Page 4 of 5 First 12345 Last
  1. #61

    Re: Is efnnouse.exe a virus?

    Quote Originally Posted by BrianDrab View Post
    Thanks for the info. While in Safe Mode with Networking, please do the following.

    Step#1 - DISM /RestoreHealth Scan
    Warning:this fix is specific to the user in this thread. No one else should follow these instructions as it may cause more harm than good. If you are after assistance, please start a thread of your own.


    1. Right-click on the Start button and select Command Prompt (Admin)
    2. When command prompt opens, Copy (Ctrl+C) and Paste (Right-click > Paste) the following command into it, then press Enter
      Dism /Online /Cleanup-Image /RestoreHealth
    3. Once it finishes, copy and paste the following into the command-prompt window and press Enter. If prompted to overwrite the existing file go ahead.
      copy %windir%\logs\cbs\cbs.log "%userprofile%\Desktop\cbs.txt"
    4. Once this has completed please go to your Desktop and you will find CBS.txt => Please zip/upload to this thread.
      Please Note:: if the file is too big (over 7MB) to upload to your next post, please upload via a service such as Dropbox or One Drive or SendSpace and just provide the link.
    2015-07-09 05:12:48, Info CBS TI: --- Initializing Trusted Installer ---
    2015-07-09 05:12:49, Info CBS TI: Last boot time: 2015-07-08 14:25:16.424
    2015-07-09 05:12:49, Info CBS TI: Anticipating that shutdown processing will be required.
    2015-07-09 05:12:49, Info CBS Starting TrustedInstaller initialization.
    2015-07-09 05:12:49, Info CBS Ending TrustedInstaller initialization.
    2015-07-09 05:12:49, Info CBS Starting the TrustedInstaller main loop.
    2015-07-09 05:12:49, Info CBS TrustedInstaller service starts successfully.
    2015-07-09 05:12:49, Info CBS No startup processing required, TrustedInstaller service was not set as autostart
    2015-07-09 05:12:49, Info CBS Startup processing thread terminated normally
    2015-07-09 05:12:49, Info CBS Starting TiWorker initialization.
    2015-07-09 05:12:49, Info CBS Ending TiWorker initialization.
    2015-07-09 05:12:49, Info CBS Starting the TiWorker main loop.
    2015-07-09 05:12:49, Info CBS TiWorker starts successfully.
    2015-07-09 05:12:49, Info CBS Universal Time is: 2015-07-09 09:12:49.462
    2015-07-09 05:12:49, Info CBS Loaded Servicing Stack v6.3.9600.17709 with Core: C:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\cbscore.dll
    2015-07-09 05:12:49, Info CSI 00000001@2015/7/9:09:12:49.524 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7ffb2a897f19 @0x7ffb3f544984 @0x7ffb3f5441bb @0x7ff62259d69a @0x7ff62259df4f @0x7ffb51912053)
    2015-07-09 05:12:49, Info CBS SQM: Initializing online with Windows opt-in: False
    2015-07-09 05:12:49, Info CBS SQM: Cleaning up report files older than 10 days.
    2015-07-09 05:12:49, Info CBS SQM: Requesting upload of all unsent reports.
    2015-07-09 05:12:49, Info CBS SQM: Failed to start upload with file pattern: C:\windows\servicing\sqm\*_std.sqm, flags: 0x2 [HRESULT = 0x80004005 - E_FAIL]
    2015-07-09 05:12:49, Info CBS SQM: Failed to start standard sample upload. [HRESULT = 0x80004005 - E_FAIL]
    2015-07-09 05:12:49, Info CBS SQM: Queued 0 file(s) for upload with pattern: C:\windows\servicing\sqm\*_all.sqm, flags: 0x6
    2015-07-09 05:12:49, Info CBS SQM: Warning: Failed to upload all unsent reports. [HRESULT = 0x80004005 - E_FAIL]
    2015-07-09 05:12:49, Info CBS NonStart: Set pending store consistency check.
    2015-07-09 05:12:49, Info CBS Session: 30456359_1837201603 initialized by client WindowsUpdateAgent.
    2015-07-09 05:14:54, Info CBS Trusted Installer successfully registered to be restarted for pre-shutdown
    2015-07-09 05:14:54, Info CBS Trusted Installer is shutting down because: SHUTDOWN_REASON_AUTOSTOP
    2015-07-09 05:14:54, Info CBS TiWorker signaled for shutdown, going to exit.
    2015-07-09 05:14:54, Info CBS Ending the TrustedInstaller main loop.
    2015-07-09 05:14:54, Info CBS Ending the TiWorker main loop.
    2015-07-09 05:14:54, Info CBS Starting TrustedInstaller finalization.
    2015-07-09 05:14:54, Info CBS Starting TiWorker finalization.
    2015-07-09 05:14:54, Info CBS Ending TrustedInstaller finalization.
    2015-07-09 05:14:54, Info CBS Ending TiWorker finalization.
    2015-07-09 10:50:45, Info CBS TI: --- Initializing Trusted Installer ---
    2015-07-09 10:50:45, Info CBS TI: Last boot time: 2015-07-08 14:25:16.424
    2015-07-09 10:50:45, Info CBS TI: Anticipating that shutdown processing will be required.
    2015-07-09 10:50:45, Info CBS Starting TrustedInstaller initialization.
    2015-07-09 10:50:45, Info CBS Ending TrustedInstaller initialization.
    2015-07-09 10:50:45, Info CBS Starting the TrustedInstaller main loop.
    2015-07-09 10:50:45, Info CBS TrustedInstaller service starts successfully.
    2015-07-09 10:50:45, Info CBS No startup processing required, TrustedInstaller service was not set as autostart
    2015-07-09 10:50:45, Info CBS Startup processing thread terminated normally
    2015-07-09 10:50:46, Info CBS Read out cached applicability from TiLight for package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, ApplicableState: 112, CurrentState:32
    2015-07-09 10:50:47, Info CBS Read out cached applicability from TiLight for package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, ApplicableState: 112, CurrentState:32
    2015-07-09 10:50:50, Info CBS Starting TiWorker initialization.
    2015-07-09 10:50:50, Info CBS Ending TiWorker initialization.
    2015-07-09 10:50:50, Info CBS Starting the TiWorker main loop.
    2015-07-09 10:50:50, Info CBS TiWorker starts successfully.
    2015-07-09 10:50:50, Info CBS Universal Time is: 2015-07-09 14:50:50.307
    2015-07-09 10:50:50, Info CBS Loaded Servicing Stack v6.3.9600.17709 with Core: C:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\cbscore.dll
    2015-07-09 10:50:50, Info CSI 00000001@2015/7/9:14:50:50.369 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7ffb46bf7f19 @0x7ffb471f4984 @0x7ffb471f41bb @0x7ff62259d69a @0x7ff62259df4f @0x7ffb51912053)
    2015-07-09 10:50:50, Info CBS SQM: Initializing online with Windows opt-in: False
    2015-07-09 10:50:50, Info CBS SQM: Cleaning up report files older than 10 days.
    2015-07-09 10:50:50, Info CBS SQM: Requesting upload of all unsent reports.
    2015-07-09 10:50:50, Info CBS SQM: Failed to start upload with file pattern: C:\windows\servicing\sqm\*_std.sqm, flags: 0x2 [HRESULT = 0x80004005 - E_FAIL]
    2015-07-09 10:50:50, Info CBS SQM: Failed to start standard sample upload. [HRESULT = 0x80004005 - E_FAIL]
    2015-07-09 10:50:50, Info CBS SQM: Queued 0 file(s) for upload with pattern: C:\windows\servicing\sqm\*_all.sqm, flags: 0x6
    2015-07-09 10:50:50, Info CBS SQM: Warning: Failed to upload all unsent reports. [HRESULT = 0x80004005 - E_FAIL]
    2015-07-09 10:50:50, Info CBS NonStart: Set pending store consistency check.
    2015-07-09 10:50:50, Info CBS Session: 30456406_2782186448 initialized by client WindowsUpdateAgent.
    2015-07-09 10:51:03, Info CBS Session: 30456406_2914999000 initialized by client WindowsUpdateAgent.
    2015-07-09 10:51:05, Info CSI 00000002 IAdvancedInstallerAwareStore_ResolvePendingTransactions (call 1) (flags = 00000004, progress = NULL, phase = 0, pdwDisposition = @0x44c5f8d750
    2015-07-09 10:51:05, Info CSI 00000003 Creating NT transaction (seq 1), objectname [6]"(null)"
    2015-07-09 10:51:05, Info CSI 00000004 Created NT transaction (seq 1) result 0x00000000, handle @0x3c4
    2015-07-09 10:51:06, Info CSI 00000005 Poqexec successfully registered in [ml:26{13},l:24{12}]"SetupExecute"
    2015-07-09 10:51:06, Info CSI 00000006@2015/7/9:14:51:06.213 Beginning NT transaction commit...
    2015-07-09 10:51:06, Info CSI 00000007@2015/7/9:14:51:06.213 CSI perf trace:
    CSIPERF:TXCOMMIT;12727
    2015-07-09 10:51:06, Info CSI 00000008 CSI Store 295380604432 (0x00000044c60e5610) initialized
    2015-07-09 10:51:06, Info CBS Appl: detect Parent, Package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, Parent: Adobe-Flash-For-Windows-Package~31bf3856ad364e35~amd64~~6.3.9600.16384, Disposition = Detect, VersionComp: EQ, ServiceComp: EQ, BuildComp: EQ, DistributionComp: GE, RevisionComp: GE, Exist: present
    2015-07-09 10:51:06, Info CBS Appl: detectParent: package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, parent found: Adobe-Flash-For-Windows-Package~31bf3856ad364e35~amd64~~6.3.9600.16384, state: Installed
    2015-07-09 10:51:06, Info CBS Appl: detect Parent, Package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, disposition state from detectParent: Installed
    2015-07-09 10:51:06, Info CBS Appl: Evaluating package applicability for package Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, applicable state: Installed
    2015-07-09 10:51:06, Info CBS Failed NTFS compressing file \\?\C:\windows\Servicing\Sessions\30456406_2914999000.xml [HRESULT = 0x80070301 - ERROR_COMPRESSION_DISABLED]
    2015-07-09 10:51:06, Info CBS Exec: Asynchrous operation, session completes later
    2015-07-09 10:51:06, Info CBS Exec: Processing started. Client: WindowsUpdateAgent, Session: 30456406_2914999000, Package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1
    2015-07-09 10:51:06, Info CBS Asynchronous Session: 30456406_2914999000 finalized. [HRESULT = 0x00000000 - S_OK]
    2015-07-09 10:51:06, Info CBS Exec: Using execution sequence: 1212
    2015-07-09 10:51:06, Info CBS Reboot mark set
    2015-07-09 10:51:06, Info CBS Winlogon: Registering for CreateSession notifications
    2015-07-09 10:51:06, Info CBS Perf: Entering stage: Planning
    2015-07-09 10:51:06, Info CBS Disabling LKG boot option
    2015-07-09 10:51:06, Info CBS Exec: Creating restore point: Package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, current: Resolved, targeted: Resolved
    2015-07-09 10:51:06, Info CBS Restore point type: Install
    2015-07-09 10:51:06, Info CBS Perf: Begin: nested restore point - begin
    2015-07-09 10:51:06, Info CBS Perf: Begin: nested restore point - complete
    2015-07-09 10:51:06, Info CBS Client specifies CbsMovePayload, or client is Windows Update, will move payload to system.
    2015-07-09 10:51:06, Info CBS Appl: detect Parent, Package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, Parent: Adobe-Flash-For-Windows-Package~31bf3856ad364e35~amd64~~6.3.9600.16384, Disposition = Detect, VersionComp: EQ, ServiceComp: EQ, BuildComp: EQ, DistributionComp: GE, RevisionComp: GE, Exist: present
    2015-07-09 10:51:06, Info CBS Appl: detectParent: package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, parent found: Adobe-Flash-For-Windows-Package~31bf3856ad364e35~amd64~~6.3.9600.16384, state: Installed
    2015-07-09 10:51:06, Info CBS Appl: detect Parent, Package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, disposition state from detectParent: Installed
    2015-07-09 10:51:06, Info CBS Appl: Evaluating package applicability for package Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, applicable state: Installed
    2015-07-09 10:51:06, Info CBS Plan: Package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, current: Resolved, pending: Default, start: Resolved, applicable: Installed, targeted: Installed, limit: Installed
    2015-07-09 10:51:06, Info CBS Plan: Package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, Update: 3065823-3_neutral_PACKAGE, current: Resolved, pending: Default, start: Resolved, applicable: Installed, targeted: Installed, limit: Installed, selected: Default
    2015-07-09 10:51:06, Info CBS Appl: detect Parent, Package: Package_for_KB3065823_RTM~31bf3856ad364e35~amd64~~6.3.1.1, Parent: Adobe-Flash-For-Windows-Package~31bf3856ad364e35~amd64~~6.3.9600.16384, Disposition = Detect, VersionComp: EQ, ServiceComp: EQ, BuildComp: EQ, DistributionComp: GE, RevisionComp: GE, Exist: present
    2015-07-09 10:51:06, Info CBS Appl: detectParent: package: Package_for_KB3065823_RTM~31bf3856ad364e35~amd64~~6.3.1.1, parent found: Adobe-Flash-For-Windows-Package~31bf3856ad364e35~amd64~~6.3.9600.16384, state: Installed
    2015-07-09 10:51:06, Info CBS Appl: detect Parent, Package: Package_for_KB3065823_RTM~31bf3856ad364e35~amd64~~6.3.1.1, disposition state from detectParent: Installed
    2015-07-09 10:51:06, Info CBS Appl: Evaluating package applicability for package Package_for_KB3065823_RTM~31bf3856ad364e35~amd64~~6.3.1.1, applicable state: Installed
    2015-07-09 10:51:06, Info CBS Plan: Package: Package_for_KB3065823_RTM~31bf3856ad364e35~amd64~~6.3.1.1, current: Resolved, pending: Default, start: Resolved, applicable: Installed, targeted: Installed, limit: Installed
    2015-07-09 10:51:06, Info CBS Plan: Package: Package_for_KB3065823_RTM~31bf3856ad364e35~amd64~~6.3.1.1, Update: 3065823-2_neutral_PACKAGE, current: Resolved, pending: Default, start: Resolved, applicable: Installed, targeted: Installed, limit: Installed, selected: Default
    2015-07-09 10:51:06, Info CBS Appl: detect Parent, Package: Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, Parent: Adobe-Flash-For-Windows-Package~31bf3856ad364e35~amd64~~6.3.9600.16384, Disposition = Detect, VersionComp: EQ, ServiceComp: EQ, BuildComp: EQ, DistributionComp: GE, RevisionComp: GE, Exist: present
    2015-07-09 10:51:06, Info CBS Appl: detectParent: package: Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, parent found: Adobe-Flash-For-Windows-Package~31bf3856ad364e35~amd64~~6.3.9600.16384, state: Installed
    2015-07-09 10:51:06, Info CBS Appl: detect Parent, Package: Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, disposition state from detectParent: Installed
    2015-07-09 10:51:06, Info CBS Appl: Evaluating package applicability for package Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, applicable state: Installed
    2015-07-09 10:51:06, Info CBS Plan: Package: Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, current: Resolved, pending: Default, start: Resolved, applicable: Installed, targeted: Installed, limit: Installed
    2015-07-09 10:51:06, Info CSI 00000009@2015/7/9:14:51:06.494 CSI Transaction @0x44c60a81b0 initialized for deployment engine {d16d444c-56d8-11d5-882d-0080c847b195} with flags 00000002 and client id [26]"TI5.30456406_2914999000:1/"

    2015-07-09 10:51:06, Info CSI 0000000a@2015/7/9:14:51:06.541 CSI Transaction @0x44c60a81b0 destroyed
    2015-07-09 10:51:06, Info CBS Appl: Selfupdate, Component: amd64_adobe-flash-for-windows_31bf3856ad364e35_0.0.0.0_none_ab9875376a174135 (6.3.9600.17927), elevation:4, lower version revision holder: 6.3.9600.17858
    2015-07-09 10:51:06, Info CBS Appl: SelfUpdate detect, component: amd64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_1ca219133d534727, elevation: 4, applicable: 1
    2015-07-09 10:51:06, Info CBS Appl: Package: Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, Update: 3065823-1_neutral_GDR, Applicable: Applicable, Disposition: Installed
    2015-07-09 10:51:06, Info CBS Plan: Package: Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, Update: 3065823-1_neutral_GDR, current: Resolved, pending: Default, start: Resolved, applicable: Installed, targeted: Installed, limit: Installed, selected: Default
    2015-07-09 10:51:06, Info CBS Plan: Start to process package watchlist.
    2015-07-09 10:51:06, Info CBS Perf: Entering stage: Resolving
    2015-07-09 10:51:06, Info CBS Perf: Resolve chain started.
    2015-07-09 10:51:06, Info CSI 0000000b@2015/7/9:14:51:06.557 CSI Transaction @0x44c6091b10 initialized for deployment engine {d16d444c-56d8-11d5-882d-0080c847b195} with flags 00000002 and client id [79]"TI1.30456406_2914999000:2/Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1"

    2015-07-09 10:51:06, Info CSI 0000000c@2015/7/9:14:51:06.557 CSI Transaction @0x44c6091b10 destroyed
    2015-07-09 10:51:06, Info CBS Perf: Resolve chain complete.
    2015-07-09 10:51:06, Info CBS Perf: Stage chain started.
    2015-07-09 10:51:06, Info CBS Perf: Entering stage: Staging
    2015-07-09 10:51:06, Info CSI 0000000d@2015/7/9:14:51:06.588 CSI Transaction @0x44c6091b10 initialized for deployment engine {d16d444c-56d8-11d5-882d-0080c847b195} with flags 00000002 and client id [79]"TI3.30456406_2914999000:3/Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1"

    2015-07-09 10:51:06, Info CSI 0000000e@2015/7/9:14:51:06.588 CSI Transaction @0x44c60a81b0 initialized for deployment engine {d16d444c-56d8-11d5-882d-0080c847b195} with flags 00000002 and client id [65]"TI2.0_0:0/Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1"

    2015-07-09 10:51:06, Info CBS Exec: Staging Package: Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, Update: 3065823-1_neutral_GDR
    2015-07-09 10:51:06, Info CBS Exec: Staging Package: Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, Update: 3065823-1_neutral_GDR, MarkDeploymentStaged: amd64_20268ebbaea8f1defc61d548921ed35d_31bf3856ad364e35_6.3.9600.17927_none_a6e3ad56aa1e25db
    2015-07-09 10:51:06, Info CSI 0000000f@2015/7/9:14:51:06.900 CSI Transaction @0x44c60a81b0 destroyed
    2015-07-09 10:51:07, Info CSI 00000010 Performing 10 operations; 10 are not lock/unlock and follow:
    (0) StageFile (2): flags: 8 app: (null) comp: Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral file: [ml:24{12},l:22{11}]"activex.vch" srcfile: @0x44c6096ce8
    (1) StageFile (2): flags: 8 app: (null) comp: Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral file: [ml:44{22},l:42{21}]"FlashUtil_ActiveX.dll" srcfile: @0x44c60961a8
    (2) StageFile (2): flags: 8 app: (null) comp: Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral file: [ml:44{22},l:42{21}]"FlashUtil_ActiveX.exe" srcfile: @0x44c6097318
    (3) StageFile (2): flags: 8 app: (null) comp: Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral file: [ml:20{10},l:18{9}]"Flash.ocx" srcfile: @0x44c60966b8
    (4) StageFile (2): flags: 8 app: (null) comp: Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral file: [ml:38{19},l:36{18}]"FlashPlayerApp.exe" srcfile: @0x44c6096988
    (5) StageFile (2): flags: 8 app: (null) comp: Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeNam
    2015-07-09 10:51:07, Info CSI e neutral, PublicKey neutral file: [ml:24{12},l:22{11}]"activex.vch" srcfile: @0x44c6096e08
    (6) StageFile (2): flags: 8 app: (null) comp: Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral file: [ml:44{22},l:42{21}]"FlashPlayerCPLApp.cpl" srcfile: @0x44c6096c58
    (7) StageFile (2): flags: 8 app: (null) comp: Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral file: [ml:44{22},l:42{21}]"FlashUtil_ActiveX.dll" srcfile: @0x44c6097168
    (8) StageFile (2): flags: 8 app: (null) comp: Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral file: [ml:44{22},l:42{21}]"FlashUtil_ActiveX.exe" srcfile: @0x44c6097dc8
    (9) StageFile (2): flags: 8 app: (null) comp: Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral file: [ml:20{10},l:18{9}]"Flash.ocx" srcfile: @0x44c6095c98
    2015-07-09 10:51:09, Info CSI 00000011 Performing 1 operations; 1 are not lock/unlock and follow:
    (0) MarkStaged (17): flags: 0 tlc: [20268ebbaea8f1defc61d548921ed35d, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral]) ref: ( flgs: 00000000 guid: {d16d444c-56d8-11d5-882d-0080c847b195} name: [l:154{77}]"Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1.3065823-1_neutral_GDR" ncdata: [l:0]"")
    2015-07-09 10:51:09, Info CSI 00000012 ICSITransaction::Commit calling IStorePendingTransaction::Apply - coldpatching=FALSE applyflags=7
    2015-07-09 10:51:09, Info CSI 00000013 Creating NT transaction (seq 2), objectname [6]"(null)"
    2015-07-09 10:51:09, Info CSI 00000014 Created NT transaction (seq 2) result 0x00000000, handle @0x4cc
    2015-07-09 10:51:09, Info CSI 00000015@2015/7/9:14:51:09.994 Beginning NT transaction commit...
    2015-07-09 10:51:10, Info CSI 00000016@2015/7/9:14:51:10.275 CSI perf trace:
    CSIPERF:TXCOMMIT;562404
    2015-07-09 10:51:10, Info CSI 00000017 Creating NT transaction (seq 3), objectname [6]"(null)"
    2015-07-09 10:51:10, Info CSI 00000018 Created NT transaction (seq 3) result 0x00000000, handle @0x4ec
    2015-07-09 10:51:10, Info CSI 00000019 Poqexec successfully registered in [ml:26{13},l:24{12}]"SetupExecute"
    2015-07-09 10:51:10, Info CSI 0000001a@2015/7/9:14:51:10.307 Beginning NT transaction commit...
    2015-07-09 10:51:10, Info CSI 0000001b@2015/7/9:14:51:10.400 CSI perf trace:
    CSIPERF:TXCOMMIT;187063
    2015-07-09 10:51:10, Info CBS CommitPackagesState: Started persisting state of packages
    2015-07-09 10:51:10, Info CBS CommitPackagesState: Completed persisting state of packages
    2015-07-09 10:51:10, Info CSI 0000001c@2015/7/9:14:51:10.432 CSI Transaction @0x44c6091b10 destroyed
    2015-07-09 10:51:10, Info CBS Perf: Stage chain complete.
    2015-07-09 10:51:10, Info CBS Failed NTFS compressing file \\?\C:\windows\Servicing\Sessions\30456406_2914999000.xml [HRESULT = 0x80070301 - ERROR_COMPRESSION_DISABLED]
    2015-07-09 10:51:10, Info CBS Perf: Execute chain started.
    2015-07-09 10:51:10, Info CBS Perf: Entering stage: Install/Uninstalling
    2015-07-09 10:51:10, Info CBS Exec: Not trying hotpatching because root package is not hotpatch-aware: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1
    2015-07-09 10:51:10, Info CSI 0000001d@2015/7/9:14:51:10.494 CSI Transaction @0x44c6091b10 initialized for deployment engine {d16d444c-56d8-11d5-882d-0080c847b195} with flags 00000002 and client id [79]"TI4.30456406_2914999000:4/Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1"

    2015-07-09 10:51:10, Info CBS Exec: Install package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1
    2015-07-09 10:51:10, Info CBS Exec: Install package: Package_for_KB3065823_RTM~31bf3856ad364e35~amd64~~6.3.1.1
    2015-07-09 10:51:10, Info CBS Exec: Install package: Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1
    2015-07-09 10:51:10, Info CBS Exec: Install package: Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, Update: 3065823-1_neutral_GDR
    2015-07-09 10:51:10, Info CBS Exec: Installing Package: Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, Update: 3065823-1_neutral_GDR, InstallDeployment: amd64_20268ebbaea8f1defc61d548921ed35d_31bf3856ad364e35_6.3.9600.17927_none_a6e3ad56aa1e25db
    2015-07-09 10:51:10, Info CSI 0000001e Performing 1 operations; 1 are not lock/unlock and follow:
    (0) AddCat (14): flags: 1 catfile: @0x44c6097d38
    2015-07-09 10:51:10, Info CBS Plan: Start to process component watchlist
    2015-07-09 10:51:10, Info CBS Setting ExecuteState key to: CbsExecuteStateFailed
    2015-07-09 10:51:10, Info CSI 0000001f Performing 1 operations; 1 are not lock/unlock and follow:
    (0) Install (5): flags: 0 tlc: [20268ebbaea8f1defc61d548921ed35d, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral]) ref: ( flgs: 00000000 guid: {d16d444c-56d8-11d5-882d-0080c847b195} name: [l:154{77}]"Package_1_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1.3065823-1_neutral_GDR" ncdata: [l:2{1}]"5") thumbprint: [l:128{64}]"ddf7eebeed4d68864843588129c3b7549c3099881026b58bcc3562f1aa8e7305"
    2015-07-09 10:51:11, Info CSI 00000020 Component change list: { 6.3.9600.17858 -> 6.3.9600.17927 Adobe-Flash-For-Windows, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral }
    { 6.3.9600.17858 -> 6.3.9600.17927 Adobe-Flash-For-Windows, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral }
    { (null) -> 6.3.9600.17927 20268ebbaea8f1defc61d548921ed35d, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral }
    2015-07-09 10:51:11, Info CSI 00000021 Performing 1 operations; 1 are not lock/unlock and follow:
    (0) LockComponentPath (10): flags: 0 comp: {l:16 b:7f857ab256bad0011e0000001c076010} pathid: {l:16 b:7f857ab256bad0011f0000001c076010} path: [l:222{111}]"\SystemRoot\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40" pid: 71c starttime: 130809270499634804 (0x01d0ba56a5756e74)
    2015-07-09 10:51:12, Info CSI 00000022 ICSITransaction::Commit calling IStorePendingTransaction::Apply - coldpatching=FALSE applyflags=15 (0x0000000f)
    2015-07-09 10:51:12, Info CSI 00000023 Creating NT transaction (seq 4), objectname [6]"(null)"
    2015-07-09 10:51:12, Info CSI 00000024 Created NT transaction (seq 4) result 0x00000000, handle @0x61c
    2015-07-09 10:51:13, Info CSI 00000025@2015/7/9:14:51:13.150 Beginning NT transaction commit...
    2015-07-09 10:51:13, Info CSI 00000026@2015/7/9:14:51:13.775 CSI perf trace:
    CSIPERF:TXCOMMIT;1227774
    2015-07-09 10:51:13, Info CSI 00000027 Begin executing advanced installer phase 24 (0x00000018) index 4 (sequence 26)
    Old component: [ml:296{148},l:294{147}]"Adobe-Flash-For-Windows, Culture=neutral, Version=6.3.9600.17858, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=amd64, versionScope=NonSxS"
    New component: [ml:296{148},l:294{147}]"Adobe-Flash-For-Windows, Culture=neutral, Version=6.3.9600.17927, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=amd64, versionScope=NonSxS"
    Install mode: uninstall
    Installer ID: {e7354f90-519d-4481-82f6-94f6e851f8f9}
    Installer name: [32]"CSI IEFileInstallAI AI installer"
    2015-07-09 10:51:13, Info CSI 00000028 Performing 1 operations; 1 are not lock/unlock and follow:
    (0) LockComponentPath (10): flags: 0 comp: {l:16 b:70b2abb356bad001250000001c076010} pathid: {l:16 b:70b2abb356bad001260000001c076010} path: [l:238{119}]"\SystemRoot\WinSxS\amd64_microsoft-windows-s..ingstack-base-extra_31bf3856ad364e35_6.3.9600.17709_none_101ebcca97054639" pid: 71c starttime: 130809270499634804 (0x01d0ba56a5756e74)
    2015-07-09 10:51:13, Info CSI 00000029 Performing 1 operations; 1 are not lock/unlock and follow:
    (0) LockComponentPath (10): flags: 0 comp: {l:16 b:8c00bab356bad001270000001c076010} pathid: {l:16 b:8c00bab356bad001280000001c076010} path: [l:204{102}]"\SystemRoot\WinSxS\amd64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17858_none_1c82a7b33d6ab72a" pid: 71c starttime: 130809270499634804 (0x01d0ba56a5756e74)
    2015-07-09 10:51:13, Info CSI 0000002a Performing 1 operations; 1 are not lock/unlock and follow:
    (0) LockComponentPath (10): flags: 0 comp: {l:16 b:9d8ac3b356bad001290000001c076010} pathid: {l:16 b:9d8ac3b356bad0012a0000001c076010} path: [l:204{102}]"\SystemRoot\WinSxS\amd64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_1ca219133d534727" pid: 71c starttime: 130809270499634804 (0x01d0ba56a5756e74)
    2015-07-09 10:51:13, Info CSI 00000001 Windows::WCP::IEFileInstallAI::IEFileInstallAI::Uninstall.
    2015-07-09 10:51:13, Info CSI 00000002 Internet Explorer IEFileInstallAI Uninstallation called.
    2015-07-09 10:51:13, Info CSI 00000003@2015/7/9:14:51:13.994 Enumerating elements in IEFileInstall table
    2015-07-09 10:51:13, Info CSI 00000004@2015/7/9:14:51:13.994 Enumerating child elements of IEFileInstallAI
    2015-07-09 10:51:13, Info CSI 00000005 Destination File: [l:92{46}]"C:\windows\System32\Macromed\Flash\activex.vch"
    2015-07-09 10:51:13, Info CSI 00000006 Windows::WCP::IEFileInstallAI::IEFileInstallAI::UninstallFile.
    2015-07-09 10:51:13, Info CSI 00000007 Destination File: [l:112{56}]"C:\windows\System32\Macromed\Flash\FlashUtil_ActiveX.dll"
    2015-07-09 10:51:13, Info CSI 00000008 Windows::WCP::IEFileInstallAI::IEFileInstallAI::UninstallFile.
    2015-07-09 10:51:14, Info CSI 00000009 Destination File: [l:112{56}]"C:\windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe"
    2015-07-09 10:51:14, Info CSI 0000000a Windows::WCP::IEFileInstallAI::IEFileInstallAI::UninstallFile.
    2015-07-09 10:51:14, Info CSI 0000000b Destination File: [l:88{44}]"C:\windows\System32\Macromed\Flash\Flash.ocx"
    2015-07-09 10:51:14, Info CSI 0000000c Windows::WCP::IEFileInstallAI::IEFileInstallAI::UninstallFile.
    2015-07-09 10:51:14, Info CSI 0000002b@2015/7/9:14:51:14.057 CSI Advanced installer perf trace:
    CSIPERF:AIDONE;{e7354f90-519d-4481-82f6-94f6e851f8f9};Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral;536544us
    2015-07-09 10:51:14, Info CSI 0000002c End executing advanced installer (sequence 26)
    Completion status: S_OK

    2015-07-09 10:51:14, Info CSI 0000002d Begin executing advanced installer phase 24 (0x00000018) index 5 (sequence 27)
    Old component: [ml:296{148},l:294{147}]"Adobe-Flash-For-Windows, Culture=neutral, Version=6.3.9600.17858, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=wow64, versionScope=NonSxS"
    New component: [ml:296{148},l:294{147}]"Adobe-Flash-For-Windows, Culture=neutral, Version=6.3.9600.17927, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=wow64, versionScope=NonSxS"
    Install mode: uninstall
    Installer ID: {e7354f90-519d-4481-82f6-94f6e851f8f9}
    Installer name: [32]"CSI IEFileInstallAI AI installer"
    2015-07-09 10:51:14, Info CSI 0000002e Performing 1 operations; 1 are not lock/unlock and follow:
    (0) LockComponentPath (10): flags: 0 comp: {l:16 b:9b9dd6b356bad0012b0000001c076010} pathid: {l:16 b:9b9dd6b356bad0012c0000001c076010} path: [l:204{102}]"\SystemRoot\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17858_none_26d7520571cb7925" pid: 71c starttime: 130809270499634804 (0x01d0ba56a5756e74)
    2015-07-09 10:51:14, Info CSI 0000002f Performing 1 operations; 1 are not lock/unlock and follow:
    (0) LockComponentPath (10): flags: 0 comp: {l:16 b:a8afe9b356bad0012d0000001c076010} pathid: {l:16 b:a8afe9b356bad0012e0000001c076010} path: [l:204{102}]"\SystemRoot\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922" pid: 71c starttime: 130809270499634804 (0x01d0ba56a5756e74)
    2015-07-09 10:51:14, Info CSI 0000000d Windows::WCP::IEFileInstallAI::IEFileInstallAI::Uninstall.
    2015-07-09 10:51:14, Info CSI 0000000e Internet Explorer IEFileInstallAI Uninstallation called.
    2015-07-09 10:51:14, Info CSI 0000000f@2015/7/9:14:51:14.244 Enumerating elements in IEFileInstall table
    2015-07-09 10:51:14, Info CSI 00000010@2015/7/9:14:51:14.244 Enumerating child elements of IEFileInstallAI
    2015-07-09 10:51:14, Info CSI 00000011 Destination File: [l:76{38}]"C:\windows\SysWOW64\FlashPlayerApp.exe"
    2015-07-09 10:51:14, Info CSI 00000012 Windows::WCP::IEFileInstallAI::IEFileInstallAI::UninstallFile.
    2015-07-09 10:51:14, Info CSI 00000013 Destination File: [l:92{46}]"C:\windows\SysWOW64\Macromed\Flash\activex.vch"
    2015-07-09 10:51:14, Info CSI 00000014 Windows::WCP::IEFileInstallAI::IEFileInstallAI::UninstallFile.
    2015-07-09 10:51:14, Info CSI 00000015 Destination File: [l:82{41}]"C:\windows\SysWOW64\FlashPlayerCPLApp.cpl"
    2015-07-09 10:51:14, Info CSI 00000016 Windows::WCP::IEFileInstallAI::IEFileInstallAI::UninstallFile.
    2015-07-09 10:51:14, Info CSI 00000017 Destination File: [l:112{56}]"C:\windows\SysWOW64\Macromed\Flash\FlashUtil_ActiveX.dll"
    2015-07-09 10:51:14, Info CSI 00000018 Windows::WCP::IEFileInstallAI::IEFileInstallAI::UninstallFile.
    2015-07-09 10:51:14, Info CSI 00000019 Destination File: [l:112{56}]"C:\windows\SysWOW64\Macromed\Flash\FlashUtil_ActiveX.exe"
    2015-07-09 10:51:14, Info CSI 0000001a Windows::WCP::IEFileInstallAI::IEFileInstallAI::UninstallFile.
    2015-07-09 10:51:14, Info CSI 0000001b Destination File: [l:88{44}]"C:\windows\SysWOW64\Macromed\Flash\Flash.ocx"
    2015-07-09 10:51:14, Info CSI 0000001c Windows::WCP::IEFileInstallAI::IEFileInstallAI::UninstallFile.
    2015-07-09 10:51:14, Info CSI 00000030@2015/7/9:14:51:14.307 CSI Advanced installer perf trace:
    CSIPERF:AIDONE;{e7354f90-519d-4481-82f6-94f6e851f8f9};Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral;489153us
    2015-07-09 10:51:14, Info CSI 00000031 End executing advanced installer (sequence 27)
    Completion status: S_OK

    2015-07-09 10:51:14, Info CSI 00000032 Begin executing advanced installer phase 38 (0x00000026) index 6 (sequence 42)
    Old component: [ml:296{148},l:294{147}]"Adobe-Flash-For-Windows, Culture=neutral, Version=6.3.9600.17858, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=wow64, versionScope=NonSxS"
    New component: [ml:296{148},l:294{147}]"Adobe-Flash-For-Windows, Culture=neutral, Version=6.3.9600.17927, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=wow64, versionScope=NonSxS"
    Install mode: install
    Installer ID: {e7354f90-519d-4481-82f6-94f6e851f8f9}
    Installer name: [32]"CSI IEFileInstallAI AI installer"
    2015-07-09 10:51:14, Info CSI 0000001d Windows::WCP::IEFileInstallAI::IEFileInstallAI::Install.
    2015-07-09 10:51:14, Info CSI 0000001e Internet Explorer IEFileInstallAI Installation started.
    2015-07-09 10:51:14, Info CSI 0000001f@2015/7/9:14:51:14.338 Enumerating elements in IEFileInstall table
    2015-07-09 10:51:14, Info CSI 00000020@2015/7/9:14:51:14.338 Enumerating child elements of IEFileInstallAI
    2015-07-09 10:51:14, Info CSI 00000021 Dest Path: [19]"$(runtime.system32)".
    2015-07-09 10:51:14, Info CSI 00000022 File Name: [18]"FlashPlayerApp.exe".
    2015-07-09 10:51:14, Info CSI 00000023 Source File: [l:240{120}]"C:\windows\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922\FlashPlayerApp.exe"
    2015-07-09 10:51:14, Info CSI 00000024 Destination File: [l:76{38}]"C:\windows\SysWOW64\FlashPlayerApp.exe"
    2015-07-09 10:51:14, Info CSI 00000025 Windows::WCP::IEFileInstallAI::IEFileInstallAI::InstallFile([ml:242{121},l:240{120}]"C:\windows\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922\FlashPlayerApp.exe", [ml:78{39},l:76{38}]"C:\windows\SysWOW64\FlashPlayerApp.exe", FALSE).
    2015-07-09 10:51:14, Info CSI 00000026 Dest Path: [34]"$(runtime.system32)\Macromed\Flash".
    2015-07-09 10:51:14, Info CSI 00000027 File Name: [11]"activex.vch".
    2015-07-09 10:51:14, Info CSI 00000028 Source File: [l:226{113}]"C:\windows\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922\activex.vch"
    2015-07-09 10:51:14, Info CSI 00000029 Destination File: [l:92{46}]"C:\windows\SysWOW64\Macromed\Flash\activex.vch"
    2015-07-09 10:51:14, Info CSI 0000002a Windows::WCP::IEFileInstallAI::IEFileInstallAI::InstallFile([ml:228{114},l:226{113}]"C:\windows\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922\activex.vch", [ml:94{47},l:92{46}]"C:\windows\SysWOW64\Macromed\Flash\activex.vch", TRUE).
    2015-07-09 10:51:14, Info CSI 0000002b Dest Path: [19]"$(runtime.system32)".
    2015-07-09 10:51:14, Info CSI 0000002c File Name: [21]"FlashPlayerCPLApp.cpl".
    2015-07-09 10:51:14, Info CSI 0000002d Source File: [l:246{123}]"C:\windows\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922\FlashPlayerCPLApp.cpl"
    2015-07-09 10:51:14, Info CSI 0000002e Destination File: [l:82{41}]"C:\windows\SysWOW64\FlashPlayerCPLApp.cpl"
    2015-07-09 10:51:14, Info CSI 0000002f Windows::WCP::IEFileInstallAI::IEFileInstallAI::InstallFile([ml:248{124},l:246{123}]"C:\windows\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922\FlashPlayerCPLApp.cpl", [ml:84{42},l:82{41}]"C:\windows\SysWOW64\FlashPlayerCPLApp.cpl", FALSE).
    2015-07-09 10:51:14, Info CSI 00000030 Dest Path: [34]"$(runtime.system32)\Macromed\Flash".
    2015-07-09 10:51:14, Info CSI 00000031 File Name: [21]"FlashUtil_ActiveX.dll".
    2015-07-09 10:51:14, Info CSI 00000032 Source File: [l:246{123}]"C:\windows\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922\FlashUtil_ActiveX.dll"
    2015-07-09 10:51:14, Info CSI 00000033 Destination File: [l:112{56}]"C:\windows\SysWOW64\Macromed\Flash\FlashUtil_ActiveX.dll"
    2015-07-09 10:51:14, Info CSI 00000034 Windows::WCP::IEFileInstallAI::IEFileInstallAI::InstallFile([ml:248{124},l:246{123}]"C:\windows\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922\FlashUtil_ActiveX.dll", [ml:114{57},l:112{56}]"C:\windows\SysWOW64\Macromed\Flash\FlashUtil_ActiveX.dll", TRUE).
    2015-07-09 10:51:14, Info CSI 00000035 Dest Path: [34]"$(runtime.system32)\Macromed\Flash".
    2015-07-09 10:51:14, Info CSI 00000036 File Name: [21]"FlashUtil_ActiveX.exe".
    2015-07-09 10:51:14, Info CSI 00000037 Source File: [l:246{123}]"C:\windows\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922\FlashUtil_ActiveX.exe"
    2015-07-09 10:51:14, Info CSI 00000038 Destination File: [l:112{56}]"C:\windows\SysWOW64\Macromed\Flash\FlashUtil_ActiveX.exe"
    2015-07-09 10:51:14, Info CSI 00000039 Windows::WCP::IEFileInstallAI::IEFileInstallAI::InstallFile([ml:248{124},l:246{123}]"C:\windows\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922\FlashUtil_ActiveX.exe", [ml:114{57},l:112{56}]"C:\windows\SysWOW64\Macromed\Flash\FlashUtil_ActiveX.exe", TRUE).
    2015-07-09 10:51:14, Info CSI 0000003a Dest Path: [34]"$(runtime.system32)\Macromed\Flash".
    2015-07-09 10:51:14, Info CSI 0000003b File Name: [9]"Flash.ocx".
    2015-07-09 10:51:14, Info CSI 0000003c Source File: [l:222{111}]"C:\windows\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922\Flash.ocx"
    2015-07-09 10:51:14, Info CSI 0000003d Destination File: [l:88{44}]"C:\windows\SysWOW64\Macromed\Flash\Flash.ocx"
    2015-07-09 10:51:14, Info CSI 0000003e Windows::WCP::IEFileInstallAI::IEFileInstallAI::InstallFile([ml:224{112},l:222{111}]"C:\windows\WinSxS\wow64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_26f6c36571b40922\Flash.ocx", [ml:90{45},l:88{44}]"C:\windows\SysWOW64\Macromed\Flash\Flash.ocx", TRUE).
    2015-07-09 10:51:14, Info CSI 00000033@2015/7/9:14:51:14.729 CSI Advanced installer perf trace:
    CSIPERF:AIDONE;{e7354f90-519d-4481-82f6-94f6e851f8f9};Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral;769125us
    2015-07-09 10:51:14, Info CSI 00000034 End executing advanced installer (sequence 42)
    Completion status: S_OK

    2015-07-09 10:51:14, Info CSI 00000035 Begin executing advanced installer phase 38 (0x00000026) index 7 (sequence 43)
    Old component: [ml:296{148},l:294{147}]"Adobe-Flash-For-Windows, Culture=neutral, Version=6.3.9600.17858, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=amd64, versionScope=NonSxS"
    New component: [ml:296{148},l:294{147}]"Adobe-Flash-For-Windows, Culture=neutral, Version=6.3.9600.17927, PublicKeyToken=31bf3856ad364e35, ProcessorArchitecture=amd64, versionScope=NonSxS"
    Install mode: install
    Installer ID: {e7354f90-519d-4481-82f6-94f6e851f8f9}
    Installer name: [32]"CSI IEFileInstallAI AI installer"
    2015-07-09 10:51:14, Info CSI 0000003f Windows::WCP::IEFileInstallAI::IEFileInstallAI::Install.
    2015-07-09 10:51:14, Info CSI 00000040 Internet Explorer IEFileInstallAI Installation started.
    2015-07-09 10:51:14, Info CSI 00000041@2015/7/9:14:51:14.744 Enumerating elements in IEFileInstall table
    2015-07-09 10:51:14, Info CSI 00000042@2015/7/9:14:51:14.744 Enumerating child elements of IEFileInstallAI
    2015-07-09 10:51:14, Info CSI 00000043 Dest Path: [34]"$(runtime.system32)\Macromed\Flash".
    2015-07-09 10:51:14, Info CSI 00000044 File Name: [11]"activex.vch".
    2015-07-09 10:51:14, Info CSI 00000045 Source File: [l:226{113}]"C:\windows\WinSxS\amd64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_1ca219133d534727\activex.vch"
    2015-07-09 10:51:14, Info CSI 00000046 Destination File: [l:92{46}]"C:\windows\System32\Macromed\Flash\activex.vch"
    2015-07-09 10:51:14, Info CSI 00000047 Windows::WCP::IEFileInstallAI::IEFileInstallAI::InstallFile([ml:228{114},l:226{113}]"C:\windows\WinSxS\amd64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_1ca219133d534727\activex.vch", [ml:94{47},l:92{46}]"C:\windows\System32\Macromed\Flash\activex.vch", TRUE).
    2015-07-09 10:51:14, Info CSI 00000048 Dest Path: [34]"$(runtime.system32)\Macromed\Flash".
    2015-07-09 10:51:14, Info CSI 00000049 File Name: [21]"FlashUtil_ActiveX.dll".
    2015-07-09 10:51:14, Info CSI 0000004a Source File: [l:246{123}]"C:\windows\WinSxS\amd64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_1ca219133d534727\FlashUtil_ActiveX.dll"
    2015-07-09 10:51:14, Info CSI 0000004b Destination File: [l:112{56}]"C:\windows\System32\Macromed\Flash\FlashUtil_ActiveX.dll"
    2015-07-09 10:51:14, Info CSI 0000004c Windows::WCP::IEFileInstallAI::IEFileInstallAI::InstallFile([ml:248{124},l:246{123}]"C:\windows\WinSxS\amd64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_1ca219133d534727\FlashUtil_ActiveX.dll", [ml:114{57},l:112{56}]"C:\windows\System32\Macromed\Flash\FlashUtil_ActiveX.dll", TRUE).
    2015-07-09 10:51:14, Info CSI 0000004d Dest Path: [34]"$(runtime.system32)\Macromed\Flash".
    2015-07-09 10:51:14, Info CSI 0000004e File Name: [21]"FlashUtil_ActiveX.exe".
    2015-07-09 10:51:14, Info CSI 0000004f Source File: [l:246{123}]"C:\windows\WinSxS\amd64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_1ca219133d534727\FlashUtil_ActiveX.exe"
    2015-07-09 10:51:14, Info CSI 00000050 Destination File: [l:112{56}]"C:\windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe"
    2015-07-09 10:51:14, Info CSI 00000051 Windows::WCP::IEFileInstallAI::IEFileInstallAI::InstallFile([ml:248{124},l:246{123}]"C:\windows\WinSxS\amd64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_1ca219133d534727\FlashUtil_ActiveX.exe", [ml:114{57},l:112{56}]"C:\windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe", TRUE).
    2015-07-09 10:51:14, Info CSI 00000052 Dest Path: [34]"$(runtime.system32)\Macromed\Flash".
    2015-07-09 10:51:14, Info CSI 00000053 File Name: [9]"Flash.ocx".
    2015-07-09 10:51:14, Info CSI 00000054 Source File: [l:222{111}]"C:\windows\WinSxS\amd64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_1ca219133d534727\Flash.ocx"
    2015-07-09 10:51:14, Info CSI 00000055 Destination File: [l:88{44}]"C:\windows\System32\Macromed\Flash\Flash.ocx"
    2015-07-09 10:51:14, Info CSI 00000056 Windows::WCP::IEFileInstallAI::IEFileInstallAI::InstallFile([ml:224{112},l:222{111}]"C:\windows\WinSxS\amd64_adobe-flash-for-windows_31bf3856ad364e35_6.3.9600.17927_none_1ca219133d534727\Flash.ocx", [ml:90{45},l:88{44}]"C:\windows\System32\Macromed\Flash\Flash.ocx", TRUE).
    2015-07-09 10:51:15, Info CSI 00000036@2015/7/9:14:51:15.057 CSI Advanced installer perf trace:
    CSIPERF:AIDONE;{e7354f90-519d-4481-82f6-94f6e851f8f9};Adobe-Flash-For-Windows, Version = 6.3.9600.17927, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral;604519us
    2015-07-09 10:51:15, Info CSI 00000037 End executing advanced installer (sequence 43)
    Completion status: S_OK

    2015-07-09 10:51:15, Info CSI 00000038 Creating NT transaction (seq 5), objectname [6]"(null)"
    2015-07-09 10:51:15, Info CSI 00000039 Created NT transaction (seq 5) result 0x00000000, handle @0x5d0
    2015-07-09 10:51:15, Info CSI 0000003a Poqexec successfully registered in [ml:26{13},l:24{12}]"SetupExecute"
    2015-07-09 10:51:15, Info CSI 0000003b@2015/7/9:14:51:15.088 Beginning NT transaction commit...
    2015-07-09 10:51:15, Info CSI 0000003c@2015/7/9:14:51:15.400 CSI perf trace:
    CSIPERF:TXCOMMIT;602136
    2015-07-09 10:51:15, Info CBS Setting ExecuteState key to: ExecuteStateNone
    2015-07-09 10:51:15, Info CBS Setting RollbackFailed flag to 0
    2015-07-09 10:51:15, Info CBS Clearing HangDetect value
    2015-07-09 10:51:15, Info CBS Saved last global progress. Current: 0, Limit: 1, ExecuteState: ExecuteStateNone
    2015-07-09 10:51:15, Info CSI 0000003d@2015/7/9:14:51:15.400 CSI Transaction @0x44c6091b10 destroyed
    2015-07-09 10:51:15, Info CBS Perf: InstallUninstallChain complete.
    2015-07-09 10:51:15, Info CBS Failed NTFS compressing file \\?\C:\windows\Servicing\Sessions\30456406_2914999000.xml [HRESULT = 0x80070301 - ERROR_COMPRESSION_DISABLED]
    2015-07-09 10:51:15, Info CBS Exec: TransientManifestCache disabled in config.
    2015-07-09 10:51:15, Info CBS Reboot mark cleared
    2015-07-09 10:51:15, Info CBS Winlogon: Deregistering for CreateSession notifications
    2015-07-09 10:51:15, Info CBS Winlogon: Stopping notify server
    2015-07-09 10:51:15, Info CBS Winlogon: Unloading SysNotify DLL
    2015-07-09 10:51:15, Info CBS FinalCommitPackagesState: Started persisting state of packages
    2015-07-09 10:51:15, Info CBS SQM: Reporting package change for package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, current: Resolved, pending: Default, start: Resolved, applicable: Installed, target: Installed, limit: Installed, hotpatch status: DisabledBecauseNoHotpatchPackagesInitiated, status: 0x0, failure source: Not Applicable, reboot required: False, client id: WindowsUpdateAgent, initiated offline: False, execution sequence: 1212, first merged sequence: 1212 reboot reason: REBOOT_NOT_REQUIRED RM App session: -1 RM App name: N/A FileName in use: N/A
    2015-07-09 10:51:15, Info CBS SQM: Upload requested for report: PackageChangeBegin_Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, session id: 142859, sample type: Standard
    2015-07-09 10:51:15, Info CBS SQM: Ignoring upload request because the sample type is not enabled: Standard
    2015-07-09 10:51:15, Info CBS SQM: Reporting package change completion for package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, current: Installed, original: Resolved, target: Installed, status: 0x0, failure source: Not Applicable, failure details: "(null)", client id: WindowsUpdateAgent, initiated offline: False, execution sequence: 1212, first merged sequence: 1212, pending decision: InteractiveInstallSucceeded, primitive execution context: Interactive
    2015-07-09 10:51:15, Info CBS SQM: Upload requested for report: PackageChangeEnd_Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1, session id: 142862, sample type: Standard
    2015-07-09 10:51:15, Info CBS SQM: Ignoring upload request because the sample type is not enabled: Standard
    2015-07-09 10:51:15, Info CBS FinalCommitPackagesState: Completed persisting state of packages
    2015-07-09 10:51:15, Info CBS Enabling LKG boot option
    2015-07-09 10:51:15, Info CBS Exec: End: nested restore point - complete.
    2015-07-09 10:51:16, Info CBS Failed NTFS compressing file \\?\C:\windows\Servicing\Sessions\30456406_2914999000.xml [HRESULT = 0x80070301 - ERROR_COMPRESSION_DISABLED]
    2015-07-09 10:51:16, Info CBS Exec: Processing complete. Session: 30456406_2914999000, Package: Package_for_KB3065823~31bf3856ad364e35~amd64~~6.3.1.1 [HRESULT = 0x00000000 - S_OK]
    2015-07-09 10:51:19, Info CBS Trusted Installer signaled for shutdown, going to exit.
    2015-07-09 10:51:19, Info CBS Trusted Installer is shutting down because: SHUTDOWN_REASON_NOTIFICATION:PRESHUTDOWN
    2015-07-09 10:51:19, Info CBS TiWorker signaled for shutdown, going to exit.
    2015-07-09 10:51:19, Info CBS Ending the TiWorker main loop.
    2015-07-09 10:51:19, Info CBS Ending the TrustedInstaller main loop.
    2015-07-09 10:51:19, Info CBS Starting TiWorker finalization.
    2015-07-09 10:51:19, Info CBS Starting TrustedInstaller finalization.
    2015-07-09 10:51:19, Info CBS Ending TrustedInstaller finalization.
    2015-07-09 10:51:21, Info CBS Ending TiWorker finalization.
    2015-07-09 11:00:06, Info CBS TI: --- Initializing Trusted Installer ---
    2015-07-09 11:00:06, Info CBS TI: Last boot time: 2015-07-09 10:55:46.496
    2015-07-09 11:00:06, Info CBS Starting TrustedInstaller initialization.
    2015-07-09 11:00:06, Info CBS Ending TrustedInstaller initialization.
    2015-07-09 11:00:06, Info CBS Starting the TrustedInstaller main loop.
    2015-07-09 11:00:06, Info CBS TrustedInstaller service starts successfully.
    2015-07-09 11:00:06, Info CBS No startup processing required, TrustedInstaller service was not set as autostart
    2015-07-09 11:00:06, Info CBS NonStart: Windows is in Safe Mode.
    2015-07-09 11:00:06, Info CBS Startup processing thread terminated normally
    2015-07-09 11:00:06, Info CBS Starting TiWorker initialization.
    2015-07-09 11:00:06, Info CBS Ending TiWorker initialization.
    2015-07-09 11:00:06, Info CBS Starting the TiWorker main loop.
    2015-07-09 11:00:06, Info CBS TiWorker starts successfully.
    2015-07-09 11:00:06, Info CBS Universal Time is: 2015-07-09 15:00:06.496
    2015-07-09 11:00:06, Info CBS Loaded Servicing Stack v6.3.9600.17709 with Core: C:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\cbscore.dll
    2015-07-09 11:00:06, Info CSI 00000001@2015/7/9:15:00:06.622 WcpInitialize (wcp.dll version 0.0.0.6) called (stack @0x7ffafaf47f19 @0x7ffafb2d4984 @0x7ffafb2d41bb @0x7ff6057dd69a @0x7ff6057ddf4f @0x7ffb0a472053)
    2015-07-09 11:00:06, Info CBS SQM: Initializing online with Windows opt-in: False
    2015-07-09 11:00:06, Info CBS SQM: Cleaning up report files older than 10 days.
    2015-07-09 11:00:06, Info CBS SQM: Requesting upload of all unsent reports.
    2015-07-09 11:00:06, Info CBS SQM: Failed to start upload with file pattern: C:\windows\servicing\sqm\*_std.sqm, flags: 0x2 [HRESULT = 0x80004005 - E_FAIL]
    2015-07-09 11:00:06, Info CBS SQM: Failed to start standard sample upload. [HRESULT = 0x80004005 - E_FAIL]
    2015-07-09 11:00:06, Info CBS SQM: Queued 0 file(s) for upload with pattern: C:\windows\servicing\sqm\*_all.sqm, flags: 0x6
    2015-07-09 11:00:06, Info CBS SQM: Warning: Failed to upload all unsent reports. [HRESULT = 0x80004005 - E_FAIL]
    2015-07-09 11:00:06, Info CBS NonStart: Windows is in Safe Mode.
    2015-07-09 11:00:06, Info CBS Session: 30456407_4048605949 initialized by client DISM Package Manager Provider.
    2015-07-09 11:00:06, Info CBS Client specifies store corruption detect and repair.
    2015-07-09 11:00:06, Info CBS Exec: Session processing started. Client: DISM Package Manager Provider, Session(Store Corruption Detect/Repair): 30456407_4048605949
    2015-07-09 11:00:06, Info CBS Reboot mark set
    2015-07-09 11:00:06, Info CBS Winlogon: Registering for CreateSession notifications
    2015-07-09 11:02:07, Info CBS Repr: CBS Store check completes
    2015-07-09 11:02:08, Info CSI 00000002 CSI Store 70887357648 (0x0000001081373cd0) initialized
    2015-07-09 11:02:08, Info CSI 00000003 StoreCorruptionRepair transaction begun. WcpVersion: [l:78{39}]"6.3.9600.17709 (winblue_r9.150219-1500)".
    2015-07-09 11:02:08, Info CSI 00000004@2015/7/9:15:02:08.329 Starting corruption detection (InnerFlags=5)
    2015-07-09 11:02:45, Info CSI 00000005 Hashes for file member \SystemRoot\WinSxS\amd64_microsoft-windows-e..host-shellnamespace_31bf3856ad364e35_6.3.9600.16441_none_9581223139116792\WorkFoldersRes.dll do not match actual file [l:36{18}]"WorkFoldersRes.dll" :
    Found: {l:32 b:8c1jfnxfcrT7rbD3oS+I9+DlveF0qE61F1SwEFTwk48=} Expected: {l:32 b:HTJAcuJY3YF7ZXybBCnrFbd2l54/+UzbMYbMuH/fTp4=}
    2015-07-09 11:12:36, Info CSI 00000006 Hashes for file member \SystemRoot\WinSxS\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.3.9600.17807_none_910ac2c6daa01c43\utc.app.json do not match actual file [l:24{12}]"utc.app.json" :
    Found: {l:32 b:d0R8gqC9V88kxd/hX2M0rym11RJzbpTyaDDbH4Mq8pg=} Expected: {l:32 b:6510UErwHGoFg3sRd3gzh3HSbTceuHem3Rnk0NraKS8=}
    2015-07-09 11:12:36, Info CSI 00000007 Hashes for file member \SystemRoot\WinSxS\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.3.9600.17807_none_910ac2c6daa01c43\telemetry.ASM-WindowsDefault.json do not match actual file [l:66{33}]"telemetry.ASM-WindowsDefault.json" :
    Found: {l:32 b:ErEvcGxrC5RD30CwVgig/0sasSdfpRLjd18ZiXseYV4=} Expected: {l:32 b:EeQJzlVPvq9GNIcA2FEwrOjEeuDam1G+ol3x61gKasQ=}
    2015-07-09 11:25:56, Info CSI 00000008@2015/7/9:15:25:56.634 Corruption detection complete. numCorruptions = 3, Disp = 1.
    2015-07-09 11:25:56, Info CBS Repr: CSI meta data corruption found, will commit repair transaction if repair is asked.
    2015-07-09 11:25:56, Info CSI 00000009@2015/7/9:15:25:56.696 CSI Transaction @0x10813a5510 initialized for deployment engine {d16d444c-56d8-11d5-882d-0080c847b195} with flags 00000002 and client id [26]"TI5.30456407_4048605949:1/"

    2015-07-09 11:25:56, Info CSI 0000000a@2015/7/9:15:25:56.699 CSI Transaction @0x10813a5510 destroyed
    2015-07-09 11:25:56, Info CBS Repr: CSI Store check completes
    2015-07-09 11:25:56, Info CBS Exec: Manual Repair feasibility evaluation, continue on download evaluation.
    2015-07-09 11:25:56, Info CBS Exec: Clients specified using Windows Update.
    2015-07-09 11:26:22, Info CBS Failed to get services collection [HRESULT = 0x8007043c - ERROR_NOT_SAFEBOOT_SERVICE]
    2015-07-09 11:26:22, Info CBS Failed to get windows update server configuration. [HRESULT = 0x8007043c - ERROR_NOT_SAFEBOOT_SERVICE]
    2015-07-09 11:26:22, Info CBS DWLD: Failed to begin WU search [HRESULT = 0x8007043c - ERROR_NOT_SAFEBOOT_SERVICE]
    2015-07-09 11:26:22, Info CBS Failed to search on Windows update [HRESULT = 0x800f0906 - CBS_E_DOWNLOAD_FAILURE]
    2015-07-09 11:26:22, Info CBS Repr: Failed to download payload files [HRESULT = 0x800f0906 - CBS_E_DOWNLOAD_FAILURE]
    2015-07-09 11:26:22, Info CBS Failed to collect payload and there is nothing to repair. [HRESULT = 0x800f0906 - CBS_E_DOWNLOAD_FAILURE]
    2015-07-09 11:26:22, Info CBS Failed to repair store. [HRESULT = 0x800f0906 - CBS_E_DOWNLOAD_FAILURE]
    2015-07-09 11:26:22, Info CBS Ensure CBS corruption flag is clear
    2015-07-09 11:26:22, Info CBS
    =================================
    Checking System Update Readiness.

    (p) CSI Payload Corrupt amd64_microsoft-windows-e..host-shellnamespace_31bf3856ad364e35_6.3.9600.16441_none_9581223139116792\WorkFoldersRes.dll
    Repair failed: Missing replacement payload.
    (p) CSI Payload Corrupt amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.3.9600.17807_none_910ac2c6daa01c43\utc.app.json
    Repair failed: Missing replacement payload.
    (p) CSI Payload Corrupt amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.3.9600.17807_none_910ac2c6daa01c43\telemetry.ASM-WindowsDefault.json
    Repair failed: Missing replacement payload.

    Summary:
    Operation: Detect and Repair
    Operation result: 0x800f0906
    Last Successful Step: Entire operation completes.
    Total Detected Corruption: 3
    CBS Manifest Corruption: 0
    CBS Metadata Corruption: 0
    CSI Manifest Corruption: 0
    CSI Metadata Corruption: 0
    CSI Payload Corruption: 3
    Total Repaired Corruption: 0
    CBS Manifest Repaired: 0
    CSI Manifest Repaired: 0
    CSI Payload Repaired: 0
    CSI Store Metadata refreshed: True

    Total Operation Time: 1576 seconds.

    2015-07-09 11:26:22, Info CBS SQM: CheckSur: hrStatus: 0x800f0906 [CBS_E_DOWNLOAD_FAILURE], download Result: 0x8007043c [ERROR_NOT_SAFEBOOT_SERVICE]
    2015-07-09 11:26:22, Info CBS Count of times corruption detected: 1
    2015-07-09 11:26:22, Info CBS Seconds between initial corruption detections: -1
    2015-07-09 11:26:22, Info CBS Seconds between corruption and repair: -1
    2015-07-09 11:26:24, Info CBS SQM: Upload requested for report: CheckSurSqm, session id: 142858, sample type: Standard
    2015-07-09 11:26:24, Info CBS SQM: Ignoring upload request because the sample type is not enabled: Standard
    2015-07-09 11:26:24, Info CBS Failed to run Detect and repair. [HRESULT = 0x800f0906 - CBS_E_DOWNLOAD_FAILURE]
    2015-07-09 11:26:25, Info CBS Reboot mark cleared
    2015-07-09 11:26:25, Info CBS Winlogon: Deregistering for CreateSession notifications
    2015-07-09 11:26:25, Info CBS Winlogon: Stopping notify server
    2015-07-09 11:26:25, Info CBS Winlogon: Unloading SysNotify DLL
    2015-07-09 11:26:25, Info CBS Exec: Processing complete, session(Corruption Repairing): 30456407_4048605949 [HRESULT = 0x800f0906 - CBS_E_DOWNLOAD_FAILURE]
    2015-07-09 11:26:25, Error CBS Session: 30456407_4048605949 failed to perform store corruption detect and repair operation. [HRESULT = 0x800f0906 - CBS_E_DOWNLOAD_FAILURE]
    2015-07-09 11:26:25, Info CBS Session: 30456407_4048605949 finalized. Download error: 0x8007043c [ERROR_NOT_SAFEBOOT_SERVICE], Reboot required: no [HRESULT = 0x800f0906 - CBS_E_DOWNLOAD_FAILURE]
    2015-07-09 11:26:25, Info CBS Failed to FinalizeEx using worker session [HRESULT = 0x800f0906]


    • Ad Bot

      advertising
      Beep.

        
       

  2. #62

    Re: Is efnnouse.exe a virus?

    I restarted the computer in normal mode and took over 5 mins. to full start. I think that the fixing didn't happen, am I right?

  3. #63
    Administrator
    Windows Update Instructor
    Security Analyst

    Join Date
    Oct 2014
    Posts
    17,512

    Re: Is efnnouse.exe a virus?

    I got the information I needed from the log so it worked fine. I was just gathering more info. Thank you. I'll be back soon.

  4. #64
    Administrator
    Windows Update Instructor
    Security Analyst

    Join Date
    Oct 2014
    Posts
    17,512

    Re: Is efnnouse.exe a virus?

    Let me ask you a question. Did you have these slowness issues when you originally came to the forum for malware removal? How long has this been going on?

  5. #65

    Re: Is efnnouse.exe a virus?

    Quote Originally Posted by BrianDrab View Post
    Let me ask you a question. Did you have these slowness issues when you originally came to the forum for malware removal? How long has this been going on?
    Yes, I had it, and I thought that it was because a virus. I began having these problems when IObit made a registry cleanings, and they became worse when I deleted the program. Please, don't tell me I have to refresh the OS!

  6. #66
    Administrator
    Windows Update Instructor
    Security Analyst

    Join Date
    Oct 2014
    Posts
    17,512

    Re: Is efnnouse.exe a virus?

    We're not quite there yet. Do you happen to have a Windows 8.1 DVD?

  7. #67

    Re: Is efnnouse.exe a virus?

    Well, what I have is a HP recovery set of disks. My computer didn't come with the OS CD. I tried to use the disks before, and it didn't work. However, maybe I can download it from Internet. I have some DVDs there that I can burn.

  8. #68
    Administrator
    Windows Update Instructor
    Security Analyst

    Join Date
    Oct 2014
    Posts
    17,512

    Re: Is efnnouse.exe a virus?

    Just wanted to check what our options are. If we get to that point you usually can contact HP to request replacement media with minimal cost. But if you know a friend, neighbor or co-worker that may have a Windows DVD that you can borrow that would work too. That way we can run a repair and you can keep all your data/programs intact.

    Let's review where we are at.
    -When booting into Safe Mode your machine appears to run fine although you had issues with firefox when attempting to paste. I don't think the firefox thing is an issue as you should always attach the files or provide a dropbox link, etc. Pasting the information can cause issues like this if the logs are large. So this means that it's likely a driver or program that is loading that is causing your issues.
    -What concerns me is that when you do a Clean Boot you still have the symptoms. A Clean Boot if done properly disables all third party drivers and startup items.
    -You also have a payload file that refuses to fix for some reason (WorkFoldersRes.dll)

    So, I'll do my best to narrow this down and fix before we decide that you need to do a repair/refresh.

    First thing I would like you to do is to uninstall the following programs. You can always re-install later when your machine is stable.

    EMET 4.1 Update 1
    IObit Uninstaller - If you are looking for a good alternative I would recommend Revo (Download Revo Uninstaller Freeware - Free and Full Download - Uninstall software, remove programs, solve uninstall problems)
    Malwarebytes Anti-Malware version 2.1.6.1022

  9. #69

    Re: Is efnnouse.exe a virus?

    Quote Originally Posted by BrianDrab View Post
    Just wanted to check what our options are. If we get to that point you usually can contact HP to request replacement media with minimal cost. But if you know a friend, neighbor or co-worker that may have a Windows DVD that you can borrow that would work too. That way we can run a repair and you can keep all your data/programs intact.

    Let's review where we are at.
    -When booting into Safe Mode your machine appears to run fine although you had issues with firefox when attempting to paste. I don't think the firefox thing is an issue as you should always attach the files or provide a dropbox link, etc. Pasting the information can cause issues like this if the logs are large. So this means that it's likely a driver or program that is loading that is causing your issues.
    -What concerns me is that when you do a Clean Boot you still have the symptoms. A Clean Boot if done properly disables all third party drivers and startup items.
    -You also have a payload file that refuses to fix for some reason (WorkFoldersRes.dll)

    So, I'll do my best to narrow this down and fix before we decide that you need to do a repair/refresh.

    First thing I would like you to do is to uninstall the following programs. You can always re-install later when your machine is stable.

    EMET 4.1 Update 1
    IObit Uninstaller - If you are looking for a good alternative I would recommend Revo (Download Revo Uninstaller Freeware - Free and Full Download - Uninstall software, remove programs, solve uninstall problems)
    Malwarebytes Anti-Malware version 2.1.6.1022
    Okey, I will delete these programs. IObit Uninstaller I already deleted, but still the file is there empty, and the system doesn't let me get rid of it. I will check the leftovers in the registry just in case. About the workfoldersres.dll I think that it is not of crucial importance, because it should be part of the "Work Files" directory that came with the computer, which I don't use.

  10. #70
    Administrator
    Windows Update Instructor
    Security Analyst

    Join Date
    Oct 2014
    Posts
    17,512

    Re: Is efnnouse.exe a virus?

    Once those programs are removed please do the following.

    Step#1 - ChkDsk Scan
    1. Right-click your Start button and select Command Prompt (Admin). Answer Yes to allow if the User Account Control dialog comes up.
    2. You should now have a black window open that you can type in to.
    3. Please type chkdsk and then press enter.
    4. Chkdsk will start to run. Please allow it to finish. You will know it is running when you see text as follows.


    5. Download ListChkdskResult.exe by SleepyDude and save it on your desktop. If it's already downloaded to your desktop, just skip this step.
    6. Right-click this file and select Run as administrator (Allow if prompted)and a text file will open (and also be saved on the desktop as ListChkdskResult.txt).
    Please copy the contents of this file and paste into your next post.

  11. #71

    Re: Is efnnouse.exe a virus?

    I have 16 programs of Visual C++. May I delete the old ones and leave only the last version?

  12. #72
    Administrator
    Windows Update Instructor
    Security Analyst

    Join Date
    Oct 2014
    Posts
    17,512

    Re: Is efnnouse.exe a virus?

    If you do that, it's likely you will break some of your programs. Programs depend on a very specific version of those runtimes so I would leave them.

  13. #73

    Re: Is efnnouse.exe a virus?

    Thank you for the advise about the Visual C++. This is the log:

    ListChkdskResult by SleepyDude v0.1.7 Beta | 21-09-2013

    ------< Log generate on 7/10/2015 9:43:28 AM >------
    Category: 0
    Computer Name: Kenny
    Event Code: 26212
    Record Number: 58054
    Source Name: Chkdsk
    Time Written: 07-10-2015 @ 03:40:59
    Event Type: Information
    User:
    Message: Chkdsk was executed in read-only mode on a volume snapshot.

    Checking file system on C:
    The type of the file system is NTFS.
    Volume label is Windows.

    WARNING! F parameter not specified.
    Running CHKDSK in read-only mode.

    Stage 1: Examining basic file system structure ...


    2096384 file records processed.

    File verification completed.


    8531 large file records processed.



    0 bad file records processed.


    Stage 2: Examining file name linkage ...


    2205298 index entries processed.

    Index verification completed.


    0 unindexed files scanned.



    0 unindexed files recovered.


    Stage 3: Examining security descriptors ...
    Security descriptor verification completed.


    54458 data files processed.

    CHKDSK is verifying Usn Journal...


    39244640 USN bytes processed.

    Usn Journal verification completed.

    Windows has scanned the file system and found no problems.
    No further action is required.

    964580351 KB total disk space.
    222258068 KB in 1238630 files.
    638848 KB in 54459 indexes.
    0 KB in bad sectors.
    2236311 KB in use by the system.
    65536 KB occupied by the log file.
    739447124 KB available on disk.

    4096 bytes in each allocation unit.
    241145087 total allocation units on disk.
    184861781 allocation units available on disk.

    -----------------------------------------------------------------------
    Category: 0
    Computer Name: Kenny
    Event Code: 26212
    Record Number: 55603
    Source Name: Chkdsk
    Time Written: 07-04-2015 @ 04:53:40
    Event Type: Information
    User:
    Message: Chkdsk was executed in read-only mode on a volume snapshot.

    Checking file system on D:
    Volume label is Recovery Image.

    Stage 1: Examining basic file system structure ...

    512 file records processed.

    File verification completed.

    0 large file records processed.


    0 bad file records processed.


    Stage 2: Examining file name linkage ...

    796 index entries processed.

    Index verification completed.





    Stage 3: Examining security descriptors ...
    Security descriptor verification completed.

    143 data files processed.

    CHKDSK is verifying Usn Journal...

    238000 USN bytes processed.

    Usn Journal verification completed.

    Windows has scanned the file system and found no problems.
    No further action is required.

    10626047 KB total disk space.
    9336708 KB in 255 files.
    52 KB in 144 indexes.
    56987 KB in use by the system.
    55216 KB occupied by the log file.
    1232300 KB available on disk.

    4096 bytes in each allocation unit.
    2656511 total allocation units on disk.
    308075 allocation units available on disk.

    -----------------------------------------------------------------------
    Category: 0
    Computer Name: Kenny
    Event Code: 26212
    Record Number: 55602
    Source Name: Chkdsk
    Time Written: 07-04-2015 @ 04:53:24
    Event Type: Information
    User:
    Message: Chkdsk was executed in read-only mode on a volume snapshot.

    Checking file system on C:
    Volume label is Windows.

    Stage 1: Examining basic file system structure ...

    2096384 file records processed.

    File verification completed.

    8518 large file records processed.


    0 bad file records processed.


    Stage 2: Examining file name linkage ...

    2205180 index entries processed.

    Index verification completed.





    Stage 3: Examining security descriptors ...
    Security descriptor verification completed.

    54399 data files processed.

    CHKDSK is verifying Usn Journal...

    33618864 USN bytes processed.

    Usn Journal verification completed.

    Windows has scanned the file system and found no problems.
    No further action is required.

    964580351 KB total disk space.
    209453292 KB in 1207397 files.
    625060 KB in 54400 indexes.
    2230903 KB in use by the system.
    65536 KB occupied by the log file.
    752271096 KB available on disk.

    4096 bytes in each allocation unit.
    241145087 total allocation units on disk.
    188067774 allocation units available on disk.

    -----------------------------------------------------------------------
    Category: 0
    Computer Name: Kenny
    Event Code: 1001
    Record Number: 48753
    Source Name: Microsoft-Windows-Wininit
    Time Written: 06-18-2015 @ 21:57:32
    Event Type: Information
    User:
    Message:

    Checking file system on C:
    The type of the file system is NTFS.
    Volume label is Windows.

    A disk check has been scheduled.
    Windows will now check the disk.

    Stage 1: Examining basic file system structure ...
    2096384 file records processed.

    File verification completed.
    7899 large file records processed.

    0 bad file records processed.


    Stage 2: Examining file name linkage ...
    2193182 index entries processed.

    Index verification completed.
    0 unindexed files scanned.

    0 unindexed files recovered.


    Stage 3: Examining security descriptors ...
    Cleaning up 2978 unused index entries from index $SII of file 0x9.
    Cleaning up 2978 unused index entries from index $SDH of file 0x9.
    Cleaning up 2978 unused security descriptors.
    Security descriptor verification completed.
    48400 data files processed.

    CHKDSK is verifying Usn Journal...
    34087648 USN bytes processed.

    Usn Journal verification completed.

    Stage 4: Looking for bad clusters in user file data ...
    2096368 files processed.

    File data verification completed.

    Stage 5: Looking for bad, free clusters ...
    187645214 free clusters processed.

    Free space verification is complete.

    Windows has made corrections to the file system.
    No further action is required.

    964580351 KB total disk space.
    211150892 KB in 1202477 files.
    617796 KB in 48401 indexes.
    0 KB in bad sectors.
    2230807 KB in use by the system.
    65536 KB occupied by the log file.
    750580856 KB available on disk.

    4096 bytes in each allocation unit.
    241145087 total allocation units on disk.
    187645214 allocation units available on disk.

    Internal Info:
    00 fd 1f 00 45 16 13 00 90 59 25 00 00 00 00 00 ....E....Y%.....
    23 03 00 00 42 00 00 00 00 00 00 00 00 00 00 00 #...B...........

    Windows has finished checking your disk.
    Please wait while your computer restarts.

    -----------------------------------------------------------------------
    Category: 0
    Computer Name: Kenny
    Event Code: 26226
    Record Number: 46341
    Source Name: Chkdsk
    Time Written: 06-14-2015 @ 23:21:56
    Event Type: Information
    User:
    Message: Chkdsk was executed in scan mode on a volume snapshot.

    Checking file system on C:
    The shadow copy provider timed out while flushing data to the volume being shadow copied. This is probably due to excessive activity on the volume. Try again later when the volume is not being used so heavily.

    A snapshot error occured while scanning this drive. You can try again, but if this problem persists, run an offline scan and fix.

    -----------------------------------------------------------------------

  14. #74
    Administrator
    Windows Update Instructor
    Security Analyst

    Join Date
    Oct 2014
    Posts
    17,512

    Re: Is efnnouse.exe a virus?

    OK, now we start to narrow down your issue. We need to do the following again.

    Please do a Clean Boot of your machine by following the article below. While in a clean boot, let me know what issues you still have. Be as specific as possible. Thanks.
    https://support.microsoft.com/en-us/kb/929135

  15. #75

    Re: Is efnnouse.exe a virus?

    Quote Originally Posted by BrianDrab View Post
    OK, now we start to narrow down your issue. We need to do the following again.

    Please do a Clean Boot of your machine by following the article below. While in a clean boot, let me know what issues you still have. Be as specific as possible. Thanks.
    https://support.microsoft.com/en-us/kb/929135
    Hi,

    Here I am, writing into a system which started clean, as you asked. Things are here working better. However, the system start took a very long time again, and a right click froze Firefox, but was just for a minute. I opened the task manager that didn't stop responding, and Firefox worked alone. What do all of these tell to you?

  16. #76
    Administrator
    Windows Update Instructor
    Security Analyst

    Join Date
    Oct 2014
    Posts
    17,512

    Re: Is efnnouse.exe a virus?

    and a right click froze Firefox
    What were you right clicking?

    I opened the task manager that didn't stop responding
    What was the reason you opened task manager? What didn't stop responding?

  17. #77

    Re: Is efnnouse.exe a virus?

    Hi Brian,

    Well, I right clicked to use my password manager to sign in, and because you wanted to know if something continued being wrong. And I opened task manager when Firefox froze with the idea to force it closed, and because before always stopped responding at opening. Did you want to know how things were working, no? Well, the PC works better now but I still don't know if it's due to one of the services that we are not running now. So, lets restart normal again to see what happens.

  18. #78

    Re: Is efnnouse.exe a virus?

    Quote Originally Posted by MONKA View Post
    Hi Brian,

    Well, I right clicked to use my password manager to sign in, and because you wanted to know if something continued being wrong. And I opened task manager when Firefox froze with the idea to force it closed, and because before always stopped responding at opening. Did you want to know how things were working, no? Well, the PC works better now but I still don't know if it's due to one of the services that we are not running now. So, lets restart normal again to see what happens.
    Looks like the PC is making fun of me. After I sent the previous message, when I closed the browser, Task Manager -that was open- freeze everything, mouse included. After about one minute, the system began working again. The reboot took over 5 minutes.

  19. #79
    Administrator
    Windows Update Instructor
    Security Analyst

    Join Date
    Oct 2014
    Posts
    17,512

    Re: Is efnnouse.exe a virus?

    Well, I right clicked to use my password manager to sign in, and because you wanted to know if something continued being wrong. And I opened task manager when Firefox froze with the idea to force it closed, and because before always stopped responding at opening. Did you want to know how things were working, no? Well, the PC works better now but I still don't know if it's due to one of the services that we are not running now. So, lets restart normal again to see what happens.
    Thanks for the clarification. Yes I did want to know the details...they were just unclear to me but this helped. Please stay in a Clean Boot state. We already know that it's much worse in a Normal boot. We'll start narrowing down the issue but I need you to stay in a Clean Boot.

    Once in a clean boot, please export your Firefox Bookmarks (if you have any) following the instructions below. Save them to your desktop.
    https://support.mozilla.org/en-US/kb/export-firefox-bookmarks-to-backup-or-transfer

    Then completely uninstall Firefox from Add/Remove programs. If asked to remove Personal Data please answer Yes.

    Then re-install the newest version of Firefox from the below link.
    https://www.mozilla.org/en-US/firefox/new/?utm_source=firefox-com&utm_medium=referral

    Then re-import your bookmarks using the link below.
    https://support.mozilla.org/en-US/kb/import-bookmarks-html-file

    Once this is done, let me know if you still have the issues with Firefox in a Clean Boot state.

    Thanks.

  20. #80

    Re: Is efnnouse.exe a virus?

    Quote Originally Posted by BrianDrab View Post
    Well, I right clicked to use my password manager to sign in, and because you wanted to know if something continued being wrong. And I opened task manager when Firefox froze with the idea to force it closed, and because before always stopped responding at opening. Did you want to know how things were working, no? Well, the PC works better now but I still don't know if it's due to one of the services that we are not running now. So, lets restart normal again to see what happens.
    Thanks for the clarification. Yes I did want to know the details...they were just unclear to me but this helped. Please stay in a Clean Boot state. We already know that it's much worse in a Normal boot. We'll start narrowing down the issue but I need you to stay in a Clean Boot.

    Once in a clean boot, please export your Firefox Bookmarks (if you have any) following the instructions below. Save them to your desktop.
    https://support.mozilla.org/en-US/kb/export-firefox-bookmarks-to-backup-or-transfer

    Then completely uninstall Firefox from Add/Remove programs. If asked to remove Personal Data please answer Yes.

    Then re-install the newest version of Firefox from the below link.
    https://www.mozilla.org/en-US/firefox/new/?utm_source=firefox-com&utm_medium=referral

    Then re-import your bookmarks using the link below.
    https://support.mozilla.org/en-US/kb/import-bookmarks-html-file

    Once this is done, let me know if you still have the issues with Firefox in a Clean Boot state.

    Thanks.
    I don't understand what happens. I have uninstalled Firefox 2 times. The second one, I manually cleaned the leftovers in the registry. But when I reinstall it, nothing has change: all my personalization and apps are there. Sometimes I think that someone, or something is controlling my PC. Yesterday, for example, after I set up the clean boot, it was reverted by itself, and the computer booted in normal mode. Before that, I disabled or deleted all the automatic tasks because the computer start up by itself at whatever time during the day, night, or preferably, overnight. The only thing I am sure with this issue is that who or what is doing it, will not pay my electric bills. I don't think that it's hacked, because the lady that help me before did a very good virus checking. What I think is that some Microsoft app is working behind my back, but I can't figure out which is. I downloaded the Revo Unistall, and that didn't get rid of Firefox properties either.

Page 4 of 5 First 12345 Last

Similar Threads

  1. Need Some Help w/ Virus or Rootkit
    By Fred Garvin in forum Security Arena
    Replies: 5
    Last Post: 12-17-2014, 10:12 AM
  2. Corrupt Files After Virus
    By Brick in forum Windows Update
    Replies: 36
    Last Post: 10-30-2013, 02:06 PM
  3. possible virus
    By Ajalon in forum Security Arena
    Replies: 16
    Last Post: 08-05-2013, 09:46 AM
  4. Issue possible virus
    By Ajalon in forum General Help & Information
    Replies: 2
    Last Post: 07-16-2013, 08:45 AM
  5. When I say 'virus,' you know exactly what I mean
    By JMH in forum News You Can Use
    Replies: 0
    Last Post: 05-11-2012, 05:24 AM

Log in

Log in