HELP! I think someone is ****HACKING ME ****** what should I DO??? Check out this LOG

Status
Not open for further replies.

Morgh77

Reputable
Apr 23, 2014
1
0
4,510
I discovered alot of crazy <mod edit> going on in my system ..... Not sure what I should do to stop this can anyone help??? Here is a notepad log I discovered after finding I had been logged into a vpn somehow...

=== Verbose logging started: 4/20/2014 5:09:39 Build type: SHIP UNICODE 3.01.4001.5512 Calling process: c:\windows\system32\msiexec.exe ===
MSI (c) (48:14) [05:09:39:718]: Resetting cached policy values
MSI (c) (48:14) [05:09:39:718]: Machine policy value 'Debug' is 0
MSI (c) (48:14) [05:09:39:718]: ******* RunEngine:
******* Product: c:\\temp\\t.msi
******* Action:
******* CommandLine: **********
MSI (c) (48:14) [05:09:39:718]: Client-side and UI is none or basic: Running entire install on the server.
MSI (c) (48:14) [05:09:39:718]: Grabbed execution mutex.
MSI (c) (48:14) [05:09:39:796]: Cloaking enabled.
MSI (c) (48:14) [05:09:39:796]: Attempting to enable all disabled priveleges before calling Install on Server
MSI (c) (48:14) [05:09:39:812]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (A0:2C) [05:09:39:828]: Grabbed execution mutex.
MSI (s) (A0:BC) [05:09:39:828]: Resetting cached policy values
MSI (s) (A0:BC) [05:09:39:828]: Machine policy value 'Debug' is 0
MSI (s) (A0:BC) [05:09:39:828]: ******* RunEngine:
******* Product: c:\\temp\\t.msi
******* Action:
******* CommandLine: **********
MSI (s) (A0:BC) [05:09:39:859]: Machine policy value 'DisableUserInstalls' is 0
MSI (s) (A0:BC) [05:09:39:875]: File will have security applied from OpCode.
MSI (s) (A0:BC) [05:09:39:890]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'c:\\temp\\t.msi' against software restriction policy
MSI (s) (A0:BC) [05:09:39:890]: SOFTWARE RESTRICTION POLICY: c:\\temp\\t.msi has a digital signature
MSI (s) (A0:BC) [05:09:40:609]: SOFTWARE RESTRICTION POLICY: c:\\temp\\t.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (A0:BC) [05:09:40:609]: End dialog not enabled
MSI (s) (A0:BC) [05:09:40:609]: Original package ==> c:\\temp\\t.msi
MSI (s) (A0:BC) [05:09:40:609]: Package we're running from ==> c:\WINDOWS\Installer\3ae604a.msi
MSI (s) (A0:BC) [05:09:40:609]: APPCOMPAT: looking for appcompat database entry with ProductCode '{E6B105B8-1F65-4428-9397-1DFD8A03B94D}'.
MSI (s) (A0:BC) [05:09:40:609]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (A0:BC) [05:09:40:609]: MSCOREE not loaded loading copy from system32
MSI (s) (A0:BC) [05:09:40:609]: Machine policy value 'TransformsSecure' is 0
MSI (s) (A0:BC) [05:09:40:609]: User policy value 'TransformsAtSource' is 0
MSI (s) (A0:BC) [05:09:40:609]: Machine policy value 'DisablePatch' is 0
MSI (s) (A0:BC) [05:09:40:609]: Machine policy value 'AllowLockdownPatch' is 0
MSI (s) (A0:BC) [05:09:40:609]: Machine policy value 'DisableLUAPatching' is 0
MSI (s) (A0:BC) [05:09:40:609]: Machine policy value 'DisableFlyWeightPatching' is 0
MSI (s) (A0:BC) [05:09:40:609]: APPCOMPAT: looking for appcompat database entry with ProductCode '{E6B105B8-1F65-4428-9397-1DFD8A03B94D}'.
MSI (s) (A0:BC) [05:09:40:609]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (A0:BC) [05:09:40:609]: Transforms are not secure.
MSI (s) (A0:BC) [05:09:40:609]: Note: 1: 2205 2: 3: Control
MSI (s) (A0:BC) [05:09:40:609]: Command Line: SOURCEGUID=6E6B36EB-9156-411B-B951-C735F4747DCF USERGUID=027E5B10-7289-EB87-9BA8-81F339385512 INSTALLING=TRUE CURRENTDIRECTORY=C:\WINDOWS\system32 CLIENTUILEVEL=3 CLIENTPROCESSID=2888
MSI (s) (A0:BC) [05:09:40:609]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{F3067088-47A4-4926-A49D-E3FBD2A659EE}'.
MSI (s) (A0:BC) [05:09:40:609]: Product Code passed to Engine.Initialize: ''
MSI (s) (A0:BC) [05:09:40:609]: Product Code from property table before transforms: '{E6B105B8-1F65-4428-9397-1DFD8A03B94D}'
MSI (s) (A0:BC) [05:09:40:609]: Product Code from property table after transforms: '{E6B105B8-1F65-4428-9397-1DFD8A03B94D}'
MSI (s) (A0:BC) [05:09:40:609]: Product not registered: beginning first-time install
MSI (s) (A0:BC) [05:09:40:609]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.
MSI (s) (A0:BC) [05:09:40:609]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (A0:BC) [05:09:40:609]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (A0:BC) [05:09:40:609]: Adding new sources is allowed.
MSI (s) (A0:BC) [05:09:40:609]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.
MSI (s) (A0:BC) [05:09:40:609]: Package name extracted from package path: 't.msi'
MSI (s) (A0:BC) [05:09:40:609]: Package to be registered: 't.msi'
MSI (s) (A0:BC) [05:09:40:609]: Note: 1: 2205 2: 3: Error
MSI (s) (A0:BC) [05:09:40:609]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:609]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:609]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:609]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2729
MSI (s) (A0:BC) [05:09:40:625]: Note: 1: 2262 2: AdminProperties 3: -2147287038
MSI (s) (A0:BC) [05:09:40:625]: Machine policy value 'DisableMsi' is 0
MSI (s) (A0:BC) [05:09:40:625]: Machine policy value 'AlwaysInstallElevated' is 1
MSI (s) (A0:BC) [05:09:40:625]: User policy value 'AlwaysInstallElevated' is 1
MSI (s) (A0:BC) [05:09:40:625]: Product installation will be elevated because user is admin and product is being installed per-machine.
MSI (s) (A0:BC) [05:09:40:625]: Running product '{E6B105B8-1F65-4428-9397-1DFD8A03B94D}' with elevated privileges: Product is assigned.
MSI (s) (A0:BC) [05:09:40:625]: PROPERTY CHANGE: Modifying SOURCEGUID property. Its current value is 'CCC9642C-CB76-46E5-AF27-7D7B5DD2348B'. Its new value: '6E6B36EB-9156-411B-B951-C735F4747DCF'.
MSI (s) (A0:BC) [05:09:40:625]: PROPERTY CHANGE: Modifying USERGUID property. Its current value is '00000000-0000-0000-0000-000000000000'. Its new value: '027E5B10-7289-EB87-9BA8-81F339385512'.
MSI (s) (A0:BC) [05:09:40:625]: PROPERTY CHANGE: Adding INSTALLING property. Its value is 'TRUE'.
MSI (s) (A0:BC) [05:09:40:625]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'C:\WINDOWS\system32'.
MSI (s) (A0:BC) [05:09:40:625]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.
MSI (s) (A0:BC) [05:09:40:625]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '2888'.
MSI (s) (A0:BC) [05:09:40:625]: TRANSFORMS property is now:
MSI (s) (A0:BC) [05:09:40:625]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '300'.
MSI (s) (A0:BC) [05:09:40:625]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\Application Data
MSI (s) (A0:BC) [05:09:40:625]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\Favorites
MSI (s) (A0:BC) [05:09:40:625]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\NetHood
MSI (s) (A0:BC) [05:09:40:625]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\My Documents
MSI (s) (A0:BC) [05:09:40:625]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\PrintHood
MSI (s) (A0:BC) [05:09:40:625]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\Recent
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\SendTo
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\Templates
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Application Data
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\Local Settings\Application Data
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\My Documents\My Pictures
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs\Startup
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Desktop
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\Start Menu\Programs\Administrative Tools
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\Start Menu\Programs\Startup
MSI (s) (A0:BC) [05:09:40:640]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\Start Menu\Programs
MSI (s) (A0:BC) [05:09:40:656]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\Start Menu
MSI (s) (A0:BC) [05:09:40:656]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\brian\Desktop
MSI (s) (A0:BC) [05:09:40:656]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Templates
MSI (s) (A0:BC) [05:09:40:656]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\Fonts
MSI (s) (A0:BC) [05:09:40:656]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16
MSI (s) (A0:BC) [05:09:40:656]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
MSI (s) (A0:BC) [05:09:40:656]: PROPERTY CHANGE: Adding USERNAME property. Its value is ' '.
MSI (s) (A0:BC) [05:09:40:656]: PROPERTY CHANGE: Adding COMPANYNAME property. Its value is ' '.
MSI (s) (A0:BC) [05:09:40:656]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'c:\WINDOWS\Installer\3ae604a.msi'.
MSI (s) (A0:BC) [05:09:40:656]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'c:\\temp\\t.msi'.
MSI (s) (A0:BC) [05:09:40:656]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (A0:BC) [05:09:40:656]: Machine policy value 'DisableRollback' is 0
MSI (s) (A0:BC) [05:09:40:656]: User policy value 'DisableRollback' is 0
MSI (s) (A0:BC) [05:09:40:656]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.
=== Logging started: 4/20/2014 5:09:40 ===
MSI (s) (A0:BC) [05:09:40:656]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
MSI (s) (A0:BC) [05:09:40:656]: Doing action: INSTALL
MSI (s) (A0:BC) [05:09:40:656]: Note: 1: 2205 2: 3: ActionText
MSI (s) (A0:BC) [05:09:40:656]: Running ExecuteSequence
MSI (s) (A0:BC) [05:09:40:656]: Doing action: FindRelatedProducts
MSI (s) (A0:BC) [05:09:40:656]: Note: 1: 2205 2: 3: ActionText
Action start 5:09:40: INSTALL.
Action start 5:09:40: FindRelatedProducts.
MSI (s) (A0:BC) [05:09:40:656]: Doing action: AppSearch
MSI (s) (A0:BC) [05:09:40:656]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: FindRelatedProducts. Return value 1.
Action start 5:09:40: AppSearch.
MSI (s) (A0:BC) [05:09:40:656]: Note: 1: 2262 2: Signature 3: -2147287038
MSI (s) (A0:BC) [05:09:40:656]: PROPERTY CHANGE: Adding MYLOCALAPPDATA property. Its value is 'c:\Documents and Settings\brian\Local Settings\Application Data\'.
MSI (s) (A0:BC) [05:09:40:656]: Doing action: LaunchConditions
MSI (s) (A0:BC) [05:09:40:656]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: AppSearch. Return value 1.
Action start 5:09:40: LaunchConditions.
MSI (s) (A0:BC) [05:09:40:656]: Doing action: ValidateProductID
MSI (s) (A0:BC) [05:09:40:656]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: LaunchConditions. Return value 1.
Action start 5:09:40: ValidateProductID.
MSI (s) (A0:BC) [05:09:40:656]: Doing action: CostInitialize
MSI (s) (A0:BC) [05:09:40:656]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: ValidateProductID. Return value 1.
MSI (s) (A0:BC) [05:09:40:671]: Machine policy value 'MaxPatchCacheSize' is 10
Action start 5:09:40: CostInitialize.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'c:\'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: Patch
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: __MsiPatchFileList
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2228 2: 3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId`
MSI (s) (A0:BC) [05:09:40:671]: Doing action: SetINSTALLLOCATION
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: CostInitialize. Return value 1.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding INSTALLLOCATION property. Its value is 'C:\Program Files\SupraSavings'.
Action start 5:09:40: SetINSTALLLOCATION.
MSI (s) (A0:BC) [05:09:40:671]: Doing action: FileCost
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: SetINSTALLLOCATION. Return value 1.
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: MsiAssembly
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: Class
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: Extension
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: TypeLib
Action start 5:09:40: FileCost.
MSI (s) (A0:BC) [05:09:40:671]: Doing action: SetChromeIdPath
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: FileCost. Return value 1.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding ChromeIdPath property. Its value is 'c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\afjegdojkkoghnbiollpogeeimocanmk'.
Action start 5:09:40: SetChromeIdPath.
MSI (s) (A0:BC) [05:09:40:671]: Doing action: SetChromeVersionPath
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: SetChromeIdPath. Return value 1.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding ChromeVersionPath property. Its value is 'c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\afjegdojkkoghnbiollpogeeimocanmk\5.0_0'.
Action start 5:09:40: SetChromeVersionPath.
MSI (s) (A0:BC) [05:09:40:671]: Doing action: CostFinalize
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: SetChromeVersionPath. Return value 1.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: Patch
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: Condition
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'c:\'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Modifying WindowsFolder property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Modifying ProgramFilesFolder property. Its current value is 'C:\Program Files\'. Its new value: 'c:\Program Files\'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Modifying INSTALLLOCATION property. Its current value is 'C:\Program Files\SupraSavings'. Its new value: 'c:\Program Files\SupraSavings\'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding Google property. Its value is 'c:\Documents and Settings\brian\Local Settings\Application Data\Google\'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding Chrome property. Its value is 'c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding User_Data property. Its value is 'c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding Default property. Its value is 'c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\Default\'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding Extensions property. Its value is 'c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Modifying ChromeIdPath property. Its current value is 'c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\afjegdojkkoghnbiollpogeeimocanmk'. Its new value: 'c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\afjegdojkkoghnbiollpogeeimocanmk\'.
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Modifying ChromeVersionPath property. Its current value is 'c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\afjegdojkkoghnbiollpogeeimocanmk\5.0_0'. Its new value: 'c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\afjegdojkkoghnbiollpogeeimocanmk\5.0_0\'.
MSI (s) (A0:BC) [05:09:40:671]: Target path resolution complete. Dumping Directory table...
MSI (s) (A0:BC) [05:09:40:671]: Note: target paths subject to change (via custom actions or browsing)
MSI (s) (A0:BC) [05:09:40:671]: Dir (target): Key: TARGETDIR , Object: c:\
MSI (s) (A0:BC) [05:09:40:671]: Dir (target): Key: WindowsFolder , Object: c:\WINDOWS\
MSI (s) (A0:BC) [05:09:40:671]: Dir (target): Key: ProgramFilesFolder , Object: c:\Program Files\
MSI (s) (A0:BC) [05:09:40:671]: Dir (target): Key: INSTALLLOCATION , Object: c:\Program Files\SupraSavings\
MSI (s) (A0:BC) [05:09:40:671]: Dir (target): Key: MYLOCALAPPDATA , Object: c:\Documents and Settings\brian\Local Settings\Application Data\
MSI (s) (A0:BC) [05:09:40:671]: Dir (target): Key: Google , Object: c:\Documents and Settings\brian\Local Settings\Application Data\Google\
MSI (s) (A0:BC) [05:09:40:671]: Dir (target): Key: Chrome , Object: c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\
MSI (s) (A0:BC) [05:09:40:671]: Dir (target): Key: User_Data , Object: c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\
MSI (s) (A0:BC) [05:09:40:671]: Dir (target): Key: Default , Object: c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\Default\
MSI (s) (A0:BC) [05:09:40:671]: Dir (target): Key: Extensions , Object: c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\
MSI (s) (A0:BC) [05:09:40:671]: Dir (target): Key: ChromeIdPath , Object: c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\afjegdojkkoghnbiollpogeeimocanmk\
MSI (s) (A0:BC) [05:09:40:671]: Dir (target): Key: ChromeVersionPath , Object: c:\Documents and Settings\brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\afjegdojkkoghnbiollpogeeimocanmk\5.0_0\
MSI (s) (A0:BC) [05:09:40:671]: PROPERTY CHANGE: Adding INSTALLLEVEL property. Its value is '1'.
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: MsiAssembly
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2228 2: 3: MsiAssembly 4: SELECT `MsiAssembly`.`Attributes`, `MsiAssembly`.`File_Application`, `MsiAssembly`.`File_Manifest`, `Component`.`KeyPath` FROM `MsiAssembly`, `Component` WHERE `MsiAssembly`.`Component_` = `Component`.`Component` AND `MsiAssembly`.`Component_` = ?
Action start 5:09:40: CostFinalize.
MSI (s) (A0:BC) [05:09:40:671]: Doing action: MigrateFeatureStates
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: CostFinalize. Return value 1.
Action start 5:09:40: MigrateFeatureStates.
MSI (s) (A0:BC) [05:09:40:671]: Doing action: InstallValidate
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: MigrateFeatureStates. Return value 0.
MSI (s) (A0:BC) [05:09:40:671]: Feature: ProductFeature; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: RegistryEntries; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: INSTALLLOCATION; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: SendJson; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: IEDLL; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: ChromeFiles; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: ChromeCAs; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: FirefoxFiles; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: RemoveChromeGoogle; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: RemoveChromeChrome; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: RemoveChromeUser_Data; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: RemoveChromeDefault; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: RemoveChromeExtensions; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: RemoveChromeId; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: RemoveChromeVersion; Installed: Absent; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: __RegistryEntries65; Installed: Null; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: __RemoveChromeGoogle65; Installed: Null; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: __RemoveChromeChrome65; Installed: Null; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: __RemoveChromeUser_Data65; Installed: Null; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: __RemoveChromeDefault65; Installed: Null; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: __RemoveChromeExtensions65; Installed: Null; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: __RemoveChromeId65; Installed: Null; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Component: __RemoveChromeVersion65; Installed: Null; Request: Local; Action: Local
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: BindImage
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: ProgId
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: PublishComponent
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: SelfReg
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: Extension
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: Font
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: Shortcut
MSI (s) (A0:BC) [05:09:40:671]: Note: 1: 2205 2: 3: Class
Action start 5:09:40: InstallValidate.
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: _RemoveFilePath
MSI (s) (A0:BC) [05:09:40:687]: PROPERTY CHANGE: Modifying CostingComplete property. Its current value is '0'. Its new value: '1'.
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: BindImage
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: ProgId
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: PublishComponent
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: SelfReg
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: Extension
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: Font
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: Shortcut
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: Class
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2727 2:
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2727 2:
MSI (s) (A0:BC) [05:09:40:687]: Doing action: RemoveExistingProducts
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: InstallValidate. Return value 1.
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: Error
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 22
Action start 5:09:40: RemoveExistingProducts.
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: Error
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 23
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: Error
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 16
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2205 2: 3: Error
MSI (s) (A0:BC) [05:09:40:687]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 21
MSI (s) (A0:BC) [05:09:40:703]: Doing action: InstallInitialize
MSI (s) (A0:BC) [05:09:40:703]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:40: RemoveExistingProducts. Return value 1.
MSI (s) (A0:BC) [05:09:40:703]: Machine policy value 'AlwaysInstallElevated' is 1
MSI (s) (A0:BC) [05:09:40:703]: User policy value 'AlwaysInstallElevated' is 1
MSI (s) (A0:BC) [05:09:40:703]: BeginTransaction: Locking Server
MSI (s) (A0:BC) [05:09:40:703]: SRSetRestorePoint skipped for this transaction.
MSI (s) (A0:BC) [05:09:40:703]: Server not locked: locking for product {E6B105B8-1F65-4428-9397-1DFD8A03B94D}

MSI (s) (A0:BC) [05:09:41:671]: Skipping action: SetParamsUninstall (condition is false)
MSI (s) (A0:BC) [05:09:41:671]: Skipping action: CustomActionUninstall (condition is false)
MSI (s) (A0:BC) [05:09:41:671]: Doing action: SetParamsJsonInstall
MSI (s) (A0:BC) [05:09:41:671]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:41: CustomActionInstall. Return value 1.
MSI (s) (A0:BC) [05:09:41:671]: PROPERTY CHANGE: Adding SendJson property. Its value is 'UserGUID:027E5B10-7289-EB87-9BA8-81F339385512 SourceGUID:6E6B36EB-9156-411B-B951-C735F4747DCF AdminPrivileges:1 Installing:TRUE'.
Action start 5:09:41: SetParamsJsonInstall.
MSI (s) (A0:BC) [05:09:41:671]: Skipping action: SetParamsJsonUninstall (condition is false)
MSI (s) (A0:BC) [05:09:41:671]: Doing action: SendJson
MSI (s) (A0:BC) [05:09:41:671]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:41: SetParamsJsonInstall. Return value 1.
Action start 5:09:41: SendJson.
MSI (s) (A0:BC) [05:09:41:671]: Doing action: WriteRegistryValues
MSI (s) (A0:BC) [05:09:41:671]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:41: SendJson. Return value 1.
Action start 5:09:41: WriteRegistryValues.
MSI (s) (A0:BC) [05:09:41:687]: Doing action: RegisterUser
MSI (s) (A0:BC) [05:09:41:687]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:41: WriteRegistryValues. Return value 1.
Action start 5:09:41: RegisterUser.
MSI (s) (A0:BC) [05:09:41:687]: Doing action: RegisterProduct
MSI (s) (A0:BC) [05:09:41:687]: Note: 1: 2205 2: 3: ActionText
Action ended 5:09:41: RegisterUser. Return value 1.
MSI (s) (A0:BC) [05:09:41:687]: Note: 1: 2205 2: 3: Error
MSI (s) (A0:BC) [05:09:41:687]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1302
m Files\SupraSavings\background.js; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:41:828]: Source for file 'chromebackground.js' is compressed
MSI (s) (A0:BC) [05:09:41:828]: SOFTWARE RESTRICTION POLICY: Verifying object --> 'c:\WINDOWS\Installer\3ae604a.msi' against software restriction policy
MSI (s) (A0:BC) [05:09:41:828]: SOFTWARE RESTRICTION POLICY: c:\WINDOWS\Installer\3ae604a.msi has a digital signature
MSI (s) (A0:BC) [05:09:41:890]: SOFTWARE RESTRICTION POLICY: c:\WINDOWS\Installer\3ae604a.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (A0:BC) [05:09:41:890]: Note: 1: 2318 2: c:\Program Files\SupraSavings\background.js
MSI (s) (A0:BC) [05:09:41:890]: Executing op: FileCopy(SourceName=_vagkn0p|CustomActionInstall,SourceCabKey=CustomActionInstall,DestName=CustomActionInstall,Attributes=512,FileSize=750048,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=21634206,HashPart2=-335398827,HashPart3=-319360909,HashPart4=2068050335,,)
MSI (s) (A0:BC) [05:09:41:890]: File: c:\Program Files\SupraSavings\CustomActionInstall; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:41:890]: Source for file 'CustomActionInstall' is compressed
MSI (s) (A0:BC) [05:09:41:890]: Note: 1: 2318 2: c:\Program Files\SupraSavings\CustomActionInstall
MSI (s) (A0:BC) [05:09:41:890]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:890]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:906]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Executing op: FileCopy(SourceName=v1r51pgm|CustomActionUninstall,SourceCabKey=CustomActionUninstall,DestName=CustomActionUninstall,Attributes=512,FileSize=679904,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-844341917,HashPart2=317871956,HashPart3=-2043211818,HashPart4=-569236099,,)
MSI (s) (A0:BC) [05:09:41:921]: File: c:\Program Files\SupraSavings\CustomActionUninstall; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:41:921]: Source for file 'CustomActionUninstall' is compressed
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2318 2: c:\Program Files\SupraSavings\CustomActionUninstall
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:921]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:41:937]: Executing op: FileCopy(SourceName=fqsd7jr9.js|ff_addon_runner.js,SourceCabKey=ff_addon_runner.js,DestName=ff_addon_runner.js,Attributes=512,FileSize=4931,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1350003814,HashPart2=-161944819,HashPart3=1270624866,HashPart4=-333340548,,)
MSI (s) (A0:BC) [05:09:41:937]: File: c:\Program Files\SupraSavings\ff_addon_runner.js; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:41:937]: Source for file 'ff_addon_runner.js' is compressed
MSI (s) (A0:BC) [05:09:41:937]: Note: 1: 2318 2: c:\Program Files\SupraSavings\ff_addon_runner.js
MSI (s) (A0:BC) [05:09:41:953]: Executing op: FileCopy(SourceName=3-fb7qwe.js|ff_addonkit_page-mod.js,SourceCabKey=ff_addonkit_pagemod.js,DestName=ff_addonkit_page-mod.js,Attributes=512,FileSize=12993,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=883860745,HashPart2=-602934867,HashPart3=1799567804,HashPart4=-541831337,,)
MSI (s) (A0:BC) [05:09:41:953]: File: c:\Program Files\SupraSavings\ff_addonkit_page-mod.js; To be installed; Won't patch; No existing file
512,FileSize=5036,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=1665015030,HashPart2=-357152522,HashPart3=625369980,HashPart4=-1876513250,,)
MSI (s) (A0:BC) [05:09:42:093]: File: c:\Program Files\SupraSavings\icon64.png; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:42:093]: Source for file 'icon64.png' is compressed
MSI (s) (A0:BC) [05:09:42:093]: Note: 1: 2318 2: c:\Program Files\SupraSavings\icon64.png
MSI (s) (A0:BC) [05:09:42:093]: Executing op: FileCopy(SourceName=icon8.png,SourceCabKey=icon8.png,DestName=icon8.png,Attributes=512,FileSize=2985,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1577158660,HashPart2=1560357933,HashPart3=-180336459,HashPart4=1950543925,,)
MSI (s) (A0:BC) [05:09:42:093]: File: c:\Program Files\SupraSavings\icon8.png; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:42:093]: Source for file 'icon8.png' is compressed
MSI (s) (A0:BC) [05:09:42:093]: Note: 1: 2318 2: c:\Program Files\SupraSavings\icon8.png
MSI (s) (A0:BC) [05:09:42:093]: Executing op: FileCopy(SourceName=2rs3.dll,SourceCabKey=IEDLL,DestName=2rs3.dll,Attributes=512,FileSize=91104,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1996536291,HashPart2=379913990,HashPart3=1571666500,HashPart4=-1248328482,,)
MSI (s) (A0:BC) [05:09:42:093]: File: c:\Program Files\SupraSavings\2rs3.dll; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:42:093]: Source for file 'IEDLL' is compressed
MSI (s) (A0:BC) [05:09:42:093]: Note: 1: 2318 2: c:\Program Files\SupraSavings\2rs3.dll
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:109]: Executing op: FileCopy(SourceName=iwalyk.js,SourceCabKey=iwalyk.js,DestName=iwalyk.js,Attributes=512,FileSize=0,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=0,HashPart2=0,HashPart3=0,HashPart4=0,,)
MSI (s) (A0:BC) [05:09:42:109]: File: c:\Program Files\SupraSavings\iwalyk.js; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:42:109]: Source for file 'iwalyk.js' is compressed
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2318 2: c:\Program Files\SupraSavings\iwalyk.js
MSI (s) (A0:BC) [05:09:42:109]: Executing op: FileCopy(SourceName=jmqdfyrj.jso|manifest.json,SourceCabKey=manifest.json,DestName=manifest.json,Attributes=512,FileSize=1039,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1224901877,HashPart2=544074028,HashPart3=1510836133,HashPart4=567222482,,)
MSI (s) (A0:BC) [05:09:42:109]: File: c:\Program Files\SupraSavings\manifest.json; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:42:109]: Source for file 'manifest.json' is compressed
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2318 2: c:\Program Files\SupraSavings\manifest.json
MSI (s) (A0:BC) [05:09:42:109]: Executing op: FileCopy(SourceName=3iioeqgh.js|marcopolo.js,SourceCabKey=marcopolo.js,DestName=marcopolo.js,Attributes=512,FileSize=607,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1150160956,HashPart2=-879076789,HashPart3=942927881,HashPart4=-1817786394,,)
MSI (s) (A0:BC) [05:09:42:109]: File: c:\Program Files\SupraSavings\marcopolo.js; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:42:109]: Source for file 'marcopolo.js' is compressed
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2318 2: c:\Program Files\SupraSavings\marcopolo.js
MSI (s) (A0:BC) [05:09:42:109]: Executing op: FileCopy(SourceName=SendJson.dll,SourceCabKey=SendJson,DestName=SendJson.dll,Attributes=512,FileSize=345600,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=2061189910,HashPart2=-198646395,HashPart3=808127545,HashPart4=1125873623,,)
MSI (s) (A0:BC) [05:09:42:109]: File: c:\Program Files\SupraSavings\SendJson.dll; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:42:109]: Source for file 'SendJson' is compressed
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2318 2: c:\Program Files\SupraSavings\SendJson.dll
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:109]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Executing op: FileCopy(SourceName=bcdeaqcu.dll|Microsoft.Deployment.WindowsInstaller.dll,SourceCabKey=WindowsInstallerdll,DestName=Microsoft.Deployment.WindowsInstaller.dll,Attributes=512,FileSize=180224,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,Version=3.6.3303.0,Language=0,InstallMode=58982400,,,,,,,)
MSI (s) (A0:BC) [05:09:42:125]: File: c:\Program Files\SupraSavings\Microsoft.Deployment.WindowsInstaller.dll; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:42:125]: Source for file 'WindowsInstallerdll' is compressed
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2318 2: c:\Program Files\SupraSavings\Microsoft.Deployment.WindowsInstaller.dll
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Executing op: FileCopy(SourceName=teowi4lc.xml|Microsoft.Deployment.WindowsInstaller.xml,SourceCabKey=WindowsInstallerxml,DestName=Microsoft.Deployment.WindowsInstaller.xml,Attributes=512,FileSize=485807,PerTick=32768,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-529702913,HashPart2=120212815,HashPart3=-1778603535,HashPart4=-1307356715,,)
MSI (s) (A0:BC) [05:09:42:125]: File: c:\Program Files\SupraSavings\Microsoft.Deployment.WindowsInstaller.xml; To be installed; Won't patch; No existing file
MSI (s) (A0:BC) [05:09:42:125]: Source for file 'WindowsInstallerxml' is compressed
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2318 2: c:\Program Files\SupraSavings\Microsoft.Deployment.WindowsInstaller.xml
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:125]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:140]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:140]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:140]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:140]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:140]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:140]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:140]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:140]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:140]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:140]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:140]: Note: 1: 2360
MSI (s) (A0:BC) [05:09:42:140]: Executing op: CacheSizeFlush(,)
MSI (s) (A0:BC) [05:09:42:140]: Executing op: InstallProtectedFiles(AllowUI=0)
MSI (s) (A0:BC) [05:09:42:140]: Executing op: ActionStart(Name=CustomActionInstall,,)
MSI (s) (A0:BC) [05:09:42:171]: Executing op: CustomActionSchedule(Action=CustomActionInstall,ActionType=3137,Source=BinaryData,Target=Install,CustomActionData=SourceGUID:6E6B36EB-9156-411B-B951-C735F4747DCF VMFlag: UserGUID:027E5B10-7289-EB87-9BA8-81F339385512 FFEnabled: IEEnabled: ChromeEnabled: Options:-1)
MSI (s) (A0:44) [05:09:42:187]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI33D.tmp, Entrypoint: Install
MSI (s) (A0:A8) [05:09:42:187]: Generating random cookie.
MSI (s) (A0:A8) [05:09:42:187]: Created Custom Action Server with PID 2856 (0xB28).
MSI (s) (A0:7C) [05:09:42:234]: Running as a service.
MSI (s) (A0:7C) [05:09:42:234]: Hello, I'm your 32bit Elevated custom action server.
Install: Initialized.
Install: Custom Action Data = 'SourceGUID:6E6B36EB-9156-411B-B951-C735F4747DCF VMFlag: UserGUID:027E5B10-7289-EB87-9BA8-81F339385512 FFEnabled: IEEnabled: ChromeEnabled: Options:-1'.
Install: In GetParameters
Install: SourceGUID = 6E6B36EB-9156-411B-B951-C735F4747DCF
Install: VMFlag =
Install: UserGUID = 027E5B10-7289-EB87-9BA8-81F339385512
Install: FFEnabled =
Install: IEEnabled =
Install: ChromeEnabled =
Install: OptionsArg Before GetParameters =
Install: OptionsArg After GetParameters= -1
Install: Completed GetParameters
Install: In Install, retrieved parameters.
Install: Attempting to open registry key Software
Install: Attempting to create registry key SupraSavings
Install: Attempting to create registry key SupraSavings
Install: Attempting to create registry key Chrome
Install: Attempting to create registry key IE
Install: Attempting to create registry key Firefox
Install: Begin Kill All Browsers
Install: Finished Kill All Browsers
Install: Firefox Timestamp...
Install: 1397988583
Install: Attempting to create registry key SupraSavings
Install: Attempting to open key Software\AppDataLow\Software\Supra Savings
Install: Attempting to set registry value 1397988583
Install: Set registry value Software\AppDataLow\Software\Supra Savings\time = 1397988583
Install: Calling SetRegistryKey("Software\SupraSavings\SupraSavings\Chrome", "INSTALLCHROMESTATUS", "FALSE")
Install: Attempting to open key Software\SupraSavings\SupraSavings\Chrome
Install: Attempting to set registry value FALSE
Install: Set registry value Software\SupraSavings\SupraSavings\Chrome\INSTALLCHROMESTATUS = FALSE
Install: In Install, IEEnabled
Install: In Install, BHO_Path = C:\Program Files\SupraSavings\2rs3.dll
Install: In Install IEEnabled, from LoadLibraryEx hLib = 13238272
Install: In Install IEEnabled, DllRegisterServer completed successfully.
Install: Calling SetRegistryKey("Software\SupraSavings\SupraSavings\IE", "INSTALLIESTATUS", "TRUE")
Install: Attempting to open key Software\SupraSavings\SupraSavings\IE
Install: Attempting to set registry value TRUE
Install: Set registry value Software\SupraSavings\SupraSavings\IE\INSTALLIESTATUS = TRUE
Install: Calling SetRegistryKey("Software\SupraSavings\SupraSavings\Firefox", "INSTALLFFSTATUS", "FALSE")
Install: Attempting to open key Software\SupraSavings\SupraSavings\Firefox
Install: Attempting to set registry value FALSE
Install: Set registry value Software\SupraSavings\SupraSavings\Firefox\INSTALLFFSTATUS = FALSE
MSI (s) (A0:BC) [05:09:43:859]: Executing op: ActionStart(Name=SendJson,,)
Install: Installation Successful
MSI (s) (A0:BC) [05:09:43:859]: Executing op: CustomActionSchedule(Action=SendJson,ActionType=3137,Source=BinaryData,Target=PostJson,CustomActionData=UserGUID:027E5B10-7289-EB87-9BA8-81F339385512 SourceGUID:6E6B36EB-9156-411B-B951-C735F4747DCF AdminPrivileges:1 Installing:TRUE)
MSI (s) (A0:68) [05:09:43:875]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI33E.tmp, Entrypoint: PostJson
PostJson: Initialized.
PostJson: Custom Action Data = 'UserGUID:027E5B10-7289-EB87-9BA8-81F339385512 SourceGUID:6E6B36EB-9156-411B-B951-C735F4747DCF AdminPrivileges:1 Installing:TRUE'.
PostJson: In PostJson, calling DoPostJson.
PostJson: In DoPostJson.
PostJson: In GetParameters
PostJson: Error 0x80070006: failed to set property: GUID
PostJson: UserGUID = 027E5B10-7289-EB87-9BA8-81F339385512
PostJson: SourceGUID = 6E6B36EB-9156-411B-B951-C735F4747DCF
PostJson: AdminPrivileges = 1
PostJson: Installing = TRUE
PostJson: WinHttpClient URL = 'http://pickuptruckobserver.com/t/i.csv'.
PostJson: In DoPostJson, wrote data to client.
PostJson: In DoPostJson, sent post request.
PostJson: In DoPostJson, SendHttpRequest success
PostJson: In DoPostJson, httpResponseHeader begin
PostJson: HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: text/plain
Date: Sun, 20 Apr 2014 10:09:47 GMT
Expires: Sun, 20 Apr 2014 10:09:46 GMT
Server: nginx
Content-Length: 0
Connection: keep-alive



Property(S): UserLanguageID = 1033
Property(S): ComputerName = DJRKV3B1
Property(S): SystemLanguageID = 1033
Property(S): ScreenX = 1024
Property(S): ScreenY = 768
Property(S): CaptionHeight = 19
Property(S): BorderTop = 1
Property(S): BorderSide = 1
Property(S): TextHeight = 16
Property(S): ColorBits = 32
Property(S): TTCSupport = 1
Property(S): Time = 5:09:44
Property(S): Date = 4/20/2014
Property(S): MsiNetAssemblySupport = 4.0.30319.1
Property(S): MsiWin32AssemblySupport = 5.1.2600.5512
Property(S): RedirectedDllSupport = 2
Property(S): Privileged = 1
Property(S): USERNAME =
Property(S): COMPANYNAME =
Property(S): DATABASE = c:\WINDOWS\Installer\3ae604a.msi
Property(S): OriginalDatabase = c:\\temp\\t.msi
Property(S): UILevel = 2
Property(S): ACTION = INSTALL
Property(S): ROOTDRIVE = c:\
Property(S): CostingComplete = 1
Property(S): INSTALLLEVEL = 1
Property(S): OutOfDiskSpace = 0
Property(S): OutOfNoRbDiskSpace = 0
Property(S): PrimaryVolumeSpaceAvailable = 0
Property(S): PrimaryVolumeSpaceRequired = 0
Property(S): PrimaryVolumeSpaceRemaining = 0
Property(S): SOURCEDIR = c:\\temp\\
Property(S): SourcedirProduct = {E6B105B8-1F65-4428-9397-1DFD8A03B94D}
Property(S): ProductToBeRegistered = 1
MSI (s) (A0:BC) [05:09:44:890]: Note: 1: 1707
MSI (s) (A0:BC) [05:09:44:890]: Note: 1: 2205 2: 3: Error
MSI (s) (A0:BC) [05:09:44:890]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1707
MSI (s) (A0:BC) [05:09:44:890]: Note: 1: 2205 2: 3: Error
MSI (s) (A0:BC) [05:09:44:890]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1709
MSI (s) (A0:BC) [05:09:44:890]: Product: SupraSavings -- Installation completed successfully.

MSI (s) (A0:BC) [05:09:44:921]: Cleaning up uninstalled install packages, if any exist
MSI (s) (A0:BC) [05:09:44:921]: MainEngineThread is returning 0
MSI (s) (A0:2C) [05:09:45:031]: Destroying RemoteAPI object.
MSI (s) (A0:A8) [05:09:45:031]: Custom Action Manager thread ending.
=== Logging stopped: 4/20/2014 5:09:44 ===
MSI (c) (48:14) [05:09:45:031]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1
MSI (c) (48:14) [05:09:45:031]: MainEngineThread is returning 0
=== Verbose logging stopped: 4/20/2014 5:09:45 ===
 

BadAsAl

Distinguished
I noticed SupraSavings in there, that is a known virus. Run some deep virus scans on your system, I like combofix, malwarebytes anti-rootkit, adwcleaner, avast. I would do a boot time scan with avast after running all the other tools as well.
 
Status
Not open for further replies.