Info CSI 0000000c ICSITransaction::Commit calling IStorePendingTransaction::Apply - coldpatching=FALSE applyflags=7 2014-09-11 00:50:36, Info CSI 0000000d Creating NT transaction (seq 2), objectname [6]"(null)" 2014-09-11 00:50:36, Info CSI 0000000e Created NT transaction (seq 2) result 0x00000000, handle @0x1fc 2014-09-11 00:50:36, Info CSI 0000000f@2014/9/10:22:50:36.969 CSI perf trace: CSIPERF:TXCOMMIT;24251 2014-09-11 00:50:36, Info CBS Scavenge: Completed, disposition: 0X1 2014-09-11 00:50:36, Info CSI 00000010@2014/9/10:22:50:36.985 CSI Transaction @0x2a30768 destroyed 2014-09-11 00:50:37, Info CBS Reboot mark refs: 0 2014-09-11 00:50:37, Info CBS Idle processing thread terminated normally 2014-09-11 00:50:37, Info CBS Ending the TrustedInstaller main loop. 2014-09-11 00:50:37, Info CBS Starting TrustedInstaller finalization. 2014-09-11 00:50:37, Info CBS Ending TrustedInstaller finalization. 2014-09-11 06:50:09, Info CBS Starting TrustedInstaller initialization. 2014-09-11 06:50:09, Info CBS Loaded Servicing Stack v6.1.7601.17592 with Core: C:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_0b0e4b4025cf4049\cbscore.dll 2014-09-11 06:50:10, Info CSI 00000001@2014/9/11:04:50:10.351 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7313de79 @0x73325d7d @0x7330205a @0xae1c99 @0xae1236 @0x77aa75a8) 2014-09-11 06:50:10, Info CSI 00000002@2014/9/11:04:50:10.366 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7313de79 @0x73367183 @0x73364013 @0xae1c99 @0xae1236 @0x77aa75a8) 2014-09-11 06:50:10, Info CSI 00000003@2014/9/11:04:50:10.366 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7313de79 @0x73734bc8 @0x737354a6 @0xae1327 @0xae1245 @0x77aa75a8) 2014-09-11 06:50:10, Info CBS Ending TrustedInstaller initialization. 2014-09-11 06:50:10, Info CBS Starting the TrustedInstaller main loop. 2014-09-11 06:50:10, Info CBS TrustedInstaller service starts successfully. 2014-09-11 06:50:10, Info CBS SQM: Initializing online with Windows opt-in: False 2014-09-11 06:50:10, Info CBS SQM: Cleaning up report files older than 10 days. 2014-09-11 06:50:10, Info CBS SQM: Requesting upload of all unsent reports. 2014-09-11 06:50:10, Info CBS SQM: Failed to start upload with file pattern: C:\windows\servicing\sqm\*_std.sqm, flags: 0x2 [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 06:50:10, Info CBS SQM: Failed to start standard sample upload. [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 06:50:10, Info CBS SQM: Queued 0 file(s) for upload with pattern: C:\windows\servicing\sqm\*_all.sqm, flags: 0x6 2014-09-11 06:50:10, Info CBS SQM: Warning: Failed to upload all unsent reports. [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 06:50:10, Info CBS No startup processing required, TrustedInstaller service was not set as autostart, or else a reboot is still pending. 2014-09-11 06:50:10, Info CBS NonStart: Checking to ensure startup processing was not required. 2014-09-11 06:50:10, Info CSI 00000004 IAdvancedInstallerAwareStore_ResolvePendingTransactions (call 1) (flags = 00000004, progress = NULL, phase = 0, pdwDisposition = @0xdbf9ec 2014-09-11 06:50:10, Info CSI 00000005 Creating NT transaction (seq 1), objectname [6]"(null)" 2014-09-11 06:50:10, Info CSI 00000006 Created NT transaction (seq 1) result 0x00000000, handle @0x1c0 2014-09-11 06:50:10, Info CSI 00000007@2014/9/11:04:50:10.398 CSI perf trace: CSIPERF:TXCOMMIT;690 2014-09-11 06:50:10, Info CBS NonStart: Success, startup processing not required as expected. 2014-09-11 06:50:10, Info CBS Startup processing thread terminated normally 2014-09-11 06:50:10, Info CSI 00000008 CSI Store 1762672 (0x001ae570) initialized 2014-09-11 06:50:10, Info CBS Session: 30395771_3722431991 initialized by client WindowsUpdateAgent. 2014-09-11 06:50:11, Info CBS Trusted Installer signaled for shutdown, going to exit. 2014-09-11 06:50:11, Info CBS Ending the TrustedInstaller main loop. 2014-09-11 06:50:11, Info CBS Starting TrustedInstaller finalization. 2014-09-11 06:50:12, Info CBS Ending TrustedInstaller finalization. 2014-09-11 17:14:04, Info CBS Starting TrustedInstaller initialization. 2014-09-11 17:14:04, Info CBS Loaded Servicing Stack v6.1.7601.17592 with Core: C:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_0b0e4b4025cf4049\cbscore.dll 2014-09-11 17:14:05, Info CSI 00000001@2014/9/11:15:14:05.469 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x5958de79 @0x59775d7d @0x5975205a @0xd81c99 @0xd81236 @0x76c975a8) 2014-09-11 17:14:05, Info CSI 00000002@2014/9/11:15:14:05.484 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x5958de79 @0x597b7183 @0x597b4013 @0xd81c99 @0xd81236 @0x76c975a8) 2014-09-11 17:14:05, Info CSI 00000003@2014/9/11:15:14:05.484 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x5958de79 @0x6c014bc8 @0x6c0154a6 @0xd81327 @0xd81245 @0x76c975a8) 2014-09-11 17:14:05, Info CBS Ending TrustedInstaller initialization. 2014-09-11 17:14:05, Info CBS Starting the TrustedInstaller main loop. 2014-09-11 17:14:05, Info CBS TrustedInstaller service starts successfully. 2014-09-11 17:14:05, Info CBS SQM: Initializing online with Windows opt-in: False 2014-09-11 17:14:05, Info CBS SQM: Cleaning up report files older than 10 days. 2014-09-11 17:14:05, Info CBS SQM: Requesting upload of all unsent reports. 2014-09-11 17:14:05, Info CBS SQM: Failed to start upload with file pattern: C:\windows\servicing\sqm\*_std.sqm, flags: 0x2 [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 17:14:05, Info CBS SQM: Failed to start standard sample upload. [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 17:14:05, Info CBS SQM: Queued 0 file(s) for upload with pattern: C:\windows\servicing\sqm\*_all.sqm, flags: 0x6 2014-09-11 17:14:05, Info CBS SQM: Warning: Failed to upload all unsent reports. [HRESULT = 0x80004005 - E_FAIL] 2014-09-11 17:14:05, Info CBS No startup processing required, TrustedInstaller service was not set as autostart, or else a reboot is still pending. 2014-09-11 17:14:05, Info CBS NonStart: Checking to ensure startup processing was not required. 2014-09-11 17:14:05, Info CSI 00000004 IAdvancedInstallerAwareStore_ResolvePendingTransactions (call 1) (flags = 00000004, progress = NULL, phase = 0, pdwDisposition = @0x150fbb4 2014-09-11 17:14:05, Info CSI 00000005 Creating NT transaction (seq 1), objectname [6]"(null)" 2014-09-11 17:14:05, Info CSI 00000006 Created NT transaction (seq 1) result 0x00000000, handle @0x1c0 2014-09-11 17:14:05, Info CSI 00000007@2014/9/11:15:14:05.609 CSI perf trace: CSIPERF:TXCOMMIT;660 2014-09-11 17:14:05, Info CBS NonStart: Success, startup processing not required as expected. 2014-09-11 17:14:05, Info CBS Startup processing thread terminated normally 2014-09-11 17:14:05, Info CSI 00000008 CSI Store 4515184 (0x0044e570) initialized 2014-09-11 17:14:05, Info CBS Session: 30395859_117581771 initialized by client WindowsUpdateAgent. 2014-09-11 17:14:05, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:05, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Installed 2014-09-11 17:14:05, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~x86~~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:05, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:05, Info CSI 00000009@2014/9/11:15:14:05.672 CSI Transaction @0x49fbf8 initialized for deployment engine {d16d444c-56d8-11d5-882d-0080c847b195} with flags 00000002 and client id [25]"TI5.30395859_117581771:1/" 2014-09-11 17:14:05, Info CSI 0000000a@2014/9/11:15:14:05.796 CSI Transaction @0x49fbf8 destroyed 2014-09-11 17:14:05, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..pdateclient-activex_31bf3856ad364e35_0.0.0.0_none_62d84d22ab3b4066 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:05, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..pdateclient-activex_31bf3856ad364e35_7.6.7600.256_none_09f272fb52ab0c3f, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:05, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..pdateclient-activex_31bf3856ad364e35_7.6.7600.256_none_09f272fb52ab0c3f, elevation: 32, applicable: 1 2014-09-11 17:14:05, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:05, Info CBS Appl: Package: WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~x86~~7.6.7600.256, Update: ActiveX, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:05, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:05, Info CBS Session: 30395859_119765775 initialized by client WindowsUpdateAgent. 2014-09-11 17:14:05, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~en-US~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:05, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~en-US~6.1.7600.16385, state: Installed 2014-09-11 17:14:05, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:05, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:05, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Aux~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:05, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Aux-AuxComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:05, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Aux-AuxComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Installed 2014-09-11 17:14:05, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Aux-AuxComp~31bf3856ad364e35~x86~~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:05, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Aux-AuxComp~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:05, Info CSI 0000000b@2014/9/11:15:14:05.999 CSI Transaction @0x4c1008 initialized for deployment engine {d16d444c-56d8-11d5-882d-0080c847b195} with flags 00000002 and client id [25]"TI5.30395859_119765775:1/" 2014-09-11 17:14:05, Info CSI 0000000c@2014/9/11:15:14:05.999 CSI Transaction @0x4c1008 destroyed 2014-09-11 17:14:05, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..owsupdateclient-aux_31bf3856ad364e35_0.0.0.0_none_b8cd8ce205840e6a (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:05, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..owsupdateclient-aux_31bf3856ad364e35_7.6.7600.256_none_5fe7b2baacf3da43, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:05, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..owsupdateclient-aux_31bf3856ad364e35_7.6.7600.256_none_5fe7b2baacf3da43, elevation: 32, applicable: 1 2014-09-11 17:14:05, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:05, Info CBS Appl: Package: WUClient-SelfUpdate-Aux-AuxComp~31bf3856ad364e35~x86~~7.6.7600.256, Update: Aux, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:05, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Aux-AuxComp~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:05, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Aux~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:05, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:05, Info CBS Session: 30395859_121169778 initialized by client WindowsUpdateAgent. 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~en-US~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~en-US~6.1.7600.16385, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CSI 0000000d@2014/9/11:15:14:06.140 CSI Transaction @0x4bcee8 initialized for deployment engine {d16d444c-56d8-11d5-882d-0080c847b195} with flags 00000002 and client id [25]"TI5.30395859_121169778:1/" 2014-09-11 17:14:06, Info CSI 0000000e@2014/9/11:15:14:06.140 CSI Transaction @0x4bcee8 destroyed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_0.0.0.0_none_d2bc5295f1c3b567 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.6.7600.256_none_79d6786e99338140, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.6.7600.256_none_79d6786e99338140, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Update: Core, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_0.0.0.0_none_d2bc5295f1c3b567 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.6.7600.256_none_79d6786e99338140, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.6.7600.256_none_79d6786e99338140, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Update: Core, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-windowsupdateclient-ui_31bf3856ad364e35_0.0.0.0_none_5069764091c7f818 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-windowsupdateclient-ui_31bf3856ad364e35_7.6.7600.256_none_f7839c193937c3f1, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-windowsupdateclient-ui_31bf3856ad364e35_7.6.7600.256_none_f7839c193937c3f1, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, Update: UI, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~x86~~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Staged 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~x86~~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Staged 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~x86~~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Staged 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, disposition state from detectParent: Staged 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Staged 2014-09-11 17:14:06, Info CBS EvaluateApplicability, package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, Package applicability: Staged. 2014-09-11 17:14:06, Info CBS Appl: Partial install Status testing, package: WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~~7.6.7600.256, partially installed (true/false), 0 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_0.0.0.0_none_d2bc5295f1c3b567 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.6.7600.256_none_79d6786e99338140, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.6.7600.256_none_79d6786e99338140, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Update: Core, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_0.0.0.0_none_d2bc5295f1c3b567 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.6.7600.256_none_79d6786e99338140, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.6.7600.256_none_79d6786e99338140, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Update: Core, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-windowsupdateclient-ui_31bf3856ad364e35_0.0.0.0_none_5069764091c7f818 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-windowsupdateclient-ui_31bf3856ad364e35_7.6.7600.256_none_f7839c193937c3f1, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-windowsupdateclient-ui_31bf3856ad364e35_7.6.7600.256_none_f7839c193937c3f1, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, Update: UI, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~x86~~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Staged 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~x86~~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Staged 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, Parent: Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~x86~~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, parent found: Microsoft-Windows-GroupPolicy-ClientTools-Package~31bf3856ad364e35~x86~~6.1.7600.16385, state: Staged 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, disposition state from detectParent: Staged 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, applicable state: Staged 2014-09-11 17:14:06, Info CBS EvaluateApplicability, package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, Package applicability: Staged. 2014-09-11 17:14:06, Info CBS Appl: Partial install Status testing, package: WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~~7.6.7600.256, partially installed (true/false), 0 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~en-US~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~en-US~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~en-US~7.6.7600.256, parent found: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~en-US~6.1.7600.16385, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~en-US~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~en-US~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~en-US~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, Parent: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, parent found: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_0.0.0.0_en-us_2830c01d265d652e (7.6.7600.256), elevation:32, lower version revision holder: 0.0.0.0 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_7.6.7600.256_en-us_cf4ae5f5cdcd3107, elevate: 32, applicable(true/false): 0 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_7.6.7600.256_en-us_cf4ae5f5cdcd3107, elevation: 32, applicable: 0 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: NotApplicable, result applicability state: Staged 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, Update: Core, Applicable: NotApplicable, Disposition: Staged 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, package applicable State: Installed, highest update applicable state: Staged, resulting applicable state:Staged 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, Parent: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, parent found: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..client-ui.resources_31bf3856ad364e35_0.0.0.0_en-us_3988c727b40b5caf (7.6.7600.256), elevation:32, lower version revision holder: 0.0.0.0 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..client-ui.resources_31bf3856ad364e35_7.6.7600.256_en-us_e0a2ed005b7b2888, elevate: 32, applicable(true/false): 0 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..client-ui.resources_31bf3856ad364e35_7.6.7600.256_en-us_e0a2ed005b7b2888, elevation: 32, applicable: 0 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: NotApplicable, result applicability state: Staged 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, Update: UI, Applicable: NotApplicable, Disposition: Staged 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, package applicable State: Installed, highest update applicable state: Staged, resulting applicable state:Staged 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, Parent: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, parent found: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, state: Staged 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, disposition state from detectParent: Staged 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, applicable state: Staged 2014-09-11 17:14:06, Info CBS EvaluateApplicability, package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~en-US~7.6.7600.256, Package applicability: Staged. 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~en-US~7.6.7600.256, package applicable State: Installed, highest update applicable state: Staged, resulting applicable state:Staged 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~en-US~7.6.7600.256, package applicable State: Installed, highest update applicable state: Staged, resulting applicable state:Staged 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~ja-JP~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~ja-JP~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, Parent: Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~x86~ja-JP~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~ja-JP~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, Parent: Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~x86~ja-JP~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, disposition state from detectParent: Absent 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, applicable state: Absent 2014-09-11 17:14:06, Info CBS EvaluateApplicability, package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ja-JP~7.6.7600.256, Package applicability: Absent. 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~ar-SA~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~ar-SA~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, Parent: Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~x86~ar-SA~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~ar-SA~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, Parent: Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~x86~ar-SA~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, disposition state from detectParent: Absent 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, applicable state: Absent 2014-09-11 17:14:06, Info CBS EvaluateApplicability, package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~ar-SA~7.6.7600.256, Package applicability: Absent. 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~zh-CN~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~zh-CN~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, Parent: Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~x86~zh-CN~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~zh-CN~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, Parent: Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~x86~zh-CN~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, disposition state from detectParent: Absent 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, applicable state: Absent 2014-09-11 17:14:06, Info CBS EvaluateApplicability, package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-CN~7.6.7600.256, Package applicability: Absent. 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~zh-TW~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~zh-TW~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, Parent: Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~x86~zh-TW~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~zh-TW~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, Parent: Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~x86~zh-TW~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, disposition state from detectParent: Absent 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, applicable state: Absent 2014-09-11 17:14:06, Info CBS EvaluateApplicability, package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~zh-TW~7.6.7600.256, Package applicability: Absent. 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~cs-CZ~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~cs-CZ~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, Parent: Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~x86~cs-CZ~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~cs-CZ~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, Parent: Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~x86~cs-CZ~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, disposition state from detectParent: Absent 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, applicable state: Absent 2014-09-11 17:14:06, Info CBS EvaluateApplicability, package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~cs-CZ~7.6.7600.256, Package applicability: Absent. 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~da-DK~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~da-DK~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, Parent: Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~x86~da-DK~6.0.6001.18000, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~da-DK~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, Parent: Microsoft-Windows-Server-LanguagePack-Package~31bf3856ad364e35~x86~da-DK~6.1.7600.16385, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, no parent found, go absent 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, disposition state from detectParent: Absent 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, applicable state: Absent 2014-09-11 17:14:06, Info CBS EvaluateApplicability, package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~da-DK~7.6.7600.256, Package applicability: Absent. 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Parent: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~de-DE~6.0.6000.16386, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~de-DE~7.6.7600.256, parent found: Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~de-DE~6.1.7600.16385, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~de-DE~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~de-DE~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~de-DE~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Parent: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, parent found: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_0.0.0.0_de-de_7f3fea24377f5969 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_7.6.7600.256_de-de_265a0ffcdeef2542, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_7.6.7600.256_de-de_265a0ffcdeef2542, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_0.0.0.0_none_d2bc5295f1c3b567 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.6.7600.256_none_79d6786e99338140, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.6.7600.256_none_79d6786e99338140, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Update: Core, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS Appl: DetectUpdate, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Remote Parent: Core, Intended State: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Update: Core, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~de-DE~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Parent: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, parent found: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_0.0.0.0_de-de_7f3fea24377f5969 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_7.6.7600.256_de-de_265a0ffcdeef2542, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_7.6.7600.256_de-de_265a0ffcdeef2542, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: DetectUpdate, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Remote Parent: Core, Intended State: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Update: Core, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Parent: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, parent found: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..client-ui.resources_31bf3856ad364e35_0.0.0.0_de-de_9097f12ec52d50ea (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..client-ui.resources_31bf3856ad364e35_7.6.7600.256_de-de_37b217076c9d1cc3, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..client-ui.resources_31bf3856ad364e35_7.6.7600.256_de-de_37b217076c9d1cc3, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-windowsupdateclient-ui_31bf3856ad364e35_0.0.0.0_none_5069764091c7f818 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-windowsupdateclient-ui_31bf3856ad364e35_7.6.7600.256_none_f7839c193937c3f1, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-windowsupdateclient-ui_31bf3856ad364e35_7.6.7600.256_none_f7839c193937c3f1, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, Update: UI, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS Appl: DetectUpdate, Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Remote Parent: UI, Intended State: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Update: UI, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Parent: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, parent found: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~~7.6.7600.256, state: Staged 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, disposition state from detectParent: Staged 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, applicable state: Staged 2014-09-11 17:14:06, Info CBS EvaluateApplicability, package: WUClient-SelfUpdate-Core-AdmComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Package applicability: Staged. 2014-09-11 17:14:06, Info CBS Appl: Partial install Status testing, package: WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~de-DE~7.6.7600.256, partially installed (true/false), 0 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-MiniLP~31bf3856ad364e35~x86~de-DE~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~de-DE~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Parent: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, parent found: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_0.0.0.0_de-de_7f3fea24377f5969 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_7.6.7600.256_de-de_265a0ffcdeef2542, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_7.6.7600.256_de-de_265a0ffcdeef2542, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: DetectUpdate, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Remote Parent: Core, Intended State: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Update: Core, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~de-DE~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Parent: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, parent found: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~~7.6.7600.256, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_0.0.0.0_de-de_7f3fea24377f5969 (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_7.6.7600.256_de-de_265a0ffcdeef2542, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..ient-core.resources_31bf3856ad364e35_7.6.7600.256_de-de_265a0ffcdeef2542, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: DetectUpdate, Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Remote Parent: Core, Intended State: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed 2014-09-11 17:14:06, Info CBS Appl: Package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Update: Core, Applicable: Applicable, Disposition: Installed 2014-09-11 17:14:06, Info CBS External EvaluateApplicability, package: WUClient-SelfUpdate-Core-CoreComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, package applicable State: Installed, highest update applicable state: Installed, resulting applicable state:Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, Parent: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, Disposition = Detect, VersionComp: EQ, ServiceComp: GE, BuildComp: GE, DistributionComp: GE, RevisionComp: GE, Exist: present 2014-09-11 17:14:06, Info CBS Appl: detectParent: package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, parent found: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~~7.6.7600.256, state: Installed 2014-09-11 17:14:06, Info CBS Appl: detect Parent, Package: WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, disposition state from detectParent: Installed 2014-09-11 17:14:06, Info CBS Appl: Evaluating package applicability for package WUClient-SelfUpdate-Core-UIComp~31bf3856ad364e35~x86~de-DE~7.6.7600.256, applicable state: Installed 2014-09-11 17:14:06, Info CBS Appl: Selfupdate, Component: x86_microsoft-windows-w..client-ui.resources_31bf3856ad364e35_0.0.0.0_de-de_9097f12ec52d50ea (7.6.7600.256), elevation:32, lower version revision holder: 7.3.7600.16385 2014-09-11 17:14:06, Info CBS Applicability(ComponentAnalyzerEvaluateSelfUpdate): Component: x86_microsoft-windows-w..client-ui.resources_31bf3856ad364e35_7.6.7600.256_de-de_37b217076c9d1cc3, elevate: 32, applicable(true/false): 1 2014-09-11 17:14:06, Info CBS Appl: SelfUpdate detect, component: x86_microsoft-windows-w..client-ui.resources_31bf3856ad364e35_7.6.7600.256_de-de_37b217076c9d1cc3, elevation: 32, applicable: 1 2014-09-11 17:14:06, Info CBS Appl: Evaluating applicability block(non detectUpdate part), disposition is: Staged, applicability: Applicable, result applicability state: Installed ok.. dafür müsste ich mehr Zeit haben. die Datei ist 6043 kb groß und man darf nur 97 kb hochladen.... ich guck mal, ob ich das Sonntag hinbekomme |
12.09.2014, 16:16 | #54 |
/// TB-Ausbilder | Bundeskriminalamt Trojaner Du kannst z.b. Pastebin.com - #1 paste tool since 2002! nutzen, ohne Anmeldung. Musst mir halt nur den Link dahin schicken.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
15.09.2014, 09:37 | #55 |
| Bundeskriminalamt Trojaner hast du noch eine Idee? Habe fünf verschiedene ausprobiert. Alle sagen die Größe sei zuviel für sie oder reagieren einfach nicht mehr.... ha, hier ist es.... textsave | The easy way to save text online! hxxp://txs.io/R0rb textsave | Der einfache Weg um Texte online zu speichern! textsave | Der einfache Weg um Texte online zu speichern! also das mit dem Link-Einfügen klappt nicht so richtig.... entweder mut den URL-Tags drumzu dieser Text oder aber er hxxp? hxxp://de.textsave.org/R0rb das müsste schon http sein |
15.09.2014, 14:04 | #56 |
/// TB-Ausbilder | Bundeskriminalamt Trojaner Lad dir bitte http://download.windowsupdate.com/v9...6.7600.256.cab auf den Desktop. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter cmd: pkgmgr /ip /m:"%userprofle%\Desktop\WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256.cab" Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Danach Rechner neustarten und erneut versuchen, SP1 zu installieren.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
15.09.2014, 19:22 | #57 |
| Bundeskriminalamt TrojanerCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-09-2014 Ran by user at 2014-09-15 19:46:56 Run:5 Running from C:\Users\user\Desktop\Trojanercheck Boot Mode: Normal ============================================== Content of fixlist: ***************** cmd: pkgmgr /ip /m:"%userprofle%\Desktop\WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256.cab" ***************** ========= pkgmgr /ip /m:"%userprofle%\Desktop\WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256.cab" ========= ========= End of CMD: ========= ==== End of Fixlog ==== Pfad nicht gefunden oder so etwas und 0xirgendwas... konnte es nicht lange genug sehen um alles zu lesen nichtsdestotrotz habe ich den rechner neu gestartet und das heruntergeladene updatefile versucht zu installieren - mit dem gleichen negativen Ergebnis |
16.09.2014, 08:25 | #58 | |
/// TB-Ausbilder | Bundeskriminalamt TrojanerZitat:
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter cmd: pkgmgr /ip /m:"%userprofile%\Desktop\WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256.cab" Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
16.09.2014, 17:17 | #59 |
| Bundeskriminalamt Trojaner diesmal ist FRST etwas länger gelaufen und ohne Probleme.... Das Resultat sieht aber identisch aus. Update nicht durchgelaufen... hier das log Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-09-2014 Ran by user at 2014-09-16 17:43:47 Run:6 Running from C:\Users\user\Desktop\Trojanercheck Boot Mode: Normal ============================================== Content of fixlist: ***************** cmd: pkgmgr /ip /m:"%userprofile%\Desktop\WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256.cab" ***************** ========= pkgmgr /ip /m:"%userprofile%\Desktop\WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.6.7600.256.cab" ========= ========= End of CMD: ========= ==== End of Fixlog ==== |
17.09.2014, 10:22 | #60 |
/// TB-Ausbilder | Bundeskriminalamt Trojaner Kannst du nochmal den Schritt in http://www.trojaner-board.de/158226-...ml#post1354598 wiederholen und dann nochmal die Updates über Windows Update starten ?
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |