mzpefinder_pcap_file.YR (Lavasoft MAS)Behaviour: Malware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 6c025c909d14bf5ec55b5f45e6411902
SHA1: aa74c97bdbf0852f7d4303149239459a0a84b923
SHA256: 6bde167ebaea486ac54d7729c1057151044dd4b522be62f4c136638b71631949
SSDeep: 12288:SSxG0z63smyt888888888888W88888888888Zl IUNr0q5LLQey71mgekpb3DSBe:ZxG8l lr75Xry71BbmOuqCGUVpAt
Size: 1060136 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: BorlandDelphi30, UPolyXv05_v6
Company: Uniblue Systems Limited
Created at: 2013-10-13 11:19:32
Analyzed on: Windows7Ada SP1 64-bit
Summary: Malware. Malware, short for malicious software, is any software used to disrupt computer operation, gather sensitive information, or gain access to private computer systems.
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Malware creates the following process(es):
aff_setup.exe:2408
MyPC Backup.exe:880
install.exe:1872
CloudBackup3581.exe:1528
thirdpartyinstaller.exe:3424
vcredist_x64.exe:2348
makecab.exe:2224
TrustedInstaller.exe:3324
pm-standalone-setup.exe:504
pm-standalone-setup.tmp:1440
%original file name%.exe:2944
6c025c909d14bf5ec55b5f45e6411902.tmp:3640
pc-mechanic.exe:4044
The Malware injects its code into the following process(es):
pc-mechanic.exe:3392
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process aff_setup.exe:2408 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Stuff2.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Stuff5.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nszA0C3.tmp\LogEx.dll (1597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Stuff4.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Stuff3.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aff.conf (491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\readme.txt (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsuA0A3.tmp (10479 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Stuff1.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\data3.dat (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nszA0C3.tmp\nsisdl.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\data1.dat (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\data2.dat (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nszA0C3.tmp\nsRandom.dll (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\log.txt (327 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nszA0C3.tmp\nsJSON.dll (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CloudBackup3581.exe (22107 bytes)
The process MyPC Backup.exe:880 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
%Program Files% (x86)\MyPC Backup\System.Data.SQLite.DLL (282 bytes)
%Program Files% (x86)\MyPC Backup\Microsoft.Win32.TaskScheduler.dll (208 bytes)
%Program Files% (x86)\MyPC Backup\Newtonsoft.Json.dll (495 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\42B9A473B4DAF01285A36B4D3C7B1662_178C086B699FD6C56B804AF3EF759CB5 (471 bytes)
%Program Files% (x86)\MyPC Backup\x64\SQLite.Interop.dll (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\66AE3BFDF94A732B262342AD2154B86E_7DD744F73D87EE469E5BC583C31249E2 (1624 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 (370 bytes)
%Program Files% (x86)\MyPC Backup\Shared Stack.dll (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarB9ED.tmp (2784 bytes)
%Program Files% (x86)\MyPC Backup\ObjectListView.dll (430 bytes)
%Program Files% (x86)\MyPC Backup\GetText.dll (12 bytes)
%Program Files% (x86)\MyPC Backup\Database\mpcb_settings.db-journal (39970 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\66AE3BFDF94A732B262342AD2154B86E_7DD744F73D87EE469E5BC583C31249E2 (471 bytes)
%Program Files% (x86)\MyPC Backup\BackupStackUI.dll (49 bytes)
C:\Users\"%CurrentUserName%"\Desktop\Sync Folder.lnk (1 bytes)
%Program Files% (x86)\MyPC Backup\AlphaFS.dll (270 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabB9EC.tmp (56 bytes)
%Program Files% (x86)\MyPC Backup\log\WAIT_HANDLES.log (540 bytes)
%Program Files% (x86)\MyPC Backup\Database\mpcb_settings.db (3213 bytes)
%Program Files% (x86)\MyPC Backup\MPCBClient.dll (192 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\42B9A473B4DAF01285A36B4D3C7B1662_178C086B699FD6C56B804AF3EF759CB5 (1624 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 (56 bytes)
%Program Files% (x86)\MyPC Backup\LinqBridge.dll (61 bytes)
The process install.exe:1872 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1033.dll (94 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredistUI6086.txt (120910 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VWLBF29.tmp (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredistMSI6086.txt (202619 bytes)
The process CloudBackup3581.exe:1528 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup\Uninstall.lnk (840 bytes)
%Program Files% (x86)\MyPC Backup\x86\SQLite.Interop.dll (5056 bytes)
%Program Files% (x86)\MyPC Backup\Service Start.exe (14 bytes)
%Program Files% (x86)\MyPC Backup\Microsoft.Win32.TaskScheduler.dll (1696 bytes)
%Program Files% (x86)\MyPC Backup\pt_PT.mo (59 bytes)
%Program Files% (x86)\MyPC Backup\Newtonsoft.Json.dll (2559 bytes)
%Program Files% (x86)\MyPC Backup\AlphaVSS.60.x64.dll (2096 bytes)
%Program Files% (x86)\MyPC Backup\AlphaVSS.52.x86.dll (644 bytes)
%Program Files% (x86)\MyPC Backup\SignupWizard.dll (4674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\AccessControl.dll (20 bytes)
%Program Files% (x86)\MyPC Backup\System.Data.SQLite.DLL (2809 bytes)
%Program Files% (x86)\MyPC Backup\Shared Stack.dll (6442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mpbtrk.log (8 bytes)
%Program Files% (x86)\MyPC Backup\PipeDiff.dll (1414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\nsSCM.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\nsRandom.dll (808 bytes)
%Program Files% (x86)\MyPC Backup\BackupStack.exe (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\NSISdl.dll (30 bytes)
%Program Files% (x86)\MyPC Backup\GetText.dll (12 bytes)
%Program Files% (x86)\MyPC Backup\Configuration Updater.exe (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup\MyPC Backup.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\nsis7z.dll (6536 bytes)
%Program Files% (x86)\MyPC Backup\NativeHashWrapper.dll (7 bytes)
C:\Users\"%CurrentUserName%"\Desktop\MyPC Backup.lnk (1 bytes)
%Program Files% (x86)\MyPC Backup\AlphaVSS.60.x86.dll (1882 bytes)
%Program Files% (x86)\MyPC Backup\uninst.exe (2301 bytes)
%Program Files% (x86)\MyPC Backup\Updater.exe (1695 bytes)
%Program Files% (x86)\MyPC Backup\MyPC Backup.exe (4808 bytes)
%Program Files% (x86)\MyPC Backup\BackupStackUI.dll (3584 bytes)
%Program Files% (x86)\MyPC Backup\RegisterExtensionDotNet20_x86.exe (20 bytes)
%Program Files% (x86)\MyPC Backup\AlphaVSS.51.x86.dll (643 bytes)
%Program Files% (x86)\MyPC Backup\LogicNP.EZShellExtensions.dll (1918 bytes)
%Program Files% (x86)\MyPC Backup\RegisterExtensionDotNet40_x64.exe (9 bytes)
%Program Files% (x86)\MyPC Backup\ObjectListView.dll (3014 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\System.dll (23 bytes)
%Program Files% (x86)\MyPC Backup\mypcbackup.ico (381 bytes)
%Program Files% (x86)\MyPC Backup\AlphaFS.dll (1631 bytes)
%Program Files% (x86)\MyPC Backup\AlphaVSS.52.x64.dll (1303 bytes)
%Program Files% (x86)\MyPC Backup\fr_FR.mo (61 bytes)
%Program Files% (x86)\MyPC Backup\Updater_.dll (1325 bytes)
%Program Files% (x86)\MyPC Backup\Ionic.Zip.dll (3317 bytes)
%Program Files% (x86)\MyPC Backup\syncicon.ico (61 bytes)
%Program Files% (x86)\MyPC Backup\de_DE.mo (60 bytes)
%Program Files% (x86)\MyPC Backup\es_ES.mo (60 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\DotNetChecker.dll (1597 bytes)
%Program Files% (x86)\MyPC Backup\InstMgr.dll (10 bytes)
%Program Files% (x86)\MyPC Backup\AlphaVSS.Common.dll (502 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\nsExec.dll (14 bytes)
%Program Files% (x86)\MyPC Backup\LinqBridge.dll (916 bytes)
%Program Files% (x86)\MyPC Backup\MPCBClient.dll (1596 bytes)
%Program Files% (x86)\MyPC Backup\RegisterExtensionDotNet20_x64.exe (1856 bytes)
%Program Files% (x86)\MyPC Backup\BplusDotNet.dll (1198 bytes)
%Program Files% (x86)\MyPC Backup\it_IT.mo (57 bytes)
%Program Files% (x86)\MyPC Backup\RegisterExtensionDotNet40_x86.exe (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vcredist_x64.exe (323789 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MyPC Backup.7z (268847 bytes)
%Program Files% (x86)\MyPC Backup\UnRegisterExtensions.exe (9 bytes)
%Program Files% (x86)\MyPC Backup\MPCBContextMenu.dll (16984 bytes)
%Program Files% (x86)\MyPC Backup\websocket-sharp.dll (1031 bytes)
%Program Files% (x86)\MyPC Backup\x64\SQLite.Interop.dll (6686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA563.tmp (16365 bytes)
%Program Files% (x86)\MyPC Backup\Signup Wizard.exe (4132 bytes)
The process thirdpartyinstaller.exe:3424 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Uniblue\Offers\aff_setup.exe (266 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\installer_mypcbackup.log (853 bytes)
The process vcredist_x64.exe:2348 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.DebugOpenMP.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.DebugCRT.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.ATL.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f (8 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1040.dll (2110 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.DebugMFC.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.DebugOpenMP.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1031.txt (229 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.DebugMFC.cat (236 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1028.txt (3 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.ini (844 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\vc_red.cab (65618 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.CRT.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1041.txt (5 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.3082.dll (989 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs (8 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.exe (13918 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.CRT.cat (630 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.MFCLOC.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.OpenMP.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1042.txt (650 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1033.dll (1452 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.2052.dll (1632 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.MFCLOC.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1049.txt (13 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\$shtdwn$.req (788 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1028.dll (1130 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.ATL.cat (155 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\vcredist.bmp (5 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.3082.txt (12 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.MFC.cat (658 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.MFC.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.2052.txt (3 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1036.dll (1355 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1031.dll (1160 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1042.dll (1988 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1040.txt (657 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.OpenMP.cat (297 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\vc_red.msi (3176 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1049.dll (1720 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1036.txt (12 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\globdata.ini (1 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1041.dll (1126 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1033.txt (10 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.DebugCRT.cat (9 bytes)
The process makecab.exe:2224 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
C:\Windows\Temp\cab_2224_6 (8 bytes)
C:\Windows\Temp\cab_2224_4 (564989 bytes)
C:\Windows\Temp\cab_2224_5 (76 bytes)
C:\Windows\Temp\cab_2224_2 (564989 bytes)
C:\Windows\Temp\cab_2224_3 (76 bytes)
C:\Windows\Logs\CBS\CbsPersist_20150130230556.cab (11744 bytes)
The process TrustedInstaller.exe:3324 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
C:\Windows\System32\config\TxR\{016888cc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.0.regtrans-ms (19520 bytes)
C:\Windows\winsxs\Temp\0eb4154fe13cd0013f000000fc0c3808\0eb4154fe13cd00141000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\61d3a54ee13cd00118000000fc0c3808\c134a84ee13cd0011a000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\569c464ee13cd00102000000fc0c3808\569c464ee13cd00103000000fc0c3808_manifest (859 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00131000000fc0c3808_mfc90cht.dll (79 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808 (4 bytes)
C:\Windows\System32\config\COMPONENTS{15e3db1a-917a-11e2-9ef7-000c29a8bd90}.TMContainer00000000000000000002.regtrans-ms (28680 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808\63deb84ee13cd00120000000fc0c3808_mfcm90.dll (670 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00137000000fc0c3808_mfc90ita.dll (129 bytes)
C:\Windows\winsxs\Temp\569c464ee13cd00102000000fc0c3808\569c464ee13cd00105000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00133000000fc0c3808_mfc90esp.dll (130 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808\63deb84ee13cd00121000000fc0c3808_mfc90u.dll (38780 bytes)
C:\Windows\winsxs\Temp\0eb4154fe13cd0013f000000fc0c3808 (4 bytes)
C:\Windows\System32 (824 bytes)
C:\Windows\winsxs\Temp\b268394fe13cd0014c000000fc0c3808\b268394fe13cd0014e000000fc0c3808_catalog (22 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\ca60f44ee13cd00130000000fc0c3808_mfc90chs.dll (78 bytes)
C:\Windows\System32\config\SOFTWARE (63648 bytes)
C:\Windows\System32\config\COMPONENTS (202636 bytes)
C:\Windows\winsxs\Temp\3ea48b4ee13cd0010f000000fc0c3808\3ea48b4ee13cd00111000000fc0c3808_msvcr90.dll (4811 bytes)
C:\Windows\System32\config\COMPONENTS{15e3db19-917a-11e2-9ef7-000c29a8bd90}.TxR.2.regtrans-ms (856 bytes)
C:\Windows\winsxs\Temp\569c464ee13cd00102000000fc0c3808 (4 bytes)
C:\Windows\Logs\CBS\CBS.log (86767 bytes)
C:\Windows\winsxs\ManifestCache\a786a517e28d5687_blobs.bin (4409 bytes)
C:\Windows\winsxs\Temp\61d3a54ee13cd00118000000fc0c3808 (4 bytes)
C:\Windows\winsxs\Temp\3ea48b4ee13cd0010f000000fc0c3808\3ea48b4ee13cd00110000000fc0c3808_manifest (5 bytes)
C:\Windows\winsxs\Temp\50fc234fe13cd00145000000fc0c3808 (4 bytes)
C:\Windows\winsxs\Temp\3ea48b4ee13cd0010f000000fc0c3808\3ea48b4ee13cd00112000000fc0c3808_msvcp90.dll (7701 bytes)
C:\Windows\System32\config\COMPONENTS{15e3db19-917a-11e2-9ef7-000c29a8bd90}.TxR.0.regtrans-ms (77937 bytes)
C:\Windows\System32\config\COMPONENTS{15e3db19-917a-11e2-9ef7-000c29a8bd90}.TxR.1.regtrans-ms (856 bytes)
C:\Windows\winsxs\Temp\9cfa7a4ee13cd00109000000fc0c3808\9cfa7a4ee13cd0010b000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\b268394fe13cd0014c000000fc0c3808\b268394fe13cd0014d000000fc0c3808_manifest (676 bytes)
C:\Windows\winsxs\Temp\3ea48b4ee13cd0010f000000fc0c3808 (4 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00139000000fc0c3808_mfc90kor.dll (95 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd0013a000000fc0c3808_mfc90rus.dll (127 bytes)
C:\Windows\winsxs\Temp\569c464ee13cd00102000000fc0c3808\569c464ee13cd00104000000fc0c3808_atl90.dll (853 bytes)
C:\Windows\winsxs\Temp\61d3a54ee13cd00118000000fc0c3808\61d3a54ee13cd00119000000fc0c3808_manifest (760 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00132000000fc0c3808_mfc90esn.dll (130 bytes)
C:\Windows\System32\config\TxR\{016888cc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.blf (1640 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\ca60f44ee13cd0012f000000fc0c3808_manifest (13 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808\c43fbb4ee13cd00122000000fc0c3808_mfc90.dll (38780 bytes)
C:\Windows\System32\config\SYSTEM.LOG1 (4395 bytes)
C:\Windows\winsxs\Temp\50fc234fe13cd00145000000fc0c3808\50fc234fe13cd00148000000fc0c3808_catalog (22 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808\63deb84ee13cd0011f000000fc0c3808_manifest (6 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00138000000fc0c3808_mfc90jpn.dll (95 bytes)
C:\Windows\winsxs\Temp\3ea48b4ee13cd0010f000000fc0c3808\3ea48b4ee13cd00113000000fc0c3808_msvcm90.dll (1526 bytes)
C:\Windows\winsxs\Temp\3ea48b4ee13cd0010f000000fc0c3808\3ea48b4ee13cd00114000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\9cfa7a4ee13cd00109000000fc0c3808\9cfa7a4ee13cd0010a000000fc0c3808_manifest (760 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00134000000fc0c3808_mfc90deu.dll (670 bytes)
C:\Windows\System32\config\SOFTWARE.LOG1 (64960 bytes)
C:\Windows\System32\config\TxR\{016888cd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms (15608 bytes)
C:\Windows\winsxs\Temp\28b7e34ee13cd00128000000fc0c3808 (4 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00136000000fc0c3808_mfc90fra.dll (670 bytes)
C:\Windows\winsxs\Temp\28b7e34ee13cd00128000000fc0c3808\28b7e34ee13cd0012a000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808\24a1bd4ee13cd00124000000fc0c3808_catalog (21 bytes)
C:\Windows\System32\config\SYSTEM (3345 bytes)
C:\Windows\System32\config\COMPONENTS.LOG1 (191164 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd0013b000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\50fc234fe13cd00145000000fc0c3808\50fc234fe13cd00147000000fc0c3808_vcomp90.dll (120 bytes)
C:\Windows\winsxs\Temp\50fc234fe13cd00145000000fc0c3808\50fc234fe13cd00146000000fc0c3808_manifest (864 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808 (4 bytes)
C:\Windows\winsxs\Temp\0eb4154fe13cd0013f000000fc0c3808\0eb4154fe13cd00140000000fc0c3808_manifest (766 bytes)
C:\Windows\winsxs\Temp\b268394fe13cd0014c000000fc0c3808 (4 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00135000000fc0c3808_mfc90enu.dll (113 bytes)
C:\Windows (288 bytes)
C:\Windows\System32\config\COMPONENTS{15e3db19-917a-11e2-9ef7-000c29a8bd90}.TxR.blf (8230 bytes)
C:\Windows\System32\config (592 bytes)
C:\Windows\winsxs\Temp\28b7e34ee13cd00128000000fc0c3808\28b7e34ee13cd00129000000fc0c3808_manifest (760 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808\c43fbb4ee13cd00123000000fc0c3808_mfcm90u.dll (670 bytes)
C:\Windows\winsxs\Temp\9cfa7a4ee13cd00109000000fc0c3808 (4 bytes)
The process pm-standalone-setup.exe:504 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-TA980.tmp\pm-standalone-setup.tmp (50 bytes)
The process pm-standalone-setup.tmp:1440 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-IBQ5C.tmp (112 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Microsoft.VC90.CRT\is-1GEN8.tmp (4545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp\windows8_with_innovation.bmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\unins000.dat (30302 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-N9PL0.tmp (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp\license.en.rtf (26 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-5ICMG.tmp (1281 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\es\LC_MESSAGES\is-QJ2BK.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-DA0NO.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-DKOGT.tmp (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp\_isetup\_setup64.tmp (6 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Microsoft.VC90.CRT\is-55FN0.tmp (3361 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\da\LC_MESSAGES\is-5L243.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-VFP0C.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-A3B01.tmp (1281 bytes)
C:\Users\Public\Desktop\PC Mechanic.lnk (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-BKC34.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\sv\LC_MESSAGES\is-3Q6ED.tmp (601 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue\PC Mechanic\PC Mechanic.lnk (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-C9T7Q.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-1LTQ0.tmp (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Setup Log 2015-01-31 #002.txt (459835 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-K23KM.tmp (1281 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-PSFT7.tmp (1281 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-DR3V7.tmp (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PC-Mechanic.lnk (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\fr\LC_MESSAGES\is-B51D6.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\pt_BR\LC_MESSAGES\is-9QQL9.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-FT8MB.tmp (28498 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-IT2DN.tmp (10 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-BO9N4.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp (4 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\nl\LC_MESSAGES\is-E6RTB.tmp (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp\printer.bmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\unins000.exe (49 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-UV01E.tmp (35285 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\de\LC_MESSAGES\is-URG36.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-MHV0A.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-0R0I5.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\unins000.msg (646 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Microsoft.VC90.CRT\is-NNP27.tmp (524 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locales\is-N7MHM.tmp (4 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\en\LC_MESSAGES\is-8B81S.tmp (62 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp\InstallerExtensions.dll (715 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-56JFR.tmp (13 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\ja\LC_MESSAGES\is-6HRBP.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-4LT1Q.tmp (1281 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-N1BQ0.tmp (1281 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-ULURG.tmp (107054 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-MV9VQ.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\ru\LC_MESSAGES\is-MC22J.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\no\LC_MESSAGES\is-8OV7F.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-5V5K2.tmp (75544 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-TNEM0.tmp (19686 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\it\LC_MESSAGES\is-T8LQT.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-F9HHB.tmp (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp\_isetup\_shfoldr.dll (47 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\fi\LC_MESSAGES\is-QFQDG.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-4B0N8.tmp (197872 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe (291 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue\PC Mechanic\Uninstall PC Mechanic.lnk (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-R5JFE.tmp (1 bytes)
The process %original file name%.exe:2944 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-P6RBB.tmp\6c025c909d14bf5ec55b5f45e6411902.tmp (50 bytes)
The process 6c025c909d14bf5ec55b5f45e6411902.tmp:3640 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\pcmechanicpm-standalone-setup[1].exe (1571123 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Uniblue\Offers\aff_setup.exe (9242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\aff_setup[1].exe (33950 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\thirdpartyinstaller.exe (98 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\_isetup\_shfoldr.dll (47 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\pm_logo.bmp (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\pm-standalone-setup.exe (115616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\license.en.rtf (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\backupmypc_logo.bmp (39 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\printer.bmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\InstallerExtensions.dll (715 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\_isetup\_setup64.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\microsoft_partner.bmp (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\banner_icon.bmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\backupmypc_check_mark.bmp (310 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Setup Log 2015-01-31 #001.txt (21109 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\windows8_with_innovation.bmp (601 bytes)
The process pc-mechanic.exe:4044 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
%Program Files% (x86)\Uniblue\PC-Mechanic\icudt.dll (2183 bytes)
C:\Windows\Tasks\PC-Mechanic Startup.job (684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Uniblue\PC-Mechanic\settings.dat (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Uniblue\PC-Mechanic\error.log (5943 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\libcef.dll (10562 bytes)
C:\Windows\Tasks\PC-Mechanic Maintenance.job (702 bytes)
C:\Windows\Tasks\PC-Mechanic Subscription.job (702 bytes)
The process pc-mechanic.exe:3392 makes changes in the file system.
The Malware creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Uniblue\PC-Mechanic\error.log (7539 bytes)
Registry activity
The process MyPC Backup.exe:880 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\29\52C64B7E]
"LanguageList" = "en-US, en"
The process CloudBackup3581.exe:1528 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%Program Files% (x86)\Google\Update\1.3.24.15, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\327c54aa\python.dll, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\327c54aa\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\nsSCM.dll,"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
"DisplayName" = "MyPC Backup"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
"DisplayVersion" = ""
"URLInfoAbout" = "http://www.mypcbackup.com"
"Publisher" = "JDi Backup Ltd"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
"DisplayIcon" = "%Program Files% (x86)\MyPC Backup\MyPC Backup.exe"
"UninstallString" = "%Program Files% (x86)\MyPC Backup\uninst.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MyPC Backup]
"(Default)" = "%Program Files% (x86)\MyPC Backup\BackupStack.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
"HelpLink" = "http://support.mypcbackup.com"
The Malware deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process TrustedInstaller.exe:3324 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:
[HKLM\COMPONENTS\CanonicalData\Catalogs\333c3c8a825eb46b5db7da4db82125807c7afa0591882445f186c767af2ac85e]
"c!policy.9.0...vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_330b958c9268999d" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1\UnstagedFiles]
"mfc90u.dll" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_92995f253c01eddb]
"i!SIAW_" = "00 00 00 00 1F 00 00 00 43 3A 5C 57 69 6E 64 6F"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d\v!9.0.30729.4148]
"S1H" = "14 AA 6E 76 31 91 54 C4 03 11 34 8A 36 B3 FF AB"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_1eef21b42ca2596f\v!9.0.30729.4148]
"(Default)" = "6"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.1]
"MCP_c22d037d" = "00 00 00 00 0F 8E 52 01 4B 08 00 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_3a15284abf58447e]
"c!policy.9.0...ft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_3a15284abf58447e" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_bbd99e435df8a088\v!9.0.30729.4148]
"sf" = "1"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.4940]
"MCP_c22d037d" = "00 00 00 00 5A 96 52 01 4B 08 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_399d052615c6abee\v!9.0.30729.4148]
"sf" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d\9.0]
"9.0.30729.1" = "01"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.4148]
"(Default)" = "6"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_951ab4128654b0c9]
"f!mfcm90.dll" = "6D 00 66 00 63 00 6D 00 39 00 30 00 2E 00 64 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.4148]
"sf" = "1"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_3624aa14c1dce505]
"ClosureFlags" = "3"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_bbd99e435df8a088\v!9.0.30729.1]
"MCP_c22d037d" = "00 00 00 00 B9 C8 52 01 CE 04 00 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"f!mfc90kor.dll" = "4D 00 46 00 43 00 39 00 30 00 4B 00 4F 00 52 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_399d052615c6abee\v!9.0.30729.1]
"MCP_c22d037d" = "00 00 00 00 00 F9 52 01 E0 04 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d\v!9.0.30729.1\UnstagedFiles]
"atl90.dll" = "41 54 4C 39 30 2E 64 6C 6C"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_39e222e84b9e7e6f]
"CatalogThumbprint" = "fe0fac4e315b16deed38f335d82d54236d1dddb87577f2cadc062421a1e828a3eÈÂÂ"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_a5325551f9d85633]
"S256H" = "24 BE B9 75 C2 7B 1D 95 FD D4 FE 4E 13 54 0E 21"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\9.0]
"9.0.30729.1" = "01"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.4148]
"(Default)" = "10"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.4148]
"MCP_c22d037d" = "00 00 00 00 98 E5 52 01 68 13 00 00"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_330b958c9268999d]
"i!SIAW_" = "00 00 00 00 1F 00 00 00 43 3A 5C 57 69 6E 64 6F"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.1]
"S1H" = "38 09 81 95 0B 31 B2 00 22 13 37 FF CF FB FF 41"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1]
"CT" = "36 00 64 00 63 00 31 00 62 00 39 00 63 00 33 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\v!9.0.21022.8]
"S1H" = "FE 8C 92 2C 75 1D 5B CC FB 3B D3 CB 22 A9 B8 23"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.4148]
"MCP_c22d037d" = "00 00 00 00 87 B0 52 01 C6 04 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_399d052615c6abee\v!9.0.30729.4148]
"S1H" = "AE 6F 51 9A C7 46 73 82 69 39 92 25 65 46 09 57"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90chs.dll" = "4D 46 43 39 30 43 48 53 2E 44 4C 4C"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_951ab4128654b0c9]
"f!mfc90u.dll" = "6D 00 66 00 63 00 39 00 30 00 75 00 2E 00 64 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.1]
"(Default)" = "6"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.1\UnstagedFiles]
"msvcm90.dll" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.1]
"S1H" = "76 C9 DC 05 BC 6B 6B 4C A3 FA EB 6F 47 42 95 CE"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\v!9.0.21022.8]
"sf" = "2"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_330b958c9268999d]
"ClosureFlags" = "3"
[HKLM\COMPONENTS\CanonicalData\Catalogs\6dc1b9c301d48eb965f7f4cee06ac63e7207040bfa6101252e8cea08a0855d4e]
"c!microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_92995f253c01eddb" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_3da38fdebd0e6822]
"Identity" = "70 6F 6C 69 63 79 2E 39 2E 30 2E 4D 69 63 72 6F"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.4148]
"MCP_c22d037d" = "00 00 00 00 A5 9E 52 01 3E 08 00 00"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_330b958c9268999d]
"CatalogThumbprint" = "333c3c8a825eb46b5db7da4db82125807c7afa0591882445f186c767af2ac85e"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\v!9.0.30729.4148]
"sf" = "1"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_951ab4128654b0c9]
"S256H" = "26 93 44 15 5C 4C F6 E2 AE DE 35 F5 1F 79 11 C0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1]
"sf" = "2"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...ft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_3da38fdebd0e6822]
"CatalogThumbprint" = "cc70a861e6263ece8ebd924aed1f90031fe1c199ab22cd0f7c7f0a2558cd9322AÈÂÂ"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\v!9.0.30729.4148]
"MCP_c22d037d" = "00 00 00 00 24 08 53 01 6C 05 00 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"f!mfc90enu.dll" = "4D 00 46 00 43 00 39 00 30 00 45 00 4E 00 55 00"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_a5325551f9d85633]
"AppID" = "4D 69 63 72 6F 73 6F 66 74 2E 56 43 39 30 2E 4F"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\v!9.0.30729.4148]
"(Default)" = "10"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...ft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_3624aa14c1dce505]
"i!SIAW_" = "00 00 00 00 1F 00 00 00 43 3A 5C 57 69 6E 64 6F"
"CatalogThumbprint" = "522ed40176b2323ddf1104a8cafa128db5f21bbac59aaf6b48e59ac154a036f7"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_bbd99e435df8a088\v!9.0.30729.4148]
"(Default)" = "6"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1]
"MCP_c22d037d" = "00 00 00 00 59 D2 52 01 3F 13 00 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_3da38fdebd0e6822]
"ClosureFlags" = "3"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_951ab4128654b0c9]
"Identity" = "4D 69 63 72 6F 73 6F 66 74 2E 56 43 39 30 2E 4D"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_bb797aeb5e404097\v!9.0.30729.4148]
"MCP_c22d037d" = "00 00 00 00 42 89 52 01 CD 04 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_1eef21b42ca2596f\v!9.0.30729.4148]
"S1H" = "E4 EC 8B 0B 75 55 36 62 51 1D 04 0E 86 AD 97 AC"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_a5325551f9d85633]
"c!microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_a5325551f9d85633" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_a5325551f9d85633]
"i!SIAW_" = "00 00 00 00 1F 00 00 00 43 3A 5C 57 69 6E 64 6F"
[HKLM\COMPONENTS\CanonicalData\Catalogs\fe0fac4e315b16deed38f335d82d54236d1dddb87577f2cadc062421a1e828a3]
"c!policy.9.0...vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_39e222e84b9e7e6f" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...ft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_3a15284abf58447e]
"AppID" = "70 6F 6C 69 63 79 2E 39 2E 30 2E 4D 69 63 72 6F"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"f!mfc90fra.dll" = "4D 00 46 00 43 00 39 00 30 00 46 00 52 00 41 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d\v!9.0.30729.4148]
"sf" = "1"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_bbd99e435df8a088\v!9.0.30729.4148]
"MCP_c22d037d" = "00 00 00 00 87 CD 52 01 D2 04 00 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"f!mfc90rus.dll" = "4D 00 46 00 43 00 39 00 30 00 52 00 55 00 53 00"
[HKLM\COMPONENTS\CanonicalData\Catalogs\a8095efeef7cae736f55a416d69c2b12e250b764bbf39505a3456a6903d27c7d]
"c!microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_99b61f5e8371c1d4" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_1eef21b42ca2596f\v!9.0.21022.8]
"MCP_c22d037d" = "00 00 00 00 90 0D 53 01 8F 04 00 00"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...ft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_3a15284abf58447e]
"i!SIAW_" = "00 00 00 00 1F 00 00 00 43 3A 5C 57 69 6E 64 6F"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_1eef21b42ca2596f\v!9.0.30729.4148]
"MCP_c22d037d" = "00 00 00 00 1F 12 53 01 D6 04 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_bb797aeb5e404097\v!9.0.30729.1]
"MCP_c22d037d" = "00 00 00 00 74 84 52 01 CE 04 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_bbd99e435df8a088\v!9.0.30729.1]
"S1H" = "EF 36 D4 10 E0 A9 EA 70 90 91 65 79 2A 07 E7 18"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.1]
"MCP_c22d037d" = "00 00 00 00 E3 A6 52 01 D4 04 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\v!9.0.21022.8\UnstagedFiles]
"vcomp90.dll" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)]
"UtilizedSpace_MCP_c22d037d" = "F7 22 52 01 00 00 00 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"c!microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_92995f253c01eddb" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_bb797aeb5e404097\v!9.0.30729.1]
"CT" = "64 00 32 00 63 00 61 00 38 00 66 00 33 00 35 00"
[HKLM\COMPONENTS\CanonicalData\Catalogs\0244eac606f513cdc5623c418d394dd7fdcf005174c9136143ffd57e370c8bba]
"c!microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_9aefdaaa829eb818" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_9aefdaaa829eb818]
"Identity" = "4D 69 63 72 6F 73 6F 66 74 2E 56 43 39 30 2E 41"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_3a15284abf58447e]
"ClosureFlags" = "3"
[HKLM\COMPONENTS\CanonicalData\Catalogs\522ed40176b2323ddf1104a8cafa128db5f21bbac59aaf6b48e59ac154a036f7]
"c!policy.9.0...ft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_3624aa14c1dce505" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.4148]
"S1H" = "83 EB 34 D7 CE D2 B9 DC 71 DB B8 49 AA 21 EA 78"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_bbd99e435df8a088\v!9.0.30729.1]
"sf" = "1"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_3a15284abf58447e]
"S256H" = "69 55 F7 F5 CC 99 69 B8 69 B9 90 86 6D B9 02 DA"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90fra.dll" = "4D 46 43 39 30 46 52 41 2E 44 4C 4C"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_92995f253c01eddb]
"AppID" = "4D 69 63 72 6F 73 6F 66 74 2E 56 43 39 30 2E 4D"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_39e222e84b9e7e6f]
"c!policy.9.0...vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_39e222e84b9e7e6f" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_99b61f5e8371c1d4]
"ClosureFlags" = "3"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d\v!9.0.30729.1]
"CT" = "30 00 32 00 34 00 34 00 65 00 61 00 63 00 36 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_330b958c9268999d]
"Identity" = "70 6F 6C 69 63 79 2E 39 2E 30 2E 4D 69 63 72 6F"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_3a15284abf58447e]
"Identity" = "70 6F 6C 69 63 79 2E 39 2E 30 2E 4D 69 63 72 6F"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_951ab4128654b0c9]
"CatalogThumbprint" = "95ce0638280a2ff1d3cb1be6be97e25e47ff2be6f7c987e85530957c3751bf90쀀ÈÂÂ"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_99b61f5e8371c1d4]
"c!microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_99b61f5e8371c1d4" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.4940]
"(Default)" = "10"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\v!9.0.30729.4148]
"S1H" = "DD 16 14 4C C5 08 00 43 4F CC B2 B6 FE 9C 3F 5E"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.4148]
"sf" = "1"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.4148]
"(Default)" = "10"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.4940]
"S1H" = "AA 99 E7 4A 4B C1 C0 3A D2 57 8D E2 4A 0B 3A 42"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"Identity" = "4D 69 63 72 6F 73 6F 66 74 2E 56 43 39 30 2E 4D"
"S256H" = "6C E2 C2 01 E1 39 B8 B7 FD D6 B0 15 1A D0 20 DB"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\v!9.0.21022.8]
"MCP_c22d037d" = "00 00 00 00 B3 02 53 01 71 05 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d\v!9.0.30729.1]
"S1H" = "23 CA 6B 65 00 D5 28 6A FC B4 CD 40 F3 13 09 16"
"sf" = "2"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_330b958c9268999d]
"AppID" = "70 6F 6C 69 63 79 2E 39 2E 30 2E 4D 69 63 72 6F"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_3da38fdebd0e6822]
"S256H" = "34 66 B6 B0 1E 23 20 74 33 3A E8 90 DE BA 8F D9"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_39e222e84b9e7e6f]
"i!SIAW_" = "00 00 00 00 1F 00 00 00 43 3A 5C 57 69 6E 64 6F"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"f!mfc90esn.dll" = "4D 00 46 00 43 00 39 00 30 00 45 00 53 00 4E 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_951ab4128654b0c9]
"c!microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_951ab4128654b0c9" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_9aefdaaa829eb818]
"f!atl90.dll" = "41 00 54 00 4C 00 39 00 30 00 2E 00 64 00 6C 00"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_a5325551f9d85633]
"CatalogThumbprint" = "4c41971c13d332f75376e357800f14c8671cabe1762b1395ecb015bdaebe1343ÈÂÂ"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\9.0]
"9.0.30729.1" = "01"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d\v!9.0.30729.1]
"MCP_c22d037d" = "00 00 00 00 9F 79 52 01 6B 05 00 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_a5325551f9d85633]
"Identity" = "4D 69 63 72 6F 73 6F 66 74 2E 56 43 39 30 2E 4F"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.4940]
"sf" = "1"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...ft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_3624aa14c1dce505]
"AppID" = "70 6F 6C 69 63 79 2E 39 2E 30 2E 4D 69 63 72 6F"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_951ab4128654b0c9]
"i!SIAW_" = "00 00 00 00 1F 00 00 00 43 3A 5C 57 69 6E 64 6F"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_39e222e84b9e7e6f]
"AppID" = "70 6F 6C 69 63 79 2E 39 2E 30 2E 4D 69 63 72 6F"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_951ab4128654b0c9]
"f!mfc90.dll" = "6D 00 66 00 63 00 39 00 30 00 2E 00 64 00 6C 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_a5325551f9d85633]
"ClosureFlags" = "3"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1]
"sf" = "2"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.4148]
"sf" = "1"
[HKLM\COMPONENTS\CanonicalData\Catalogs\d2ca8f3588969dd145bf8b1a7124f0754cebffde0e20d205e2e767ee4bf69d2a]
"c!policy.9.0...ft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_3a15284abf58447e" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_399d052615c6abee\v!9.0.30729.1]
"(Default)" = "6"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_1eef21b42ca2596f\v!9.0.30729.4148]
"sf" = "1"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.4148]
"S1H" = "59 FC 44 3F E4 A9 36 69 AC E0 F5 9F A7 98 6B C9"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_3624aa14c1dce505]
"Identity" = "70 6F 6C 69 63 79 2E 39 2E 30 2E 4D 69 63 72 6F"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.1\UnstagedFiles]
"msvcr90.dll" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"ClosureFlags" = "3"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.4148]
"MCP_c22d037d" = "00 00 00 00 FC BE 52 01 BD 09 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.4940]
"MCP_c22d037d" = "00 00 00 00 B7 AB 52 01 D0 04 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90enu.dll" = "4D 46 43 39 30 45 4E 55 2E 44 4C 4C"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.1]
"sf" = "1"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"f!mfc90jpn.dll" = "4D 00 46 00 43 00 39 00 30 00 4A 00 50 00 4E 00"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_951ab4128654b0c9]
"AppID" = "4D 69 63 72 6F 73 6F 66 74 2E 56 43 39 30 2E 4D"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_399d052615c6abee\v!9.0.30729.4148]
"(Default)" = "6"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_99b61f5e8371c1d4]
"AppID" = "4D 69 63 72 6F 73 6F 66 74 2E 56 43 39 30 2E 43"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1]
"CT" = "39 00 35 00 63 00 65 00 30 00 36 00 33 00 38 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\9.0]
"9.0.21022.8" = "01"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.1]
"(Default)" = "10"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_9aefdaaa829eb818]
"c!microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_9aefdaaa829eb818" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_3624aa14c1dce505]
"c!policy.9.0...ft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_3624aa14c1dce505" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"f!mfc90deu.dll" = "4D 00 46 00 43 00 39 00 30 00 44 00 45 00 55 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_bb797aeb5e404097\v!9.0.30729.1]
"(Default)" = "6"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.1]
"sf" = "2"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_bb797aeb5e404097\v!9.0.30729.4148]
"sf" = "1"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.1\UnstagedFiles]
"msvcp90.dll" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_92995f253c01eddb]
"CatalogThumbprint" = "6dc1b9c301d48eb965f7f4cee06ac63e7207040bfa6101252e8cea08a0855d4eÈÂÂ"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_bbd99e435df8a088\v!9.0.30729.4148]
"S1H" = "4F C7 D7 36 AD BC B2 7C 10 86 7E 21 90 BD D1 34"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\v!9.0.21022.8]
"CT" = "34 00 63 00 34 00 31 00 39 00 37 00 31 00 63 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_951ab4128654b0c9]
"ClosureFlags" = "3"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.4940]
"(Default)" = "6"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...ft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_3da38fdebd0e6822]
"i!SIAW_" = "00 00 00 00 1F 00 00 00 43 3A 5C 57 69 6E 64 6F"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1\UnstagedFiles]
"mfc90.dll" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1]
"S1H" = "DA 6E 20 D5 AE 2F 76 AF 71 19 31 70 48 42 36 52"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_399d052615c6abee\v!9.0.30729.1]
"sf" = "1"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d\v!9.0.30729.1]
"(Default)" = "10"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90kor.dll" = "4D 46 43 39 30 4B 4F 52 2E 44 4C 4C"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.1]
"CT" = "61 00 38 00 30 00 39 00 35 00 65 00 66 00 65 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.4148]
"sf" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\9.0]
"9.0.30729.1" = "01"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_bbd99e435df8a088\v!9.0.30729.1]
"(Default)" = "6"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.1]
"CT" = "63 00 63 00 37 00 30 00 61 00 38 00 36 00 31 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_bb797aeb5e404097\v!9.0.30729.1]
"sf" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide]
"PublisherPolicyChangeTime" = "Type: REG_QWORD, Length: 8"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_9aefdaaa829eb818]
"i!SIAW_" = "00 00 00 00 1F 00 00 00 43 3A 5C 57 69 6E 64 6F"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_399d052615c6abee\v!9.0.30729.4148]
"MCP_c22d037d" = "00 00 00 00 E0 FD 52 01 D3 04 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_399d052615c6abee\v!9.0.30729.1]
"S1H" = "E6 CA F0 F6 A2 0D C9 9F 62 27 42 55 D7 B2 1B 34"
"CT" = "66 00 65 00 30 00 66 00 61 00 63 00 34 00 65 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_bbd99e435df8a088\v!9.0.30729.1]
"CT" = "35 00 32 00 32 00 65 00 64 00 34 00 30 00 31 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_99b61f5e8371c1d4]
"f!msvcm90.dll" = "6D 00 73 00 76 00 63 00 6D 00 39 00 30 00 2E 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_3da38fdebd0e6822]
"c!policy.9.0...ft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_3da38fdebd0e6822" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\ServicingStackVersions]
"6.1.7601.17592 (win7sp1_gdr.110408-1631)" = "2015/1/30:23:5:57.167 6.1.7601.17592 (win7sp1_gdr.110408-1631)"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_bb797aeb5e404097\v!9.0.30729.1]
"S1H" = "64 21 A7 13 7F 81 51 EC C9 C6 32 1F CB 89 4E ED"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_a5325551f9d85633]
"f!vcomp90.dll" = "76 00 63 00 6F 00 6D 00 70 00 39 00 30 00 2E 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_39e222e84b9e7e6f]
"ClosureFlags" = "3"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"f!mfc90esp.dll" = "4D 00 46 00 43 00 39 00 30 00 45 00 53 00 50 00"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_99b61f5e8371c1d4]
"CatalogThumbprint" = "a8095efeef7cae736f55a416d69c2b12e250b764bbf39505a3456a6903d27c7dË•ÈÂÂ"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1]
"S1H" = "CC E5 48 A1 81 09 83 7C D5 26 1A F8 35 AB 54 9D"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_bb797aeb5e404097\9.0]
"9.0.30729.1" = "01"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_1eef21b42ca2596f\v!9.0.21022.8]
"(Default)" = "6"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90esp.dll" = "4D 46 43 39 30 45 53 50 2E 44 4C 4C"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.4940]
"S1H" = "74 EA A7 88 4B 21 D7 1F 33 34 94 89 89 7C 0A F6"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"f!mfc90ita.dll" = "4D 00 46 00 43 00 39 00 30 00 49 00 54 00 41 00"
[HKLM\COMPONENTS\CanonicalData\Catalogs\95ce0638280a2ff1d3cb1be6be97e25e47ff2be6f7c987e85530957c3751bf90]
"c!microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_951ab4128654b0c9" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_bb797aeb5e404097\v!9.0.30729.4148]
"(Default)" = "6"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"f!mfc90cht.dll" = "4D 00 46 00 43 00 39 00 30 00 43 00 48 00 54 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90esn.dll" = "4D 46 43 39 30 45 53 4E 2E 44 4C 4C"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_99b61f5e8371c1d4]
"f!msvcp90.dll" = "6D 00 73 00 76 00 63 00 70 00 39 00 30 00 2E 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_330b958c9268999d]
"c!policy.9.0...vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_330b958c9268999d" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_bb797aeb5e404097\v!9.0.30729.4148]
"S1H" = "80 93 28 44 A9 44 70 27 55 3E C3 07 5D F5 63 DF"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.4148]
"(Default)" = "10"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1\UnstagedFiles]
"mfcm90u.dll" = "Type: REG_BINARY, Length: 0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_bbd99e435df8a088\9.0]
"9.0.30729.1" = "01"
[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\29\52C64B7E]
"LanguageList" = "en-US, en"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.4940]
"sf" = "1"
[HKLM\COMPONENTS\CanonicalData\Catalogs\4c41971c13d332f75376e357800f14c8671cabe1762b1395ecb015bdaebe1343]
"c!microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_a5325551f9d85633" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1]
"(Default)" = "10"
[HKLM\COMPONENTS]
"StoreDirty" = "01"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\v!9.0.30729.4148]
"S1H" = "31 95 AA CA BF 6A 85 7B 8A 02 CC 29 B3 F8 BA 35"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1]
"MCP_c22d037d" = "00 00 00 00 4D B5 52 01 AF 09 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\v!9.0.21022.8]
"(Default)" = "10"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_99b61f5e8371c1d4]
"S256H" = "08 8C D1 14 A3 5A A0 03 0F 8A C8 09 40 2C 7C 22"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_1eef21b42ca2596f\v!9.0.21022.8]
"CT" = "33 00 33 00 33 00 63 00 33 00 63 00 38 00 61 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_39e222e84b9e7e6f]
"Identity" = "70 6F 6C 69 63 79 2E 39 2E 30 2E 4D 69 63 72 6F"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1]
"(Default)" = "10"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...ft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_3a15284abf58447e]
"CatalogThumbprint" = "d2ca8f3588969dd145bf8b1a7124f0754cebffde0e20d205e2e767ee4bf69d2a"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90jpn.dll" = "4D 46 43 39 30 4A 50 4E 2E 44 4C 4C"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_3624aa14c1dce505]
"S256H" = "8D C0 05 84 25 4A F1 6C 47 CA 9C 96 C9 44 75 51"
[HKLM\COMPONENTS]
"ExecutionState" = "2"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d\v!9.0.30729.4148]
"MCP_c22d037d" = "00 00 00 00 0A 7F 52 01 6A 05 00 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1\UnstagedFiles]
"mfcm90.dll" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_9aefdaaa829eb818]
"ClosureFlags" = "3"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_330b958c9268999d]
"S256H" = "FE AE 5D B0 21 40 AA 1D 6C CD 8E EF 81 27 94 DF"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913\9.0]
"9.0.30729.1" = "01"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_9aefdaaa829eb818]
"S256H" = "EB E1 76 88 C7 DC EA 0B F8 87 58 62 C8 C7 2A 58"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90rus.dll" = "4D 46 43 39 30 52 55 53 2E 44 4C 4C"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d\v!9.0.30729.4148]
"(Default)" = "10"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_9aefdaaa829eb818]
"AppID" = "4D 69 63 72 6F 73 6F 66 74 2E 56 43 39 30 2E 41"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90deu.dll" = "4D 46 43 39 30 44 45 55 2E 44 4C 4C"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_99b61f5e8371c1d4]
"Identity" = "4D 69 63 72 6F 73 6F 66 74 2E 56 43 39 30 2E 43"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_99b61f5e8371c1d4]
"i!SIAW_" = "00 00 00 00 1F 00 00 00 43 3A 5C 57 69 6E 64 6F"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_399d052615c6abee\9.0]
"9.0.30729.1" = "01"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_99b61f5e8371c1d4]
"f!msvcr90.dll" = "6D 00 73 00 76 00 63 00 72 00 39 00 30 00 2E 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_1eef21b42ca2596f\v!9.0.21022.8]
"S1H" = "9E 2C 9A 79 1D 8E C7 78 4A 73 08 8C 2E 1E AF C1"
[HKLM\COMPONENTS\DerivedData\Components\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_39e222e84b9e7e6f]
"S256H" = "0E DF 78 65 CB 6E 59 40 E6 8D 63 1A FE E7 83 B0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_1eef21b42ca2596f\9.0]
"9.0.21022.8" = "01"
[HKLM\COMPONENTS\CanonicalData\Catalogs\cc70a861e6263ece8ebd924aed1f90031fe1c199ab22cd0f7c7f0a2558cd9322]
"c!policy.9.0...ft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_3da38fdebd0e6822" = "Type: REG_BINARY, Length: 0"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.4148]
"S1H" = "E3 17 DA F8 C4 AE B9 52 16 AF B2 EE 85 45 57 D7"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_1eef21b42ca2596f\v!9.0.21022.8]
"sf" = "1"
[HKLM\COMPONENTS\CanonicalData\Deployments\microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_9aefdaaa829eb818]
"CatalogThumbprint" = "0244eac606f513cdc5623c418d394dd7fdcf005174c9136143ffd57e370c8bba4ÈÂÂ"
[HKLM\COMPONENTS\CanonicalData\Deployments\policy.9.0...ft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_3da38fdebd0e6822]
"AppID" = "70 6F 6C 69 63 79 2E 39 2E 30 2E 4D 69 63 72 6F"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb]
"f!mfc90chs.dll" = "4D 00 46 00 43 00 39 00 30 00 43 00 48 00 53 00"
[HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_951ab4128654b0c9]
"f!mfcm90u.dll" = "6D 00 66 00 63 00 6D 00 39 00 30 00 75 00 2E 00"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90cht.dll" = "4D 46 43 39 30 43 48 54 2E 44 4C 4C"
"mfc90ita.dll" = "4D 46 43 39 30 49 54 41 2E 44 4C 4C"
The Malware deletes the following registry key(s):
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.1\UnstagedFiles]
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d\v!9.0.30729.1\UnstagedFiles]
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1\UnstagedFiles]
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\v!9.0.21022.8\UnstagedFiles]
The Malware deletes the following value(s) in system registry:
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90fra.dll"
"mfc90esp.dll"
[HKLM\COMPONENTS]
"PoqexecFailure"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_bbd99e435df8a088]
"SomeUnparsedVersionsExist"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90rus.dll"
"mfc90enu.dll"
[HKLM\COMPONENTS]
"PendingXmlIdentifier"
"LastScavengeFlags"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_1eef21b42ca2596f]
"SomeUnparsedVersionsExist"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90esn.dll"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809\v!9.0.21022.8\UnstagedFiles]
"vcomp90.dll"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_bb797aeb5e404097]
"SomeUnparsedVersionsExist"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1\UnstagedFiles]
"mfcm90u.dll"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d\v!9.0.30729.1\UnstagedFiles]
"atl90.dll"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.1\UnstagedFiles]
"msvcr90.dll"
"msvcp90.dll"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90jpn.dll"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_none_a268ec259de3174d]
"SomeUnparsedVersionsExist"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1\UnstagedFiles]
"mfc90.dll"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90chs.dll"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2]
"SomeUnparsedVersionsExist"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471\v!9.0.30729.1\UnstagedFiles]
"msvcm90.dll"
[HKLM\COMPONENTS]
"RepairTransactionPended"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90kor.dll"
[HKLM\COMPONENTS]
"LastScavengeCookie"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90deu.dll"
[HKLM\COMPONENTS]
"ExecutionState"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_bb22ca2f5e815913]
"SomeUnparsedVersionsExist"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1\UnstagedFiles]
"mfc90u.dll"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_399d052615c6abee]
"SomeUnparsedVersionsExist"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4]
"SomeUnparsedVersionsExist"
[HKLM\COMPONENTS]
"StoreDirty"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_none_a2f75f3b9d7989e4\v!9.0.30729.1\UnstagedFiles]
"mfcm90.dll"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90cht.dll"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_none_ba5d016b21242809]
"SomeUnparsedVersionsExist"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_none_a28692199dcba471]
"SomeUnparsedVersionsExist"
[HKLM\COMPONENTS\DerivedData\VersionedIndex\6.1.7601.17592 (win7sp1_gdr.110408-1631)\ComponentFamilies\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_none_f0ee8071fb10f4e2\v!9.0.30729.1\UnstagedFiles]
"mfc90ita.dll"
The process pm-standalone-setup.tmp:1440 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F88FC5D-4D46-448A-AF59-7061FFC6ABBF}_is1]
"Inno Setup: Icon Group" = "Uniblue\PC Mechanic"
[HKCR\pc-mechanic]
"URL Protocol" = ""
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F88FC5D-4D46-448A-AF59-7061FFC6ABBF}_is1]
"NoModify" = "1"
"NoRepair" = "1"
"Inno Setup: Language" = "en"
"EstimatedSize" = "60952"
"InstallDate" = "20150131"
"Comments" = "Uninstall PC Mechanic"
"MinorVersion" = "0"
[HKLM\SOFTWARE\Wow6432Node\Uniblue\PC-Mechanic]
"EcommercePlatform" = "cleverbridge"
[HKCR\pc-mechanic\DefaultIcon]
"(Default)" = "pc-mechanic.exe,1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F88FC5D-4D46-448A-AF59-7061FFC6ABBF}_is1]
"Inno Setup: Selected Tasks" = "desktopicon,quicklaunchicon"
"Inno Setup: User" = "%CurrentUserName%"
"Inno Setup: Deselected Tasks" = ""
[HKLM\SOFTWARE\Wow6432Node\Uniblue\PC-Mechanic]
"InstalledLocation" = "%Program Files% (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F88FC5D-4D46-448A-AF59-7061FFC6ABBF}_is1]
"QuietUninstallString" = "%Program Files% (x86)\Uniblue\PC-Mechanic\unins000.exe /SILENT"
[HKLM\SOFTWARE\Wow6432Node\Uniblue\PC-Mechanic]
"PurchaseUrl" = "http://www.uniblue.com/cm/afterdownload/pcmechanicpm/cast-de-01/purchase/"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F88FC5D-4D46-448A-AF59-7061FFC6ABBF}_is1]
"URLUpdateInfo" = "http://uniblue.com/software/pcmechanicpm/updates/"
"UninstallString" = "%Program Files% (x86)\Uniblue\PC-Mechanic\unins000.exe"
[HKCR\pc-mechanic]
"(Default)" = "URL:PC-Mechanic Protocol"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F88FC5D-4D46-448A-AF59-7061FFC6ABBF}_is1]
"MajorVersion" = "1"
"DisplayName" = "PC Mechanic"
"Publisher" = "Uniblue Systems Limited"
"HelpLink" = "http://www.uniblue.com/support/manuals/"
[HKLM\SOFTWARE\Wow6432Node\Uniblue\PC-Mechanic]
"InstallDate" = "2015-01-31"
[HKCR\pc-mechanic\shell\open\command]
"(Default)" = "%Program Files% (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe --serial=%1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F88FC5D-4D46-448A-AF59-7061FFC6ABBF}_is1]
"Inno Setup: Setup Version" = "5.5.4 (u)"
"DisplayIcon" = "%Program Files% (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe"
"InstallLocation" = "%Program Files% (x86)\Uniblue\PC-Mechanic\"
"DisplayVersion" = "1.0.3.2"
"URLInfoAbout" = "http://www.uniblue.com/support/"
[HKLM\SOFTWARE\Wow6432Node\Uniblue\PC-Mechanic]
"lang" = "en"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F88FC5D-4D46-448A-AF59-7061FFC6ABBF}_is1]
"Inno Setup: App Path" = "%Program Files% (x86)\Uniblue\PC-Mechanic"
The Malware deletes the following value(s) in system registry:
[HKCR\pc-mechanic]
"URL Protocol"
[HKCR\pc-mechanic\DefaultIcon]
"(Default)"
[HKCR\pc-mechanic]
"(Default)"
[HKCR\pc-mechanic\shell\open\command]
"(Default)"
[HKLM\SOFTWARE\Wow6432Node\Uniblue\PC-Mechanic]
"PurchaseUrl"
"InstalledLocation"
The process 6c025c909d14bf5ec55b5f45e6411902.tmp:3640 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "9D 31 BE 43 E1 3C D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKLM\SOFTWARE\Wow6432Node\Uniblue\PC-Mechanic]
"InstallerBuiltWithOffers" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{9C99CCBB-10A0-4B2A-A5BE-4CAC43F74632}]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f3-c8-bd]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{9C99CCBB-10A0-4B2A-A5BE-4CAC43F74632}]
"WpadNetworkName" = "Network 3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f3-c8-bd]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 40 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{9C99CCBB-10A0-4B2A-A5BE-4CAC43F74632}]
"WpadDecisionReason" = "1"
"WpadDecisionTime" = "9D 31 BE 43 E1 3C D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f3-c8-bd]
"WpadDecisionTime" = "9D 31 BE 43 E1 3C D0 01"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Malware deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f3-c8-bd]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{9C99CCBB-10A0-4B2A-A5BE-4CAC43F74632}]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process pc-mechanic.exe:4044 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Uniblue\PC-Mechanic]
"IsRegistered" = "0"
To automatically run itself each time Windows is booted, the Malware adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VMware User Process" = "%Program Files%\VMware\VMware Tools\vmtoolsd.exe -n vmusr"
"VMware Tools" = "%Program Files%\VMware\VMware Tools\VMwareTray.exe"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM" = "%Program Files% (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" = "%Program Files% (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched" = "%Program Files% (x86)\Common Files\Java\Java Update\jusched.exe"
The process pc-mechanic.exe:3392 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Uniblue\PC-Mechanic]
"IsRegistered" = "0"
To automatically run itself each time Windows is booted, the Malware adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VMware User Process" = "%Program Files%\VMware\VMware Tools\vmtoolsd.exe -n vmusr"
"VMware Tools" = "%Program Files%\VMware\VMware Tools\VMwareTray.exe"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM" = "%Program Files% (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" = "%Program Files% (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched" = "%Program Files% (x86)\Common Files\Java\Java Update\jusched.exe"
Dropped PE files
MD5 | File path |
---|---|
96f6e497f8ce5bc21b9d3140965104aa | c:\Program Files (x86)\MyPC Backup\AlphaFS.dll |
5bfc53c0daee82e70ef02b9cf7ae3042 | c:\Program Files (x86)\MyPC Backup\AlphaVSS.51.x86.dll |
ba1d420f7fa1b4eef8cc127bee74a023 | c:\Program Files (x86)\MyPC Backup\AlphaVSS.52.x64.dll |
568754948b2aa5fcc41217fb28425cc5 | c:\Program Files (x86)\MyPC Backup\AlphaVSS.52.x86.dll |
a3ef02398e089dcd9708cbc4e427d0f7 | c:\Program Files (x86)\MyPC Backup\AlphaVSS.60.x64.dll |
057cf7fd20135899d616714534d0b7a8 | c:\Program Files (x86)\MyPC Backup\AlphaVSS.60.x86.dll |
3116e40a8b9709917e1dc1db4e068152 | c:\Program Files (x86)\MyPC Backup\AlphaVSS.Common.dll |
a0a4dd8d711d55884c163a3784eac55e | c:\Program Files (x86)\MyPC Backup\BackupStack.exe |
3c3cb9d58660b527d47e7d46d292940c | c:\Program Files (x86)\MyPC Backup\BackupStackUI.dll |
d15d57943417ca58884e643da0ce2464 | c:\Program Files (x86)\MyPC Backup\BplusDotNet.dll |
f5b669bd36f27089b36323ccbf8ebcda | c:\Program Files (x86)\MyPC Backup\Configuration Updater.exe |
76928476bdcf7ea4dbe8589d85793315 | c:\Program Files (x86)\MyPC Backup\GetText.dll |
c97cc489f20c67c3b2f36782ca139ce4 | c:\Program Files (x86)\MyPC Backup\InstMgr.dll |
6ded8fcbf5f1d9e422b327ca51625e24 | c:\Program Files (x86)\MyPC Backup\Ionic.Zip.dll |
e5cc3997457cd365e43c19f0f9110148 | c:\Program Files (x86)\MyPC Backup\LinqBridge.dll |
9b2ac62a9aab3369b253411c14b92fcb | c:\Program Files (x86)\MyPC Backup\LogicNP.EZShellExtensions.dll |
e4da474b2f2415664a286c07022222a0 | c:\Program Files (x86)\MyPC Backup\MPCBClient.dll |
dddf97700f9d4a951783b73d5971ce48 | c:\Program Files (x86)\MyPC Backup\MPCBContextMenu.dll |
24b83d9a02acf4b10c3fe0e9f7153eef | c:\Program Files (x86)\MyPC Backup\Microsoft.Win32.TaskScheduler.dll |
01623e484d03fe777a733f3f6f28d673 | c:\Program Files (x86)\MyPC Backup\MyPC Backup.exe |
f89e670f3f9de99e80b4d39436a27d9e | c:\Program Files (x86)\MyPC Backup\NativeHashWrapper.dll |
16da92c91e58f6d8a22e493ae442edbf | c:\Program Files (x86)\MyPC Backup\Newtonsoft.Json.dll |
6e0e7abd35565d70986eedc71f1a7bb5 | c:\Program Files (x86)\MyPC Backup\ObjectListView.dll |
6605874ea071ad6904aa8f67e75c18a1 | c:\Program Files (x86)\MyPC Backup\PipeDiff.dll |
4bb211393828d585cb5396a273008d94 | c:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet20_x64.exe |
74a8c01b69adedd7f1330245cd994821 | c:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet20_x86.exe |
bb830033c3e24a0b82caf23662918278 | c:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet40_x64.exe |
a6a26e38b3596fa740f7039d98bd3a22 | c:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet40_x86.exe |
0d8aa68059d0103b04ef5afdf755f779 | c:\Program Files (x86)\MyPC Backup\Service Start.exe |
6f5ab2bf45a14dedcb642e804480c9c7 | c:\Program Files (x86)\MyPC Backup\Shared Stack.dll |
9d0cc110ab0605885d98ae08377f6f66 | c:\Program Files (x86)\MyPC Backup\Signup Wizard.exe |
eeabc4815562083a50a666e2709c5998 | c:\Program Files (x86)\MyPC Backup\SignupWizard.dll |
0790e1d72901d1b98a9abfd43d1c592c | c:\Program Files (x86)\MyPC Backup\System.Data.SQLite.DLL |
ba95c010731d3a1b20816242995e5a5a | c:\Program Files (x86)\MyPC Backup\UnRegisterExtensions.exe |
da063ab4cd89efa829dbdce1fcb1cf70 | c:\Program Files (x86)\MyPC Backup\Updater.exe |
0cc8dad6c96bb0f2a833e0cb460d4191 | c:\Program Files (x86)\MyPC Backup\Updater_.dll |
53b9dfe8be74f29dc10d12df6b438f31 | c:\Program Files (x86)\MyPC Backup\uninst.exe |
1688cecb8af9cedde1b60163c98d1765 | c:\Program Files (x86)\MyPC Backup\websocket-sharp.dll |
fd666249228fb1be3f9fc9399aa70d3a | c:\Program Files (x86)\MyPC Backup\x64\SQLite.Interop.dll |
f25a493607f771a033a3afe8ac26a505 | c:\Program Files (x86)\MyPC Backup\x86\SQLite.Interop.dll |
48ce483b35ec55934a93b8c32cede736 | c:\Program Files (x86)\Uniblue\PC-Mechanic\InstallerExtensions.dll |
6de5c66e434a9c1729575763d891c6c2 | c:\Program Files (x86)\Uniblue\PC-Mechanic\Microsoft.VC90.CRT\msvcp90.dll |
e7d91d008fe76423962b91c43c88e4eb | c:\Program Files (x86)\Uniblue\PC-Mechanic\Microsoft.VC90.CRT\msvcr90.dll |
5434e18b933e03f274d8da59fda4c676 | c:\Program Files (x86)\Uniblue\PC-Mechanic\icudt.dll |
28888738b5521923a244fac763767db4 | c:\Program Files (x86)\Uniblue\PC-Mechanic\libcef.dll |
5f80133157f2ef44e19ea964137848e3 | c:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe |
a729dd5a4af3bd99e3a86e121e142021 | c:\Program Files (x86)\Uniblue\PC-Mechanic\thirdpartyinstaller.exe |
c92d15d69405371b6c833b682d6f5607 | c:\Program Files (x86)\Uniblue\PC-Mechanic\unins000.exe |
256f360db3c119ab9e1b6eb4c8f66680 | c:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\aff_setup[1].exe |
52f5313d363b68bad93495af8bc771a6 | c:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\pcmechanicpm-standalone-setup[1].exe |
bcba8747ab53932f8613c006444078e9 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\CloudBackup3581.exe |
256f360db3c119ab9e1b6eb4c8f66680 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\Uniblue\Offers\aff_setup.exe |
48ce483b35ec55934a93b8c32cede736 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\InstallerExtensions.dll |
526426126ae5d326d0a24706c77d8c5c | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\_isetup\_setup64.tmp |
92dc6ef532fbb4a5c3201469a5b5eb63 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\_isetup\_shfoldr.dll |
52f5313d363b68bad93495af8bc771a6 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\pm-standalone-setup.exe |
62efa7b730eb0523a026ea4325403b77 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\nsSCM.dll |
40395c175553cb14d2050888efccdf00 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\vcredist_x64.exe |
c101f49f8fbdc203757ebf954d83af12 | c:\Windows\Installer\$PatchCache$\Managed\EFEE0228DC83E77358593193D847A0EC\9.0.30729\FL_msdia71_dll_2_60035_amd64_ln.3643236F_FC70_11D3_A536_0090278A1BB8 |
45e475fa46d8f04a682eb5eed5476e08 | c:\Windows\winsxs\amd64_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_9aefdaaa829eb818\ATL90.dll |
1e7ce519349ca4b49930ad843470a3f9 | c:\Windows\winsxs\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_99b61f5e8371c1d4\msvcm90.dll |
1f914c93052445e6629c37b81d421f7b | c:\Windows\winsxs\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_99b61f5e8371c1d4\msvcp90.dll |
425d035880430fbed64dd6205c77f5b2 | c:\Windows\winsxs\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_99b61f5e8371c1d4\msvcr90.dll |
e75de70a944462a9912c93e888b4106f | c:\Windows\winsxs\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_951ab4128654b0c9\mfc90.dll |
6962af1e97d8566e9c3496dc118fd3b7 | c:\Windows\winsxs\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_951ab4128654b0c9\mfc90u.dll |
e6ffdd8f997366fd88a799743579d389 | c:\Windows\winsxs\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_951ab4128654b0c9\mfcm90.dll |
f668d2f0c2377cc3b1459506a00b0f0b | c:\Windows\winsxs\amd64_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_951ab4128654b0c9\mfcm90u.dll |
deebddd75a0ecb8afd463bd3b2d9131a | c:\Windows\winsxs\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb\MFC90CHS.DLL |
b0552cba0f603e1730762056add5eb9a | c:\Windows\winsxs\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb\MFC90CHT.DLL |
2822498a5df669d223e6b093c00cb93a | c:\Windows\winsxs\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb\MFC90DEU.DLL |
91e5d7df820fb0fe7ead68c32bead0da | c:\Windows\winsxs\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb\MFC90ENU.DLL |
85bdf40f2af1944f579a7a134bd08a34 | c:\Windows\winsxs\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb\MFC90ESN.DLL |
390ab412debb2be22fcaca5a59c9a3c2 | c:\Windows\winsxs\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb\MFC90ESP.DLL |
598dcb951afd9a3d3d2e1abf7603de60 | c:\Windows\winsxs\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb\MFC90FRA.DLL |
9e87f90e281ea1f41669920b349189c5 | c:\Windows\winsxs\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb\MFC90ITA.DLL |
67695d68d782b48625a6c3ec08954216 | c:\Windows\winsxs\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb\MFC90JPN.DLL |
91f1a8b875354dd5a1939e329af45656 | c:\Windows\winsxs\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb\MFC90KOR.DLL |
32a4c8c6c2d09b98b14af92cd991a6d8 | c:\Windows\winsxs\amd64_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_92995f253c01eddb\MFC90RUS.DLL |
63e472c8410a0e9ce25c35a0482bbbbf | c:\Windows\winsxs\amd64_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_a5325551f9d85633\vcomp90.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
aff_setup.exe:2408
MyPC Backup.exe:880
install.exe:1872
CloudBackup3581.exe:1528
thirdpartyinstaller.exe:3424
vcredist_x64.exe:2348
makecab.exe:2224
TrustedInstaller.exe:3324
pm-standalone-setup.exe:504
pm-standalone-setup.tmp:1440
%original file name%.exe:2944
6c025c909d14bf5ec55b5f45e6411902.tmp:3640
pc-mechanic.exe:4044 - Delete the original Malware file.
- Delete or disinfect the following files created/modified by the Malware:
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Stuff2.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Stuff5.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nszA0C3.tmp\LogEx.dll (1597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Stuff4.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Stuff3.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aff.conf (491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\readme.txt (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsuA0A3.tmp (10479 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Stuff1.txt (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\data3.dat (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nszA0C3.tmp\nsisdl.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\data1.dat (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\data2.dat (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nszA0C3.tmp\nsRandom.dll (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\log.txt (327 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nszA0C3.tmp\nsJSON.dll (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CloudBackup3581.exe (22107 bytes)
%Program Files% (x86)\MyPC Backup\System.Data.SQLite.DLL (282 bytes)
%Program Files% (x86)\MyPC Backup\Microsoft.Win32.TaskScheduler.dll (208 bytes)
%Program Files% (x86)\MyPC Backup\Newtonsoft.Json.dll (495 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\42B9A473B4DAF01285A36B4D3C7B1662_178C086B699FD6C56B804AF3EF759CB5 (471 bytes)
%Program Files% (x86)\MyPC Backup\x64\SQLite.Interop.dll (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\66AE3BFDF94A732B262342AD2154B86E_7DD744F73D87EE469E5BC583C31249E2 (1624 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 (370 bytes)
%Program Files% (x86)\MyPC Backup\Shared Stack.dll (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarB9ED.tmp (2784 bytes)
%Program Files% (x86)\MyPC Backup\ObjectListView.dll (430 bytes)
%Program Files% (x86)\MyPC Backup\GetText.dll (12 bytes)
%Program Files% (x86)\MyPC Backup\Database\mpcb_settings.db-journal (39970 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\66AE3BFDF94A732B262342AD2154B86E_7DD744F73D87EE469E5BC583C31249E2 (471 bytes)
%Program Files% (x86)\MyPC Backup\BackupStackUI.dll (49 bytes)
C:\Users\"%CurrentUserName%"\Desktop\Sync Folder.lnk (1 bytes)
%Program Files% (x86)\MyPC Backup\AlphaFS.dll (270 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabB9EC.tmp (56 bytes)
%Program Files% (x86)\MyPC Backup\log\WAIT_HANDLES.log (540 bytes)
%Program Files% (x86)\MyPC Backup\MPCBClient.dll (192 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\42B9A473B4DAF01285A36B4D3C7B1662_178C086B699FD6C56B804AF3EF759CB5 (1624 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 (56 bytes)
%Program Files% (x86)\MyPC Backup\LinqBridge.dll (61 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1033.dll (94 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredistUI6086.txt (120910 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VWLBF29.tmp (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\dd_vcredistMSI6086.txt (202619 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup\Uninstall.lnk (840 bytes)
%Program Files% (x86)\MyPC Backup\x86\SQLite.Interop.dll (5056 bytes)
%Program Files% (x86)\MyPC Backup\Service Start.exe (14 bytes)
%Program Files% (x86)\MyPC Backup\pt_PT.mo (59 bytes)
%Program Files% (x86)\MyPC Backup\AlphaVSS.60.x64.dll (2096 bytes)
%Program Files% (x86)\MyPC Backup\AlphaVSS.52.x86.dll (644 bytes)
%Program Files% (x86)\MyPC Backup\SignupWizard.dll (4674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\AccessControl.dll (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mpbtrk.log (8 bytes)
%Program Files% (x86)\MyPC Backup\PipeDiff.dll (1414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\nsSCM.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\nsRandom.dll (808 bytes)
%Program Files% (x86)\MyPC Backup\BackupStack.exe (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\NSISdl.dll (30 bytes)
%Program Files% (x86)\MyPC Backup\Configuration Updater.exe (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup\MyPC Backup.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\nsis7z.dll (6536 bytes)
%Program Files% (x86)\MyPC Backup\NativeHashWrapper.dll (7 bytes)
C:\Users\"%CurrentUserName%"\Desktop\MyPC Backup.lnk (1 bytes)
%Program Files% (x86)\MyPC Backup\AlphaVSS.60.x86.dll (1882 bytes)
%Program Files% (x86)\MyPC Backup\uninst.exe (2301 bytes)
%Program Files% (x86)\MyPC Backup\Updater.exe (1695 bytes)
%Program Files% (x86)\MyPC Backup\MyPC Backup.exe (4808 bytes)
%Program Files% (x86)\MyPC Backup\RegisterExtensionDotNet20_x86.exe (20 bytes)
%Program Files% (x86)\MyPC Backup\AlphaVSS.51.x86.dll (643 bytes)
%Program Files% (x86)\MyPC Backup\LogicNP.EZShellExtensions.dll (1918 bytes)
%Program Files% (x86)\MyPC Backup\RegisterExtensionDotNet40_x64.exe (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\System.dll (23 bytes)
%Program Files% (x86)\MyPC Backup\mypcbackup.ico (381 bytes)
%Program Files% (x86)\MyPC Backup\AlphaVSS.52.x64.dll (1303 bytes)
%Program Files% (x86)\MyPC Backup\fr_FR.mo (61 bytes)
%Program Files% (x86)\MyPC Backup\Updater_.dll (1325 bytes)
%Program Files% (x86)\MyPC Backup\Ionic.Zip.dll (3317 bytes)
%Program Files% (x86)\MyPC Backup\syncicon.ico (61 bytes)
%Program Files% (x86)\MyPC Backup\de_DE.mo (60 bytes)
%Program Files% (x86)\MyPC Backup\es_ES.mo (60 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\DotNetChecker.dll (1597 bytes)
%Program Files% (x86)\MyPC Backup\InstMgr.dll (10 bytes)
%Program Files% (x86)\MyPC Backup\AlphaVSS.Common.dll (502 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA564.tmp\nsExec.dll (14 bytes)
%Program Files% (x86)\MyPC Backup\RegisterExtensionDotNet20_x64.exe (1856 bytes)
%Program Files% (x86)\MyPC Backup\BplusDotNet.dll (1198 bytes)
%Program Files% (x86)\MyPC Backup\it_IT.mo (57 bytes)
%Program Files% (x86)\MyPC Backup\RegisterExtensionDotNet40_x86.exe (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\vcredist_x64.exe (323789 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MyPC Backup.7z (268847 bytes)
%Program Files% (x86)\MyPC Backup\UnRegisterExtensions.exe (9 bytes)
%Program Files% (x86)\MyPC Backup\MPCBContextMenu.dll (16984 bytes)
%Program Files% (x86)\MyPC Backup\websocket-sharp.dll (1031 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsoA563.tmp (16365 bytes)
%Program Files% (x86)\MyPC Backup\Signup Wizard.exe (4132 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Uniblue\Offers\aff_setup.exe (266 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\installer_mypcbackup.log (853 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.DebugOpenMP.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.DebugCRT.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.ATL.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1040.dll (2110 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.DebugMFC.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.DebugOpenMP.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1031.txt (229 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.DebugMFC.cat (236 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1028.txt (3 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.ini (844 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\vc_red.cab (65618 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.CRT.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1041.txt (5 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.3082.dll (989 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.exe (13918 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.CRT.cat (630 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.MFCLOC.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.OpenMP.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1042.txt (650 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.2052.dll (1632 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.MFCLOC.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1049.txt (13 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\$shtdwn$.req (788 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1028.dll (1130 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.ATL.cat (155 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\vcredist.bmp (5 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.3082.txt (12 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.MFC.cat (658 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\Microsoft.VC90.MFC.cat (9 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.2052.txt (3 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1036.dll (1355 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1031.dll (1160 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1042.dll (1988 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1040.txt (657 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.OpenMP.cat (297 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\vc_red.msi (3176 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1049.dll (1720 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1036.txt (12 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\globdata.ini (1 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\install.res.1041.dll (1126 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\eula.1033.txt (10 bytes)
C:\bf79ab0483c84e397086a4c13a55087f\Program Files(64)\Microsoft Visual Studio 9.0\Vc7\WinSXS\AMD64 catalogs\policy.9.00.Microsoft.VC90.DebugCRT.cat (9 bytes)
C:\Windows\Temp\cab_2224_6 (8 bytes)
C:\Windows\Temp\cab_2224_4 (564989 bytes)
C:\Windows\Temp\cab_2224_5 (76 bytes)
C:\Windows\Temp\cab_2224_2 (564989 bytes)
C:\Windows\Temp\cab_2224_3 (76 bytes)
C:\Windows\Logs\CBS\CbsPersist_20150130230556.cab (11744 bytes)
C:\Windows\System32\config\TxR\{016888cc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.0.regtrans-ms (19520 bytes)
C:\Windows\winsxs\Temp\0eb4154fe13cd0013f000000fc0c3808\0eb4154fe13cd00141000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\61d3a54ee13cd00118000000fc0c3808\c134a84ee13cd0011a000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\569c464ee13cd00102000000fc0c3808\569c464ee13cd00103000000fc0c3808_manifest (859 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00131000000fc0c3808_mfc90cht.dll (79 bytes)
C:\Windows\System32\config\COMPONENTS{15e3db1a-917a-11e2-9ef7-000c29a8bd90}.TMContainer00000000000000000002.regtrans-ms (28680 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808\63deb84ee13cd00120000000fc0c3808_mfcm90.dll (670 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00137000000fc0c3808_mfc90ita.dll (129 bytes)
C:\Windows\winsxs\Temp\569c464ee13cd00102000000fc0c3808\569c464ee13cd00105000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00133000000fc0c3808_mfc90esp.dll (130 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808\63deb84ee13cd00121000000fc0c3808_mfc90u.dll (38780 bytes)
C:\Windows\winsxs\Temp\b268394fe13cd0014c000000fc0c3808\b268394fe13cd0014e000000fc0c3808_catalog (22 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\ca60f44ee13cd00130000000fc0c3808_mfc90chs.dll (78 bytes)
C:\Windows\System32\config\SOFTWARE (63648 bytes)
C:\Windows\winsxs\Temp\3ea48b4ee13cd0010f000000fc0c3808\3ea48b4ee13cd00111000000fc0c3808_msvcr90.dll (4811 bytes)
C:\Windows\System32\config\COMPONENTS{15e3db19-917a-11e2-9ef7-000c29a8bd90}.TxR.2.regtrans-ms (856 bytes)
C:\Windows\Logs\CBS\CBS.log (86767 bytes)
C:\Windows\winsxs\ManifestCache\a786a517e28d5687_blobs.bin (4409 bytes)
C:\Windows\winsxs\Temp\3ea48b4ee13cd0010f000000fc0c3808\3ea48b4ee13cd00110000000fc0c3808_manifest (5 bytes)
C:\Windows\winsxs\Temp\50fc234fe13cd00145000000fc0c3808 (4 bytes)
C:\Windows\winsxs\Temp\3ea48b4ee13cd0010f000000fc0c3808\3ea48b4ee13cd00112000000fc0c3808_msvcp90.dll (7701 bytes)
C:\Windows\System32\config\COMPONENTS{15e3db19-917a-11e2-9ef7-000c29a8bd90}.TxR.0.regtrans-ms (77937 bytes)
C:\Windows\System32\config\COMPONENTS{15e3db19-917a-11e2-9ef7-000c29a8bd90}.TxR.1.regtrans-ms (856 bytes)
C:\Windows\winsxs\Temp\9cfa7a4ee13cd00109000000fc0c3808\9cfa7a4ee13cd0010b000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\b268394fe13cd0014c000000fc0c3808\b268394fe13cd0014d000000fc0c3808_manifest (676 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00139000000fc0c3808_mfc90kor.dll (95 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd0013a000000fc0c3808_mfc90rus.dll (127 bytes)
C:\Windows\winsxs\Temp\569c464ee13cd00102000000fc0c3808\569c464ee13cd00104000000fc0c3808_atl90.dll (853 bytes)
C:\Windows\winsxs\Temp\61d3a54ee13cd00118000000fc0c3808\61d3a54ee13cd00119000000fc0c3808_manifest (760 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00132000000fc0c3808_mfc90esn.dll (130 bytes)
C:\Windows\System32\config\TxR\{016888cc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.blf (1640 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\ca60f44ee13cd0012f000000fc0c3808_manifest (13 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808\c43fbb4ee13cd00122000000fc0c3808_mfc90.dll (38780 bytes)
C:\Windows\System32\config\SYSTEM.LOG1 (4395 bytes)
C:\Windows\winsxs\Temp\50fc234fe13cd00145000000fc0c3808\50fc234fe13cd00148000000fc0c3808_catalog (22 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808\63deb84ee13cd0011f000000fc0c3808_manifest (6 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00138000000fc0c3808_mfc90jpn.dll (95 bytes)
C:\Windows\winsxs\Temp\3ea48b4ee13cd0010f000000fc0c3808\3ea48b4ee13cd00113000000fc0c3808_msvcm90.dll (1526 bytes)
C:\Windows\winsxs\Temp\3ea48b4ee13cd0010f000000fc0c3808\3ea48b4ee13cd00114000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\9cfa7a4ee13cd00109000000fc0c3808\9cfa7a4ee13cd0010a000000fc0c3808_manifest (760 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00134000000fc0c3808_mfc90deu.dll (670 bytes)
C:\Windows\System32\config\SOFTWARE.LOG1 (64960 bytes)
C:\Windows\System32\config\TxR\{016888cd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms (15608 bytes)
C:\Windows\winsxs\Temp\28b7e34ee13cd00128000000fc0c3808 (4 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00136000000fc0c3808_mfc90fra.dll (670 bytes)
C:\Windows\winsxs\Temp\28b7e34ee13cd00128000000fc0c3808\28b7e34ee13cd0012a000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808\24a1bd4ee13cd00124000000fc0c3808_catalog (21 bytes)
C:\Windows\System32\config\COMPONENTS.LOG1 (191164 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd0013b000000fc0c3808_catalog (21 bytes)
C:\Windows\winsxs\Temp\50fc234fe13cd00145000000fc0c3808\50fc234fe13cd00147000000fc0c3808_vcomp90.dll (120 bytes)
C:\Windows\winsxs\Temp\50fc234fe13cd00145000000fc0c3808\50fc234fe13cd00146000000fc0c3808_manifest (864 bytes)
C:\Windows\winsxs\Temp\0eb4154fe13cd0013f000000fc0c3808\0eb4154fe13cd00140000000fc0c3808_manifest (766 bytes)
C:\Windows\winsxs\Temp\ca60f44ee13cd0012e000000fc0c3808\2ac2f64ee13cd00135000000fc0c3808_mfc90enu.dll (113 bytes)
C:\Windows\System32\config\COMPONENTS{15e3db19-917a-11e2-9ef7-000c29a8bd90}.TxR.blf (8230 bytes)
C:\Windows\winsxs\Temp\28b7e34ee13cd00128000000fc0c3808\28b7e34ee13cd00129000000fc0c3808_manifest (760 bytes)
C:\Windows\winsxs\Temp\63deb84ee13cd0011e000000fc0c3808\c43fbb4ee13cd00123000000fc0c3808_mfcm90u.dll (670 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-TA980.tmp\pm-standalone-setup.tmp (50 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-IBQ5C.tmp (112 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Microsoft.VC90.CRT\is-1GEN8.tmp (4545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp\windows8_with_innovation.bmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\unins000.dat (30302 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-N9PL0.tmp (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp\license.en.rtf (26 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-5ICMG.tmp (1281 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\es\LC_MESSAGES\is-QJ2BK.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-DA0NO.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-DKOGT.tmp (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp\_isetup\_setup64.tmp (6 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Microsoft.VC90.CRT\is-55FN0.tmp (3361 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\da\LC_MESSAGES\is-5L243.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-VFP0C.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-A3B01.tmp (1281 bytes)
C:\Users\Public\Desktop\PC Mechanic.lnk (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-BKC34.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\sv\LC_MESSAGES\is-3Q6ED.tmp (601 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue\PC Mechanic\PC Mechanic.lnk (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-C9T7Q.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-1LTQ0.tmp (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Setup Log 2015-01-31 #002.txt (459835 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-K23KM.tmp (1281 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-PSFT7.tmp (1281 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-DR3V7.tmp (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PC-Mechanic.lnk (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\fr\LC_MESSAGES\is-B51D6.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\pt_BR\LC_MESSAGES\is-9QQL9.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-FT8MB.tmp (28498 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-IT2DN.tmp (10 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-BO9N4.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\nl\LC_MESSAGES\is-E6RTB.tmp (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp\printer.bmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\unins000.exe (49 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-UV01E.tmp (35285 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\de\LC_MESSAGES\is-URG36.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-MHV0A.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-0R0I5.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\unins000.msg (646 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Microsoft.VC90.CRT\is-NNP27.tmp (524 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locales\is-N7MHM.tmp (4 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\en\LC_MESSAGES\is-8B81S.tmp (62 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp\InstallerExtensions.dll (715 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-56JFR.tmp (13 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\ja\LC_MESSAGES\is-6HRBP.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-4LT1Q.tmp (1281 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-N1BQ0.tmp (1281 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-ULURG.tmp (107054 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-MV9VQ.tmp (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\ru\LC_MESSAGES\is-MC22J.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\no\LC_MESSAGES\is-8OV7F.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-5V5K2.tmp (75544 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-TNEM0.tmp (19686 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\it\LC_MESSAGES\is-T8LQT.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\fonts\is-F9HHB.tmp (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-L767M.tmp\_isetup\_shfoldr.dll (47 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\locale\fi\LC_MESSAGES\is-QFQDG.tmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\is-4B0N8.tmp (197872 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe (291 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue\PC Mechanic\Uninstall PC Mechanic.lnk (1 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\Third-party Terms\is-R5JFE.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-P6RBB.tmp\6c025c909d14bf5ec55b5f45e6411902.tmp (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F7QBP14P\pcmechanicpm-standalone-setup[1].exe (1571123 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\046C1ZNT\aff_setup[1].exe (33950 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\thirdpartyinstaller.exe (98 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\_isetup\_shfoldr.dll (47 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\pm_logo.bmp (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\pm-standalone-setup.exe (115616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\license.en.rtf (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\backupmypc_logo.bmp (39 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\printer.bmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\InstallerExtensions.dll (715 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\_isetup\_setup64.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\microsoft_partner.bmp (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\banner_icon.bmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\backupmypc_check_mark.bmp (310 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Setup Log 2015-01-31 #001.txt (21109 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-GM70U.tmp\windows8_with_innovation.bmp (601 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\icudt.dll (2183 bytes)
C:\Windows\Tasks\PC-Mechanic Startup.job (684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Uniblue\PC-Mechanic\settings.dat (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Uniblue\PC-Mechanic\error.log (5943 bytes)
%Program Files% (x86)\Uniblue\PC-Mechanic\libcef.dll (10562 bytes)
C:\Windows\Tasks\PC-Mechanic Maintenance.job (702 bytes)
C:\Windows\Tasks\PC-Mechanic Subscription.job (702 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VMware User Process" = "%Program Files%\VMware\VMware Tools\vmtoolsd.exe -n vmusr"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VMware Tools" = "%Program Files%\VMware\VMware Tools\VMwareTray.exe"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM" = "%Program Files% (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher" = "%Program Files% (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched" = "%Program Files% (x86)\Common Files\Java\Java Update\jusched.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
Company Name: Uniblue Systems Limited
Product Name: PC Mechanic
Product Version: 1.0.3.2
Legal Copyright: Copyright (c) Uniblue Systems Limited
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1.0.3.2
File Description: PC Mechanic Setup
Comments: This installation was built with Inno Setup.
Language: English (Australia)
Company Name: Uniblue Systems LimitedProduct Name: PC Mechanic Product Version: 1.0.3.2Legal Copyright: Copyright (c) Uniblue Systems LimitedLegal Trademarks: Original Filename: Internal Name: File Version: 1.0.3.2File Description: PC Mechanic Setup Comments: This installation was built with Inno Setup.Language: English (Australia)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 61740 | 61952 | 4.43024 | 3a126e478661f20816f9d9285615f98e |
.itext | 69632 | 2884 | 3072 | 3.97317 | ba48b9b17b3dd8b92da3bd93f20ddb34 |
.data | 73728 | 3208 | 3584 | 1.55702 | d7fd5f4b562d7961758f3d6a8c834fd0 |
.bss | 77824 | 22196 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.idata | 102400 | 3536 | 3584 | 3.44625 | 93d91a2b90e60bd758fc0c4908856ae1 |
.tls | 106496 | 8 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rdata | 110592 | 24 | 512 | 0.14174 | 3dffc444ccc131c9dcee18db49ee6403 |
.rsrc | 114688 | 240000 | 240128 | 3.69359 | 8bd4bcdd4c24b123c23fabbacecaebda |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 24
595f1fc6db9af2f5b74feffe71c7a123
185a96db3a2bbc40bddc627ce7ec02e0
e8efd38733bce8baad5da44d84e6f8de
e468ff0cb996937f4c29123e934b2a14
743f5c6ba924c3c101bb870b4c6fa5b2
af31602770ddfc6fe3f066cfa4c6c976
2b4e0076bf5a1bed17f4613e25f5644c
b03b26ac6825ba3011e85283e52300a0
58339a97c3c8bc0bbe81505a84c81d29
992cdcc9ece43dcbd3218ab143f22d3d
2e9bfaecf43dadbb705859240444b2f7
3c3b5caa1b052aa242e2a6df5b15710f
a0beccade004ab445975852b3c7b8c92
5bf203b8dde9bdf175b72878ebb1a2fc
50041e10befe22aacfb639a30a31d61b
d0312c748c6cf0eb401e7bce1edc9afb
14b7408523502e4f9c3814f8ce3d5887
4a39555aa14899fa694affa0ef16882c
d17192950a65ee8af656f4fa2ed16b51
e0c1a7969a62d89dd6bd2e63e84fb1c8
e147ae86f5cafbcbe5333820fe97b765
587d0a009b155e73294e178818afba22
3c04a5a809040d1d32f785285e591996
75e7eceef8e7ca5b32d0ad799f4d6c53
Network Activity
URLs
URL | IP |
---|---|
hxxp://backupgrid.jdibackup.netdna-cdn.com/aff_setup.exe | |
hxxp://tracking-uniblue-com-1314478381.eu-west-1.elb.amazonaws.com/v1/collect | |
hxxp://splitter-load-balancer-1436536024.us-east-1.elb.amazonaws.com/product/pm/1.0.3.2/pcmechanicpm-standalone-setup.exe | |
hxxp://d21bsqatndqkg8.cloudfront.net/product/pm/1.0.3.2/pcmechanicpm-standalone-setup.exe | 54.230.203.106 |
hxxp://splitter-load-balancer-1436536024.us-east-1.elb.amazonaws.com/pm/version.txt?from=1.0.3.2 | |
hxxp://tracking-uniblue-com-1314478381.eu-west-1.elb.amazonaws.com/v1/track | |
hxxp://s3-1-w.amazonaws.com/latest_updates/application.txt | |
hxxp://api.uniblue.net/v1/geo/country-code | 54.228.215.241 |
hxxp://track.mypcbackup.com/9bf5853a/D0wnloads-PC-Mechanic/MyPCBackup_Setup.exe | 184.154.139.131 |
hxxp://uniblue.com/api/v1/geo/country-code | 176.34.125.17 |
hxxp://uniblue-cdn-lb-eu-774953051.eu-west-1.elb.amazonaws.com/api/v1/geo/country-code | |
hxxp://mypcbackup.jdibackup.netdna-cdn.com/MyPCBackup_Setup.exe | |
hxxp://track.mypcbackup.com/aadebc4830c51c2794a960fe5a9e11df.php | 184.154.139.131 |
hxxp://a767.dscms.akamai.net/download/2/d/6/2d61c766-107b-409d-8fba-c39e61ca08e8/vcredist_x64.exe | |
hxxp://ep.backupgrid.net/install/win/1/live/net2 | 184.154.139.137 |
hxxp://backupgrid.jdibackup.netdna-cdn.com/mypcbackup.1.5.0.2.101.7z | |
hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?733473ba9bf116c3 | |
hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c716edbe6e72edb3 | |
hxxp://cs9.wac.edgecastcdn.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir/SSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW+VUAg= | |
hxxp://cs9.wac.edgecastcdn.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt+lGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAyvGbEyaFTw/abLEQ3zC1w= | |
hxxp://a1363.dscg.akamai.net/pki/crl/products/microsoftrootcert.crl | |
hxxp://a1363.dscg.akamai.net/pki/crl/products/WinPCA.crl | |
hxxp://a1363.dscg.akamai.net/pki/crl/products/MicrosoftTimeStampPCA.crl | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= | |
hxxp://e6845.ce.akamaiedge.net/pca3.crl | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ/xkCfyHfJr7GQ6M658NRZ4SHo/AQUCPVR6Pv+PT1kNnxoz1t4qN+5xTcCEGC2x6sSmevembHfY1acIZk= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEGwkCSV07gf3g5QOsqmf+MY= | |
hxxp://a1363.dscg.akamai.net/pki/crl/products/MicCodSigPCA_08-31-2010.crl | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= | |
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEDi14wrtdPbNBdjyDxjokeI= | |
hxxp://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl | 87.245.202.48 |
hxxp://download.microsoft.com/download/2/d/6/2d61c766-107b-409d-8fba-c39e61ca08e8/vcredist_x64.exe | 80.239.149.72 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEGwkCSV07gf3g5QOsqmf+MY= | 23.43.139.27 |
hxxp://pm.uniblue.com.s3.amazonaws.com/latest_updates/application.txt | 54.231.13.41 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ/xkCfyHfJr7GQ6M658NRZ4SHo/AQUCPVR6Pv+PT1kNnxoz1t4qN+5xTcCEGC2x6sSmevembHfY1acIZk= | 23.43.139.27 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= | 23.43.139.27 |
hxxp://tracking.uniblue.com/v1/collect | 54.247.176.17 |
hxxp://crl.verisign.com/pca3.crl | 23.43.133.163 |
hxxp://cdn.backupgrid.net/aff_setup.exe | 94.31.29.237 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= | 23.43.139.27 |
hxxp://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt+lGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAyvGbEyaFTw/abLEQ3zC1w= | 93.184.220.29 |
hxxp://www.uniblue.com/api/v1/geo/country-code | 54.247.110.16 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEDi14wrtdPbNBdjyDxjokeI= | 23.43.139.27 |
hxxp://crl.microsoft.com/pki/crl/products/WinPCA.crl | 87.245.202.48 |
hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?733473ba9bf116c3 | 87.245.202.24 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= | 23.43.139.27 |
hxxp://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl | 87.245.202.48 |
hxxp://tracking.uniblue.com/v1/track | 54.247.176.17 |
hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c716edbe6e72edb3 | 87.245.202.24 |
hxxp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl | 87.245.202.48 |
hxxp://update.uniblue.com/pm/version.txt?from=1.0.3.2 | 107.21.127.37 |
hxxp://cdn.mypcbackup.com/MyPCBackup_Setup.exe | 94.31.29.238 |
hxxp://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir/SSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW+VUAg= | 93.184.220.29 |
hxxp://download.uniblue.com/product/pm/1.0.3.2/pcmechanicpm-standalone-setup.exe | 54.243.120.72 |
hxxp://cdn.backupgrid.net/mypcbackup.1.5.0.2.101.7z | 94.31.29.237 |
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= | 23.43.139.27 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /pm/version.txt?from=1.0.3.2 HTTP/1.1
Accept-Encoding: identity
Host: update.uniblue.com
Connection: close
User-Agent: Python-urllib/2.7
HTTP/1.1 302 Found
Cache-Control: max-age=600
Content-Type: text/plain
Date: Fri, 30 Jan 2015 23:05:28 GMT
Location: hXXp://pm.uniblue.com.s3.amazonaws.com/latest_updates/application.txt
Server: openresty/1.5.8.1
Content-Length: 69
Connection: Close
hXXp://pm.uniblue.com.s3.amazonaws.com/latest_updates/application.txt..
GET /aff_setup.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/6.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C)
Host: cdn.backupgrid.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 30 Jan 2015 23:05:20 GMT
Content-Type: application/octet-stream
Transfer-Encoding: chunked
Connection: keep-alive
x-amz-id-2: q8QzEF0XsVq/YuqVDjkP5X7Kse9cUYcmA9rz4E TA7ApR6avXQzdDUoGY4dRSUNZ
x-amz-request-id: 1F8A317A1558F2BC
Last-Modified: Mon, 06 Oct 2014 10:15:06 GMT
ETag: W/"256f360db3c119ab9e1b6eb4c8f66680"
Server: NetDNA-cache/2.2
X-Cache: HIT
Content-Encoding: gzip
900a.............}.\TU...f.......mR,..YHIh..E.D.Gf..$..&..{M[.a.>.x...V[m..j..[....2......d.Vd..i..4D%....;.....g..~_.?>.z=...<.9.y..<..K.m... .....B......?....C.xm....w.l..}.....ZKuM......e...U..N..F...WZr..- ..\.....#M__.x.<4\...G.X~...Y....Q/...y..G.....K.*..\P..Mu...DA.........M..L...8A(F.^....7 l.TS)..........#T.* JZ.A@....zT.?/<(Q.\ ./..^p.....}..l.\...!..(....$..ZB.........d..Y.a....R.T......).NK..~V.d.VL8...k#2........BpRe.`...5.^*WS[..E4.........Yy....7....EJ....W.h...o."&.I..T...n.)...6U6.r.*...C.U...g..Jf....f'. ..,........q--.iJ]...#(#.V....3.......az..)../`..[.;....N..... ..I....../`.V.-...B.....6...Y......M/..w..S6.A........._L.i.$.)f ........Yu....UU}.-R%..j....Z.A.....D.....7..v...PS.(..Z.TS.)$' ...p.....-(g....I3....{LD>..t.HR..;.d.o...,(s.....f..>{..T,5.SY.c...#.....P.3..];Sy.|...ruF....#.g.G....A.{...H.....,.V>.......C.j^,..Z.y..%..4....B............@...I....$T..[b..Y..R\....<cv.G"W.Y..H.M5.f.......-`O...5..z[..^..{[uR,.aD..c....f[F....i.|u..t.W.'Hq.yFk..e....:.....1....82z}g,.S.8)VM...N%fK.|I.:......K.D]8&..?&.~..1.x..m....f.V.......f..L'..b.".e..J.n...VT2...6.2.wg.<N...A 8.QA....g...c..]...1.J R....)..U..;...-.S)....}...R.;E..c6.Jn..1X7...`.).v%..(d.....t(R.1.Q..$3P. ..o.M.I.6...N...IE6..@cP6X......J..V...DA.N..........tO.........*..1.nUJOUS.paco....%..jr].;.NI":......#.............U0Q}.fH.f..`%..../.....{3..|Z..*E]J.r..D..........7.3........`(8.k=.;.c...d ...<.*.m....Z....g.}V.^S.....)K.w..a..z^U.Qz7.....mc}7..6.3C. ..t...1....k5.{...^5e.5..b.]1Y%...J.R.
<<< skipped >>>
POST /v1/track HTTP/1.1
Accept-Encoding: identity
Content-Length: 111
Host: tracking.uniblue.com
Content-Type: application/json
Connection: close
User-Agent: Python-urllib/2.7
{"recipient": "uniblue.pm-1_0_3_2.web", "event": "prod.pm.mypcbackup_offer_install_completed", "client_id": ""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:42 GMT
Server: ngx_openresty
Content-Length: 20
Connection: Close
{. "status": "OK".}..
GET /pki/crl/products/microsoftrootcert.crl HTTP/1.1
Cache-Control: max-age = 812
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Thu, 23 Oct 2014 05:05:32 GMT
If-None-Match: "a2f3ff97eeecf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Wed, 07 Jan 2015 06:02:43 GMT
Accept-Ranges: bytes
ETag: "88c4768d3f2ad01:0"
Server: Microsoft-IIS/8.0
VTag: 438542942000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 813
Cache-Control: max-age=900
Date: Fri, 30 Jan 2015 23:06:03 GMT
Connection: keep-alive
0..)0......0...*.H........0_1.0.....&...,d....com1.0.....&...,d....microsoft1-0 ..U...$Microsoft Root Certificate Authority..150106214825Z..150407100825Z0.0...a......../..100208014912Z._0]0...U.#..0......`@V'..%..*..S.Y..0... .....7.......0...U......(0... .....7......150406215825Z0...*.H..............vQ..r..L.Q.N..=#.......V;..r../\.m..<.."...F/U....(:.....xm.....P.e.F..BE8......=...G....6t:...?...L..B.v..p.M........z..Q.%J.6..I.......8...U. .g..=T=K....L..$w...^....y~..-a.'...*s#N.o..Qs.$h..:duV'~....8.6..w..b3.... .~)...|.I.y".>R.nJq.ws...3.....f}.E)\......EB.d\.2.....h...lMjT.7..lj.'lj.b....".L.Os6{.s...@....f.|7z.. ......>..Q...(......._....UM.EN.@.K\]#..Y.*.......T. .C.....A'..5FW.ETDvX..tE.....g5.....&..&.....x.^H;...../7..'9.t.I&<[.HX.j....Qw......}...qy3..q`<.....LB.9w|....;..Qw..a ..=.C.:.........
GET /pki/crl/products/WinPCA.crl HTTP/1.1
Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Mon, 06 Oct 2014 05:06:02 GMT
If-None-Match: "3e1c83923e1cf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Sun, 21 Dec 2014 06:03:02 GMT
Accept-Ranges: bytes
ETag: "d2e35dc7e31cd01:0"
Server: Microsoft-IIS/8.5
VTag: 791633315200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 561
Cache-Control: max-age=900
Date: Fri, 30 Jan 2015 23:06:03 GMT
Connection: keep-alive
0..-0......0...*.H........0..1.0...U....US1.0...U....Washington1.0...U....Redmond1.0...U....Microsoft Corporation1 0)..U..."Microsoft Windows Verification PCA..141220223154Z..150321105154Z._0]0...U.#..0.......p............<.J0... .....7.......0...U......30... .....7......150320224154Z0...*.H.............h.~oH#i.J.vh_.....A'B..g...........F....9c.{.m@Q.M.p...g.^ 4.r..Wv.Q.0.w..j....c9..w....I..%.~.l..F.......xo...._...o...7BR.;<..\R/ .....b.(....~..]|.v.u.i.X.B....I......./*...P..A..fi.}& .x.v{TFP[.G......A......L.o...)R.......V.u..V.../.Q..(L.].....uki~......
GET /pki/crl/products/MicrosoftTimeStampPCA.crl HTTP/1.1
Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Sat, 04 Oct 2014 05:06:12 GMT
If-None-Match: "58cddbea90dfcf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Fri, 19 Dec 2014 06:02:00 GMT
Accept-Ranges: bytes
ETag: "9a9a44d511bd01:0"
Server: Microsoft-IIS/8.0
VTag: 279252244600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 550
Cache-Control: max-age=900
Date: Fri, 30 Jan 2015 23:06:03 GMT
Connection: keep-alive
0.."0......0...*.H........0w1.0...U....US1.0...U....Washington1.0...U....Redmond1.0...U....Microsoft Corporation1!0...U....Microsoft Time-Stamp PCA..141218221600Z..150319103600Z._0]0...U.#..0...#4..RFp..@.v.. ..5..0... .....7.......0...U......10... .....7......150318222600Z0...*.H............./..0Q~.r.}.E....&\....F.Z.C..#..F.s........<&\..9G..-....j..N... .C.Fk....;l.....2.K5D.........-.>...(...g.0.S.[?...T4q>.ln...z..L.......5.5s@d.q.('..e...Y..Bo..q..........I....'....i>..y:.eH@h`..\...UA.m#.~.. ;.3..d..;..<..........p..s..J..N `Az......@..lHTTP/1.1 200 OK..Content-Type: application/pkix-crl..Last-Modified: Fri, 19 Dec 2014 06:02:00 GMT..Accept-Ranges: bytes..ETag: "9a9a44d511bd01:0"..Server: Microsoft-IIS/8.0..VTag: 279252244600000000..P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"..X-Powered-By: ASP.NET..Content-Length: 550..Cache-Control: max-age=900..Date: Fri, 30 Jan 2015 23:06:03 GMT..Connection: keep-alive..0.."0......0...*.H........0w1.0...U....US1.0...U....Washington1.0...U....Redmond1.0...U....Microsoft Corporation1!0...U....Microsoft Time-Stamp PCA..141218221600Z..150319103600Z._0]0...U.#..0...#4..RFp..@.v.. ..5..0... .....7.......0...U......10... .....7......150318222600Z0...*.H............./..0Q~.r.}.E....&\....F.Z.C..#..F.s........<&\..9G..-....j..N... .C.Fk....;l.....2.K5D.........-.>...(...g.0.S.[?...T4q>.ln...z..L.......5.5s@d.q.('..e...Y..Bo..q..........I....'....i>..y:.eH@h`..\...UA.m#.~.. ;.3..
<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEGwkCSV07gf3g5QOsqmf+MY= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=427064, public, no-transform, must-revalidate
Last-Modified: Wed, 28 Jan 2015 21:47:43 GMT
Expires: Wed, 4 Feb 2015 21:47:43 GMT
Date: Fri, 30 Jan 2015 23:09:59 GMT
Connection: keep-alive
0..........0..... .....0......0...0........6?s....V....OlL".O..20150128214743Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5.......l$.%t...............20150128214743Z....20150204214743Z0...*.H.............ETI..}..0.5yi.W...v.ln..I..G.3i.......{.....Y.o..4......./..=..K%...%..^..[L.q..c.....K.>..(...QHl...(<..N..a.l.9.MC?x.u.>.u.t.|..A(.G.VK.l ...3.......q...UNj...[.O.;2...U.a..acxT/...?....3!....|...e...*z.-g}.V...[s..P."......KT..).QE.mQ...x..h.=.pi.}uaz.....#0...0...0..........<o&S.-S..}...e.30...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code Signing 2009-2 CA0...141205000000Z..150305235959Z0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://VVV.verisign.com/rpa (c)091<0:..U...3VeriSign Class 3 Code Signing 2009-2 OCSP Responder0.."0...*.H.............0.........{(..t....2.Vf.....&;6).i*FK....W@....F....jnb.w._p.E.6.|.mk....(..........p...........X.DF....^0N....b9.:..J. ZK.".^..\..p.'.$..JA..~QG.d.}...r...gv... f...z.#..}..J...r9h.........LI-..^.......PUD.h<.l....(n..i.....E.....2....^./Y......Y.m...'...hz..y..E..........0...0...U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.verisign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS incorp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U........0... .....0......0"..U....0...0.1.0...U....TGV-B-24710...
<<< skipped >>>
GET /MyPCBackup_Setup.exe HTTP/1.0
Host: cdn.mypcbackup.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 200 OK
Date: Fri, 30 Jan 2015 23:05:21 GMT
Content-Type: application/octet-stream
Content-Length: 297672
Connection: close
x-amz-id-2: ITSfTeTXt7nuSaLoUJg24XmzZcO6StHVwLM5wJapi75duw8Sx8YDdBsZh0xfQyneSKJD7WgytLk=
x-amz-request-id: 3805B55A5D27E049
Last-Modified: Mon, 24 Nov 2014 22:28:10 GMT
ETag: "bcba8747ab53932f8613c006444078e9"
Server: NetDNA-cache/2.2
X-Cache: HIT
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......1p.:u..iu..iu..i...iw..iu..i...i...id..i!2.i...i...it..iRichu..i........PE..L...^..K.................b...........6............@..................................c..................................................(m..........hx..`............................................................................................text....a.......b.................. ..`.rdata...............f..............@..@.data................x..............@....ndata.......p...........................rsrc...(m.......n..................@..@........................................................................................................................................................................................................................................................................................................................................................................................U....\.}..t .}.F.E.u..H.....cB..H.P.u..u..u...T.@..B...SV.5.cB..E.WP.u...X.@..e...E..E.P.u...\.@..}..e....D.@........FR..VV..U... M.......M....3.....FQ.....NU..M..........VT..U.....FP..E...............E.P.M...H.@..E...E.P.E.P.u...`.@..u....E..9}...w....~X.te.v4..L.@....E.tU.}.j.W.E......E.......P.@..vXW..T.@..u..5X.@.W...E..E.h ...Pj.h.[B.W..d.@..u.W...u....E.P.u...h.@._^3.[.....L$..(cB...Si.....VW.T.....tO.q.3.;5,cB.sB..i......D.......t.G.....t...O..t .....u...3....3...F.....;5,cB.r._^[...U..QQ.U.SV..i....
<<< skipped >>>
GET /api/v1/geo/country-code HTTP/1.1
Accept-Encoding: identity
Host: uniblue.com
Connection: close
User-Agent: Python-urllib/2.7
HTTP/1.1 301 Moved Permanently
Content-Type: text/html
Date: Fri, 30 Jan 2015 23:05:28 GMT
Location: hXXp://VVV.uniblue.com/api/v1/geo/country-code
Server: ngx_openresty
Content-Length: 178
Connection: Close
<html>..<head><title>301 Moved Permanently</title></head>..<body bgcolor="white">..<center><h1>301 Moved Permanently</h1></center>..<hr><center>nginx</center>..</body>..</html>....
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir/SSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW+VUAg= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com
HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=508440
Content-Type: application/ocsp-response
Date: Fri, 30 Jan 2015 23:05:35 GMT
Etag: "54cbd786-1d7"
Expires: Fri, 06 Feb 2015 11:05:35 GMT
Last-Modified: Fri, 30 Jan 2015 19:12:06 GMT
Server: ECS (frf/87DB)
X-Cache: HIT
Content-Length: 471
0..........0..... .....0......0...0......E.......1-Q...!..m....20150129200000Z0s0q0I0... ............@..D3=?..Mn8...Q..E.......1-Q...!..m........_..fuSC.o.P.....20150129200000Z....20150205200000Z0...*.H................Y..R..z...].H..M.8..a.t..C=V.yc..1...0>...n...l}...r...H3o.;..>Z...3..;y\ia....w.,..M....i....i...vOu...8.....z.,j.cL'...qu..T..].!....[..l.*NG.z......Q......h....SK.;Y..w=.....y ..Õ.....lf......?.ZL..]M.....%.vj6...v;r...:..|..f...`a.[P[L.]v........h....
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt+lGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAyvGbEyaFTw/abLEQ3zC1w= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com
HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=510224
Content-Type: application/ocsp-response
Date: Fri, 30 Jan 2015 23:05:35 GMT
Etag: "54cbdf3f-1d7"
Expires: Fri, 06 Feb 2015 11:05:35 GMT
Last-Modified: Fri, 30 Jan 2015 19:45:03 GMT
Server: ECS (frf/87CA)
X-Cache: HIT
Content-Length: 471
0..........0..... .....0......0...0......Z..{*....q..`.-.eu.X..20150130193000Z0s0q0I0... .........G.h...#......Vm.Q....Z..{*....q..`.-.eu.X......2hT........\....20150130193000Z....20150206194500Z0...*.H...............?....iE../...|-Y..F.P.rj.1..:..].= V...N..`8....J..........m.. .p`..y..G%.s....P.(^..\......Ju........8-.Vk..7...{*..*...6]y.K...h...m..m.G.t......|.W......C.%...z.......q.....@.@.....e.}....ib3.^.8...B..4h......C.JNZ.0..,7.?#gw.G.I.....h..q .z..=.1...n.HTTP/1.1 200 OK..Accept-Ranges: bytes..Cache-Control: max-age=510224..Content-Type: application/ocsp-response..Date: Fri, 30 Jan 2015 23:05:35 GMT..Etag: "54cbdf3f-1d7"..Expires: Fri, 06 Feb 2015 11:05:35 GMT..Last-Modified: Fri, 30 Jan 2015 19:45:03 GMT..Server: ECS (frf/87CA)..X-Cache: HIT..Content-Length: 471..0..........0..... .....0......0...0......Z..{*....q..`.-.eu.X..20150130193000Z0s0q0I0... .........G.h...#......Vm.Q....Z..{*....q..`.-.eu.X......2hT........\....20150130193000Z....20150206194500Z0...*.H...............?....iE../...|-Y..F.P.rj.1..:..].= V...N..`8....J..........m.. .p`..y..G%.s....P.(^..\......Ju........8-.Vk..7...{*..*...6]y.K...h...m..m.G.t......|.W......C.%...z.......q.....@.@.....e.}....ib3.^.8...B..4h......C.JNZ.0..,7.?#gw.G.I.....h..q .z..=.1...n...
<<< skipped >>>
GET /install/win/1/live/net2 HTTP/1.0
Host: ep.backupgrid.net
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 302 Found
Date: Fri, 30 Jan 2015 23:05:31 GMT
Server: Apache
Set-Cookie: SESSID=f3ocsup07l462vc3fejc7ek4a5; path=/; domain=.backupgrid.net
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Location: hXXp://cdn.backupgrid.net/mypcbackup.1.5.0.2.101.7z
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8
GET /aadebc4830c51c2794a960fe5a9e11df.php HTTP/1.0
Host: track.mypcbackup.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 200 OK
Date: Fri, 30 Jan 2015 23:05:29 GMT
Server: Apache
Set-Cookie: SESSID=kgh2ftcqh17ib8b8qj4lbpkom4; path=/; domain=.mypcbackup.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: LC_CURRENCY=US; expires=Mon, 09-Feb-2015 23:05:30 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: ?uva6aT*=US; expires=Mon, 09-Feb-2015 23:05:30 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: LC_CURRENCY=US; expires=Mon, 09-Feb-2015 23:05:30 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: ?uva6aT*=US; expires=Mon, 09-Feb-2015 23:05:30 GMT; path=/; domain=.mypcbackup.com
Content-Length: 8
Connection: close
Content-Type: text/html; charset=UTF-8
Complete..
GET /9bf5853a/D0wnloads-PC-Mechanic/MyPCBackup_Setup.exe HTTP/1.0
Host: track.mypcbackup.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 301 Moved Permanently
Date: Fri, 30 Jan 2015 23:05:28 GMT
Server: Apache
Set-Cookie: SESSID=otdk0p0ig0dqp84ip1sus5lbv5; path=/; domain=.mypcbackup.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: LC_CURRENCY=US; expires=Mon, 09-Feb-2015 23:05:28 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: ?uva6aT*=US; expires=Mon, 09-Feb-2015 23:05:28 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: LC_CURRENCY=US; expires=Mon, 09-Feb-2015 23:05:29 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: ?uva6aT*=US; expires=Mon, 09-Feb-2015 23:05:29 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: 748a7624422584634822bd3a2bf604ae=e2afb1a4115f381508963c7b35718ecd; expires=Sat, 30-May-2015 23:05:29 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: intc=1; expires=Sat, 31-Jan-2015 23:05:29 GMT; path=/; domain=.mypcbackup.com
P3P: CP="We do not have a P3P policy"
location: hXXp://cdn.mypcbackup.com/MyPCBackup_Setup.exe
Set-Cookie: aff_id=67333; expires=Tue, 03-Mar-2015 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: hop_name=MaxiDisk1; expires=Tue, 03-Mar-2015 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: hop_id=97175; expires=Tue, 03-Mar-2015 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: hash=5a308dc56ed541e26bda689724fd34c0; expires=Tue, 03-Mar-2015 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: tid=D0wnloads-PC-Mechanic; expires=Tue, 03-Mar-2015 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: 9bf5853aunique=true; expires=Thu, 30-Apr-2015 23:05:29 GMT; path=/; domain=mypcbackup.com
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8
<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1762
content-transfer-encoding: binary
Cache-Control: max-age=546911, public, no-transform, must-revalidate
Last-Modified: Fri, 30 Jan 2015 07:02:40 GMT
Expires: Fri, 6 Feb 2015 07:02:40 GMT
Date: Fri, 30 Jan 2015 23:10:03 GMT
Connection: keep-alive
0..........0..... .....0......0...0......;O}a.!..u...au..eUNp..20150130070240Z0s0q0I0... ...................B.>.I.$&.....e......0..C9...313..R...%V.......K3.....20150130070240Z....20150206070240Z0...*.H......................j.{..u.f....g..I....T....0...."h...j~.q....-...n........i!@....D.>..(..s.~.n.Kee.......V`..%n.vEH.L.'.\`HR.:...............LI>.[..h..*..jZ.C.z.j~.......D.w...l.t.,0........&e....mI.........X.....T..7e.....)X.{G.....3.!..q.........,...N....:K7@...d....0...0...0...........2...'U.BM...g.B0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1(c) 2006 VeriSign, Inc. - For authorized use only1E0C..U...<VeriSign Class 3 Public Primary Certification Authority - G50...141202000000Z..151216235959Z0..1.0...U....US1.0...U....Symantec Corporation1.0...U....Symantec Trust Network1?0=..U...6Symantec Class 3 PCA - G5 OCSP Responder Certificate 30.."0...*.H.............0...............2&..PL...,..2....:..tH...`JG.%..*...s.c%...?t..J..0.q....~..k@X.l.i....0..kk..h.9"1.5?..s.....3[...u......]...R0..Z}....l..I.Y.....j\H.q...#.uw.4qz.#.J.....@2$"..$l.B.......D.ye..(..2.........@...... ...."... E..0M,..b{.^..s'....f.6.pr4.J........'j..........0...0...U.......0.0l..U. .e0c0a..`.H...E....0R0&.. .........hXXp://VVV.symauth.com/cps0(.. .......0...hXXp://VVV.symauth.com/rpa0...U.%..0... .......0...U...........0... .....0......0!..U....0...0.1.0...U....TGV-B-2760...U......;O}a.!..u...au..eUNp0...U.#..0.....e......0..C9...3130...*.H.............(.&..Dgr.Ve..#...5
<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEDi14wrtdPbNBdjyDxjokeI= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1725
content-transfer-encoding: binary
Cache-Control: max-age=430091, public, no-transform, must-revalidate
Last-Modified: Wed, 28 Jan 2015 22:37:30 GMT
Expires: Wed, 4 Feb 2015 22:37:30 GMT
Date: Fri, 30 Jan 2015 23:10:03 GMT
Connection: keep-alive
0..........0..... .....0......0...0......u\..3Oo?U...H.....O!..20150128223730Z0s0q0I0... ...................F....0.yV......{&.K......&.......8....t..............20150128223730Z....20150204223730Z0...*.H...............T?5....&.........w.B....u.[.s.H%n..%r..l...~........a...B..Nck.xQ..G%.T.ix^..3.3<.....`.E[.eIeH(.1K.....c..u..V..E.[v...`....f.y.$fJ]\...........7.W.SR\2..nd...f`.KNh..75.P:..,.J.Y.....(.......9.u.52..Z.v.}.....4J...a......}.J.c..M.....(...'G....OCvZ........0...0...0........../...nj0...}..i..0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at https://VVV.verisign.com/rpa (c)101.0,..U...%VeriSign Class 3 Code Signing 2010 CA0...141204000000Z..150304235959Z0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1VeriSign Class 3 Code Signing 2010 OCSP Responder0.."0...*.H.............0.........4.4...........o....?..f.........I.!.b.L...L..U.........rM.,.....=..cR4d.~*..k..x......=.WT.<.A2n1.qZyM.M..Q_...8....9....d.... ...'.........h..Z..I...(.b.jK..DO.ra..gb..j..A.(....mrzU.w.......Bv...l.:s..L....y.....u..n.)W......Y!....Q...,.i|.....:.Mu..DD1.........0...0...U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.verisign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS incorp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U........0... .....0......0"..U....0...0.1.0...U....TGV-B-24600...*.H..............pjd....VpE.6.tO..@.....7.=.. ...........hi.......>....Q.?
<<< skipped >>>
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab?c716edbe6e72edb3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Wed, 12 Mar 2014 20:20:10 GMT
If-None-Match: "0b96c77303ecf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ctldl.windowsupdate.com
HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: application/octet-stream
Last-Modified: Fri, 12 Sep 2014 18:47:05 GMT
Accept-Ranges: bytes
ETag: "805a83f2b9cecf1:0"
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
X-Powered-By: ARR/2.5
X-Powered-By: ASP.NET
Content-Length: 56928
Date: Fri, 30 Jan 2015 23:05:34 GMT
Connection: keep-alive
MSCF....`.......,...................I.................,E.Y .authroot.stl..Y-..8..CK...<T...g.v!M.d..f.%d..}K..5..F. ...T..%.,YJ.,!T......_..x.<=O.....yy....;3..>.|..~..\.....|......;..8..~.za...."A...q.......g..m......<X........j"I........!..-w.....w....P...H..(.?}..2.N. .u..a. ...=.C..D.F>rC.. ..|).=.. ..3b.8H.M...(...u8.%...W.g...\YB.m:.....dE.........V....$....Dn:....0...S."...o..q.....K...I..K...(x%....>A.R...`.0 .........<`L0mp...%....y.....g.n...R0Op..<..,....`0$z.@..&.x"....T..H...<........~..E..".....<<.\B(.....................@.....L.........KNAy8/"...f.......k..Jm7j....R.5q....Rz..!@...].......Y.[........4.. .D8..&...t.J^O..Q.._..1.J.m5<'k.,....%T....i.\.;.;q..S./ 8.?Bu.............}D.Q....L....*..[.."e......15m..._.0.M........#..v!..<...@..?sc.y....*.....tX[........{.W4.Q...^u@..*..QP.......~.L9N....2r...4.....B..-\(...b.d...K...O.8..Un.......V.<.......A...V.....(..s..f..q.{N0.hS.,..;M.|G|.@.M.._.....7._6...C.0...A;L....%...M=Y.....f.JV.(.5.....0..?*...KZ....jM...8.6U...#...ew.?..?...........WE.Or..O>..{.'W2.........3m.O.u..Z8....H4@.w}.o:?~....]<!...%....}@.d...L.p.a.g ..K."..N1!%..S.bT.H.-.....e..`.0$...0t..DX..{.....#./...8.5..M...T.......D......V\C.zy.....3E:..>.{..).QW......q....9..n..1....8%,.........r.p@.>. ...Q.?.p..7.?..7...&..!.........`. .=....Sf..q.l.A.....L...t.}g..;...f....=.e.~.z....C..*R....H-..=...f..(t'.."....F...g._....n.J..U.4vr`}.....1..o@.....@.#...R. L8....z..].|......3..y..-./....K..6{...s.<R`.}6....?.......-..@.g..S....
<<< skipped >>>
GET /pki/crl/products/MicCodSigPCA_08-31-2010.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Wed, 28 Jan 2015 06:05:55 GMT
Accept-Ranges: bytes
ETag: "75565c7ac03ad01:0"
Server: Microsoft-IIS/8.0
VTag: 279455044500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 554
Cache-Control: max-age=900
Date: Fri, 30 Jan 2015 23:10:02 GMT
Connection: keep-alive
0..&0......0...*.H........0y1.0...U....US1.0...U....Washington1.0...U....Redmond1.0...U....Microsoft Corporation1#0!..U....Microsoft Code Signing PCA..150127173215Z..150428055215Z.a0_0...U.#..0..........X..7.3...L...0... .....7.........0...U......Y0... .....7......150427174215Z0...*.H......................YIw.. ..(..y..O.G].B.."?.@...[1.}.X...]...e.J....pP.I....!6...%.D.k...>c.|R.?.i..yt.z..B.........b....n..m5...0....2..I!)v....z....y.#pXz.DO.....mF...e.'e...@.%...6./.bPZ...=....bp..j....lo....4........T9j...S.7Q.@.W..@.. ...M....z....Q...{u. .W....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 128
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.web","client_id":"","event":"prod.pm.mypcbackup_offer_included","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:05 GMT
Server: ngx_openresty
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:05 GMT..Server: ngx_openresty..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 125
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.web","client_id":"","event":"prod.pm.mypcbackup_offer_shown","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:16 GMT
Server: ngx_openresty
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:16 GMT..Server: ngx_openresty..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 129
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.web","client_id":"","event":"prod.pm.third_party_offer_accepted","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:21 GMT
Server: ngx_openresty
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:21 GMT..Server: ngx_openresty..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 140
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.web","client_id":"","event":"prod.pm.install_standalone_download_completed","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:27 GMT
Server: ngx_openresty
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:27 GMT..Server: ngx_openresty..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 119
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.web","client_id":"","event":"prod.pm.install_launched","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:04 GMT
Server: ngx_openresty/1.2.6.6
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:04 GMT..Server: ngx_openresty/1.2.6.6..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 126
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.web","client_id":"","event":"prod.pm.third_party_offer_shown","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:15 GMT
Server: ngx_openresty/1.2.6.6
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:15 GMT..Server: ngx_openresty/1.2.6.6..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 118
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.web","client_id":"","event":"prod.pm.install_started","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:20 GMT
Server: ngx_openresty/1.2.6.6
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:20 GMT..Server: ngx_openresty/1.2.6.6..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 138
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.web","client_id":"","event":"prod.pm.install_standalone_download_started","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:24 GMT
Server: ngx_openresty/1.2.6.6
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 138
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.web","client_id":"","event":"prod.pm.mypcbackup_offer_download_initiated","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:34 GMT
Server: ngx_openresty/1.2.6.6
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}....
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=518430, public, no-transform, must-revalidate
Last-Modified: Thu, 29 Jan 2015 23:10:33 GMT
Expires: Thu, 5 Feb 2015 23:10:33 GMT
Date: Fri, 30 Jan 2015 23:10:03 GMT
Connection: keep-alive
0..........0..... .....0......0...0........6?s....V....OlL".O..20150129231033Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5.......A..2.....:...:......20150129231033Z....20150205231033Z0...*.H.............pVD...&.`...[..x_].....WR...o...D.%.....;......b.....aMa^........2&..5BF......L......n.....Pqn3......;...;..jE........^..";...%..Q';6..]i.m...=.)~..GL ].0am....c.....z6.dD....a..L.D.8!.k....r&.....k.d.g#. ....o....K*.F.......j..dq....r/.]C...eS..2|.....RL....#0...0...0..........<o&S.-S..}...e.30...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at https://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code Signing 2009-2 CA0...141205000000Z..150305235959Z0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://VVV.verisign.com/rpa (c)091<0:..U...3VeriSign Class 3 Code Signing 2009-2 OCSP Responder0.."0...*.H.............0.........{(..t....2.Vf.....&;6).i*FK....W@....F....jnb.w._p.E.6.|.mk....(..........p...........X.DF....^0N....b9.:..J. ZK.".^..\..p.'.$..JA..~QG.d.}...r...gv... f...z.#..}..J...r9h.........LI-..^.......PUD.h<.l....(n..i.....E.....2....^./Y......Y.m...'...hz..y..E..........0...0...U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.verisign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS incorp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U........0... .....0......0"..U....0...0.1.0...U....TGV-B-24710...*.H......
<<< skipped >>>
POST /v1/track HTTP/1.1
Accept-Encoding: identity
Content-Length: 111
Host: tracking.uniblue.com
Content-Type: application/json
Connection: close
User-Agent: Python-urllib/2.7
{"recipient": "uniblue.pm-1_0_3_2.web", "event": "prod.pm.mypcbackup_offer_install_initiated", "client_id": ""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:35 GMT
Server: ngx_openresty/1.2.6.6
Content-Length: 20
Connection: Close
{. "status": "OK".}..
GET /product/pm/1.0.3.2/pcmechanicpm-standalone-setup.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/6.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C)
Connection: Keep-Alive
Host: d21bsqatndqkg8.cloudfront.net
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 18615048
Connection: keep-alive
Date: Wed, 28 Jan 2015 14:08:33 GMT
Cache-Control: max-age=86400, public
Last-Modified: Wed, 28 Jan 2015 13:46:31 GMT
ETag: "52f5313d363b68bad93495af8bc771a6"
Accept-Ranges: bytes
Server: AmazonS3
Age: 41219
X-Cache: Hit from cloudfront
Via: 1.1 457b75182c63eff39fe8e72b11b6c74d.cloudfront.net (CloudFront)
X-Amz-Cf-Id: yH5XhL_hdRI-XTMUE2WAbwSrQaFrbFgUGB9IBIA2JUDeuZs9xFbwQQ==
MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....WZR..................................... ....@..........................p.......W...........@...................................................................................................................................................text...,........................... ..`.itext..D........................... ..`.data........ ......................@....bss.....V...0...........................idata..............................@....tls.....................................rdata..............................@..@.rsrc................ ..............@..@....................................@..@..................................................................................................................................................................@...AnsiChar............@...string(.@...AnsiString......@...............................@......... 9@.(9@..9@..9@..9@..9@..9@..9@.,8@.H8@..8@..TObject.%..A....%..A....%..A....%..A....%..A....%..A....%(.A....%..A....%$.A....%..A....%..A....%..A....%..A....%..A....%|.A....%x.A....%t.A....%p.A....%l.A....%h.A....% .A....%d.A....%`.A....%\.A....%..A....%..A....%..A....%X.A....%T.A....%..A....%..A....%..A....%P.A....%L.A....%H.A....%D.A....%@.A...S..........$D...T.J....D$,.t...\$0....D[..@..%<.A....%8.A....
<<< skipped >>>
GET /download/2/d/6/2d61c766-107b-409d-8fba-c39e61ca08e8/vcredist_x64.exe HTTP/1.0
Host: download.microsoft.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.0 200 OK
Content-Type: application/octet-stream
Last-Modified: Fri, 08 Aug 2008 21:48:10 GMT
Accept-Ranges: bytes
ETag: "df115773a0f9c81:0"
Server: Microsoft-IIS/8.5
Content-Disposition: attachment
Content-Length: 4961800
Date: Fri, 30 Jan 2015 23:05:30 GMT
Connection: close
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........K...K...K.......D...K... ......._.......J.......J...RichK...........PE..L...{..B.................z..........rY... ........... ..............................9.L.......... ..........................@...........t.............K..$...........!............................................... ...............................text....x... ...z.................. ..`.data................~..............@....rsrc...t.........K.................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................................t...Z...................&...<...L............................................... ...:...J...V...^...x.......................................&...<...J...^...t.......................................(...:...R...b...p...................................&...N...b...|...............r.......\...L...:...,...........................................~...f.......................z...............................&...0...D...:...............:...........$...................{..B.............&..................Z.
<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1453
content-transfer-encoding: binary
Cache-Control: max-age=368207, public, no-transform, must-revalidate
Last-Modified: Wed, 28 Jan 2015 05:22:19 GMT
Expires: Wed, 4 Feb 2015 05:22:19 GMT
Date: Fri, 30 Jan 2015 23:09:56 GMT
Connection: keep-alive
0..........0..... .....0......0...0......T3t.%..O.E..~..F.=....20150128052219Z0s0q0I0... ........H.dI.....3..^B...d6Q....ZL%."..1.m..._)..a..eR&.....Y.)..".\....20150128052219Z....20150204052219Z0...*.H..............q._#...U...Z..0.^..E..Q&j.%^..{[o..:Cd...A..*eM.d.....C..R.S....j......1..5.eB$ n.........q_C.<xs...f;z...m<..Q.....F..2.G..(.n.&iMR.f...H...C.....XC<o.}y..........A....{................@..$1..D....a....Y.![f.0..[.,..K..e....d..ZrZ..3..;JP2.M'...........L....0...0...0..3......./...b.v..-....l}0...*.H........0_1.0...U....US1.0...U....VeriSign, Inc.1705..U....Class 3 Public Primary Certification Authority0...141202000000Z..151216235959Z0..1.0...U....US1.0...U....Symantec Corporation1.0...U....Symantec Trust Network1?0=..U...6Symantec Class 3 PCA - G1 OCSP Responder Certificate 30.."0...*.H.............0..........'......Y..x.3B1.7..Q..`..d.. ....s..t.$a.....j2R.{ ,*..c{.3.....H..3-; ).....0._...*..9M..V...... ...{m...-.......)..tR..{D....~...M...T..pS.p..^|o....S..v.).).....r.v.qo$......C.V!....@.h#qh...u1T.].G0.]E...=._...... ........TE...Sa.s4........r...3.............0..0...U....0.0l..U. .e0c0a..`.H...E....0R0&.. .........hXXp://VVV.symauth.com/cps0(.. .......0...hXXp://VVV.symauth.com/rpa0...U.%..0... .......0...U........0... .....0......0!..U....0...0.1.0...U....TGV-B-2730...*.H.............$..H......oU....Y!.z{*.V.M..u.._z..3>.. 0....3..m.....e.......a..D...........e..F6:.y.....di.......<y.Z.......x}..q.2....UZ1 :,....
<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=457484, public, no-transform, must-revalidate
Last-Modified: Thu, 29 Jan 2015 06:12:33 GMT
Expires: Thu, 5 Feb 2015 06:12:33 GMT
Date: Fri, 30 Jan 2015 23:09:56 GMT
Connection: keep-alive
0..........0..... .....0......0...0........6?s....V....OlL".O..20150129061233Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5........M.s.Q~...@?j.......20150129061233Z....20150205061233Z0...*.H...............H `._pIsjnQ...........{ .........&t.26OO.....[........-u-.1G.......Es.....P..B.K,a=a6..i8.!.f...l.-.] .....:..`.40H.'p....4g]sJ`.n$...._P.t.t....E..u...T7U..X..*y.o I.l..S...X..L<..&.....y.m.4. ZB.(.t:0...5C%.x7..o.Z..._/.X]h:D.D^_...O....@.....$.m..95hu...#0...0...0..........<o&S.-S..}...e.30...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code Signing 2009-2 CA0...141205000000Z..150305235959Z0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://VVV.verisign.com/rpa (c)091<0:..U...3VeriSign Class 3 Code Signing 2009-2 OCSP Responder0.."0...*.H.............0.........{(..t....2.Vf.....&;6).i*FK....W@....F....jnb.w._p.E.6.|.mk....(..........p...........X.DF....^0N....b9.:..J. ZK.".^..\..p.'.$..JA..~QG.d.}...r...gv... f...z.#..}..J...r9h.........LI-..^.......PUD.h<.l....(n..i.....E.....2....^./Y......Y.m...'...hz..y..E..........0...0...U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.verisign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS incorp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U........0... .....0......0"..U....0...0.1.0...U....TGV-B-24710...*.H...
<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ/xkCfyHfJr7GQ6M658NRZ4SHo/AQUCPVR6Pv+PT1kNnxoz1t4qN+5xTcCEGC2x6sSmevembHfY1acIZk= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1697
content-transfer-encoding: binary
Cache-Control: max-age=494263, public, no-transform, must-revalidate
Last-Modified: Thu, 29 Jan 2015 16:27:40 GMT
Expires: Thu, 5 Feb 2015 16:27:40 GMT
Date: Fri, 30 Jan 2015 23:09:57 GMT
Connection: keep-alive
0..........0..... .....0......0...0...A0?1=0;..U...4VeriSign Class 3 Code Signing 2004 CA OCSP Responder..20150129162740Z0s0q0I0... ........?.@..w.........Y.!......Q...==d6|h.[x....7..`..........cV.!.....20150129162740Z....20150205162740Z0...*.H.............n)cde....v.2.....Y..1.L...D..~~cI2.h...qD(.~.btg..x4....]F............')^.L..,....p6..Bv}r.^H.h,$...... .Y.L.X.M..9>..>B..7..;IEVb.......t.....P.HN..F.......Jc.._q.x.I4)L..$\,Lx.Y.:...@.?0m......N.s..gi .J.9>..\V]0F4...>...v).h........uYa..\T........z..P.4....0...0...0..{.........[..I|.....Zm..0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://VVV.verisign.com/rpa (c)041.0,..U...%VeriSign Class 3 Code Signing 2004 CA0...140428000000Z..150729235959Z0?1=0;..U...4VeriSign Class 3 Code Signing 2004 CA OCSP Responder0.."0...*.H.............0.........Y....h..@..>.....%.-.....O...' y.........x..Gw.xF.....?..Z..u,.X.&..........3C..H.l.....f..;]s!.\"v...|....].@.....K7m2...N......-S.I......5n...G7. ..W....n..*..-f?EY.......UN...r...........-_.%..,P;b.....)(.P.4...,.%....<..6.....[r^X.EV..S...5#'Y.. .TD...........0...0...U.......0.0...U.%..0... .......0...U...........0... .....0......0f..U. ._0]0[..`.H...E....0L0#.. .........hXXps://d.symcb.com/cps0%.. .......0...hXXps://d.symcb.com/rpa0!..U....0...0.1.0...U....TGV-B-1080...U......"...?....`>q..i1o...0...U.#..0.....Q...==d6|h.[x....70...*.H.............B8@.$..wo......E.....P52"b*@'C\.y.(...n....h.f..7f.....v...pb<...]..|..
<<< skipped >>>
HEAD /aff_setup.exe HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: cdn.backupgrid.net
HTTP/1.1 200 OK
Date: Fri, 30 Jan 2015 23:04:49 GMT
Content-Type: application/octet-stream
Content-Length: 263224
Connection: keep-alive
x-amz-id-2: q8QzEF0XsVq/YuqVDjkP5X7Kse9cUYcmA9rz4E TA7ApR6avXQzdDUoGY4dRSUNZ
x-amz-request-id: 1F8A317A1558F2BC
Last-Modified: Mon, 06 Oct 2014 10:15:06 GMT
ETag: "256f360db3c119ab9e1b6eb4c8f66680"
Server: NetDNA-cache/2.2
X-Cache: HIT
HTTP/1.1 200 OK..Date: Fri, 30 Jan 2015 23:04:49 GMT..Content-Type: application/octet-stream..Content-Length: 263224..Connection: keep-alive..x-amz-id-2: q8QzEF0XsVq/YuqVDjkP5X7Kse9cUYcmA9rz4E TA7ApR6avXQzdDUoGY4dRSUNZ..x-amz-request-id: 1F8A317A1558F2BC..Last-Modified: Mon, 06 Oct 2014 10:15:06 GMT..ETag: "256f360db3c119ab9e1b6eb4c8f66680"..Server: NetDNA-cache/2.2..X-Cache: HIT..
GET /product/pm/1.0.3.2/pcmechanicpm-standalone-setup.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/6.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C)
Host: download.uniblue.com
Connection: Keep-Alive
HTTP/1.1 302 Moved Temporarily
Content-Type: text/html
Date: Fri, 30 Jan 2015 23:05:17 GMT
Location: hXXp://d21bsqatndqkg8.cloudfront.net/product/pm/1.0.3.2/pcmechanicpm-standalone-setup.exe
Server: openresty/1.5.8.1
Content-Length: 166
Connection: keep-alive
<html>..<head><title>302 Found</title></head>..<body bgcolor="white">..<center><h1>302 Found</h1></center>..<hr><center>openresty/1.5.8.1</center>..</body>..</html>..HTTP/1.1 302 Moved Temporarily..Content-Type: text/html..Date: Fri, 30 Jan 2015 23:05:17 GMT..Location: hXXp://d21bsqatndqkg8.cloudfront.net/product/pm/1.0.3.2/pcmechanicpm-standalone-setup.exe..Server: openresty/1.5.8.1..Content-Length: 166..Connection: keep-alive..<html>..<head><title>302 Found</title></head>..<body bgcolor="white">..<center><h1>302 Found</h1></center>..<hr><center>openresty/1.5.8.1</center>..</body>..</html>....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 126
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.standalone","client_id":"","event":"prod.pm.install_launched","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:28 GMT
Server: ngx_openresty/1.2.6.6
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:28 GMT..Server: ngx_openresty/1.2.6.6..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 125
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.standalone","client_id":"","event":"prod.pm.install_started","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:29 GMT
Server: ngx_openresty/1.2.6.6
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:29 GMT..Server: ngx_openresty/1.2.6.6..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}..
GET /api/v1/geo/country-code HTTP/1.1
Accept-Encoding: identity
Host: VVV.uniblue.com
Connection: close
User-Agent: Python-urllib/2.7
HTTP/1.1 200 OK
Cache-Control: max-age=7200
Content-Type: text/plain
Date: Fri, 30 Jan 2015 23:05:29 GMT
Server: ngx_openresty
Content-Length: 3
Connection: Close
UA...
GET /v1/geo/country-code HTTP/1.1
Accept-Encoding: identity
Host: api.uniblue.net
Connection: close
User-Agent: Python-urllib/2.7
HTTP/1.1 302 Moved Temporarily
Content-Type: text/html
Date: Fri, 30 Jan 2015 23:05:36 GMT
Location: hXXp://uniblue.com/api/v1/geo/country-code
Server: nginx/1.1.19
Content-Length: 161
Connection: Close
<html>..<head><title>302 Found</title></head>..<body bgcolor="white">..<center><h1>302 Found</h1></center>..<hr><center>nginx/1.1.19</center>..</body>..</html>....
GET /latest_updates/application.txt HTTP/1.1
Accept-Encoding: identity
Host: pm.uniblue.com.s3.amazonaws.com
Connection: close
User-Agent: Python-urllib/2.7
HTTP/1.1 200 OK
x-amz-id-2: /Mba6jNbVr7P8Ic2pm7Gfm2l 9/ T77Wk53wNSJi7f9uKLWWVJTumra3nQr9dS3/ojEcmv7xCqM=
x-amz-request-id: A997756071B107DE
Date: Fri, 30 Jan 2015 23:05:29 GMT
Cache-Control: max-age=86400, public
Last-Modified: Thu, 29 Jan 2015 11:04:45 GMT
ETag: "19a766f0861dc1fcfa3a8689ea036e95"
Accept-Ranges: bytes
Content-Type: text/plain
Content-Length: 7
Server: AmazonS3
1.0.2.1..
GET /mypcbackup.1.5.0.2.101.7z HTTP/1.0
Host: cdn.backupgrid.net
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 200 OK
Date: Fri, 30 Jan 2015 23:05:24 GMT
Content-Type: application/octet-stream
Content-Length: 4072385
Connection: close
x-amz-id-2: 9UzL00lJRzw93yst0dXJgg6RTfdv FMvHMTg0fIOUh6TVxWt9EZTuRV5odgm2XhA
x-amz-request-id: 7F91279ECCC00982
Last-Modified: Tue, 25 Nov 2014 19:49:29 GMT
ETag: "dea41132628ea08c816693a67102fd48"
Server: NetDNA-cache/2.2
X-Cache: HIT
..'Pg7....'.>.~...h...2....S..".2......L..|r"?.....x...rW9..i...|...*.AQ......1&r.e..6....dUh..6z......@c.e...].E...Q.....t).,X.I..w:..;.c...D..*.'.^0....2.Z.Ub.......=U..,..&.XR.!..i.... ....nEp..Ef.!...1..........^...&fx..bC.q..\....$.)1/.u....R.b..c?.L\\..5W......F...:t..Vy..7...wW^E.Za.....;z..f...#...e3@...........zt."..].y..egv.#...E8.D..._.e...?_G.A_.<..ft.K'.TH.e..`..jX....pe.....T.n.w.9.1......hY......N.....Ef`..8..*G.Z.AB....?..9?...F.;.@P..3.)...Kc.0.4.Z.1y..$;......r....2a.X..w.u..Lb.T.{!..f.....O........F4.`g..B..n..OA.v...&.....c.T.....S.f.#.'.......f...$..FB..T9....C.U..0.....U...8...EMx..b1h.K1!...G..H..|r..|T.w..P..p.b.!.=.1^...G8........[...jD..R5..{wCFOb.S..e!....5..JJ...$>s.}.77]..........WI....^.....yk..0#.&t.[ ..;....@.....k.yN*.....mh......^"...!~.oI..,...I..G.y..xwDH0....'.,(.pG....}0.Md.o.}.@K.......z\.......1..Zi....in.-.....Ut.RB..G5o|.v..1.X........o...%.....;.....F.....,.I...v_QOy...B....Z.U..3f.....C.a...U......H.PI....}F.....m`.Wh.FX.i2..C......b~.........}..:*...h...f...q..........`:t*..^...Q..*i......p......d.1~..i(.......a|.VDL.....-.........<.}U....C...G...|.|y..0h..b7A..:..C...(......Q0..fA....O./^.w..L8.M ?....1...1..e.j..oWMo..7..(..c..u.U(...%R..2rd.[....Y..<.W.%.v..XF[.q..R...^._cd8G....3..".P.<.7]."....^....}..<.Z\.!.#. .bwzC4Xo.U..#.P..rnhox....cb.7Whj..^....r...t">..w.u.e.E..U....)....>y2.t...D2....X[..~....G@cv..v...6...R.Eg.RP]Y.. r.|#>3-.hS..Er...~...@|.uS.".....vs..c{g...(..bF.?P.....<*H.A...W.N........xV^..6V..S.....'.. ..a.....,..
<<< skipped >>>
GET /msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?733473ba9bf116c3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Thu, 03 Jul 2014 23:34:12 GMT
If-None-Match: "0b2464b1797cf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ctldl.windowsupdate.com
HTTP/1.1 304 Not Modified
Content-Type: application/octet-stream
Last-Modified: Thu, 03 Jul 2014 23:34:12 GMT
ETag: "0b2464b1797cf1:0"
Cache-Control: max-age=86400
Date: Fri, 30 Jan 2015 23:05:32 GMT
Connection: keep-alive
GET /pca3.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.verisign.com
HTTP/1.1 200 OK
Server: Apache
ETag: "66304c4a5660ab8615727e6bb27b3cdb:1418950819"
Last-Modified: Fri, 19 Dec 2014 01:00:19 GMT
Date: Fri, 30 Jan 2015 23:09:57 GMT
Content-Length: 933
Connection: keep-alive
Content-Type: application/pkix-crl
0...0...0...*.H........0_1.0...U....US1.0...U....VeriSign, Inc.1705..U....Class 3 Public Primary Certification Authority..141210000000Z..150331235959Z0..x0!...v....a_>..2......020924164823Z0!.....A.....{2..Y.#..140129175709Z0!...,.|.|...<...j ...080605174907Z0!...`y..q.......fh...020923171400Z0!...?A....a.nF`.P....020923171548Z0!............R.e.53..010207212458Z0!..!......Y...ISi....010706171411Z0!..$-..I{r....u<._...080403172226Z0!..&.."?..y..51}..1..010706172118Z0!..4....2....{W......080605175030Z0!..B....c............070411175910Z0!..H.Py...N....* ....010207212031Z0!..N....-.1Gq.@...C..040401175251Z0!..Y......w`G........070411175657Z0!..Z`..H.@B....Z.*q..080403172017Z0!..l....I...Y..] .c..010706171749Z0"......T=deQ...1u.]...010207212247Z0".....p..1..7<.....e..010207211822Z0...*.H............5..v...V.._)....A... ....>.5]....6.(.0uFW.*:T...6$.....R...Y.N.k........%Jn..I.j*.6.3~...r../=l..?...9..V0..@Tk......fn?....0.A.HTTP/1.1 200 OK..Server: Apache..ETag: "66304c4a5660ab8615727e6bb27b3cdb:1418950819"..Last-Modified: Fri, 19 Dec 2014 01:00:19 GMT..Date: Fri, 30 Jan 2015 23:09:57 GMT..Content-Length: 933..Connection: keep-alive..Content-Type: application/pkix-crl..0...0...0...*.H........0_1.0...U....US1.0...U....VeriSign, Inc.1705..U....Class 3 Public Primary Certification Authority..141210000000Z..150331235959Z0..x0!...v....a_>..2......020924164823Z0!.....A.....{2..Y.#..140129175709Z0!...,.|.|...<...j ...080605174907Z0!...`y..q.......fh...020923171400Z0!...?A....a.nF`.P....020923171548Z0!.
<<< skipped >>>
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 137
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.standalone","client_id":"","event":"prod.pm.third_party_offer_not_shown","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:29 GMT
Server: ngx_openresty
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:29 GMT..Server: ngx_openresty..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 127
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.standalone","client_id":"","event":"prod.pm.install_completed","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:34 GMT
Server: ngx_openresty
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:34 GMT..Server: ngx_openresty..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}..
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 128
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.web","client_id":"","event":"prod.pm.mypcbackup_offer_accepted","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:21 GMT
Server: ngx_openresty/1.2.6.6
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:21 GMT..Server: ngx_openresty/1.2.6.6..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}....
POST /v1/collect HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json; Charset=UTF-8
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Content-Length: 139
Host: tracking.uniblue.com
{"recipient":"uniblue.pm-1_0_3_2.web","client_id":"","event":"prod.pm.third_party_offer_download_initiated","buildtest_id":"","unit_id":""}
HTTP/1.1 200 OK
Content-Type: application/json
Date: Fri, 30 Jan 2015 23:05:35 GMT
Server: ngx_openresty/1.2.6.6
Content-Length: 20
Connection: keep-alive
{. "status": "OK".}HTTP/1.1 200 OK..Content-Type: application/json..Date: Fri, 30 Jan 2015 23:05:35 GMT..Server: ngx_openresty/1.2.6.6..Content-Length: 20..Connection: keep-alive..{. "status": "OK".}..
Map
The Malware connects to the servers at the folowing location(s):
Strings from Dumps
pc-mechanic.exe_3392:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
tCPV
tCPV
USER32.dll
USER32.dll
MSVCR90.dll
MSVCR90.dll
_amsg_exit
_amsg_exit
_acmdln
_acmdln
_crt_debugger_hook
_crt_debugger_hook
GetProcessHeap
GetProcessHeap
KERNEL32.dll
KERNEL32.dll
windows_exe
windows_exe
%s\%s
%s\%s
PYTHON27.DLL
PYTHON27.DLL
zlib.pyd
zlib.pyd
ZLIB.PYD
ZLIB.PYD
Not enough space for new sys.path
Not enough space for new sys.path
no mem for late sys.path
no mem for late sys.path
PY2EXE_VERBOSE
PY2EXE_VERBOSE
PyImport_ImportModule
PyImport_ImportModule
PyExc_ImportError
PyExc_ImportError
PyImport_AddModule
PyImport_AddModule
undefined symbol %s -> exit(-1)
undefined symbol %s -> exit(-1)
Importer which can load extension modules from memory
Importer which can load extension modules from memory
s#sss:import_module
s#sss:import_module
MemoryLoadLibrary failed loading %s
MemoryLoadLibrary failed loading %s
Could not find function %s
Could not find function %s
import_module
import_module
import_module(code, initfunc, dllname[, finder]) -> module
import_module(code, initfunc, dllname[, finder]) -> module
_memimporter
_memimporter
%Program Files% (x86)\Uniblue\PC-Mechanic\library.dat
%Program Files% (x86)\Uniblue\PC-Mechanic\library.dat
%Program Files% (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe
%Program Files% (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe
%Program Files% (x86)\Uniblue\PC-Mechanic
%Program Files% (x86)\Uniblue\PC-Mechanic
pc-mechanic.exe
pc-mechanic.exe
library.dat
library.dat
windows_exet
windows_exet
.logc
.logc
The logfile '%s' could not be opened:
The logfile '%s' could not be opened:
See the logfile '%s' for details(
See the logfile '%s' for details(
C:\jenkins\jobs\pm\workspace\env\lib\site-packages\py2exe-0.6.9-py2.7-win32.egg\py2exe\boot_common.pyR
C:\jenkins\jobs\pm\workspace\env\lib\site-packages\py2exe-0.6.9-py2.7-win32.egg\py2exe\boot_common.pyR
C:\jenkins\jobs\pm\workspace\env\lib\site-packages\py2exe-0.6.9-py2.7-win32.egg\py2exe\boot_common.pyt
C:\jenkins\jobs\pm\workspace\env\lib\site-packages\py2exe-0.6.9-py2.7-win32.egg\py2exe\boot_common.pyt
zipextimportert
zipextimportert
R$
R$
library.dats
library.dats
app.main(
app.main(
joint
joint
__import__t
__import__t
bootstrap_main.pyR$
bootstrap_main.pyR$
332222##
332222##
%%cxaax
%%cxaax
`>>>>=>`
`>>>>=>`
\4544545454545444
\4544545454545444
C.yLF
C.yLF
xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">
xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">
1.0.3.2
1.0.3.2
pc-mechanic.exe_3392_rwx_0C20A000_000F5000:
%u3%Z
%u3%Z
PVh%u3%
PVh%u3%
pc-mechanic.exe_3392_rwx_0D90A000_00060000:
0%UwQ
0%UwQ
Ph%S1%
Ph%S1%