Trojan.Win32.Swrort_ddbacc89df

by malwarelabrobot on December 13th, 2014 in Malware Descriptions.

TrojanSwrort.YR (Lavasoft MAS)
Behaviour: Trojan


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: ddbacc89dfd4a2c00602501454102d63
SHA1: af99d469f2c705247e2a3e03a489ff82be8c172b
SHA256: d42cf6403220c2801760d8e910fca411cb84c1d5e6b60657264c92598cd5401a
SSDeep: 98304:vfYs3YSgpg1m2 MDGoqfW UCkTgfuDN6Wi0EMpI3G8FuN:nYgYS2g1mE5qfYEfuR6WilMpyG80N
Size: 4520456 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: PC Drivers HeadQuarters LP
Created at: 2014-10-07 07:40:17
Analyzed on: Windows7Ada SP1 64-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

DriverSupport.exe:3068
viometer.exe:2616
csc.exe:3920
csc.exe:3824
csc.exe:2716
csc.exe:3908
csc.exe:1836
csc.exe:4024
csc.exe:3388
csc.exe:2948
csc.exe:3148
csc.exe:3040
csc.exe:3684
csc.exe:2820
csc.exe:3652
csc.exe:3452
csc.exe:2132
csc.exe:2544
csc.exe:3512
csc.exe:3340
csc.exe:872
csc.exe:3516
csc.exe:1856
csc.exe:3792
csc.exe:2056
csc.exe:3300
csc.exe:3368
csc.exe:3760
csc.exe:3488
csc.exe:2460
csc.exe:2876
csc.exe:3456
csc.exe:3952
csc.exe:3608
csc.exe:3400
csc.exe:3724
csc.exe:3268
csc.exe:2632
csc.exe:2832
csc.exe:3176
csc.exe:3780
csc.exe:3232
csc.exe:3420
csc.exe:3888
csc.exe:1808
csc.exe:3160
csc.exe:2376
csc.exe:2252
%original file name%.exe:1120
DriverSupportAOsvc.exe:3804
cvtres.exe:1348
cvtres.exe:1324
cvtres.exe:3636
cvtres.exe:3100
cvtres.exe:980
cvtres.exe:4004
cvtres.exe:3944
cvtres.exe:1200
cvtres.exe:3324
cvtres.exe:1856
cvtres.exe:3676
cvtres.exe:3292
cvtres.exe:2940
cvtres.exe:3476
cvtres.exe:792
cvtres.exe:1056
cvtres.exe:3364
cvtres.exe:3512
cvtres.exe:3648
cvtres.exe:4048
cvtres.exe:3412
cvtres.exe:3180
cvtres.exe:2368
cvtres.exe:3816
cvtres.exe:3912
cvtres.exe:3748
cvtres.exe:2420
cvtres.exe:3480
cvtres.exe:1376
cvtres.exe:3484
cvtres.exe:3708
cvtres.exe:3404
cvtres.exe:3288
cvtres.exe:2956
cvtres.exe:3248
cvtres.exe:3880
cvtres.exe:3784
cvtres.exe:3444
cvtres.exe:3112
cvtres.exe:3468
cvtres.exe:3092
cvtres.exe:3376
cvtres.exe:3848
cvtres.exe:3980
ipterbg.exe:3336
ipterbg.exe:3776
netsh.exe:1608
netsh.exe:2864
netsh.exe:792
netsh.exe:3472
netsh.exe:2272
netsh.exe:2548
netsh.exe:3032
netsh.exe:2632
netsh.exe:2096
netsh.exe:2368
netsh.exe:2352
netsh.exe:2504
netsh.exe:1380
netsh.exe:2372
DriverSupportAO.exe:1200
WmiApSrv.exe:3004
WmiApSrv.exe:2412
Agent.CPU.exe:2040

The Trojan injects its code into the following process(es):

csc.exe:3856
DriverSupportAOsvc.exe:3832
DriverSupportAO.exe:3856

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process DriverSupport.exe:3068 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ks81vfgg.0.cs (676 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\67f133336051498bae20d8a42c66cea0 (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scll4vkp.0.cs (676 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jowf_gms.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hgdi-q6i.0.cs (44948 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\54_uzr2d.cmdline (516 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ks81vfgg.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\c8xlzoj1.newcfg (6393 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hlrultwe.cmdline (460 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ghgvxgmj.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ckmtu3np.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ko37ladf.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wz3nllzp.out (807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n9b-3a4i.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n8eqm2oz.cmdline (459 bytes)
C:\ProgramData\Driver Support\Driver Support\RuleEngine\GlobalActions.dat (1100 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ql4ya16q.0.cs (196 bytes)
C:\ProgramData\Driver Support\Driver Support\dd.lic (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ou5ph5wn.0.cs (196 bytes)
C:\ProgramData\Driver Support\Driver Support\UXState.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\3n3dno5j.out (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\2saonv2b.newcfg (3846 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\majx6vcq.0.cs (196 bytes)
C:\ProgramData\Driver Support\Driver Support\RuleEngine\GlobalEnvironmentEvents.dat (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\bstn2rrt.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\9s6fbgha.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rclvi9--.cmdline (704 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\0pemeuyw.out (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\3n3dno5j.cmdline (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hgdi-q6i.out (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rclvi9--.out (807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pbifxxgm.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n8eqm2oz.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\egeu-bpl.0.cs (24148 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\fniuwqsj.newcfg (10420 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F6DEB9C1F3251400F7D6EB743CB14FB4 (452 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\k1l3ncvv.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ou5ph5wn.out (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wz3nllzp.cmdline (704 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hkkpqirm.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\fqvkndp7.cmdline (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n9b-3a4i.0.cs (37988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rdyawuc6.out (623 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\xurbrp4o.newcfg (12988 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\7519e2ac1b724f779dde1e587bb60e49 (1506148 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\bstn2rrt.0.cs (37988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n9b-3a4i.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ekilrb1z.out (508 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\39b7b31f79b5423fb1f9d8a46c900bd7 (1924 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rii4bvdv.out (560 bytes)
C:\ProgramData\Driver Support\Driver Support\WL.dat (2 bytes)
C:\ProgramData\Driver Support\Driver Support\RuleEngine\GlobalEnvironmentProperties.dat (1242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jjnryppy.out (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wz3nllzp.0.cs (388 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hzgkbspj.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\egeu-bpl.out (783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\f7d8eojk.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zvtxrn0a.cmdline (460 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\7hpnegaf.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mqbtijot.0.cs (676 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\5b0d7dtb.newcfg (16215 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\0pemeuyw.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xuiljsd9.out (602 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hkkpqirm.cmdline (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ugte--cj.out (563 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ghgvxgmj.0.cs (7332 bytes)
C:\ProgramData\Driver Support\Driver Support\DDSM\ScanManager.dat (33774 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pbifxxgm.cmdline (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mqbtijot.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\k1l3ncvv.cmdline (405 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\DownloadResourceManager.dat (5992 bytes)
C:\ProgramData\Driver Support\Driver Support\RuleEngine\GlobalRules.dat (24016 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hgdi-q6i.cmdline (680 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\osgzrzst.0.cs (676 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nt5jn1ho.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\fqvkndp7.out (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zp_bzj6l.cmdline (459 bytes)
C:\ProgramData\Driver Support\Driver Support\RuleEngine\RuleHistoryController.dat (986 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\osgzrzst.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F6DEB9C1F3251400F7D6EB743CB14FB4 (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n8eqm2oz.out (562 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\9a370d032c3b43ba9c16035637d5bdb6 (1444 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\exhkewak.newcfg (2519 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jwybd_jj.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\lg0bf1l_.cmdline (460 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ghgvxgmj.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rlyvchat.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\lg0bf1l_.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hkkpqirm.out (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ckmtu3np.0.cs (2500 bytes)
%Program Files% (x86)\Driver Support\Common.dll (48 bytes)
%Program Files% (x86)\Driver Support\ExceptionLogging.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\k1l3ncvv.out (508 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\psmntriu.newcfg (10380 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ko37ladf.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\9s6fbgha.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_40F159D44D8C605036811A9D469F7AD9 (1504 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scll4vkp.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zvtxrn0a.out (563 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\fqvkndp7.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\f7d8eojk.out (562 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\14a11a95bc3d4011a82af56b5864fdb2 (5572 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\54_uzr2d.out (619 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rdyawuc6.cmdline (520 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\c319d7f190d649d3a4100511b6132314 (388 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jjnryppy.0.cs (40972 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pqis5zx7.out (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\54_uzr2d.0.cs (676 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rlyvchat.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xuiljsd9.0.cs (6740 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pqis5zx7.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\majx6vcq.out (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hzgkbspj.0.cs (676 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jowf_gms.out (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nt5jn1ho.0.cs (1444 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\7hpnegaf.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jwybd_jj.cmdline (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ekilrb1z.cmdline (405 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\7f804686e64f45cabd8107097dc688a3 (4708 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ql4ya16q.cmdline (704 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\0pemeuyw.cmdline (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jowf_gms.cmdline (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rii4bvdv.cmdline (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\bstn2rrt.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\024haam9.newcfg (1456 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\osgzrzst.cmdline (459 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\043835d9630e45e39f87449f3af42366 (5572 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_40F159D44D8C605036811A9D469F7AD9 (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hlrultwe.out (563 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\f0e18b584afe4b37b328737aebd980f9 (2500 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rlyvchat.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\majx6vcq.cmdline (457 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\4436b4f25b814365839a2bdcf97307fa (7332 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_lmw7aa4.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\f7d8eojk.0.cs (2500 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hlrultwe.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rdyawuc6.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\egeu-bpl.cmdline (680 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\8hcqdkos.newcfg (1854 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hzgkbspj.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ra-mrtty.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ckmtu3np.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ugte--cj.cmdline (460 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mqbtijot.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rii4bvdv.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_lmw7aa4.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_lmw7aa4.0.cs (2500 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xuiljsd9.cmdline (499 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nt5jn1ho.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rclvi9--.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\ltb3ipvd.newcfg (6393 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zvtxrn0a.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zp_bzj6l.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\lg0bf1l_.out (563 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ugte--cj.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scll4vkp.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pbifxxgm.out (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pqis5zx7.cmdline (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ou5ph5wn.cmdline (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ra-mrtty.0.cs (388 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ql4ya16q.out (807 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\636258a27768481b92b8e563d2c198d8 (1444 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jjnryppy.cmdline (680 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ra-mrtty.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ekilrb1z.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ks81vfgg.cmdline (459 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\7hpnegaf.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ko37ladf.0.cs (676 bytes)
C:\ProgramData\Driver Support\Driver Support\DDRM\7f816ca43b494c62bb80ee53ea76e10b (676 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zp_bzj6l.0.cs (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jwybd_jj.out (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\9s6fbgha.out (562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\3n3dno5j.0.cs (196 bytes)

The process viometer.exe:2616 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Windows\SysWOW64\rnd_chunk.bin (166456 bytes)
C:\Windows\SysWOW64\_tmp_total_results.txt (174705 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\7a965e8de7cc4fba744fa7016513e423\File.dll (12034 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616 (4 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\e790df575748f7ddfa6d074eefbd3af9\Dumper.dll (4744 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\perl510.dll (3645 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\cc6074bff1906afc872db1ac09b9f547\Process.dll (3204 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\eec708426f797e3eae1af772a856fdae\OLE.dll (12170 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\5a043c9ceeb6d93382986c196a4fafd4\API.dll (4744 bytes)
C:\Windows\SysWOW64\_tmp_file.txt (5720758 bytes)
C:\Windows\SysWOW64\_tmp_results.txt (138546 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\84c73e03b82ca27738913a411aab1a36\Win32.dll (6577 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\5bec2b7324c81f25bdf5c087fdf888e2\Util.dll (4744 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\bca7aac987d374edc35a6e36445e61af\Fcntl.dll (2528 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\1fb9e4724fa361b2039d7108d86facb1\IO.dll (4744 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\7fd1f1fe740136136caf3658edc53f83\FastCalc.dll (3204 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\baeb31b10de41e0fd6fecc1b786c31f3\SHA.dll (7045 bytes)
C:\Windows\Temp\pdk-SYSTEM-2616\278e95d3c70d01bffd43d0d6f0a68d54\HiRes.dll (2528 bytes)
C:\Windows\Temp\PFR6kZWcM5\_results.txt (29752 bytes)

The process csc.exe:3920 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC954C.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jwybd_jj.dll (3886 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jwybd_jj.out (396 bytes)

The process csc.exe:3824 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC93A7.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rii4bvdv.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rii4bvdv.dll (3694 bytes)

The process csc.exe:2716 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ko37ladf.dll (4740 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCBFB6.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ko37ladf.out (396 bytes)

The process csc.exe:3908 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC3294.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zvtxrn0a.dll (3614 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zvtxrn0a.out (396 bytes)

The process csc.exe:1836 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\f7d8eojk.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\f7d8eojk.dll (5228 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCC216.tmp (664 bytes)

The process csc.exe:4024 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nt5jn1ho.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nt5jn1ho.dll (4312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCA044.tmp (664 bytes)

The process csc.exe:3388 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\egeu-bpl.out (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC79E0.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\egeu-bpl.dll (5166 bytes)

The process csc.exe:2948 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wz3nllzp.out (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCCD9A.tmp (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wz3nllzp.dll (3600 bytes)

The process csc.exe:3148 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCA256.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\54_uzr2d.dll (3552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\54_uzr2d.out (396 bytes)

The process csc.exe:3040 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hgdi-q6i.out (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4BAF.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hgdi-q6i.dll (5394 bytes)

The process csc.exe:3684 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pqis5zx7.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pqis5zx7.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC89E7.tmp (664 bytes)

The process csc.exe:2820 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\lg0bf1l_.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC450B.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\lg0bf1l_.dll (3662 bytes)

The process csc.exe:3652 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\majx6vcq.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\majx6vcq.dll (3224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC8979.tmp (664 bytes)

The process csc.exe:3452 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC7AD9.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hzgkbspj.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hzgkbspj.dll (4230 bytes)

The process csc.exe:2132 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC515A.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jjnryppy.dll (4258 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jjnryppy.out (198 bytes)

The process csc.exe:2544 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCBF48.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zp_bzj6l.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zp_bzj6l.dll (3534 bytes)

The process csc.exe:3512 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n8eqm2oz.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4F09.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n8eqm2oz.dll (3630 bytes)

The process csc.exe:3340 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC7905.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mqbtijot.dll (4950 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mqbtijot.out (396 bytes)

The process csc.exe:872 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rclvi9--.dll (3742 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4845.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rclvi9--.out (198 bytes)

The process csc.exe:3516 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rdyawuc6.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC1B2D.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rdyawuc6.dll (3646 bytes)

The process csc.exe:1856 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ghgvxgmj.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC5955.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ghgvxgmj.dll (4806 bytes)

The process csc.exe:3792 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jowf_gms.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC932A.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jowf_gms.dll (3646 bytes)

The process csc.exe:3856 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC9423.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\0pemeuyw.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\0pemeuyw.dll (3790 bytes)

The process csc.exe:2056 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4DC1.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\7hpnegaf.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\7hpnegaf.dll (3646 bytes)

The process csc.exe:3300 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC7703.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ntgnb1p9.dll (4950 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ntgnb1p9.out (396 bytes)

The process csc.exe:3368 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCDA66.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n9b-3a4i.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n9b-3a4i.dll (4662 bytes)

The process csc.exe:3760 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pbifxxgm.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC92BD.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pbifxxgm.dll (3000 bytes)

The process csc.exe:3488 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_lmw7aa4.dll (5228 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC7F3D.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_lmw7aa4.out (396 bytes)

The process csc.exe:2460 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rlyvchat.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4E9C.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rlyvchat.dll (3518 bytes)

The process csc.exe:2876 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ekilrb1z.dll (3646 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCC293.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ekilrb1z.out (396 bytes)

The process csc.exe:3456 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC1AA1.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ugte--cj.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ugte--cj.dll (3566 bytes)

The process csc.exe:3952 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC9626.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\fqvkndp7.dll (3192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\fqvkndp7.out (396 bytes)

The process csc.exe:3608 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC85B2.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\3n3dno5j.dll (3032 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\3n3dno5j.out (396 bytes)

The process csc.exe:3400 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\k1l3ncvv.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCDB41.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\k1l3ncvv.dll (3710 bytes)

The process csc.exe:3724 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hkkpqirm.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hkkpqirm.dll (3304 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC8D9E.tmp (664 bytes)

The process csc.exe:3268 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kuwfyi5l.dll (4838 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kuwfyi5l.out (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC7638.tmp (664 bytes)

The process csc.exe:2632 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\bstn2rrt.dll (4662 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\bstn2rrt.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCC34E.tmp (664 bytes)

The process csc.exe:2832 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ra-mrtty.dll (3938 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCC199.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ra-mrtty.out (396 bytes)

The process csc.exe:3176 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ckmtu3np.dll (3136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ckmtu3np.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4652.tmp (664 bytes)

The process csc.exe:3780 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hlrultwe.dll (3614 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hlrultwe.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC2F2A.tmp (664 bytes)

The process csc.exe:3232 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scll4vkp.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCC12C.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scll4vkp.dll (4950 bytes)

The process csc.exe:3420 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ks81vfgg.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC7A6C.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ks81vfgg.dll (4548 bytes)

The process csc.exe:3888 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC94CF.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ou5ph5wn.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ou5ph5wn.dll (3678 bytes)

The process csc.exe:1808 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xuiljsd9.out (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4153.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xuiljsd9.dll (4838 bytes)

The process csc.exe:3160 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCC071.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\osgzrzst.out (396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\osgzrzst.dll (4548 bytes)

The process csc.exe:2376 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC477B.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ql4ya16q.out (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ql4ya16q.dll (3854 bytes)

The process csc.exe:2252 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4E2F.tmp (664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\9s6fbgha.dll (3630 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\9s6fbgha.out (396 bytes)

The process %original file name%.exe:1120 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\Driver Support\ICSharpCode.SharpZipLib.dll (7192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\nsDialogs.dll (21 bytes)
%Program Files% (x86)\Driver Support\Agent.Common.XmlSerializers.dll (11344 bytes)
%Program Files% (x86)\Driver Support\RuleEngine.dll (17848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\modern-wizard.bmp (5520 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\modern-header.bmp (784 bytes)
%Program Files% (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.Downloaders.dll (1552 bytes)
%Program Files% (x86)\Driver Support\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.dll (2392 bytes)
%Program Files% (x86)\Driver Support\Common.dll (33536 bytes)
%Program Files% (x86)\Driver Support\ExceptionLogging.dll (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\System.dll (23 bytes)
%Program Files% (x86)\Driver Support\Agent.CPU.exe (1856 bytes)
%Program Files% (x86)\Driver Support\ISUninstall.exe (784 bytes)
%Program Files% (x86)\Driver Support\Interop.WUApiLib.dll (3312 bytes)
%Program Files% (x86)\Driver Support\Agent.ExceptionLogging.XmlSerializers.dll (1552 bytes)
%Program Files% (x86)\Driver Support\cpuidsdk.dll (28288 bytes)
%Program Files% (x86)\Driver Support\Agent.Common.dll (13368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Driver Support\Uninstall Driver Support.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\DotNetChecker.dll (1597 bytes)
%Program Files% (x86)\Driver Support\Microsoft.Practices.EnterpriseLibrary.Common.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\UserInfo.dll (8 bytes)
%Program Files% (x86)\Driver Support\DriverSupport.exe (190439 bytes)
%Program Files% (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.dll (4992 bytes)
%Program Files% (x86)\Driver Support\DriverSupport.Updater.exe.config (2 bytes)
%Program Files% (x86)\Driver Support\Microsoft.Win32.TaskScheduler.dll (5064 bytes)
%Program Files% (x86)\Driver Support\RuleEngine.XmlSerializers.dll (2392 bytes)
%Program Files% (x86)\Driver Support\Microsoft.Practices.ObjectBuilder.dll (1856 bytes)
%Program Files% (x86)\Driver Support\config.dat (2 bytes)
%Program Files% (x86)\Driver Support\Uninstall.exe (2469 bytes)
%Program Files% (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.ActivationProcessors.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Driver Support\Driver Support.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc9CDB.tmp (390115 bytes)
%Program Files% (x86)\Driver Support\XPBurnComponent.dll (1856 bytes)
%Program Files% (x86)\Driver Support\DriverSupport.chm (1552 bytes)
%Program Files% (x86)\Driver Support\ThemePack.DriverSupport.dll (31856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\LangDLL.dll (13 bytes)
%Program Files% (x86)\Driver Support\Agent.ExceptionLogging.dll (1856 bytes)
%Program Files% (x86)\Driver Support\Agent.Communication.dll (15536 bytes)
%Program Files% (x86)\Driver Support\DriverSupport.exe.config (2 bytes)
%Program Files% (x86)\Driver Support\Agent.Communication.XmlSerializers.dll (16288 bytes)
%Program Files% (x86)\Driver Support\DriverSupport.Updater.exe (7192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\Linker.dll (16 bytes)

The process DriverSupportAOsvc.exe:3804 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\Veloxum\iPTE\ipte_svc.log (46 bytes)

The process DriverSupportAOsvc.exe:3832 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\Veloxum\iPTE\ipte_svc.log (362 bytes)

The process cvtres.exe:1348 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES1B2E.tmp (3698 bytes)

The process cvtres.exe:1324 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESBF49.tmp (3698 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4BB0.tmp (3698 bytes)

The process cvtres.exe:3636 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES85B3.tmp (3698 bytes)

The process cvtres.exe:3100 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESC072.tmp (3698 bytes)

The process cvtres.exe:980 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4DC2.tmp (3698 bytes)

The process cvtres.exe:4004 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES32A4.tmp (3698 bytes)

The process cvtres.exe:3944 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES954D.tmp (3698 bytes)

The process cvtres.exe:1200 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES5956.tmp (3698 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES2F2B.tmp (3698 bytes)

The process cvtres.exe:3324 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES7704.tmp (3698 bytes)

The process cvtres.exe:1856 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4653.tmp (3698 bytes)

The process cvtres.exe:3676 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES897A.tmp (3698 bytes)

The process cvtres.exe:3292 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES7639.tmp (3698 bytes)

The process cvtres.exe:2940 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESC217.tmp (3698 bytes)

The process cvtres.exe:3476 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES7ADA.tmp (3698 bytes)

The process cvtres.exe:792 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESC294.tmp (3698 bytes)

The process cvtres.exe:1056 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4846.tmp (3698 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESBFB7.tmp (3698 bytes)

The process cvtres.exe:3364 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES7906.tmp (3698 bytes)

The process cvtres.exe:3512 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES7F4D.tmp (3698 bytes)

The process cvtres.exe:3648 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4F0A.tmp (3698 bytes)

The process cvtres.exe:4048 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESA045.tmp (3698 bytes)

The process cvtres.exe:3412 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES79E1.tmp (3698 bytes)

The process cvtres.exe:3180 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESA257.tmp (3698 bytes)

The process cvtres.exe:2368 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4154.tmp (3698 bytes)

The process cvtres.exe:3816 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES932B.tmp (3698 bytes)

The process cvtres.exe:3912 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES94D0.tmp (3698 bytes)

The process cvtres.exe:3748 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES8D9F.tmp (3698 bytes)

The process cvtres.exe:2420 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES477C.tmp (3698 bytes)

The process cvtres.exe:3480 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES1AA2.tmp (3698 bytes)

The process cvtres.exe:1376 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES451B.tmp (3698 bytes)

The process cvtres.exe:3484 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4E9D.tmp (3698 bytes)

The process cvtres.exe:3708 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES89E8.tmp (3698 bytes)

The process cvtres.exe:3404 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESDB42.tmp (3698 bytes)

The process cvtres.exe:3288 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESCD9B.tmp (3666 bytes)

The process cvtres.exe:2956 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES515B.tmp (3698 bytes)

The process cvtres.exe:3248 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESC34F.tmp (3698 bytes)

The process cvtres.exe:3880 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES9424.tmp (3698 bytes)

The process cvtres.exe:3784 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES92BE.tmp (3698 bytes)

The process cvtres.exe:3444 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES7A6D.tmp (3698 bytes)

The process cvtres.exe:3112 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESC12D.tmp (3698 bytes)

The process cvtres.exe:3468 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4E30.tmp (3698 bytes)

The process cvtres.exe:3092 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESC19A.tmp (3698 bytes)

The process cvtres.exe:3376 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESDA67.tmp (3698 bytes)

The process cvtres.exe:3848 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES93A8.tmp (3698 bytes)

The process cvtres.exe:3980 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES9627.tmp (3698 bytes)

The process ipterbg.exe:3336 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3336\perl510.dll (3645 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3336\e790df575748f7ddfa6d074eefbd3af9\Dumper.dll (4744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3336\cc6074bff1906afc872db1ac09b9f547\Process.dll (3204 bytes)
%Program Files% (x86)\Veloxum\iPTE\DriverSupportAO.exe (485 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3336 (4 bytes)

The process ipterbg.exe:3776 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3776\perl510.dll (3645 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3776\e790df575748f7ddfa6d074eefbd3af9\Dumper.dll (4744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3776\cc6074bff1906afc872db1ac09b9f547\Process.dll (3204 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3776 (4 bytes)
%Program Files% (x86)\Veloxum\iPTE\DriverSupportAOsvc.exe (49 bytes)

The process DriverSupportAO.exe:3856 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\Veloxum\iPTE\reg.dat (676 bytes)
C:\Windows\Temp\pdk-SYSTEM-3856\XML\SAX\ParserDetails.ini (70 bytes)

The process DriverSupportAO.exe:1200 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-1200\XML\SAX\ParserDetails.ini (70 bytes)

The process Agent.CPU.exe:2040 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\cpuz136\cpuz136_x64.sys (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kuwfyi5l.0.cs (6740 bytes)
C:\ProgramData\Driver Support\Driver Support\CPUID.dat (856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ntgnb1p9.0.cs (676 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ntgnb1p9.cmdline (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ntgnb1p9.out (558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kuwfyi5l.cmdline (497 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kuwfyi5l.out (598 bytes)

Registry activity

The process DriverSupport.exe:3068 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"fveui.dll,-844" = "BitLocker Data Recovery Agent"

[HKLM\SOFTWARE\DriverSupport]
"uuid" = "13682300-b037-44d0-9742-3c77ad4178ee"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"fveui.dll,-843" = "BitLocker Drive Encryption"

[HKCU\Software\DriverSupport\Install]
"DhqScanStatusDescription" = "Scanning Your Computer"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

"UNCAsIntranet" = "0"

[HKCU\Software\DriverSupport\Install]
"DhqScanFinish" = "12/12/2014 1:39:45 PM"

[HKCU\Software\DriverSupport]
"APIPort" = "65411"

[HKCU\Software\DriverSupport\Install]
"VeloxumInstallDate" = "12/12/2014 1:40:01 PM"
"DhqScanStart" = "12/12/2014 1:39:29 PM"
"VeloxumScanStart" = "12/12/2014 1:40:02 PM"
"VeloxumScanStatus" = "10"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\SOFTWARE\Microsoft\Tracing\DriverSupport_RASMANCS]
"FileTracingMask" = "4294901760"
"ConsoleTracingMask" = "4294901760"

[HKCU\Software\DriverSupport\Install]
"ScanProgress" = "15"
"VeloxumInstallStatus" = "-2"
"ScanFinish" = "12/12/2014 1:41:18 PM"
"VeloxumScanStatusDescription" = "Contacting Server"

[HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7C4656C3061F7F4C0D67B319A855F60EBC11FC44]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 7C 46 56 C3"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE]
"DHQSessionID" = "S-1-5-21-2858020935-2156992550-3658131804-1003"

[HKCU\Software\DriverSupport\Install]
"uuid" = "13682300-b037-44d0-9742-3c77ad4178ee"

[HKLM\SOFTWARE\Microsoft\Tracing\DriverSupport_RASAPI32]
"MaxFileSize" = "1048576"
"FileTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\DriverSupport_RASMANCS]
"MaxFileSize" = "1048576"
"EnableFileTracing" = "0"

[HKCU\Software\DriverSupport\Install]
"DhqScanStatus" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\DriverSupport_RASMANCS]
"FileDirectory" = "%windir%\tracing"

[HKCU\Software\DriverSupport\Install]
"VeloxumScanFinish" = "12/12/2014 1:41:18 PM"
"ScanStatus" = "0"
"ScanStatusDescription" = "Scanning Your Computer"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4]
"Blob" = "04 00 00 00 01 00 00 00 10 00 00 00 91 DE 06 25"

[HKLM\SOFTWARE\Microsoft\Tracing\DriverSupport_RASAPI32]
"FileDirectory" = "%windir%\tracing"

[HKCU\Software\DriverSupport\Install]
"ScanStart" = "12/12/2014 1:39:29 PM"

[HKLM\SOFTWARE\Microsoft\Tracing\DriverSupport_RASAPI32]
"ConsoleTracingMask" = "4294901760"
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\DriverSupport_RASMANCS]
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\DriverSupport]
"APIPort" = "65411"

[HKLM\SOFTWARE\Microsoft\Tracing\DriverSupport_RASAPI32]
"EnableFileTracing" = "0"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Driver Support" = "%Program Files% (x86)\Driver Support\DriverSupport.exe /applicationMode:systemTray /showWelcome:false"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\SystemCertificates\CA\Certificates]
"7C4656C3061F7F4C0D67B319A855F60EBC11FC44"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\DriverSupport\Install]
"VeloxumScanFinish"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\DriverSupport\Install]
"ScanFinish"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates]
"2796BAE63F1801E277261BA0D77770028F20EEE4"

[HKCU\Software\DriverSupport\Install]
"DhqScanFinish"

The process %original file name%.exe:1120 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DriverSupport]
"InstallLocation" = "%Program Files% (x86)\Driver Support"
"Publisher" = "PC Drivers HeadQuarters LP"
"HelpTelephone" = "512.373.3518"
"DisplayName" = "Driver Support"
"NoModify" = "1"
"EstimatedSize" = "12120"
"UninstallString" = "%Program Files% (x86)\Driver Support\Uninstall.exe"
"InstallerLanguage" = "1033"
"URLInfoAbout" = "http://www.driversupport.com"
"HelpLink" = "http://account.driversupport.com/support/contact?wlid=30"
"DisplayVersion" = "9.1.4.66"

[HKCU\Software\DriverSupport\Install]
"UILevel" = "5"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DriverSupport]
"ProductID" = "{597FB4A5-DD86-4316-A410-7E8074CC2CCE}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\App Paths\DriverSupport.exe]
"(Default)" = "%Program Files% (x86)\Driver Support\DriverSupport.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DriverSupport]
"NoRepair" = "1"
"DisplayIcon" = "%Program Files% (x86)\Driver Support\DriverSupport.exe,0"

[HKCU\Software\DriverSupport\Install]
"InstallStatus" = "0"

The process DriverSupportAOsvc.exe:3804 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\services\DSAO]
"Description" = "Driver Support Active Optimization Service"

The process netsh.exe:1608 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo]
"http://127.0.0.1:65411/" = "01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"
"eapqec.dll,-102" = "1.0"
"eapqec.dll,-103" = "Microsoft Corporation"

The process netsh.exe:2864 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo]
"http://127.0.0.1:65411/client/status/" = "01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"

The process netsh.exe:792 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"napipsec.dll,-3" = "Microsoft Corporation"
"napipsec.dll,-2" = "Provides IPsec based enforcement for Network Access Protection"
"napipsec.dll,-1" = "IPsec Relying Party"
"napipsec.dll,-4" = "1.0"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"tsgqec.dll,-100" = "RD Gateway Quarantine Enforcement Client"

[HKLM\System\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo]
"http://127.0.0.1:65411/license/status/" = "01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"

The process netsh.exe:3472 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2B\52C64B7E\@%SystemRoot%\system32]
"napipsec.dll,-4" = "1.0"
"tsgqec.dll,-102" = "1.0"
"napipsec.dll,-2" = "Provides IPsec based enforcement for Network Access Protection"
"napipsec.dll,-3" = "Microsoft Corporation"
"napipsec.dll,-1" = "IPsec Relying Party"
"dhcpqec.dll,-103" = "1.0"
"dhcpqec.dll,-102" = "Microsoft Corporation"
"dhcpqec.dll,-101" = "Provides DHCP based enforcement for NAP"
"dhcpqec.dll,-100" = "DHCP Quarantine Enforcement Client"
"dnsapi.dll,-103" = "Domain Name System (DNS) Server Trust"

[HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\2B\52C64B7E]
"LanguageList" = "en-US, en"

[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2B\52C64B7E\@%SystemRoot%\system32]
"p2pcollab.dll,-8042" = "Peer to Peer Trust"
"tsgqec.dll,-101" = "Provides RD Gateway enforcement for NAP"
"tsgqec.dll,-100" = "RD Gateway Quarantine Enforcement Client"
"eapqec.dll,-101" = "Provides Network Access Protection enforcement for EAP authenticated network connections, such as those used with 802.1X and VPN technologies."
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"
"eapqec.dll,-103" = "Microsoft Corporation"
"eapqec.dll,-102" = "1.0"
"tsgqec.dll,-103" = "Microsoft Corporation"

The process netsh.exe:2272 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"tsgqec.dll,-102" = "1.0"

[HKLM\System\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo]
"http://127.0.0.1:65411/tests/progress/" = "01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"
"eapqec.dll,-101" = "Provides Network Access Protection enforcement for EAP authenticated network connections, such as those used with 802.1X and VPN technologies."
"eapqec.dll,-102" = "1.0"
"eapqec.dll,-103" = "Microsoft Corporation"

The process netsh.exe:2548 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"tsgqec.dll,-101" = "Provides RD Gateway enforcement for NAP"
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"
"eapqec.dll,-101" = "Provides Network Access Protection enforcement for EAP authenticated network connections, such as those used with 802.1X and VPN technologies."

[HKLM\System\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo]
"http://localhost:65411/tests/progress/" = "01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00"

The process netsh.exe:3032 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo]
"http://127.0.0.1:65411/media/status/" = "01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"

The process netsh.exe:2632 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo]
"http://127.0.0.1:65411/client/reboot/" = "01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"eapqec.dll,-101" = "Provides Network Access Protection enforcement for EAP authenticated network connections, such as those used with 802.1X and VPN technologies."
"eapqec.dll,-102" = "1.0"
"eapqec.dll,-103" = "Microsoft Corporation"

The process netsh.exe:2096 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"napipsec.dll,-1" = "IPsec Relying Party"
"napipsec.dll,-4" = "1.0"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"tsgqec.dll,-101" = "Provides RD Gateway enforcement for NAP"
"tsgqec.dll,-102" = "1.0"

[HKLM\System\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo]
"http://localhost:65411/media/status/" = "01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"
"eapqec.dll,-101" = "Provides Network Access Protection enforcement for EAP authenticated network connections, such as those used with 802.1X and VPN technologies."

The process netsh.exe:2368 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo]
"http://localhost:65411/client/status/" = "01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"tsgqec.dll,-101" = "Provides RD Gateway enforcement for NAP"
"tsgqec.dll,-103" = "Microsoft Corporation"
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"
"eapqec.dll,-101" = "Provides Network Access Protection enforcement for EAP authenticated network connections, such as those used with 802.1X and VPN technologies."

The process netsh.exe:2352 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"tsgqec.dll,-101" = "Provides RD Gateway enforcement for NAP"

[HKLM\System\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo]
"http://localhost:65411/license/status/" = "01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"
"eapqec.dll,-101" = "Provides Network Access Protection enforcement for EAP authenticated network connections, such as those used with 802.1X and VPN technologies."

The process netsh.exe:2504 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo]
"http://localhost:65411/" = "01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00"

The process netsh.exe:1380 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"napipsec.dll,-2" = "Provides IPsec based enforcement for Network Access Protection"
"napipsec.dll,-1" = "IPsec Relying Party"
"napipsec.dll,-4" = "1.0"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"tsgqec.dll,-100" = "RD Gateway Quarantine Enforcement Client"
"tsgqec.dll,-102" = "1.0"
"tsgqec.dll,-101" = "Provides RD Gateway enforcement for NAP"
"dhcpqec.dll,-100" = "DHCP Quarantine Enforcement Client"
"dhcpqec.dll,-101" = "Provides DHCP based enforcement for NAP"
"dhcpqec.dll,-102" = "Microsoft Corporation"
"dhcpqec.dll,-103" = "1.0"

[HKLM\System\CurrentControlSet\Services\HTTP\Parameters\UrlAclInfo]
"http://localhost:65411/client/reboot/" = "01 00 04 80 00 00 00 00 00 00 00 00 00 00 00 00"

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E\@%SystemRoot%\system32]
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"
"eapqec.dll,-101" = "Provides Network Access Protection enforcement for EAP authenticated network connections, such as those used with 802.1X and VPN technologies."

The process netsh.exe:2372 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Services\Tcpip\Parameters]
"Tcp1323Opts" = "0"

[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2B\52C64B7E\@%SystemRoot%\system32]
"qagentrt.dll,-10" = "System Health Authentication"
"fveui.dll,-843" = "BitLocker Drive Encryption"

[HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\2B\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\0]
"0200" = "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"

[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2B\52C64B7E\@%SystemRoot%\system32]
"fveui.dll,-844" = "BitLocker Data Recovery Agent"

[HKLM\System\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\0]
"1700" = "FF FF FF FF FF 00 FF FF FF FF FF FF FF FF FF FF"

The process DriverSupportAO.exe:3856 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{dCMTSSit-ulLxVTsni1mdQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{fKLE1 HmoD1yU1EE5Xmk0g}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{rZQI4BBSqLCPc69we3-IIA}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{yuv8WGK4myn1O6EmMU7j5g}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{CtFsXDtvfYMU6eRCH6ArYQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]
"explorer.exe" = "4"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{yuv8WGK4myn1O6EmMU7j5g}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{0AsbcZ6HMQ-0FcUxFjv9wg}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{1ogatTn6iFrPUHjVK6266Q}" = ""

[HKLM\System\CurrentControlSet\Control\FileSystem]
"NtfsDisableLastAccessUpdate" = "1"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{hS1Bqw iq0JuxK7EaN3AJw}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{7XwTbSS A4UtcEPBpJFnJQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{1RWAw8I0p7uuJQjxuebQFA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{IuwDsvo4RArrBTI58WhzEA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{X9sSFFVcFfRI2g2G2R1Qrg}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{JUMC3rNCGyJUQ7na-ZjfZw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{XJCocwmCeGdOvUvmc GYww}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{zT-HwT1cAEyjYomkb2o4xQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{QW0skbqrYnwlJxS-hOtwFg}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE]
"APIPort" = "8000"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{d4Uj-SuyKM39YzKWWng8Dw}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{B-dlSm0yaeROuLBBl9xomA}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{nZ15HNx9khRCNbWtBmzeqw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{G2iHHI1C2vShX6uu615Jug}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{zT-HwT1cAEyjYomkb2o4xQ}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{J2jl q47pBR74hljNtQsZQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{IuwDsvo4RArrBTI58WhzEA}" = ""
"{EQudHbu9e7CFgnam7994Bg}" = "0x00000001"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{9E6I5ohWAcg61xdY42Z4lA}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{QVDOqbfDHw3TTosNbbprWA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{Y4lV6r9QLDyWjxEuzf9fOQ}" = "0x00000000"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{4GI4K7GWi4ZbHHntt3bf4g}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{QVDOqbfDHw3TTosNbbprWA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{vT e6cuK46T2i9OhzTP-Yg}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{fKLE1 HmoD1yU1EE5Xmk0g}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{9E6I5ohWAcg61xdY42Z4lA}" = ""

[HKLM\System\CurrentControlSet\services\Disk]
"TimeOutValue" = "60"

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{8oobfQpRkPgWUUxjNihSTw}" = ""
"{dCMTSSit-ulLxVTsni1mdQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{be6wIr-WiheJIg9 eSvrpQ}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{9E6I5ohWAcg61xdY42Z4lA}" = ""
"{4GI4K7GWi4ZbHHntt3bf4g}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{be6wIr-WiheJIg9 eSvrpQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{9RXqGPXM7H7lDfi qeaP1w}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{9RXqGPXM7H7lDfi qeaP1w}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{m8pSPo7VuGE6pJxgxOXENA}" = ""
"{tOJDwTtjbf9F8u4lyIIMNA}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{B-dlSm0yaeROuLBBl9xomA}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{NyYRwEJ9QGFFRrpe Ywi-A}" = "0x00000000"
"{1HSnpeCk3xavZ9FT-8ZU2A}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{6TCsjtv5uir3InUfgi8d4A}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{ENhMHOR1FOHM0IhKkfULeg}" = ""
"{XJCocwmCeGdOvUvmc GYww}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{XJCocwmCeGdOvUvmc GYww}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{qKVwnrQO5eVV5qyo0gcl w}" = "0x00000002"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{YM2l77f7Gj BRgSt73 aMQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{be6wIr-WiheJIg9 eSvrpQ}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{1RWAw8I0p7uuJQjxuebQFA}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{8oobfQpRkPgWUUxjNihSTw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{LBAAwsBmgm79DKi3LdHs-Q}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{EEVSyuRbPs1nN4AflfPHCw}" = "400"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{a0nnKm-HPHNi6siWQxZsjg}" = "0"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{9RXqGPXM7H7lDfi qeaP1w}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{zT-HwT1cAEyjYomkb2o4xQ}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{FVQzpVoqxoAz1xaw1i8KxQ}" = ""

[HKLM\System\CurrentControlSet\Services\Tcpip\Parameters]
"EnableWsd" = "1"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{YM2l77f7Gj BRgSt73 aMQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE]
"WinLogonRecordNumber" = "2894"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{4KJuF0QN5vs1wzphstDrfg}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{LviLN4JiC8tBGIociKPa6g}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{dcKsQhr6UZDf76rF5HCPxw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{Vq71qS74KNJAkWVHIkqcdA}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{a0nnKm-HPHNi6siWQxZsjg}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{BeBxCymtdrrW-5DT5uvEHw}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{a0nnKm-HPHNi6siWQxZsjg}" = "0"

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{IGCoRVVJRepggR 2omclpA}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{Ku0VOaKd0KU6yc 5m4VYBg}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{YM2l77f7Gj BRgSt73 aMQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{YM2l77f7Gj BRgSt73 aMQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{B-dlSm0yaeROuLBBl9xomA}" = "0"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{Vq71qS74KNJAkWVHIkqcdA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{NdO9dgwqqKR5EXDh1qbH9g}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{1RWAw8I0p7uuJQjxuebQFA}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{CtFsXDtvfYMU6eRCH6ArYQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{dYh18bQbd xyCdW0Te7WEw}" = "0x00000004"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{Doo41B8svFmIGbxrORK5tQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{WP960zkT6U9 -JsdbjM0bw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{ndexgajdMUwOnZ6bisyGNg}" = "0x0000003C"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{oG4t9LVhjm0ZnPlvUEEPPA}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{1904fSPWawri7CqONu8-LA}" = "0"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{CtFsXDtvfYMU6eRCH6ArYQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{B-dlSm0yaeROuLBBl9xomA}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{LBAAwsBmgm79DKi3LdHs-Q}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{keSe7N f6BldaLOJSmY8FQ}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{4GI4K7GWi4ZbHHntt3bf4g}" = ""
"{XJCocwmCeGdOvUvmc GYww}" = ""
"{9RXqGPXM7H7lDfi qeaP1w}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{be6wIr-WiheJIg9 eSvrpQ}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{dCMTSSit-ulLxVTsni1mdQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{yuv8WGK4myn1O6EmMU7j5g}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{EEVSyuRbPs1nN4AflfPHCw}" = "400"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{9E6I5ohWAcg61xdY42Z4lA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{0qDikGqmrjDfPi-NDPO81g}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{B-dlSm0yaeROuLBBl9xomA}" = "0"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{HI7M6xwNomkYaXHuyiteuw}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{cblQbL0QQ8KXIm 4lLdqkA}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{LBAAwsBmgm79DKi3LdHs-Q}" = ""
"{LviLN4JiC8tBGIociKPa6g}" = "0"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{4KJuF0QN5vs1wzphstDrfg}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{iouqpMDqGAZnYvRRsEu5rg}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{a0nnKm-HPHNi6siWQxZsjg}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{1RWAw8I0p7uuJQjxuebQFA}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{MEjOJxSFwNFAxKDDBTATLw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{0AsbcZ6HMQ-0FcUxFjv9wg}" = ""
"{ 6SoUolsYuuxDrlRm0Om5Q}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{a0nnKm-HPHNi6siWQxZsjg}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]
"explorer.exe" = "2"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{UCbyW-dAvnHEh8Qb9TMXzg}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{4GI4K7GWi4ZbHHntt3bf4g}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{ENhMHOR1FOHM0IhKkfULeg}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{EQudHbu9e7CFgnam7994Bg}" = "0x00000001"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{freZo-a bd Ycplj7hrr8Q}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{be6wIr-WiheJIg9 eSvrpQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{Doo41B8svFmIGbxrORK5tQ}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{LLJ9anhPl8EaxT0zwcUDUA}" = "0"
"{4KJuF0QN5vs1wzphstDrfg}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{6pHUYa9Bd R7UVLdeo80eA}" = ""
"{KyXdhC9VKTWQYJbukBLkUQ}" = ""
"{cblQbL0QQ8KXIm 4lLdqkA}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{9RXqGPXM7H7lDfi qeaP1w}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{Vuwt-AQzGWboLaUGj6qa w}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{ENhMHOR1FOHM0IhKkfULeg}" = ""
"{QVDOqbfDHw3TTosNbbprWA}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{YM2l77f7Gj BRgSt73 aMQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{MEjOJxSFwNFAxKDDBTATLw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{iQDruAshIipc5n1oc4-zug}" = ""
"{ 4llrkdZ3Tc-FWuQu-T2QA}" = ""

[HKU\S-1-5-19\Control Panel\Desktop]
"MenuShowDelay" = "400"

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{Vq71qS74KNJAkWVHIkqcdA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{JusGnxCLifr9oQX0NlaXjQ}" = "0"

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{rZQI4BBSqLCPc69we3-IIA}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{nZ15HNx9khRCNbWtBmzeqw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{2YxuFy8K60efhinIte KTw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{MbpmFHFOdmkrfodsfN1wbQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{UCbyW-dAvnHEh8Qb9TMXzg}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{be6wIr-WiheJIg9 eSvrpQ}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{9E6I5ohWAcg61xdY42Z4lA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{EmzQs2pKcAPe3PQeEC27nA}" = "0x00000000"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{LLJ9anhPl8EaxT0zwcUDUA}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{j9ItjWeTJhiJcIPoSbjzRQ}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{ERWFjfNEz G0GGkDMBKWvw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{BFvlAodh8F4O QAqeXC5Sw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{nZ15HNx9khRCNbWtBmzeqw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{hS1Bqw iq0JuxK7EaN3AJw}" = "0"

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{J2jl q47pBR74hljNtQsZQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{t4Z6WW5kn1h8uSx7E5bZ5Q}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{6TCsjtv5uir3InUfgi8d4A}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{Ku0VOaKd0KU6yc 5m4VYBg}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{hS1Bqw iq0JuxK7EaN3AJw}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{ERWFjfNEz G0GGkDMBKWvw}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{B-dlSm0yaeROuLBBl9xomA}" = "0"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{MEjOJxSFwNFAxKDDBTATLw}" = ""
"{EEVSyuRbPs1nN4AflfPHCw}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{1ogatTn6iFrPUHjVK6266Q}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{JlnqQo8UzfuUhgwB1hOZ4A}" = "0x00000001"
"{oXvetsUTaodKsYQd8oTEPw}" = "0x00000000"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{Ku0VOaKd0KU6yc 5m4VYBg}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{S5ND192tfzOELWSXdBsEZQ}" = "0x00000001"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{Ku0VOaKd0KU6yc 5m4VYBg}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{IvvRj-VfUg64KffK5NkFzw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{4GI4K7GWi4ZbHHntt3bf4g}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{J2jl q47pBR74hljNtQsZQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{rZQI4BBSqLCPc69we3-IIA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{OuXKK1TdASeH3RtMdGeOvg}" = ""
"{LAEVAU8xjKmfLUMEAj Uaw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{ 4llrkdZ3Tc-FWuQu-T2QA}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{IGCoRVVJRepggR 2omclpA}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{XJCocwmCeGdOvUvmc GYww}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{ENhMHOR1FOHM0IhKkfULeg}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{OuXKK1TdASeH3RtMdGeOvg}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{dCMTSSit-ulLxVTsni1mdQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{CtFsXDtvfYMU6eRCH6ArYQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{ENhMHOR1FOHM0IhKkfULeg}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{LviLN4JiC8tBGIociKPa6g}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{MEjOJxSFwNFAxKDDBTATLw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{tOJDwTtjbf9F8u4lyIIMNA}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{IGCoRVVJRepggR 2omclpA}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{QVDOqbfDHw3TTosNbbprWA}" = ""
"{LLJ9anhPl8EaxT0zwcUDUA}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{-Uc8DxA8xh-lifiLiZL Aw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{iQDruAshIipc5n1oc4-zug}" = ""
"{S5ND192tfzOELWSXdBsEZQ}" = "0x00000001"
"{2YxuFy8K60efhinIte KTw}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{FVQzpVoqxoAz1xaw1i8KxQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{BeBxCymtdrrW-5DT5uvEHw}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{LviLN4JiC8tBGIociKPa6g}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{yuv8WGK4myn1O6EmMU7j5g}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{K1Tq5H4duZuu3lJTzk436A}" = ""
"{Pp2I8E3wOzVRY9dl4b6alg}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{7XwTbSS A4UtcEPBpJFnJQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{X9sSFFVcFfRI2g2G2R1Qrg}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{WP960zkT6U9 -JsdbjM0bw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{eRpQ3suumS6HrVEV-IpBPA}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{LLJ9anhPl8EaxT0zwcUDUA}" = "0"

[HKLM\System\CurrentControlSet\Control\FileSystem]
"NtfsMemoryUsage" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{EmzQs2pKcAPe3PQeEC27nA}" = "0x00000000"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{B-dlSm0yaeROuLBBl9xomA}" = "0"
"{hS1Bqw iq0JuxK7EaN3AJw}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{HI7M6xwNomkYaXHuyiteuw}" = "0"

[HKLM\System\CurrentControlSet\Control\PriorityControl]
"Win32PrioritySeparation" = "2"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{8oobfQpRkPgWUUxjNihSTw}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{Ku0VOaKd0KU6yc 5m4VYBg}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{ldOblZsJpMir2ezpmGe yQ}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{YM2l77f7Gj BRgSt73 aMQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{QW0skbqrYnwlJxS-hOtwFg}" = ""

[HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters]
"EnablePrefetcher" = "3"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{PKzrwN2Umqad1v K Q38Mg}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{EEVSyuRbPs1nN4AflfPHCw}" = "400"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{1904fSPWawri7CqONu8-LA}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{EWRuAw-fU3MoNmi4EaHfTQ}" = "0x00000003"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{a0nnKm-HPHNi6siWQxZsjg}" = "0"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{QW0skbqrYnwlJxS-hOtwFg}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{QW0skbqrYnwlJxS-hOtwFg}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{yuv8WGK4myn1O6EmMU7j5g}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{ JKFODUFTLbTP5Oh64gXLw}" = "0x00000000"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{CtFsXDtvfYMU6eRCH6ArYQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{ 6SoUolsYuuxDrlRm0Om5Q}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{nZ15HNx9khRCNbWtBmzeqw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{YEiiMS89x1K KwYvrfs2zw}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{HI7M6xwNomkYaXHuyiteuw}" = "0"

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{1904fSPWawri7CqONu8-LA}" = "0"
"{nZ15HNx9khRCNbWtBmzeqw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{hS1Bqw iq0JuxK7EaN3AJw}" = "0"

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{4KJuF0QN5vs1wzphstDrfg}" = "0"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{IGCoRVVJRepggR 2omclpA}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{LLJ9anhPl8EaxT0zwcUDUA}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{jxk7dVEVqx7zYOMrGefriA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{keSe7N f6BldaLOJSmY8FQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{d4Uj-SuyKM39YzKWWng8Dw}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{nZ15HNx9khRCNbWtBmzeqw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{9RXqGPXM7H7lDfi qeaP1w}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{7XwTbSS A4UtcEPBpJFnJQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{ERWFjfNEz G0GGkDMBKWvw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{oG4t9LVhjm0ZnPlvUEEPPA}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{QVDOqbfDHw3TTosNbbprWA}" = ""

[HKLM\System\CurrentControlSet\Control\Session Manager\Executive]
"AdditionalDelayedWorkerThreads" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{jxk7dVEVqx7zYOMrGefriA}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{Vq71qS74KNJAkWVHIkqcdA}" = ""
"{rZQI4BBSqLCPc69we3-IIA}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{QVDOqbfDHw3TTosNbbprWA}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{yuv8WGK4myn1O6EmMU7j5g}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{9E6I5ohWAcg61xdY42Z4lA}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{hS1Bqw iq0JuxK7EaN3AJw}" = "0"

[HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters]
"EnableSuperfetch" = "3"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{og-mg8ovnDtF5T9mg0B0XQ}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{Vq71qS74KNJAkWVHIkqcdA}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{zT-HwT1cAEyjYomkb2o4xQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{QW0skbqrYnwlJxS-hOtwFg}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{MbpmFHFOdmkrfodsfN1wbQ}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{Vq71qS74KNJAkWVHIkqcdA}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{rZQI4BBSqLCPc69we3-IIA}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{FVQzpVoqxoAz1xaw1i8KxQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{6pHUYa9Bd R7UVLdeo80eA}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{j9ItjWeTJhiJcIPoSbjzRQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{ERWFjfNEz G0GGkDMBKWvw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{3Gia3k9A-IIo0O4utu2xBw}" = ""

[HKU\S-1-5-20\Control Panel\Desktop]
"MenuShowDelay" = "400"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{XJCocwmCeGdOvUvmc GYww}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{WP960zkT6U9 -JsdbjM0bw}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{CtFsXDtvfYMU6eRCH6ArYQ}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{LviLN4JiC8tBGIociKPa6g}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{EEVSyuRbPs1nN4AflfPHCw}" = "400"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{WP960zkT6U9 -JsdbjM0bw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{YEiiMS89x1K KwYvrfs2zw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{dYq6WqqBNJXKmBcM2FnO-A}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{BeBxCymtdrrW-5DT5uvEHw}" = ""
"{hS1Bqw iq0JuxK7EaN3AJw}" = "0"

[HKCU\Control Panel\Desktop]
"MenuShowDelay" = "400"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{QVDOqbfDHw3TTosNbbprWA}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{QW0skbqrYnwlJxS-hOtwFg}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{rZQI4BBSqLCPc69we3-IIA}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{Ku0VOaKd0KU6yc 5m4VYBg}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{4KJuF0QN5vs1wzphstDrfg}" = "0"

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{LBAAwsBmgm79DKi3LdHs-Q}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{dCMTSSit-ulLxVTsni1mdQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{9RXqGPXM7H7lDfi qeaP1w}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{4KJuF0QN5vs1wzphstDrfg}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{LviLN4JiC8tBGIociKPa6g}" = "0"

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{be6wIr-WiheJIg9 eSvrpQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{nVUbf4QZvYMSzNauE6mWFw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{1ogatTn6iFrPUHjVK6266Q}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{IGCoRVVJRepggR 2omclpA}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{a0nnKm-HPHNi6siWQxZsjg}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{8oobfQpRkPgWUUxjNihSTw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{dcKsQhr6UZDf76rF5HCPxw}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{ERWFjfNEz G0GGkDMBKWvw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{BeBxCymtdrrW-5DT5uvEHw}" = ""

[HKLM\System\CurrentControlSet\Services\Tcpip\Parameters]
"Tcp1323Opts" = "1"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{Vuwt-AQzGWboLaUGj6qa w}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{HI7M6xwNomkYaXHuyiteuw}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{MEjOJxSFwNFAxKDDBTATLw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{Y4lV6r9QLDyWjxEuzf9fOQ}" = "0x00000000"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{CtFsXDtvfYMU6eRCH6ArYQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{J2jl q47pBR74hljNtQsZQ}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{ENhMHOR1FOHM0IhKkfULeg}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{ENhMHOR1FOHM0IhKkfULeg}" = ""
"{QW0skbqrYnwlJxS-hOtwFg}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{1ogatTn6iFrPUHjVK6266Q}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{LviLN4JiC8tBGIociKPa6g}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{1RWAw8I0p7uuJQjxuebQFA}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{YM2l77f7Gj BRgSt73 aMQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{Vq71qS74KNJAkWVHIkqcdA}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{8oobfQpRkPgWUUxjNihSTw}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{BeBxCymtdrrW-5DT5uvEHw}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{4GI4K7GWi4ZbHHntt3bf4g}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{Pp2I8E3wOzVRY9dl4b6alg}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{7XwTbSS A4UtcEPBpJFnJQ}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{QW0skbqrYnwlJxS-hOtwFg}" = ""
"{rZQI4BBSqLCPc69we3-IIA}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{1ogatTn6iFrPUHjVK6266Q}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{7XwTbSS A4UtcEPBpJFnJQ}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{MEjOJxSFwNFAxKDDBTATLw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{t4Z6WW5kn1h8uSx7E5bZ5Q}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{4GI4K7GWi4ZbHHntt3bf4g}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{7XwTbSS A4UtcEPBpJFnJQ}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{j9ItjWeTJhiJcIPoSbjzRQ}" = ""

[HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management]
"DisablePagingExecutive" = "0"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{EEVSyuRbPs1nN4AflfPHCw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{qKVwnrQO5eVV5qyo0gcl w}" = "0x00000002"
"{uxFlPa32q 7MaWJptxqZgg}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{NdO9dgwqqKR5EXDh1qbH9g}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{j9ItjWeTJhiJcIPoSbjzRQ}" = ""
"{9E6I5ohWAcg61xdY42Z4lA}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{1904fSPWawri7CqONu8-LA}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{IGCoRVVJRepggR 2omclpA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{EWRuAw-fU3MoNmi4EaHfTQ}" = "0x00000003"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{j9ItjWeTJhiJcIPoSbjzRQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{dCMTSSit-ulLxVTsni1mdQ}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{ERWFjfNEz G0GGkDMBKWvw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{KyXdhC9VKTWQYJbukBLkUQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{HI7M6xwNomkYaXHuyiteuw}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{3Gia3k9A-IIo0O4utu2xBw}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{FVQzpVoqxoAz1xaw1i8KxQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{zVT2iaBra8Hw0flSiVWrSg}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{CGHf936-0ZAA13qghAlH6A}" = ""
"{K1Tq5H4duZuu3lJTzk436A}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{MEjOJxSFwNFAxKDDBTATLw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{eXx5PvLJDq67QrFrGurXkQ}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{WP960zkT6U9 -JsdbjM0bw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{eXx5PvLJDq67QrFrGurXkQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{dYh18bQbd xyCdW0Te7WEw}" = "0x00000004"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{zVT2iaBra8Hw0flSiVWrSg}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{1904fSPWawri7CqONu8-LA}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{EEVSyuRbPs1nN4AflfPHCw}" = "400"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{JusGnxCLifr9oQX0NlaXjQ}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{1904fSPWawri7CqONu8-LA}" = "0"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{LLJ9anhPl8EaxT0zwcUDUA}" = "0"

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{zT-HwT1cAEyjYomkb2o4xQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{4KJuF0QN5vs1wzphstDrfg}" = "0"
"{4GI4K7GWi4ZbHHntt3bf4g}" = ""
"{WP960zkT6U9 -JsdbjM0bw}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{LBAAwsBmgm79DKi3LdHs-Q}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{1RWAw8I0p7uuJQjxuebQFA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{vT e6cuK46T2i9OhzTP-Yg}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{WP960zkT6U9 -JsdbjM0bw}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{9RXqGPXM7H7lDfi qeaP1w}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{Ku0VOaKd0KU6yc 5m4VYBg}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{J2jl q47pBR74hljNtQsZQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{nVUbf4QZvYMSzNauE6mWFw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{0qDikGqmrjDfPi-NDPO81g}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{og-mg8ovnDtF5T9mg0B0XQ}" = ""
"{PKzrwN2Umqad1v K Q38Mg}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{CGHf936-0ZAA13qghAlH6A}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{Vq71qS74KNJAkWVHIkqcdA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{BFvlAodh8F4O QAqeXC5Sw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{B-dlSm0yaeROuLBBl9xomA}" = "0"

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{LLJ9anhPl8EaxT0zwcUDUA}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{IGCoRVVJRepggR 2omclpA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE]
"WinLogonTime" = "1418386277"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{uxFlPa32q 7MaWJptxqZgg}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{ERWFjfNEz G0GGkDMBKWvw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{be6wIr-WiheJIg9 eSvrpQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{4KJuF0QN5vs1wzphstDrfg}" = "0"
"{BeBxCymtdrrW-5DT5uvEHw}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{J2jl q47pBR74hljNtQsZQ}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{8oobfQpRkPgWUUxjNihSTw}" = ""
"{Ku0VOaKd0KU6yc 5m4VYBg}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{IUAePKPBy1KloIk8HmlE8w}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{HI7M6xwNomkYaXHuyiteuw}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{HI7M6xwNomkYaXHuyiteuw}" = "0"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{LBAAwsBmgm79DKi3LdHs-Q}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{1RWAw8I0p7uuJQjxuebQFA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{f5auSfrcL74wNPk6s3O0lA}" = "0x00000002"

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{J2jl q47pBR74hljNtQsZQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{G2iHHI1C2vShX6uu615Jug}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{BeBxCymtdrrW-5DT5uvEHw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{freZo-a bd Ycplj7hrr8Q}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{LBAAwsBmgm79DKi3LdHs-Q}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{nZ15HNx9khRCNbWtBmzeqw}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{FVQzpVoqxoAz1xaw1i8KxQ}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{zT-HwT1cAEyjYomkb2o4xQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{B4FoY9i-Vp94ql8iFGUCUA}" = ""
"{eRpQ3suumS6HrVEV-IpBPA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup]
"(Default)" = "1"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{1RWAw8I0p7uuJQjxuebQFA}" = ""
"{dCMTSSit-ulLxVTsni1mdQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{LLJ9anhPl8EaxT0zwcUDUA}" = "0"
"{MEjOJxSFwNFAxKDDBTATLw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{iXt77BkLSi4VICYpPBcSnw}" = "0x00000003"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{P--FtBN U5oT6m5Np0XH-Q}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{1ogatTn6iFrPUHjVK6266Q}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{dCMTSSit-ulLxVTsni1mdQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{9E6I5ohWAcg61xdY42Z4lA}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{FVQzpVoqxoAz1xaw1i8KxQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{IGCoRVVJRepggR 2omclpA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{ JKFODUFTLbTP5Oh64gXLw}" = "0x00000000"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{1904fSPWawri7CqONu8-LA}" = "0"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
"{8oobfQpRkPgWUUxjNihSTw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{dYq6WqqBNJXKmBcM2FnO-A}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{1904fSPWawri7CqONu8-LA}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{ndexgajdMUwOnZ6bisyGNg}" = "0x0000003C"
"{JUMC3rNCGyJUQ7na-ZjfZw}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{nZ15HNx9khRCNbWtBmzeqw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{oXvetsUTaodKsYQd8oTEPw}" = "0x00000000"

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{a0nnKm-HPHNi6siWQxZsjg}" = "0"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{j9ItjWeTJhiJcIPoSbjzRQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{LAEVAU8xjKmfLUMEAj Uaw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{m8pSPo7VuGE6pJxgxOXENA}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{FVQzpVoqxoAz1xaw1i8KxQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{iouqpMDqGAZnYvRRsEu5rg}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{j9ItjWeTJhiJcIPoSbjzRQ}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{zT-HwT1cAEyjYomkb2o4xQ}" = ""

[HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management]
"LargeSystemCache" = "0"

[HKLM\System\CurrentControlSet\Control\Session Manager\Executive]
"AdditionalCriticalWorkerThreads" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{P--FtBN U5oT6m5Np0XH-Q}" = ""
"{B4FoY9i-Vp94ql8iFGUCUA}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{XJCocwmCeGdOvUvmc GYww}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{ERWFjfNEz G0GGkDMBKWvw}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{8oobfQpRkPgWUUxjNihSTw}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{1ogatTn6iFrPUHjVK6266Q}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{zT-HwT1cAEyjYomkb2o4xQ}" = ""
"{EEVSyuRbPs1nN4AflfPHCw}" = "400"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{7XwTbSS A4UtcEPBpJFnJQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{BeBxCymtdrrW-5DT5uvEHw}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{IvvRj-VfUg64KffK5NkFzw}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{yuv8WGK4myn1O6EmMU7j5g}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{1ogatTn6iFrPUHjVK6266Q}" = ""

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{ENhMHOR1FOHM0IhKkfULeg}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{LBAAwsBmgm79DKi3LdHs-Q}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{7XwTbSS A4UtcEPBpJFnJQ}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{YM2l77f7Gj BRgSt73 aMQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{jZ23tcad35 X 1iPL5xgIA}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
"{rZQI4BBSqLCPc69we3-IIA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{JlnqQo8UzfuUhgwB1hOZ4A}" = "0x00000001"

[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
"{WP960zkT6U9 -JsdbjM0bw}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{j9ItjWeTJhiJcIPoSbjzRQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{1HSnpeCk3xavZ9FT-8ZU2A}" = ""

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{J2jl q47pBR74hljNtQsZQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{LviLN4JiC8tBGIociKPa6g}" = "0"

[HKCU\Software\Veloxum\iPTE\Backup\0]
"{HI7M6xwNomkYaXHuyiteuw}" = "0"

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{CtFsXDtvfYMU6eRCH6ArYQ}" = ""

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
"{QVDOqbfDHw3TTosNbbprWA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{iXt77BkLSi4VICYpPBcSnw}" = "0x00000003"

[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
"{XJCocwmCeGdOvUvmc GYww}" = ""
"{FVQzpVoqxoAz1xaw1i8KxQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{ldOblZsJpMir2ezpmGe yQ}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{NyYRwEJ9QGFFRrpe Ywi-A}" = "0x00000000"

[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
"{yuv8WGK4myn1O6EmMU7j5g}" = ""

[HKCU\Software\Veloxum\iPTE\Backup\1]
"{hS1Bqw iq0JuxK7EaN3AJw}" = "0"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{IUAePKPBy1KloIk8HmlE8w}" = ""
"{jZ23tcad35 X 1iPL5xgIA}" = ""

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{f5auSfrcL74wNPk6s3O0lA}" = "0x00000002"
"{-Uc8DxA8xh-lifiLiZL Aw}" = ""

The Trojan deletes the following registry key(s):

[HKCU\Software\Veloxum\iPTE\Backup]
[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup]
[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\0]
[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup\1]
[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup]
[HKCU\Software\Veloxum\iPTE\Backup\0]
[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\0]
[HKU\S-1-5-19\Software\Veloxum\iPTE\Backup\1]
[HKU\S-1-5-20\Software\Veloxum\iPTE\Backup]
[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup]
[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\1]
[HKU\.DEFAULT\SOFTWARE\Veloxum\iPTE\Backup\0]
[HKCU\Software\Veloxum\iPTE\Backup\1]

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\LSI_SCSI\Parameters\Device0]
"NumberOfRequests"

[HKLM\System\CurrentControlSet\Control\FileSystem]
"ContigFileAllocSize"

[HKLM\System\CurrentControlSet\services\SiSRaid2\Parameters\Device1]
"NumberOfRequests"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings]
"TcpAutotuning"

[HKLM\System\CurrentControlSet\services\LSI_SAS\Parameters\Device]
"DriverParameter"

[HKLM\System\CurrentControlSet\Services\Tcpip\Parameters]
"TcpMaxDupAcks"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{a4P11DIJiAf4EXudmt6NSQ}"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Settings]
"TCPNoDelay"

[HKLM\System\CurrentControlSet\Services\lanmanworkstation\parameters]
"UtilizeNTCaching"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{a4P11DIJiAf4EXudmt6NSQ}"

[HKLM\System\CurrentControlSet\Services\Tcpip\Parameters]
"TcpMaxDataRetransmissions"

[HKU\.DEFAULT\Control Panel\Desktop]
"MenuShowDelay"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MaxConnectionsPer1_0Server"

[HKLM\System\CurrentControlSet\services\megasas\Parameters\Device1]
"NumberOfRequests"

[HKLM\System\CurrentControlSet\services\megasas\Parameters\Device0]
"NumberOfRequests"

[HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management]
"SystemCacheDirtyPageThreshold"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]
"iexplore.exe"

[HKLM\System\CurrentControlSet\services\ql40xx\Parameters\Device1]
"NumberOfRequests"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MaxConnectionsPerServer"

[HKLM\System\CurrentControlSet\services\ql2300\Parameters\Device0]
"NumberOfRequests"

[HKLM\System\CurrentControlSet\Services\AFD\Parameters]
"DefaultReceiveWindow"

[HKLM\System\CurrentControlSet\services\LSI_FC\Parameters\Device1]
"NumberOfRequests"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]
"iexplore.exe"

[HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MaxConnectionsPerServer"

[HKLM\System\CurrentControlSet\services\ql40xx\Parameters\Device0]
"NumberOfRequests"

[HKLM\System\CurrentControlSet\services\SiSRaid4\Parameters\Device1]
"NumberOfRequests"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{2xpkDefL4k7222N6ED246w}"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{2xpkDefL4k7222N6ED246w}"

[HKLM\System\CurrentControlSet\Services\AFD\Parameters]
"NonBlockingSendSpecialBuffering"

[HKLM\System\CurrentControlSet\services\LSI_SAS\Parameters\Device0]
"NumberOfRequests"

[HKLM\System\CurrentControlSet\services\ql2300\Parameters\Device]
"DriverParameter"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\0]
"{YzOmCm43JltoXAOH-GWDzw}"

[HKLM\System\CurrentControlSet\services\SiSRaid4\Parameters\Device0]
"NumberOfRequests"

[HKLM\System\CurrentControlSet\services\ql2300\Parameters\Device1]
"NumberOfRequests"

[HKLM\System\CurrentControlSet\services\LSI_SAS\Parameters\Device1]
"NumberOfRequests"

[HKLM\System\CurrentControlSet\Services\Tcpip\Parameters]
"TcpWindowSize"

[HKLM\System\CurrentControlSet\Services\AFD\Parameters]
"DefaultSendWindow"

[HKLM\System\CurrentControlSet\Services\lanmanserver\parameters]
"SizReqBuf"

[HKLM\System\CurrentControlSet\Services\Tcpip\Parameters]
"SackOpts"
"DisableTaskOffload"

[HKLM\System\CurrentControlSet\services\LSI_SCSI\Parameters\Device]
"DriverParameter"

[HKLM\SOFTWARE\Microsoft\MSMQ\Parameters]
"TCPNoDelay"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MaxConnectionsPer1_0Server"

[HKLM\System\CurrentControlSet\Services\Tcpip\Parameters]
"TcpMaxConnectRetransmissions"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Settings]
"TcpAckFrequency"

[HKLM\System\CurrentControlSet\services\iScsiPrt\Parameters\Device1]
"NumberOfRequests"

[HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MaxConnectionsPerServer"

[HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MaxConnectionsPer1_0Server"

[HKLM\System\CurrentControlSet\services\iScsiPrt\Parameters\Device0]
"NumberOfRequests"

[HKLM\System\CurrentControlSet\services\LSI_SCSI\Parameters\Device1]
"NumberOfRequests"

[HKLM\System\CurrentControlSet\services\SiSRaid2\Parameters\Device0]
"NumberOfRequests"

[HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management]
"ContigFileAllocSize"

[HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MaxConnectionsPer1_0Server"

[HKLM\System\CurrentControlSet\services\LSI_FC\Parameters\Device0]
"NumberOfRequests"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MaxConnectionsPerServer"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Backup\1]
"{YzOmCm43JltoXAOH-GWDzw}"

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE\Settings]
"TcpDelAckTicks"

The process DriverSupportAO.exe:1200 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE]
"ProductCode" = "{E8C8B9FA-1C5E-4D3E-8936-AC3A17888B3C}"
"proxy" = ""
"Server" = "front.veloxum.com"
"Path" = "%Program Files% (x86)\Veloxum\iPTE\"
"ServerPort" = "5000"
"Version" = "1.0.4.7683"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Veloxum\iPTE]
"Debug"

The process WmiApSrv.exe:3004 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance]
"Performance Refreshed" = "0"

The process WmiApSrv.exe:2412 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance]
"Performance Refreshed" = "0"

The process Agent.CPU.exe:2040 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\2A\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4]
"Blob" = "0F 00 00 00 01 00 00 00 14 00 00 00 5D 82 AD B9"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates]
"2796BAE63F1801E277261BA0D77770028F20EEE4"

Dropped PE files

MD5 File path
800a695a3cfa228f8f0be3a6b9c17bf9 c:\Program Files (x86)\Driver Support\Agent.CPU.exe
8d271bf16b55ee1938a9436597c1d85b c:\Program Files (x86)\Driver Support\Agent.Common.XmlSerializers.dll
f3706e5a58730d14c0c9e609f254afdb c:\Program Files (x86)\Driver Support\Agent.Common.dll
ce40f304aabccf7cb4d69ad03e56e0ff c:\Program Files (x86)\Driver Support\Agent.Communication.XmlSerializers.dll
f297a7c79e40ecd015b566399ba3baba c:\Program Files (x86)\Driver Support\Agent.Communication.dll
8eea496a3b72a958f0bd4dfdf9ed6a04 c:\Program Files (x86)\Driver Support\Agent.ExceptionLogging.XmlSerializers.dll
8ca8174ccdfa5b38eb8ed17956b19813 c:\Program Files (x86)\Driver Support\Agent.ExceptionLogging.dll
346042ec3afb66af1c1b28d81356b5a6 c:\Program Files (x86)\Driver Support\Common.dll
b9a129c8d0f87ce0d60b2eae266d8d03 c:\Program Files (x86)\Driver Support\DriverSupport.Updater.exe
53e6c89f0e004ca19fde4ac10349ea06 c:\Program Files (x86)\Driver Support\DriverSupport.exe
ed868d44841cc9314955b4aa63ed17b1 c:\Program Files (x86)\Driver Support\ExceptionLogging.dll
6d3f048bb44cae29a5b602d99dc7660b c:\Program Files (x86)\Driver Support\ICSharpCode.SharpZipLib.dll
f6f3a73d440745e5d05433765d0cd753 c:\Program Files (x86)\Driver Support\ISUninstall.exe
7cb7ec9528fed0b466b1c5de05865e64 c:\Program Files (x86)\Driver Support\Interop.WUApiLib.dll
6905a2910234e631014f6e7875dd8d53 c:\Program Files (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.ActivationProcessors.dll
04a7046973198bb1b981724ac9e37a10 c:\Program Files (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.Downloaders.dll
012f8291780c495d9456393d67a7732c c:\Program Files (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.dll
88b8737a4110d1e75d9f0afd39cc78aa c:\Program Files (x86)\Driver Support\Microsoft.Practices.EnterpriseLibrary.Common.dll
1dba058a92e65e5fae61c0177bc7746a c:\Program Files (x86)\Driver Support\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.dll
3eb6e2b12a61e8bbb46da2c34458177f c:\Program Files (x86)\Driver Support\Microsoft.Practices.ObjectBuilder.dll
90b2cba1679f60a05101953aa4cc29e5 c:\Program Files (x86)\Driver Support\Microsoft.Win32.TaskScheduler.dll
32d69b4f530afca4e77920664d24b266 c:\Program Files (x86)\Driver Support\RuleEngine.XmlSerializers.dll
e436b1067ada37ef803b143bdd78b576 c:\Program Files (x86)\Driver Support\RuleEngine.dll
058fbd620db0121da5ce1bb9362e2db6 c:\Program Files (x86)\Driver Support\ThemePack.DriverSupport.dll
abc445b1d45bcef314b319a99536a869 c:\Program Files (x86)\Driver Support\Uninstall.exe
4e752c12d4388cd0dce51db8ac696f8c c:\Program Files (x86)\Driver Support\XPBurnComponent.dll
75d978563d11f33c7e516d53900be7c9 c:\Program Files (x86)\Driver Support\cpuidsdk.dll
c74129901569c3b9c77852df113c6472 c:\Program Files (x86)\Veloxum\iPTE\DriverSupportAO.exe
ce7593d45a27cc468aca1c6537302a7f c:\Program Files (x86)\Veloxum\iPTE\DriverSupportAOsvc.exe
145dd6ed4b4a595fa4e27489c2764d6d c:\Program Files (x86)\Veloxum\iPTE\ipterbg.exe
fae54d4dc7ffbb345d40776bd3bc81c9 c:\Program Files (x86)\Veloxum\iPTE\ipteup.exe
39234060ded6364dff115dd28a21fdf7 c:\Program Files (x86)\Veloxum\iPTE\viometer.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name: PC Drivers HeadQuarters LP
Product Name: Driver Support
Product Version: 9.1.4.66
Legal Copyright: PC Drivers HeadQuarters LP
Legal Trademarks:
Original Filename: DriverSupport.exe
Internal Name:
File Version: 9.1.4.66
File Description:
Comments:
Language: English (United States)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 23540 23552 4.49035 92032f5e50e74fe0fe80a33ba4ca92db
.rdata 28672 4558 4608 3.6294 5801d712ecba58aa87d1e7d1aa24f3aa
.data 36864 108536 1024 3.48334 f2470ac8847791744aff280e7e2f5353
.ndata 147456 86016 0 0 d41d8cd98f00b204e9800998ecf8427e
.rsrc 233472 30416 30720 3.47553 acf7e504e9fb2a428b5dbe5cafd328d8

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CECMkFlOTkMQ5KGdSAcojyz8=
hxxp://gdcrl.godaddy.com.akadns.net/repository/gd_intermediate.crt
hxxp://blob.by1prdstr01a.store.core.windows.net/ipte/iPTE.1.0.4.7683.msi
hxxp://www.drivershq.com/driverdetective/dd.html?whitelabel=driversupport&utm_source=ddloc&utm_medium=en&utm_campaign=ddtracking
hxxp://a1363.g.akamai.net/pki/crl/products/microsoftrootcert.crl
hxxp://a1363.g.akamai.net/pki/crl/products/WinPCA.crl
hxxp://a1363.g.akamai.net/pki/crl/products/MicrosoftTimeStampPCA.crl
hxxp://a1383.dscg10.akamai.net/usb2.png
hxxp://a1383.dscg10.akamai.net/video.png
hxxp://a1383.dscg10.akamai.net/monitor.png
hxxp://a1383.dscg10.akamai.net/input.png
hxxp://a1383.dscg10.akamai.net/cd-rom.png
hxxp://a1383.dscg10.akamai.net/hardDrive.png
hxxp://a20.dscg10.akamai.net/pro1000pf_dualport_preview.jpg.rendition.cq5dam.thumbnail.219.146.png
hxxp://a1383.dscg10.akamai.net/scsi.png
hxxp://a90.dscg10.akamai.net/printer.png
hxxp://a34.dscg10.akamai.net/$(KGrHqF,!iMFD)meJw 1BRF!H4Mw !~~60_35.JPG
hxxp://a38.dscg10.akamai.net/input.png
hxxp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults 162.242.141.70
hxxp://apps.driversupport.com/imagefactory.ashx?modelid=0 162.242.141.70
hxxp://pagead.l.doubleclick.net/pagead/conversion.js
hxxp://e5799.g.akamaiedge.net/359eb7b28b26c98a238e6cdedc877947afb6a2ef/satelliteLib-6d2ff207543454d05c23a4bcb6934a30b796a147.js
hxxp://e6640.g.akamaiedge.net/js/176561969.js
hxxp://apps.driversupport.com/content/themes/base/images/win7_compatible.png 162.242.141.70
hxxp://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js 54.192.230.39
hxxp://d1pmrmlzxdx671.cloudfront.net/content/themes/reset.css?v=1.0.0.13 54.192.231.115
hxxp://d1pmrmlzxdx671.cloudfront.net/content/themes/UI/Argon/ScanResults.css?v=1.0.0.13 54.192.231.115
hxxp://d1pmrmlzxdx671.cloudfront.net/content/themes/UI/Argon/images/dsLogoNoCogWithBreak.png?v=1.0.0.13 54.192.231.115
hxxp://d1pmrmlzxdx671.cloudfront.net/content/themes/base/images/ms-certified-partner.png?v=1.0.0.13 54.192.231.115
hxxp://d1pmrmlzxdx671.cloudfront.net/content/themes/UI/Argon/AltHeader.css?v=1.0.0.13 54.192.231.115
hxxp://d1pmrmlzxdx671.cloudfront.net/Scripts/custom.js?v=1.0.0.13 54.192.231.115
hxxp://d1pmrmlzxdx671.cloudfront.net/bundles/TSUIBase?v=1.0.0.13 54.192.231.115
hxxp://d1pmrmlzxdx671.cloudfront.net/bundles/TSUIScanResults?v=1.0.0.13 54.192.231.115
hxxp://e6845.ce.akamaiedge.net/crls/secureca.crl
hxxp://d1pmrmlzxdx671.cloudfront.net/content/themes/UI/Argon/images/bigFixit.png 54.192.231.115
hxxp://d1pmrmlzxdx671.cloudfront.net/content/themes/UI/Argon/images/leftArrow.png 54.192.231.115
hxxp://d1pmrmlzxdx671.cloudfront.net/content/themes/UI/Argon/images/rightArrow.png 54.192.231.115
hxxp://d1pmrmlzxdx671.cloudfront.net/content/themes/UI/Argon/images/upcarrot.png 54.192.231.115
hxxp://d1pmrmlzxdx671.cloudfront.net/content/themes/UI/Argon/images/severityIcon.png 54.192.231.115
hxxp://d1pmrmlzxdx671.cloudfront.net/content/themes/UI/Argon/images/fititButtonSprite.gif 54.192.231.115
hxxp://e8218.ce.akamaiedge.net/MEQwQjBAMD4wPDAJBgUrDgMCGgUABBSxtDkXkBa3l3lQEfFgudSiPNvt7gQUAPkqw0GRtsnCuD5V8sCXEROgByACAwI6dg==
hxxp://g.msn.com.nsatc.net/bat.js
hxxp://stats.l.doubleclick.net/dc.js
hxxp://g.msn.com.nsatc.net/action/0?ti=4002897&Ver=2&mid=d2180211-1d49-87f4-90bc-7a999623f1d5&evt=pageLoad&pi=0&lg=en-US&sw=1683&sh=901&sc=24&tl=DriverSupport - Available Driver Updates&p=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&r=&rn=122091
hxxp://clients.l.google.com/ocsp/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBTy4Gr5hYodjXCbSRkjeqm1Gih+ZAQUSt0GFhu89mi1dvWBtrtiGrpagS8CCCv3k0jGH6Vn
hxxp://g.msn.com.nsatc.net/action-uic/0?ti=4002897&Ver=2&mid=d2180211-1d49-87f4-90bc-7a999623f1d5&evt=pageLoad&pi=0&lg=en-US&sw=1683&sh=901&sc=24&tl=DriverSupport - Available Driver Updates&p=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&r=&rn=26480
hxxp://stats.l.doubleclick.net/__utm.gif?utmwv=5.6.1dc&utms=1&utmn=527317186&utmhn=apps.driversupport.com&utmcs=utf-8&utmsr=1683x901&utmvp=1667x779&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=-&utmdt=DriverSupport - Available Driver Updates&utmhid=146776347&utmr=-&utmp=/postinstall/ScanResultsMedia?cart=https%253a%252f%252fsecure.driversupport.com%252fregistration%252fcart%253faf%253dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&utmht=1418391591398&utmac=UA-2010741-4&utmcc=__utma=164611050.148068296.1418391591.1418391591.1418391591.1;+__utmz=164611050.1418391591.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmu=qB~
hxxp://pagead.l.doubleclick.net/pagead/conversion/996887577/?random=1418391591441&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1
hxxp://e5799.g.akamaiedge.net/359eb7b28b26c98a238e6cdedc877947afb6a2ef/s-code-contents-1ce25cd3cd6d4f446079f5924eec249f6b3d3a78.js
hxxp://apps.driversupport.com/postinstall/LogUIDOMReady 162.242.141.70
hxxp://apps.driversupport.com/imagefactory.ashx?rguid=c5f07e3a-a197-4627-9438-974b57fd6373&catid=4d36e972-e325-11ce-bfc1-08002be10318 162.242.141.70
hxxp://apps.driversupport.com/postinstall/LogUIPageLoaded 162.242.141.70
hxxp://pagead.l.doubleclick.net/pagead/viewthroughconversion/996887577/?random=1418391591445&cv=7&fst=1418391591441&num=2&fmt=1&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1
hxxp://pagead.l.doubleclick.net/pagead/viewthroughconversion/996887577/?random=1793213668&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0
hxxp://www.google.com/ads/conversion/996887577/?random=1793213668&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&cdct=2&convclickts=0&random=3718956492 173.194.113.212
hxxp://www.google.com/ads/user-lists/996887577/?fmt=1&num=2&cv=7&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&random=2059655862 173.194.113.212
hxxp://www.google.com.ua/ads/user-lists/996887577/?fmt=1&num=2&cv=7&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&random=2059655862&ipr=y 173.194.113.207
hxxp://www.google.com.ua/ads/conversion/996887577/?random=1793213668&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&cdct=2&convclickts=0&random=3718956492&ipr=y 173.194.113.207
hxxp://d1pmrmlzxdx671.cloudfront.net/content/themes/base/images/favicon.ico?v=1.0.0.13 54.192.231.115
hxxp://pcdrivers.sc.omtrdc.net/b/ss/pcdprod/1/JS-1.4.1-D4BD/s21961665157399?AQB=1&ndh=1&pf=1&t=12/11/2014 15:39:51 5 -120&D=D=&fid=76BE5A97284AA5DF-17D25A9DFE865738&ce=UTF-8&pageName=apps.driversupport.com/postinstall/ScanResultsMedia&g=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&events=event7&c2=%Content: Category (p2)%&c3=%Content: Section (p3)%&c4=%Content: Sub-Section (p4)%&c6=ScanResults&c8=/postinstall/ScanResultsMedia&v11=%Content: Category (p2)%&v12=%Content: Section (p3)%&v13=%Content: Sub-Section (p4)%&v26=13682300-b037-44d0-9742-3c77ad4178ee&v28=30&v30=media&v33=9.1.4.66&v34=9.1.4.66&v52=ScanResults&v53=ScanResults&s=1683x901&c=24&j=1.6&v=Y&k=Y&bw=1683&bh=779&ct=lan&AQE=1 66.235.138.209
hxxp://a1363.g.akamai.net/j/roundtrip.js
hxxp://www.upsellit.com/custom/drivershq.jsp 67.207.180.40
hxxp://pcdrivers.sc.omtrdc.net/b/ss/pcdprod/1/JS-1.4.1-D4BD/s21961665157399?AQB=1&pccr=true&&ndh=1&pf=1&t=12/11/2014 15:39:51 5 -120&D=D=&fid=76BE5A97284AA5DF-17D25A9DFE865738&ce=UTF-8&pageName=apps.driversupport.com/postinstall/ScanResultsMedia&g=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&events=event7&c2=%Content: Category (p2)%&c3=%Content: Section (p3)%&c4=%Content: Sub-Section (p4)%&c6=ScanResults&c8=/postinstall/ScanResultsMedia&v11=%Content: Category (p2)%&v12=%Content: Section (p3)%&v13=%Content: Sub-Section (p4)%&v26=13682300-b037-44d0-9742-3c77ad4178ee&v28=30&v30=media&v33=9.1.4.66&v34=9.1.4.66&v52=ScanResults&v53=ScanResults&s=1683x901&c=24&j=1.6&v=Y&k=Y&bw=1683&bh=779&ct=lan&AQE=1 66.235.138.209
hxxp://adservers-users-4-181763155.eu-west-1.elb.amazonaws.com/pixel/ID6YJCUG4BA7BHFUIYCHOX/MJDFCCTA3JETLDLZWCFYDD?pv=90388517125.22636&cookie=&keyw=
hxxp://www.upsellit.com/hound/monitor.jsp?qs=222263239272274311291323337332321338325289311328311346277328329&siteID=10238 67.207.180.40
hxxp://a1363.g.akamai.net/pixel/ID6YJCUG4BA7BHFUIYCHOX/MJDFCCTA3JETLDLZWCFYDD/IBURATUZTNHBFDLWQBB66R.js
hxxp://adservers-users-4-181763155.eu-west-1.elb.amazonaws.com/cm/r/out
hxxp://pagead.l.doubleclick.net/pagead/conversion/933633792/?label=NtOJCPjf1hEQgL6YvQM&guid=ON&script=0&ord=3418199282196799
hxxp://pagead.l.doubleclick.net/pagead/conversion/933633792/?label=xn2YCKKm-1UQgL6YvQM&guid=ON&script=0&ord=3418199282196799
hxxp://pagead.l.doubleclick.net/pagead/viewthroughconversion/933633792/?label=NtOJCPjf1hEQgL6YvQM&guid=ON&script=0&ord=3418199282196799&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0&random=2010159716
hxxp://adservers-users-4-181763155.eu-west-1.elb.amazonaws.com/cm/f/out
hxxp://adservers-users-4-181763155.eu-west-1.elb.amazonaws.com/cm/l/out
hxxp://adservers-users-4-181763155.eu-west-1.elb.amazonaws.com/cm/w/out
hxxp://adservers-users-4-181763155.eu-west-1.elb.amazonaws.com/cm/x/out
hxxp://adservers-users-4-181763155.eu-west-1.elb.amazonaws.com/cm/b/out
hxxp://pagead.l.doubleclick.net/pagead/viewthroughconversion/933633792/?label=xn2YCKKm-1UQgL6YvQM&guid=ON&script=0&ord=3418199282196799&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0&random=603867099
hxxp://adservers-users-4-181763155.eu-west-1.elb.amazonaws.com/cm/g/out?google_nid=adroll4
hxxp://ib.anycast.adnxs.com/seg?add=1602123&t=2
hxxp://ib.anycast.adnxs.com/seg?add=1973902&t=2
hxxp://www.google.com/ads/user-lists/933633792/?label=NtOJCPjf1hEQgL6YvQM&script=0&ct_cookie_present=false&random=3244418699 173.194.113.212
hxxp://www.google.com/ads/user-lists/933633792/?label=xn2YCKKm-1UQgL6YvQM&script=0&ct_cookie_present=false&random=1583785290 173.194.113.212
hxxp://ib.anycast.adnxs.com/bounce?/seg?add=1602123&t=2
hxxp://www.google.com.ua/ads/user-lists/933633792/?label=NtOJCPjf1hEQgL6YvQM&script=0&ct_cookie_present=false&random=3244418699&ipr=y 173.194.113.207
hxxp://www.google.com.ua/ads/user-lists/933633792/?label=xn2YCKKm-1UQgL6YvQM&script=0&ct_cookie_present=false&random=1583785290&ipr=y 173.194.113.207
hxxp://ib.anycast.adnxs.com/bounce?/seg?add=1973902&t=2
hxxp://ds-any-world.ngd.ysm.yahoodns.net/pixel?id=2498203&t=2&piggyback=http://ads.yahoo.com/cms/v1?esig=1~bf4e7dc4546a90c08591652d78a230d3f2ef5733&nwid=10001032567&sigv=1
hxxp://pagead.l.doubleclick.net/pixel?google_sc&google_nid=artb&google_hm=5l2siGo7dg2UgG9a_YGMZQ&google_ula=1535926
hxxp://ds-any-world.ngd.ysm.yahoodns.net/cms/v1?esig=1~bf4e7dc4546a90c08591652d78a230d3f2ef5733&nwid=10001032567&sigv=1
hxxp://adservers-users-4-181763155.eu-west-1.elb.amazonaws.com/cm/g/in?google_ula=1535926,0
hxxp://adservers-users-4-181763155.eu-west-1.elb.amazonaws.com/cm/r/in?xid=KBgCC6FUe9PSyWP2DG4.yWXZ
hxxp://idsync-ext.rlcdn.com/377928.gif?partner_uid=e65dac886a3b760d94806f5afd818c65
hxxp://star.c10r.facebook.com/fr/u.php?t=2592000&p=443937282305007&m=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU
hxxp://x.bidswitch.net/sync?dsp_id=44&user_id=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU 23.251.130.39
hxxp://x.bidswitch.net/ul_cb/sync?dsp_id=44&user_id=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU 23.251.130.39
hxxp://idsync-ext.rlcdn.com/377928.gif?partner_uid=e65dac886a3b760d94806f5afd818c65&redirect=1
hxxp://simage2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZqcz0xJmNvZGU9Mjk0NSZ0bD0xMjk2MDA=&piggybackCookie=f095a25f-0045-4490-8164-f197a9fa4acf 198.47.127.15
hxxp://cs9.wac.edgecastcdn.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEApfEU0DWxeRF9Lv1AOMPzs=
hxxp://e8218.ce.akamaiedge.net/MEQwQjBAMD4wPDAJBgUrDgMCGgUABBSxtDkXkBa3l3lQEfFgudSiPNvt7gQUAPkqw0GRtsnCuD5V8sCXEROgByACAwI20A==
hxxp://cs9.wac.edgecastcdn.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTtSK3dy3sA4g6EKqm0CfGsMDTPlgQUUOpzidsp+xCPnuUBINTeeZlIg/cCEAJwu3i4ZpYdN6xM1SVvBys=
hxxp://e8218.ce.akamaiedge.net/MEQwQjBAMD4wPDAJBgUrDgMCGgUABBQ/m36Fj2BE19VBYXRO62zrgIYp0gQUQnlUG2HNVSs+Y9U8SFf1n/tFzkoCAwJ35A==
hxxp://gs1.wac.v2cdn.net/baltimoreroot/MEUwQzBBMD8wPTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom/nYB45SPUEwQU5Z1ZMIJHWMys+ghUNoZ7OrUETfACBAcnqkY=
hxxp://hostedocsp.globalsign.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSfAP5wz6TZE9AhTecbrorIUEieTwQU3Igt2WxNPQBQM/EVuXj7weahJK8CExkAAAlE5E3bN0hKjHcAAQAACUQ=
hxxp://a1363.g.akamai.net/pki/crl/products/MicCodSigPCA_08-31-2010.crl
hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8=
hxxp://googleads.g.doubleclick.net/pagead/viewthroughconversion/933633792/?label=NtOJCPjf1hEQgL6YvQM&guid=ON&script=0&ord=3418199282196799&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0&random=2010159716 173.194.113.217
hxxp://d.adroll.com/cm/w/out 54.217.249.23
hxxp://d.adroll.com/cm/f/out 54.217.249.23
hxxp://a.adroll.com/j/roundtrip.js 87.245.202.48
hxxp://g.symcd.com/MEQwQjBAMD4wPDAJBgUrDgMCGgUABBSxtDkXkBa3l3lQEfFgudSiPNvt7gQUAPkqw0GRtsnCuD5V8sCXEROgByACAwI6dg== 23.43.139.27
hxxp://efd765d1ec5992c99482-0705b69156f5fc427c1a0e8338e226b8.r32.cf1.rackcdn.com/$(KGrHqF,!iMFD)meJw 1BRF!H4Mw !~~60_35.JPG 213.155.152.218
hxxp://d.adroll.com/cm/x/out 54.217.249.23
hxxp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl 87.245.202.48
hxxp://ib.adnxs.com/seg?add=1973902&t=2 37.252.163.115
hxxp://cm.g.doubleclick.net/pixel?google_sc&google_nid=artb&google_hm=5l2siGo7dg2UgG9a_YGMZQ&google_ula=1535926 173.194.113.205
hxxp://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEApfEU0DWxeRF9Lv1AOMPzs= 93.184.220.29
hxxp://clients1.google.com/ocsp/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBTy4Gr5hYodjXCbSRkjeqm1Gih+ZAQUSt0GFhu89mi1dvWBtrtiGrpagS8CCCv3k0jGH6Vn 173.194.113.192
hxxp://idsync.rlcdn.com/377928.gif?partner_uid=e65dac886a3b760d94806f5afd818c65&redirect=1 54.88.49.148
hxxp://ib.adnxs.com/bounce?/seg?add=1602123&t=2 37.252.163.115
hxxp://70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com/scsi.png 213.155.152.224
hxxp://70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com/monitor.png 213.155.152.224
hxxp://gtssl-ocsp.geotrust.com/MEQwQjBAMD4wPDAJBgUrDgMCGgUABBQ/m36Fj2BE19VBYXRO62zrgIYp0gQUQnlUG2HNVSs+Y9U8SFf1n/tFzkoCAwJ35A== 23.43.139.27
hxxp://70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com/input.png 213.155.152.224
hxxp://ocsp.omniroot.com/baltimoreroot/MEUwQzBBMD8wPTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom/nYB45SPUEwQU5Z1ZMIJHWMys+ghUNoZ7OrUETfACBAcnqkY= 93.184.220.20
hxxp://www.googleadservices.com/pagead/conversion/933633792/?label=NtOJCPjf1hEQgL6YvQM&guid=ON&script=0&ord=3418199282196799 173.194.113.205
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= 23.43.139.27
hxxp://d.adroll.com/cm/l/out 54.217.249.23
hxxp://70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com/cd-rom.png 213.155.152.224
hxxp://d.adroll.com/pixel/ID6YJCUG4BA7BHFUIYCHOX/MJDFCCTA3JETLDLZWCFYDD?pv=90388517125.22636&cookie=&keyw= 54.217.249.23
hxxp://www.googleadservices.com/pagead/conversion.js 173.194.113.205
hxxp://crl.geotrust.com/crls/secureca.crl 23.43.133.163
hxxp://cdn.driversupport.com/ipte/iPTE.1.0.4.7683.msi 168.62.0.14
hxxp://ocsp.geotrust.com/MEQwQjBAMD4wPDAJBgUrDgMCGgUABBSxtDkXkBa3l3lQEfFgudSiPNvt7gQUAPkqw0GRtsnCuD5V8sCXEROgByACAwI20A== 23.43.139.27
hxxp://bat.r.msn.com/action-uic/0?ti=4002897&Ver=2&mid=d2180211-1d49-87f4-90bc-7a999623f1d5&evt=pageLoad&pi=0&lg=en-US&sw=1683&sh=901&sc=24&tl=DriverSupport - Available Driver Updates&p=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&r=&rn=26480 1.103.192.18
hxxp://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTtSK3dy3sA4g6EKqm0CfGsMDTPlgQUUOpzidsp+xCPnuUBINTeeZlIg/cCEAJwu3i4ZpYdN6xM1SVvBys= 93.184.220.29
hxxp://d.adroll.com/cm/r/out 54.217.249.23
hxxp://ocsp.msocsp.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSfAP5wz6TZE9AhTecbrorIUEieTwQU3Igt2WxNPQBQM/EVuXj7weahJK8CExkAAAlE5E3bN0hKjHcAAQAACUQ= 108.162.232.203
hxxp://d.adroll.com/cm/b/out 54.217.249.23
hxxp://bat.bing.com/action/0?ti=4002897&Ver=2&mid=d2180211-1d49-87f4-90bc-7a999623f1d5&evt=pageLoad&pi=0&lg=en-US&sw=1683&sh=901&sc=24&tl=DriverSupport - Available Driver Updates&p=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&r=&rn=122091 207.46.194.14
hxxp://a.adroll.com/pixel/ID6YJCUG4BA7BHFUIYCHOX/MJDFCCTA3JETLDLZWCFYDD/IBURATUZTNHBFDLWQBB66R.js 87.245.202.48
hxxp://bat.bing.com/bat.js 207.46.194.14
hxxp://www.facebook.com/fr/u.php?t=2592000&p=443937282305007&m=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU 173.252.100.27
hxxp://assets.adobedtm.com/359eb7b28b26c98a238e6cdedc877947afb6a2ef/s-code-contents-1ce25cd3cd6d4f446079f5924eec249f6b3d3a78.js 23.64.225.120
hxxp://ads.yahoo.com/cms/v1?esig=1~bf4e7dc4546a90c08591652d78a230d3f2ef5733&nwid=10001032567&sigv=1 217.163.21.34
hxxp://1b168f054a2c3427459f-daaeafaf8ae4e7adccb47a82a8360bf0.r36.cf1.rackcdn.com/input.png 213.155.152.195
hxxp://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl 87.245.202.48
hxxp://idsync.rlcdn.com/377928.gif?partner_uid=e65dac886a3b760d94806f5afd818c65 54.88.49.148
hxxp://d.adroll.com/cm/g/out?google_nid=adroll4 54.217.249.23
hxxp://cdn.optimizely.com/js/176561969.js 23.64.228.211
hxxp://ib.adnxs.com/seg?add=1602123&t=2 37.252.163.115
hxxp://d.adroll.com/cm/r/in?xid=KBgCC6FUe9PSyWP2DG4.yWXZ 54.217.249.23
hxxp://certificates.godaddy.com/repository/gd_intermediate.crt 50.63.243.228
hxxp://70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com/video.png 213.155.152.224
hxxp://e49b30b1dab19bb21dcf-bce5d432a4997ec4ca1b037336914d84.r88.cf1.rackcdn.com/printer.png 195.12.225.73
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CECMkFlOTkMQ5KGdSAcojyz8= 23.43.139.27
hxxp://googleads.g.doubleclick.net/pagead/viewthroughconversion/996887577/?random=1793213668&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0 173.194.113.217
hxxp://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl 87.245.202.48
hxxp://downloads.drivershq.com/driverdetective/dd.html?whitelabel=driversupport&utm_source=ddloc&utm_medium=en&utm_campaign=ddtracking 192.237.193.236
hxxp://d.adroll.com/cm/g/in?google_ula=1535926,0 54.217.249.23
hxxp://9478ead64acb3b167847-1e1b59e1b8bb5e93fbebd0cc2fdbf9a2.r18.cf1.rackcdn.com/pro1000pf_dualport_preview.jpg.rendition.cq5dam.thumbnail.219.146.png 213.155.152.226
hxxp://ib.adnxs.com/bounce?/seg?add=1973902&t=2 37.252.163.115
hxxp://70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com/hardDrive.png 213.155.152.224
hxxp://stats.g.doubleclick.net/dc.js 64.233.165.155
hxxp://www.googleadservices.com/pagead/conversion/996887577/?random=1418391591441&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1 173.194.113.205
hxxp://www.googleadservices.com/pagead/conversion/933633792/?label=xn2YCKKm-1UQgL6YvQM&guid=ON&script=0&ord=3418199282196799 173.194.113.205
hxxp://crl.microsoft.com/pki/crl/products/WinPCA.crl 87.245.202.48
hxxp://stats.g.doubleclick.net/__utm.gif?utmwv=5.6.1dc&utms=1&utmn=527317186&utmhn=apps.driversupport.com&utmcs=utf-8&utmsr=1683x901&utmvp=1667x779&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=-&utmdt=DriverSupport - Available Driver Updates&utmhid=146776347&utmr=-&utmp=/postinstall/ScanResultsMedia?cart=https%253a%252f%252fsecure.driversupport.com%252fregistration%252fcart%253faf%253dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&utmht=1418391591398&utmac=UA-2010741-4&utmcc=__utma=164611050.148068296.1418391591.1418391591.1418391591.1;+__utmz=164611050.1418391591.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmu=qB~ 64.233.165.155
hxxp://googleads.g.doubleclick.net/pagead/viewthroughconversion/933633792/?label=xn2YCKKm-1UQgL6YvQM&guid=ON&script=0&ord=3418199282196799&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0&random=603867099 173.194.113.217
hxxp://70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com/usb2.png 213.155.152.224
hxxp://ads.yahoo.com/pixel?id=2498203&t=2&piggyback=http://ads.yahoo.com/cms/v1?esig=1~bf4e7dc4546a90c08591652d78a230d3f2ef5733&nwid=10001032567&sigv=1 217.163.21.34
hxxp://assets.adobedtm.com/359eb7b28b26c98a238e6cdedc877947afb6a2ef/satelliteLib-6d2ff207543454d05c23a4bcb6934a30b796a147.js 23.64.225.120
webservices.drivershq.com 64.49.225.72
ajax.googleapis.com 64.233.165.95
analytics.twitter.com 1.115.192.22
ieonline.microsoft.com 204.79.197.200


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

SURICATA UDPv4 invalid checksum
SURICATA IPv4 invalid checksum
SURICATA STREAM Packet with invalid ack
SURICATA STREAM ESTABLISHED invalid ack

Traffic

GET /ads/user-lists/996887577/?fmt=1&num=2&cv=7&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&random=2059655862&ipr=y HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: VVV.google.com.ua


HTTP/1.1 200 OK
Date: Fri, 12 Dec 2014 13:39:51 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Content-Encoding: gzip
Server: adclick_server
Content-Length: 76
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
............(....I.O.T(...I.UJJL.N/./.K.M.../.*)J. .H,J. Q......R`....
h.?...HTTP/1.1 200 OK..Date: Fri, 12 Dec 2014 13:39:51 GMT..Pragma: no
-cache..Expires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cach
e, no-store, must-revalidate..Content-Type: text/html; charset=UTF-8..
X-Content-Type-Options: nosniff..Content-Encoding: gzip..Server: adcli
ck_server..Content-Length: 76..X-XSS-Protection: 1; mode=block..Altern
ate-Protocol: 80:quic,p=0.002..............(....I.O.T(...I.UJJL.N/./.K
.M.../.*)J. .H,J. Q......R`....h.?...
....



GET /ads/user-lists/933633792/?label=NtOJCPjf1hEQgL6YvQM&script=0&ct_cookie_present=false&random=3244418699&ipr=y HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: VVV.google.com.ua


HTTP/1.1 200 OK
Content-Type: image/gif
Date: Fri, 12 Dec 2014 13:39:53 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate
X-Content-Type-Options: nosniff
Server: adclick_server
Content-Length: 42
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
GIF89a.............!.......,...........D.;HTTP/1.1 200 OK..Content-Typ
e: image/gif..Date: Fri, 12 Dec 2014 13:39:53 GMT..Pragma: no-cache..E
xpires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache, no-sto
re, must-revalidate..X-Content-Type-Options: nosniff..Server: adclick_
server..Content-Length: 42..X-XSS-Protection: 1; mode=block..Alternate
-Protocol: 80:quic,p=0.002..GIF89a.............!.......,...........D.;
..


GET /b/ss/pcdprod/1/JS-1.4.1-D4BD/s21961665157399?AQB=1&ndh=1&pf=1&t=12/11/2014 15:39:51 5 -120&D=D=&fid=76BE5A97284AA5DF-17D25A9DFE865738&ce=UTF-8&pageName=apps.driversupport.com/postinstall/ScanResultsMedia&g=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&events=event7&c2=%Content: Category (p2)%&c3=%Content: Section (p3)%&c4=%Content: Sub-Section (p4)%&c6=ScanResults&c8=/postinstall/ScanResultsMedia&v11=%Content: Category (p2)%&v12=%Content: Section (p3)%&v13=%Content: Sub-Section (p4)%&v26=13682300-b037-44d0-9742-3c77ad4178ee&v28=30&v30=media&v33=9.1.4.66&v34=9.1.4.66&v52=ScanResults&v53=ScanResults&s=1683x901&c=24&j=1.6&v=Y&k=Y&bw=1683&bh=779&ct=lan&AQE=1 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: pcdrivers.sc.omtrdc.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 302 Found
Date: Fri, 12 Dec 2014 13:39:52 GMT
Server: Omniture DC/2.0.0
Access-Control-Allow-Origin: *
Set-Cookie: s_vi_wdcwuhc=[CS]v4|0-0|548AF028[CE]; Expires=Sun, 11 Dec 2016 13:39:52 GMT; Domain=.omtrdc.net; Path=/
Location: hXXp://pcdrivers.sc.omtrdc.net/b/ss/pcdprod/1/JS-1.4.1-D4BD/s21961665157399?AQB=1&pccr=true&&ndh=1&pf=1&t=12/11/2014 15:39:51 5 -120&D=D=&fid=76BE5A97284AA5DF-17D25A9DFE865738&ce=UTF-8&pageName=apps.driversupport.com/postinstall/ScanResultsMedia&g=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&events=event7&c2=%Content: Category (p2)%&c3=%Content: Section (p3)%&c4=%Content: Sub-Section (p4)%&c6=ScanResults&c8=/postinstall/ScanResultsMedia&v11=%Content: Category (p2)%&v12=%Content: Section (p3)%&v13=%Content: Sub-Section (p4)%&v26=13682300-b037-44d0-9742-3c77ad4178ee&v28=30&v30=media&v33=9.1.4.66&v34=9.1.4.66&v52=ScanResults&v53=ScanResults&s=1683x901&c=24&j=1.6&v=Y&k=Y&bw=1683&bh=779&ct=lan&AQE=1
X-C: ms-4.9.2
Expires: Thu, 11 Dec 2014 13:39:52 GMT
Last-Modified: Sat, 13 Dec 2014 13:39:52 GMT
Cache-Control: no-cache, no-store, max-age=0, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www2404
Content-Length: 0
Keep-Alive: timeout=15
Connection: Keep-Alive
Content-Type: text/plain
....

<<< skipped >>>

GET /b/ss/pcdprod/1/JS-1.4.1-D4BD/s21961665157399?AQB=1&pccr=true&&ndh=1&pf=1&t=12/11/2014 15:39:51 5 -120&D=D=&fid=76BE5A97284AA5DF-17D25A9DFE865738&ce=UTF-8&pageName=apps.driversupport.com/postinstall/ScanResultsMedia&g=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&events=event7&c2=%Content: Category (p2)%&c3=%Content: Section (p3)%&c4=%Content: Sub-Section (p4)%&c6=ScanResults&c8=/postinstall/ScanResultsMedia&v11=%Content: Category (p2)%&v12=%Content: Section (p3)%&v13=%Content: Sub-Section (p4)%&v26=13682300-b037-44d0-9742-3c77ad4178ee&v28=30&v30=media&v33=9.1.4.66&v34=9.1.4.66&v52=ScanResults&v53=ScanResults&s=1683x901&c=24&j=1.6&v=Y&k=Y&bw=1683&bh=779&ct=lan&AQE=1 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: pcdrivers.sc.omtrdc.net
DNT: 1
Connection: Keep-Alive

HTTP/1.1 200 OK
Date: Fri, 12 Dec 2014 13:39:52 GMT
Server: Omniture DC/2.0.0
Access-Control-Allow-Origin: *
Set-Cookie: s_vi_wdcwuhc=[CS]v4|2A45781405192AF1-4000060A60001698|548AF028[CE]; Expires=Sun, 11 Dec 2016 13:39:52 GMT; Domain=.omtrdc.net; Path=/
X-C: ms-4.9.2
Expires: Thu, 11 Dec 2014 13:39:52 GMT
Last-Modified: Sat, 13 Dec 2014 13:39:52 GMT
Cache-Control: no-cache, no-store, max-age=0, no-transform, private
Pragma: no-cache
ETag: "548AF028-55C4-179530F7"
Vary: *
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www2483
Content-Length: 43
Keep-Alive: timeout=15
Connection: Keep-Alive
Content-Type: image/gif
GIF89a.............!.......,............Q.;HTTP/1.1 200 OK..Date: Fri,
12 Dec 2014 13:39:52 GMT..Server: Omniture DC/2.0.0..Access-Control-A
llow-Origin: *..Set-Cookie: s_vi_wdcwuhc=[CS]v4|2A45781405192AF1-40000
60A60001698|548AF028[CE]; Expires=Sun, 11 Dec 2016 13:39:52 GMT; Domai
n=.omtrdc.net; Path=/..X-C: ms-4.9.2..Expires: Thu, 11 Dec 2014 13:39:
52 GMT..Last-Modified: Sat, 13 Dec 2014 13:39:52 GMT..Cache-Control: n
o-cache, no-store, max-age=0, no-transform, private..Pragma: no-cache.
.ETag: "548AF028-55C4-179530F7"..Vary: *..P3P: policyref="/w3c/p3p.xml
", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"..xserver: www2483..Con
tent-Length: 43..Keep-Alive: timeout=15..Connection: Keep-Alive..Conte
nt-Type: image/gif..GIF89a.............!.......,............Q.;..


GET /bounce?/seg?add=1973902&t=2 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: ib.adnxs.com
DNT: 1
Connection: Keep-Alive
Cookie: uuid2=5354660186873097728; sess=1


HTTP/1.1 302 Found
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="hXXp://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
X-XSS-Protection: 0
Set-Cookie: uuid2=5354660186873097728; path=/; expires=Thu, 12-Mar-2015 13:39:53 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: sess=1; path=/; expires=Sat, 13-Dec-2014 13:39:53 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: anj=dTM7k!M4/8DYRWSDgEREg(U`btg4V6%phwSNS v_o5U_uNW34jQJkEwLwRio!@ADa'qfSm; path=/; expires=Thu, 12-Mar-2015 13:39:53 GMT; domain=.adnxs.com; HttpOnly
Location: hXXps://VVV.facebook.com/fr/u.php?p=391363987594223&m=5354660186873097728
Content-Type: text/html; charset=utf-8
Date: Fri, 12 Dec 2014 13:39:53 GMT
Content-Length: 0
HTTP/1.1 302 Found..Cache-Control: no-store, no-cache, private..Pragma
: no-cache..Expires: Sat, 15 Nov 2008 16:00:00 GMT..P3P: policyref="ht
tp://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo
OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"..X-XSS-Protection: 0..Set
-Cookie: uuid2=5354660186873097728; path=/; expires=Thu, 12-Mar-2015 1
3:39:53 GMT; domain=.adnxs.com; HttpOnly..Set-Cookie: sess=1; path=/;
expires=Sat, 13-Dec-2014 13:39:53 GMT; domain=.adnxs.com; HttpOnly..Se
t-Cookie: anj=dTM7k!M4/8DYRWSDgEREg(U`btg4V6%phwSNS v_o5U_uNW34jQJkEwL
wRio!@ADa'qfSm; path=/; expires=Thu, 12-Mar-2015 13:39:53 GMT; domain=
.adnxs.com; HttpOnly..Location: hXXps://VVV.facebook.com/fr/u.php?p=39
1363987594223&m=5354660186873097728..Content-Type: text/html; charset=
utf-8..Date: Fri, 12 Dec 2014 13:39:53 GMT..Content-Length: 0..

<<< skipped >>>

GET /pagead/conversion/933633792/?label=xn2YCKKm-1UQgL6YvQM&guid=ON&script=0&ord=3418199282196799 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: VVV.googleadservices.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 302 Found
P3P: policyref="hXXp://VVV.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA IVD OTP OUR OTR IND OTC"
Date: Fri, 12 Dec 2014 13:39:52 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Location: hXXp://googleads.g.doubleclick.net/pagead/viewthroughconversion/933633792/?label=xn2YCKKm-1UQgL6YvQM&guid=ON&script=0&ord=3418199282196799&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0&random=603867099
Content-Type: image/gif
X-Content-Type-Options: nosniff
Server: cafe
Content-Length: 42
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
GIF89a.............!.......,...........D.;HTTP/1.1 302 Found..P3P: pol
icyref="hXXp://VVV.googleadservices.com/pagead/p3p.xml", CP="NOI DEV P
SA PSD IVA IVD OTP OUR OTR IND OTC"..Date: Fri, 12 Dec 2014 13:39:52 G
MT..Pragma: no-cache..Expires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Co
ntrol: no-cache, must-revalidate..Location: hXXp://googleads.g.doublec
lick.net/pagead/viewthroughconversion/933633792/?label=xn2YCKKm-1UQgL6
YvQM&guid=ON&script=0&ord=3418199282196799&ctc_id=CAIVAgAAAB0CAAAA&ct_
cookie_present=false&convclickts=0&random=603867099..Content-Type: ima
ge/gif..X-Content-Type-Options: nosniff..Server: cafe..Content-Length:
42..X-XSS-Protection: 1; mode=block..Alternate-Protocol: 80:quic,p=0.
002..GIF89a.............!.......,...........D.;..


GET /pro1000pf_dualport_preview.jpg.rendition.cq5dam.thumbnail.219.146.png HTTP/1.1
Host: 9478ead64acb3b167847-1e1b59e1b8bb5e93fbebd0cc2fdbf9a2.r18.cf1.rackcdn.com
Connection: Close


HTTP/1.1 200 OK
Last-Modified: Fri, 11 Apr 2014 19:48:23 GMT
ETag: 1115d22970934168c37ec2b5829c86b2
X-Trans-Id: tx3278a6275b534567923b7-005463449adfw1
Content-Length: 19586
Content-Disposition: attachment; filename=pro1000pf_dualport_preview.jpg.rendition.cq5dam.thumbnail.219.146.png
Accept-Ranges: bytes
X-Timestamp: 1397245702.32015
Content-Type: image/png
Cache-Control: public, max-age=247525
Expires: Mon, 15 Dec 2014 10:25:10 GMT
Date: Fri, 12 Dec 2014 13:39:45 GMT
Connection: close
.PNG........IHDR...................LIIDATx....t[g.-..........3.....;ff
.. .23.2.....8..ff..9q.an.R.6M..I..}^Y......i..u".H.........A0...Y.=..
.&..6....&.`..`.L0.l..&.M0....&.`....L0.l..&.M0....&.`....L..`..&.M0..
..&..6...L..`..`.L0....&..6....&.`..`.L0.l..&..6....&.`....L0.l..&.M0.
...&.`....L..`.....[OO.;...O........m...k.S?..w.......5..6.\..........
.......?..K.p..m.....\...?..u3pusl.o....v...=...?.==...l..}..~7{aW7.=.
/.}|?...)......<~.._}..>..c.<y..7o..5k.z.j.......{.}....&.O.f
.h..~....'..W.]...W.a.^]<.3Z...`..\..u`S....o8....d.....e.0}.t..?..
V.....[q..y.....l.f...c5.......I....c...<.b.....`l...=...9.~o..W%#.
.......r..<x.okii.....t.Rl....m..9X.b...J..@.)...,....>.M.yw'.$.
......=.<...%..K.........x.N&?.}...._.H:......m..;|.0..=........]..
..c..yX.h.v...........S\._I.7..y'.z.........)....S9...}. [email protected]{..gM
..........d......^$.k....lo.C...{.4..{.......{.n.....'9I~....9...1....
.s...|k`E.....}..bWg;..^2.1f#X..dl...l...1.......0y.L....9..fb.h;.a...
".Sq..E<c|'.....o.{.U1.2.A2.d".m....`t{..!.9r..6l..F,[email protected]&f..._..g
.q....D..O.:.........\/....../q..I,..........s..h:.CUd.5'C.......jnF..
.C......=....g?.nr.l....2.O...s'..=.7.<...8q..I...W#...G.F...^.x...
.ft...>.[.......!..s.c..._.=..<.B.../...g7....T..ATa,.....[b4c.1
"..:..[=.v..j/..:.A...CD.0..av.b.._p.| .~c.._..:::.N.../_....8mmm\F...
.F,F..2e../^..H@..(..&...r....7aL.u.:{..........c..u..=.....<..x...
I................vu..7LCLy.\..`.`.1.z..6.{s....H;C..3..'c.s2....tD&..t
<...f.qB.,$.p........$......)......X.`..L......._~..F #p).%....

<<< skipped >>>

GET /pixel?id=2498203&t=2&piggyback=http://ads.yahoo.com/cms/v1?esig=1~bf4e7dc4546a90c08591652d78a230d3f2ef5733&nwid=10001032567&sigv=1 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Cookie: B=52qa5ah9dvsod&b=3&s=ur; RMBX=52qa5ah9dvsod&b=3&s=ur&t=33; ih="b!!!!#!C'Wg!!!!#>[b?c"
DNT: 1
Connection: Keep-Alive
Host: ads.yahoo.com


HTTP/1.1 302 Found
Date: Fri, 12 Dec 2014 13:39:53 GMT
Server: ATS
X-RightMedia-Hostname: raptor0707.rm.ch1.yahoo.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Location: hXXp://ads.yahoo.com/cms/v1?esig=1~bf4e7dc4546a90c08591652d78a230d3f2ef5733&nwid=10001032567&sigv=1
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
Vary: *
Last-Modified: Fri, 12 Dec 2014 13:39:53 GMT
Expires: Fri, 12 Dec 2014 13:39:53 GMT
Pragma: no-cache
Content-Length: 0
Content-Encoding: gzip
Age: 0
Connection: keep-alive
....



GET /cms/v1?esig=1~bf4e7dc4546a90c08591652d78a230d3f2ef5733&nwid=10001032567&sigv=1 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Cookie: B=52qa5ah9dvsod&b=3&s=ur; RMBX=52qa5ah9dvsod&b=3&s=ur&t=33; ih="b!!!!#!C'Wg!!!!#>[b?c"
DNT: 1
Connection: Keep-Alive
Host: ads.yahoo.com


HTTP/1.1 302 Found
Date: Fri, 12 Dec 2014 13:39:53 GMT
P3P: policyref="hXXp://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Set-Cookie: RMBX=52qa5ah9dvsod&b=3&s=ur&t=33; path=/; expires=Sun, 11-Dec-2016 13:39:53 GMT
Set-Cookie: RMBX=52qa5ah9dvsod&b=3&s=ur&t=33; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT; domain=.yahoo.com
Location: hXXp://d.adroll.com/cm/r/in?xid=KBgCC6FUe9PSyWP2DG4.yWXZ
Cache-Control: private
Content-Length: 0
Content-Type: text/plain; charset=utf-8
Age: 0
Connection: keep-alive
Server: ATS
HTTP/1.1 302 Found..Date: Fri, 12 Dec 2014 13:39:53 GMT..P3P: policyre
f="hXXp://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI
PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY
ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"..Set-Coo
kie: RMBX=52qa5ah9dvsod&b=3&s=ur&t=33; path=/; expires=Sun, 11-Dec-201
6 13:39:53 GMT..Set-Cookie: RMBX=52qa5ah9dvsod&b=3&s=ur&t=33; path=/;
expires=Mon, 01-Mar-2004 00:00:00 GMT; domain=.yahoo.com..Location: ht
tp://d.adroll.com/cm/r/in?xid=KBgCC6FUe9PSyWP2DG4.yWXZ..Cache-Control:
private..Content-Length: 0..Content-Type: text/plain; charset=utf-8..
Age: 0..Connection: keep-alive..Server: ATS..


GET /ads/conversion/996887577/?random=1793213668&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&cdct=2&convclickts=0&random=3718956492&ipr=y HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: VVV.google.com.ua


HTTP/1.1 200 OK
Content-Type: image/gif
Date: Fri, 12 Dec 2014 13:39:51 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate
X-Content-Type-Options: nosniff
Server: adclick_server
Content-Length: 42
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
GIF89a.............!.......,...........D.;HTTP/1.1 200 OK..Content-Typ
e: image/gif..Date: Fri, 12 Dec 2014 13:39:51 GMT..Pragma: no-cache..E
xpires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache, no-sto
re, must-revalidate..X-Content-Type-Options: nosniff..Server: adclick_
server..Content-Length: 42..X-XSS-Protection: 1; mode=block..Alternate
-Protocol: 80:quic,p=0.002..GIF89a.............!.......,...........D.;
....



GET /ads/user-lists/933633792/?label=xn2YCKKm-1UQgL6YvQM&script=0&ct_cookie_present=false&random=1583785290&ipr=y HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: VVV.google.com.ua


HTTP/1.1 200 OK
Content-Type: image/gif
Date: Fri, 12 Dec 2014 13:39:53 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate
X-Content-Type-Options: nosniff
Server: adclick_server
Content-Length: 42
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
GIF89a.............!.......,...........D.;HTTP/1.1 200 OK..Content-Typ
e: image/gif..Date: Fri, 12 Dec 2014 13:39:53 GMT..Pragma: no-cache..E
xpires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache, no-sto
re, must-revalidate..X-Content-Type-Options: nosniff..Server: adclick_
server..Content-Length: 42..X-XSS-Protection: 1; mode=block..Alternate
-Protocol: 80:quic,p=0.002..GIF89a.............!.......,...........D.;
..


GET /seg?add=1973902&t=2 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: ib.adnxs.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 302 Found
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="hXXp://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
X-XSS-Protection: 0
Set-Cookie: uuid2=0; path=/; expires=Thu, 12-Mar-2015 13:39:52 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: sess=1; path=/; expires=Sat, 13-Dec-2014 13:39:52 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=5354660186873097728; path=/; expires=Thu, 12-Mar-2015 13:39:52 GMT; domain=.adnxs.com; HttpOnly
Location: hXXp://ib.adnxs.com/bounce?/seg?add=1973902&t=2
Content-Type: text/html; charset=utf-8
Date: Fri, 12 Dec 2014 13:39:52 GMT
Content-Length: 0
....



GET /bounce?/seg?add=1602123&t=2 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: ib.adnxs.com
DNT: 1
Connection: Keep-Alive
Cookie: uuid2=1752085521283445628; sess=1


HTTP/1.1 302 Found
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="hXXp://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
X-XSS-Protection: 0
Set-Cookie: uuid2=1752085521283445628; path=/; expires=Thu, 12-Mar-2015 13:39:53 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: sess=1; path=/; expires=Sat, 13-Dec-2014 13:39:53 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: anj=dTM7k!M4/8DYRWSDgEREg(U`btg4V6%phwSNS v_o5U_uNW34jQJkEwLwRio!@ADa'qfSm; path=/; expires=Thu, 12-Mar-2015 13:39:53 GMT; domain=.adnxs.com; HttpOnly
Location: hXXps://VVV.facebook.com/fr/u.php?p=391363987594223&m=1752085521283445628
Content-Type: text/html; charset=utf-8
Date: Fri, 12 Dec 2014 13:39:53 GMT
Content-Length: 0
HTTP/1.1 302 Found..Cache-Control: no-store, no-cache, private..Pragma
: no-cache..Expires: Sat, 15 Nov 2008 16:00:00 GMT..P3P: policyref="ht
tp://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo
OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"..X-XSS-Protection: 0..Set
-Cookie: uuid2=1752085521283445628; path=/; expires=Thu, 12-Mar-2015 1
3:39:53 GMT; domain=.adnxs.com; HttpOnly..Set-Cookie: sess=1; path=/;
expires=Sat, 13-Dec-2014 13:39:53 GMT; domain=.adnxs.com; HttpOnly..Se
t-Cookie: anj=dTM7k!M4/8DYRWSDgEREg(U`btg4V6%phwSNS v_o5U_uNW34jQJkEwL
wRio!@ADa'qfSm; path=/; expires=Thu, 12-Mar-2015 13:39:53 GMT; domain=
.adnxs.com; HttpOnly..Location: hXXps://VVV.facebook.com/fr/u.php?p=39
1363987594223&m=1752085521283445628..Content-Type: text/html; charset=
utf-8..Date: Fri, 12 Dec 2014 13:39:53 GMT..Content-Length: 0..

<<< skipped >>>

GET /pixel/ID6YJCUG4BA7BHFUIYCHOX/MJDFCCTA3JETLDLZWCFYDD?pv=90388517125.22636&cookie=&keyw= HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d.adroll.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 302 Moved Temporarily
Cache-Control: no-store, no-cache, must-revalidate
Date: Fri, 12 Dec 2014 13:39:52 GMT
Location: hXXp://a.adroll.com/pixel/ID6YJCUG4BA7BHFUIYCHOX/MJDFCCTA3JETLDLZWCFYDD/IBURATUZTNHBFDLWQBB66R.js
P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Pragma: no-cache
Server: nginx/1.6.2
Set-Cookie: __adroll=e65dac886a3b760d94806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:51 GMT; Max-Age=157680000; Path=/
X-Conversion-Currency: 
X-Conversion-Value: 0
Content-Length: 0
Connection: keep-alive
HTTP/1.1 302 Moved Temporarily..Cache-Control: no-store, no-cache, mus
t-revalidate..Date: Fri, 12 Dec 2014 13:39:52 GMT..Location: hXXp://a.
adroll.com/pixel/ID6YJCUG4BA7BHFUIYCHOX/MJDFCCTA3JETLDLZWCFYDD/IBURATU
ZTNHBFDLWQBB66R.js..P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
..Pragma: no-cache..Server: nginx/1.6.2..Set-Cookie: __adroll=e65dac88
6a3b760d94806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:51
GMT; Max-Age=157680000; Path=/..X-Conversion-Currency: ..X-Conversion
-Value: 0..Content-Length: 0..Connection: keep-alive..
....



GET /cm/r/out HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d.adroll.com
DNT: 1
Connection: Keep-Alive
Cookie: __adroll=e65dac886a3b760d94806f5afd818c65


HTTP/1.1 302 Moved Temporarily
Cache-Control: no-store, no-cache, must-revalidate
Date: Fri, 12 Dec 2014 13:39:52 GMT
Location: hXXp://ads.yahoo.com/pixel?id=2498203&t=2&piggyback=http://ads.yahoo.com/cms/v1?esig=1~bf4e7dc4546a90c08591652d78a230d3f2ef5733&nwid=10001032567&sigv=1
P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Pragma: no-cache
Server: nginx/1.6.2
Set-Cookie: __adroll=e65dac886a3b760d94806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max-Age=157680000; Path=/
Content-Length: 179
Connection: keep-alive
Go to hXXp://ads.yahoo.com/pixel?id=2498203&t=2&piggyback=http:/%2
Fads.yahoo.com/cms/v1?esig=1~bf4e7dc4546a90c08591652d78a230d3f
2ef5733&nwid=10001032567&sigv=1
....



GET /cm/g/out?google_nid=adroll4 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d.adroll.com
DNT: 1
Connection: Keep-Alive
Cookie: __adroll=e65dac886a3b760d94806f5afd818c65


HTTP/1.1 302 Moved Temporarily
Cache-Control: no-store, no-cache, must-revalidate
Date: Fri, 12 Dec 2014 13:39:52 GMT
Location: hXXp://cm.g.doubleclick.net/pixel?google_sc&google_nid=artb&google_hm=5l2siGo7dg2UgG9a_YGMZQ&google_ula=1535926
P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Pragma: no-cache
Server: nginx/1.6.2
Set-Cookie: __adroll=e65dac886a3b760d94806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max-Age=157680000; Path=/
Content-Length: 117
Connection: keep-alive
Go to hXXp://cm.g.doubleclick.net/pixel?google_sc&google_nid=artb&goog
le_hm=5l2siGo7dg2UgG9a_YGMZQ&google_ula=1535926HTTP/1.1 302 Moved Temp
orarily..Cache-Control: no-store, no-cache, must-revalidate..Date: Fri
, 12 Dec 2014 13:39:52 GMT..Location: hXXp://cm.g.doubleclick.net/pixe
l?google_sc&google_nid=artb&google_hm=5l2siGo7dg2UgG9a_YGMZQ&google_ul
a=1535926..P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"..Pragma:
no-cache..Server: nginx/1.6.2..Set-Cookie: __adroll=e65dac886a3b760d9
4806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max
-Age=157680000; Path=/..Content-Length: 117..Connection: keep-alive..G
o to hXXp://cm.g.doubleclick.net/pixel?google_sc&google_nid=artb&googl
e_hm=5l2siGo7dg2UgG9a_YGMZQ&google_ula=1535926..


GET /MEQwQjBAMD4wPDAJBgUrDgMCGgUABBSxtDkXkBa3l3lQEfFgudSiPNvt7gQUAPkqw0GRtsnCuD5V8sCXEROgByACAwI6dg== HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: g.symcd.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1363
content-transfer-encoding: binary
Cache-Control: max-age=411451, public, no-transform, must-revalidate
Last-Modified: Wed, 10 Dec 2014 07:53:01 GMT
Expires: Wed, 17 Dec 2014 07:53:01 GMT
Date: Fri, 12 Dec 2014 13:39:50 GMT
Connection: keep-alive
0..O......H0..D.. .....0.....50..10......7).nj./P(.3.\\.;.B....2014121
0075301Z0f0d0<0... ..........9.....yP..`...<.......*.A.....>U
....... ...:v....20141210075301Z....20141217075301Z0...*.H............
.Q......ci.......2.a..).D.xa..K./.r ..1.v)xV.q.../......... .2.......
z.>).....C...V..2y...UL0...r..>.,..i,..H.d*.^..q..c|@..~I..W{2$.
[email protected]:........Z3...Q.VxD%YQ.o..$......0..0..A8...#{.g..
...e.:....... .....wK],..lm{|\.........m....I............0...0..}0..e.
.......:}0...*.H........0B1.0...U....US1.0...U....GeoTrust Inc.1.0...U
....GeoTrust Global CA0...141201130534Z..151216130534Z02100...U...'Geo
Trust Global CA TGV OCSP Responder 30.."0...*.H.............0.........
...\.hpc..J.a.j-.t......F`Aw...)L.YE.2..~..-...2.Y(.".CZ.w..T..Y. syd.
....x..YE..<....lwv.:J.76>U....uF.a.|8N.. ..1p...`f.X...B>x..
............6..m.&...'..W.plK....[.m.V..h..lI.........?~.....>.|'..
..o...A!.Pm.*.N ...<.....3...*|.x._..1..m.W<*....._S............
.0..0...U.#..0....z.h.....d..}.}e...N0... .....0......0...U.%..0... ..
.....0...U...........0...U.......0.0!..U....0...0.1.0...U....TGV-B-283
0...*.H.............~....2!...V..0...Y....L..k....z}~a.3Y.x..dS.L...Dk
$a...nR9_......B......m....Y....U.5....'.....<{....v&=.2].....j*.r(
7...=..w.I...z....\.#.J.ac.....I.[.[....6.X....0...g.3d...z.i.H..f...v
.....\.....^.N..1.J<.)`Z.....4.-.E..n.E.~t....v.e.T...?. ......i..%
....

<<< skipped >>>

GET /usb2.png HTTP/1.1
Host: 70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com
Connection: Close


HTTP/1.1 200 OK
Last-Modified: Fri, 24 Oct 2014 17:06:44 GMT
ETag: bea72b85914ad8b9df71c60690406a55
X-Trans-Id: tx62245962a4b44141bd5bb-005466783ford1
Content-Length: 9403
Accept-Ranges: bytes
X-Timestamp: 1414170403.53559
Content-Type: image/png
Cache-Control: public, max-age=718
Expires: Fri, 12 Dec 2014 13:51:43 GMT
Date: Fri, 12 Dec 2014 13:39:45 GMT
Connection: close
.PNG........IHDR..............X\X....PLTE......&*-....' ..............
.............' 1................$'......... /4#,,-197<?...?CF......
.........)-0...........................#(,y|.......149/25...39;...HJM.
..............<>@..................os}......6=E/6=............%.
/FJU.........~......../66...............ko{...|..;BE...MOQvy|BIK:>F
[]a.........uw....hjn&.3......HOR?CM# 0......cil......qv.BFQ58=orv....
..............TXc...dhq...*36TWZ...DFJ...!*(.........{{{............%/
)......RQV...NQ]WZg......iot......~.....;AJ......QU_tz.MXcttwbcf\`e...
~~.PUY...................'%....."nop[_l........."##...2-*./0......v{.3
8By~.z}.^cr_dk............T_j......gkwDEE...KOZ............)22...`gu..
.en}......(&'Wfq.........khhYX\...............81-......C<6...>5.
...HTa/)$8/&inn776...........}[email protected]...\QQ......f.....!vIDATx
...wX........a..u.u]......)...!4.^..t.#.fP.w.B.&E..QDb...F.7".1....xSn
.}..O|o.......>.q....Y...9...9g....................................
................1,,,DH..G...A5.|\.#..../..m.mM.Lm.A.(Es.4p0P.].(V1*JQ1
..(.f......[..r.hf.o.:.e._t..T... ,......J..F$..{DD.......O.>....W.
.8.t.r...--y.....s... W.WTT8......[..KK..b...b..\.. .........Ca...#N..
............}...|.V[7m..g..-.....L..=zd......G_>zT....#.....C.B.a.&
.....f0^.].h.c._I6BaD....DDD.. .....G.b..Q............J....m..v...m.V.
.7..l...44$........b|...V.....wJ...HI_..*.......#..x0X,...,..X.. ...C.
.Xt..#.X..? @.q...p.....,.v$....xy...Q.5...B.<..!..~.~~:?I.....0..:
.\.??...r.`..'G.Y../W..fN.........\[email protected].,.........

<<< skipped >>>

GET /ocsp/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBTy4Gr5hYodjXCbSRkjeqm1Gih+ZAQUSt0GFhu89mi1dvWBtrtiGrpagS8CCCv3k0jGH6Vn HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: clients1.google.com


HTTP/1.1 200 OK
Content-Type: application/ocsp-response
Date: Tue, 09 Dec 2014 04:37:14 GMT
Expires: Sat, 13 Dec 2014 04:37:14 GMT
Server: ocsp_responder
Content-Length: 463
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Age: 291757
Cache-Control: public, max-age=345600
Alternate-Protocol: 80:quic,p=0.002
0..........0..... .....0......0...0......J......h.v....b..Z./..2014120
9010332Z0k0i0A0... ..........j.....p.I.#z...(~d..J......h.v....b..Z./.
. ..H...g....20141209010332Z....20141216010332Z0...*.H..............h.
>'(...."6.&.....j..&..8^.._.>...X.1.C.X.}(.....2".Cm..O...^q.|..
%.h.L.__.#4..|..o..!..n.....Wn ..r.yl......X0.......@.%?..zbn\....hlN.
......b8.].L"R1...HH$..c.!|._~.7...)...$..Z..`.jG..~.*.1...../Yd.v..h.
..v.rXy.M.....p(.......C|..t.}M....g..Z...T[..G.xHTTP/1.1 200 OK..Cont
ent-Type: application/ocsp-response..Date: Tue, 09 Dec 2014 04:37:14 G
MT..Expires: Sat, 13 Dec 2014 04:37:14 GMT..Server: ocsp_responder..Co
ntent-Length: 463..X-XSS-Protection: 1; mode=block..X-Frame-Options: S
AMEORIGIN..Age: 291757..Cache-Control: public, max-age=345600..Alterna
te-Protocol: 80:quic,p=0.002..0..........0..... .....0......0...0.....
.J......h.v....b..Z./..20141209010332Z0k0i0A0... ..........j.....p.I.#
z...(~d..J......h.v....b..Z./.. ..H...g....20141209010332Z....20141216
010332Z0...*.H..............h.>'(...."6.&.....j..&..8^.._.>...X.
1.C.X.}(.....2".Cm..O...^q.|..%.h.L.__.#4..|..o..!..n.....Wn ..r.yl...
...X0.......@.%?..zbn\....hlN.......b8.].L"R1...HH$..c.!|._~.7...)...$
..Z..`.jG..~.*.1...../Yd.v..h...v.rXy.M.....p(.......C|..t.}M....g..Z.
..T[..G.x..

<<< skipped >>>

GET /fr/u.php?t=2592000&p=443937282305007&m=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: VVV.facebook.com


HTTP/1.1 200 OK
Date: Fri, 12 Dec 2014 05:39:53 PST
Content-Type: image/gif
Pragma: public
Cache-Control: public, max-age=0
Expires: Fri, 12 Dec 2014 05:39:53 PST
X-XSS-Protection: 0
X-Content-Type-Options: nosniff
X-UA-Compatible: IE=edge,chrome=1
Content-Encoding: gzip
X-FB-Debug: HqxT67LrgHGKfx4tghHevV qEhBh1he1hROGkXLPxP2FS7hwYgQELR HV n5 0vWerYSu0k 2PHoXTLT4nteaw==
Transfer-Encoding: chunked
Connection: keep-alive
2f............r.t..Ldd`dh`....,. Z.D.d...\...........a....v.h. .....0.
.


GET /pixel?google_sc&google_nid=artb&google_hm=5l2siGo7dg2UgG9a_YGMZQ&google_ula=1535926 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Cookie: id=caebd6253000002||t=1384780400|et=730|cs=002213fd480c4c2631f7c541a4
DNT: 1
Connection: Keep-Alive
Host: cm.g.doubleclick.net


HTTP/1.1 302 Found
P3P: policyref="hXXp://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Location: hXXp://d.adroll.com/cm/g/in?google_ula=1535926,0
Date: Fri, 12 Dec 2014 13:39:53 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
Server: HTTP server (unknown)
Content-Length: 245
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
<HTML><HEAD><meta http-equiv="content-type" content="te
xt/html;charset=utf-8">.<TITLE>302 Moved</TITLE></HE
AD><BODY>.<H1>302 Moved</H1>.The document has mov
ed.<A HREF="hXXp://d.adroll.com/cm/g/in?google_ula=1535926,0">he
re</A>...</BODY></HTML>..HTTP/1.1 302 Found..P3P: po
licyref="hXXp://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="
CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV
OTC NOI DSP COR"..Location: hXXp://d.adroll.com/cm/g/in?google_ula=153
5926,0..Date: Fri, 12 Dec 2014 13:39:53 GMT..Pragma: no-cache..Expires
: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache, must-revalid
ate..Content-Type: text/html; charset=UTF-8..Server: HTTP server (unkn
own)..Content-Length: 245..X-XSS-Protection: 1; mode=block..Alternate-
Protocol: 80:quic,p=0.002..<HTML><HEAD><meta http-equiv
="content-type" content="text/html;charset=utf-8">.<TITLE>302
Moved</TITLE></HEAD><BODY>.<H1>302 Moved</
H1>.The document has moved.<A HREF="hXXp://d.adroll.com/cm/g/in?
google_ula=1535926,0">here</A>...</BODY></HTML>..
..

<<< skipped >>>

GET /input.png HTTP/1.1
Host: 1b168f054a2c3427459f-daaeafaf8ae4e7adccb47a82a8360bf0.r36.cf1.rackcdn.com
Connection: Close


HTTP/1.1 200 OK
Last-Modified: Tue, 25 Mar 2014 19:35:42 GMT
ETag: 8ac9dd4affeafc8104360b139946cae6
X-Trans-Id: txdf3d3de9924b48e78027c-00542c6f4ddfw1
Content-Length: 40826
Content-Disposition: attachment; filename=input.png
Accept-Ranges: bytes
X-Timestamp: 1395776141.03421
Content-Type: image/png
Cache-Control: public, max-age=106327
Expires: Sat, 13 Dec 2014 19:11:53 GMT
Date: Fri, 12 Dec 2014 13:39:46 GMT
Connection: close
.PNG........IHDR.......,.....b.r.....tEXtSoftware.Adobe ImageReadyq.e&
lt;..."iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c061 64.140949, 2010/12/07-10:57:01 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CS5.1 Windows" xmpMM:InstanceID="xmp.iid:752358267EC911E3A2F1BF9A
FE5296D1" xmpMM:DocumentID="xmp.did:752358277EC911E3A2F1BF9AFE5296D1"&
gt; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:752358247EC911E3A2
F1BF9AFE5296D1" stRef:documentID="xmp.did:752358257EC911E3A2F1BF9AFE52
96D1"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
; <?xpacket end="r"?>[email protected]\
..66m.M..t:....i;.I[;.e&...I....I....("."(. F.*"."..qI~.~_..x?...C..=.
0.....~.r...s......_..U.R.J..._..R.J..*U.T..V.J.*`U.T.R..J.*U..U.R..X.
*U.T..R.J.*`U.T..V.J.*U..T.R..X.*U..U.R.J..*U.T..V.J.*`U.T.R..J.*U..U.
R..X.*U.T..R.J.*`U.T..V.J.*U..T.R..X.*U..U.R.J..*U.T..V.J.*`U.T.R..J.*
U..T.R..X.*U.T..R.J..*U.T..V.J.*U..T.R..J.*U..U.R.J..*U.T..R.J.*`U.T.R
..J.*U..T.R..X.*U.T.k..7.|s..u...j..J..&.P.`../...i....7o...#F.8.....T
.T.k/._..Wo......Y.V.Zu.I'm..y....8qb.....T....Cr.(..z...W.X.d.=......
<.......'..'.]v....U.T..>....Q.#t....p....{.~..w.]wm.....__.

<<< skipped >>>

GET /hardDrive.png HTTP/1.1
Host: 70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com
Connection: Close


HTTP/1.1 200 OK
Last-Modified: Fri, 24 Oct 2014 17:06:36 GMT
ETag: 1ecccf3727b0b0de7146a8c1f8995ba0
Content-Length: 4901
Accept-Ranges: bytes
X-Timestamp: 1414170395.59644
Content-Type: image/png
X-Trans-Id: tx46f3eeefe381495b9fe4b-00544a88eaord1
Cache-Control: public, max-age=8
Expires: Fri, 12 Dec 2014 13:39:53 GMT
Date: Fri, 12 Dec 2014 13:39:45 GMT
Connection: close
.PNG........IHDR.......,......i......PLTE........}.....\...........q..
_..r..h..i..o..z..f..l..e..b..`..]..Y..Z..V..W..S..N..P..P..K..H..F..J
[email protected]..?..=..<..7.....9..6../..3..4..1..... ..)..$..%..#.. ....
...................|...........v.....w..t...........y..z..k..n.....m..
n..k..f..c..h..d..c..a..}..M..X..V..Q.....T..T..R..M..L..I..G..A..D..D
..:..C..7..;..9..<..4.....2..0..*..-..,..-..(.....&..(..'.."..".. .
..............................y.....s..l..f..`...u......yV(...........
~...........}....................u..c.....s............fff..q.....p..y
............................................xiii...ooo........o.....v.
................j........j...........i........uxxx~[-.................
............Q..^.....x...........]..E.....X.uH..N..Z..........g9..>
.....=.....U.....a..3........,.....9.{4.|$....}j........IDATx...]O.W..
..:[email protected].$...n.]..o.K>..0..:8$S../pq..)[email protected]... ....[...
.Ez[.9..y.96...}~\D.#Y._.<s....B.!..B.!..B.!..B.!..B.!..B.!........
..WK...R!.J.2....p..*......h...)A.... ,q.n75....]\$6;.T...X..uj....).h
...a.G.,.A.>.s....G. r..d....o.......7.K.L......k.].dn.d...4.%.. .F
.m.f.A......,8uMDtu_..". O...U.VD.?.r..Y0~a.n..I....s....f|...!T%.F[S`
[email protected]#.Vw...xx(I.,........9g..].d...NbD.4-).2..
".._.....V....G. ..%U..r...#.........?}..C.A..C....G....B......7??..E.
|.X......o59....;....0r....... .o._1....q2g2I..n0..Z}... F.z.G4.....C
g{.... ...8.#..........v..kY=.s.;{$.{..L....Y0....D'........Q...8O....
.!j=...Q.......X..A....EY..Q..0........]...{=.]?....YA...yH.C...s.

<<< skipped >>>

GET /359eb7b28b26c98a238e6cdedc877947afb6a2ef/satelliteLib-6d2ff207543454d05c23a4bcb6934a30b796a147.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: assets.adobedtm.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache
ETag: "2d0f7175d096c4871870d2620c9cf80d:1417019825"
Last-Modified: Wed, 26 Nov 2014 16:37:05 GMT
Accept-Ranges: bytes
Content-Type: application/x-javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 19148
Date: Fri, 12 Dec 2014 13:39:50 GMT
Connection: keep-alive
...........}[{.F.......(...".vB......~v..9.s.f< .......% "..VU.....
}..&..hT......N.e...l.Za:...%K.8K.V...2.J..l..\...u../...7[...r....w#.
[...L..t.....`&,.ZN..P.b.."L.....QxJ..FA..Ry...|.."..gqR.../.u......&l
t;uX....}...p. `m....`......,[[email protected]..'...8.......Y..r...
S.`T..U.......4....}.:.^d.,......O.....]./.c...`.fatQ.D...A*:..K...A..
_........ZL`..UF......f5*.|.....%..4[..... .....\^.e...5.?...i\.a...\o
........zS....=..........I{.%.k..n.7.k.....'8...,'..[.&<....]Yx'P..
%..-8R.a.Ut.q..Q.#t.`..O.p.T[.x.#.._....eI;.a.............z....1...k.a
1........N.....p...!..".....S..l....hU.....n.v.b.nq.67(....4:..xY.....
.....).a>/.f..$..B.xU...[.U...{#QG..........0...9.......=..*...A:q.
|.....g....%l.........R..J..d...S.IT.d...7.......Q......E.....#.c.S.^.
..6...l.v.Ox.Z....o...A>.....Z.T.%0|.T...a1*...,... Ha.#.~.W..a*...
.ona._"%.e...i N[..42.d..........l..M.q.2...>...O.u.M.e. -.1F.r....
... ..^....t.${.,[email protected]|...8...T.GFSu.a^..c.._._E..WS....
P|Og`c...........|[b.wq..S.4.=w..}...x._9.....J...eW,?........ZCd..q..
C.:a...../.A..Z....l.........;.....V.a./.A..b.=.....H.K...'......M....
..}.x.mt[az}...6.m..A<.c.in<.8]..^.f.h..f..w.O...c....0.e.(d.#q.
..x...N...3z....*......I.T_..&.........@N.).....<.j:..2..|c..8T...=
r|.3Q....A..~Y....]...-..e._......{.h....0...L.ra..R}v~>......Hz.m.
..k...9...........z.W.k.......w..............*;.'Y..=_d..........N...3
z...T...q.R...vh...R.....b...|...>.2.6..\..s..L.....'..q<].z...l
.I...t..VX..z..G."&.. ...C....>;..A."[email protected]......

<<< skipped >>>

GET /359eb7b28b26c98a238e6cdedc877947afb6a2ef/s-code-contents-1ce25cd3cd6d4f446079f5924eec249f6b3d3a78.js HTTP/1.1

Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: assets.adobedtm.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache
ETag: "9f7cd65bb731ab2c8e0cd9ca5bf9c135:1417019825"
Last-Modified: Wed, 26 Nov 2014 16:37:05 GMT
Accept-Ranges: bytes
Content-Type: application/x-javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Date: Fri, 12 Dec 2014 13:39:51 GMT
Content-Length: 10393
Connection: keep-alive
...........=kw.6... d....`Zr.>$#:N.4n.$.........LK"............D;{.
.."..........M.. ........h..^..h...t....O.....~o..y....q{...o........*
...e.I....7..O.e...I.....w.u....xy..........v.{.g.. .$k.D..>.....&g
t;m...Lnd.j...l..$nC..\xs..Y.*......z...(.......o.Z.U.g0n.:....I;..U..
SWC.-...b....(...pb......9...0..cf.y...2SI..y.T.%..y:4.......W5.......
.{...|.P...Y..a....|..E.......^../p.......N'.t,.[..px..E..v.rmQ.^.i.yL
[email protected]. =n.n..=...Q..%t6.".Z@.. ......E..t....U.p. ...\../K
_0.|..i.><...L...@.....:k.C....y.A.{....;..L}.,..).........z\F~.
...N^..e.!/y.QB........u.......v.m...K.$...`..w....;/x...=........Y]..
.D...;....f.......|\.e.J..v..L.......l.....Z......1.m9..xN............
....D_.X....W.XH&.....8...(^.0z/.0.RM..`....k.Ng.Z...v.......;..s..d..
........3........'..3.ivb..Z...=.s.D..D1..?t..2...,vw.U`...7.J...j79S.
."...I>..R..R"...&. 8.......f!..B...8.Cr..7....!...;`.e....E...~..*
.iv.$4..e K.......xl...e.y..y...Y.'..E.%G&.....O...B`..P......#......H
C...`......wo-.<..}....m{.......(.....w=gd.<......mn*.......~r..
o....g.s...J.'..}."...kz.t.w..A..^o..`0\..Ms.r.......9y..b...t.a{). .7
..vm.#.-o.a"S..#..:....?..QN...,P,iu.)gef...\......`....[..)..B...h.b.
....;.x...{CE....6HtJ..Z.j.-_<6...Zz.0.....Az..`...$.V.x.B.&..>.
..I.3..d.H....Xz.p.p.......A|..S..C..8v!....$.i.f2..=....&....$....F&0
..rp.. ;.9"..lg.l$....F.S..q..b[[email protected]......?.,...$.....a....
.; ."_..)Z....M.....9..*C'.:.La.Eo.......p.j...d30d...^x..W fT..>..
^...$..a.^".l......w.cW,..;..Z. . ...r....~..2.*.......U4..H. ..S.

<<< skipped >>>

GET /pagead/conversion.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: VVV.googleadservices.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
P3P: policyref="hXXp://VVV.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA IVD OTP OUR OTR IND OTC"
Content-Type: text/javascript; charset=UTF-8
ETag: 9603012329940890601
Date: Fri, 12 Dec 2014 09:02:19 GMT
Expires: Sat, 13 Dec 2014 09:02:19 GMT
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="f.txt"
Content-Encoding: gzip
Server: cafe
Content-Length: 4017
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=86400
Age: 16651
Alternate-Protocol: 80:quic,p=0.002
...........Z.r.......PS.1b(..3..aU..8g.;'q&g..u.$D2.H.II.-..v....g.j.\
..h4.@_....W...q...5O:s..A.....U........n.s.....d.1.B.x....4...l.....D
d.$".......Br..m.<.STc..Y.s.Y.5K..3...0.T`.4.|."[email protected]...&..\.-.V
.[$.(.d.".2..#.... ...V..2...T/(..Iv.!=..".v......(a.>..R..../.m..7
..I%.U)T.<..0.......:.$.....h...*..Jq.;y.a...)....p..w.........H...
.8.....u8}dD>O/7..|..)....l.X.....|..tW.TM...40.X6.......{..Q.1H3..
d......5.....;.....Mp...Q........xX.i.'66u?p]....e".....G....f|..rc#..
..G.a..}.x&.[n,....z.D.l.....q(...LlF.Z.q|.y...P..UG..=uz=...1....l.
.HG.....awM.k....l.xD7..j..............n.W...P....e..X.k.4.V.......pE.
...me..Jw;....`N....s......'..=.yV.. .....n....z.'.1W.6l...1|E..3.7...
...d.......lnD|.x<...\..~.a..U*......7......D..N...3B..o.K.....-...
..%.%'..>......>.U...g-.>}.p.#..G...mL.._...Y.1...-O.F .e....
..SR..|...m.h{I....6...^on`..EV.,'.k..0F...[8..X..[g.P.d}=...}M.Y.j.tk
.....\..d..n.5..;.Gl.K'.|...Av=......Z..5...6.O.h..f...1.......s...H,Q
F....O. .y|.O..J'*....ARM....Q#"1l6.Y..3H.E...Pw.O<9Q.'r.>q.~..j
...........Q(Gi.;.Sp'...2......C....I...0.h.....O<...C.Xh4. .5.(Z.@
....../"..|...|%..fRK...I..Ylx".".....H5.Z.y..l...x.j....5.>.....O%
e...W.....Y...aZ.q\Y....K.....c....*...v;..-X......q4.8......{......8L
....O..... [...r.KUvt.[..........H......1..i......-.8....*....^..5.a..
Y%......8L...m.[.m..0N......n..d~..<...|..[.....Qx.F.].I.O..e. ....
..,^..k.......m..,..?.........A.fs.../..`..{.a...T..R.."[email protected]
...-.1..4.....;...Rd).Y.1v.*..A.......K.F[./.....A.-...F..S.>..

<<< skipped >>>

GET /pagead/conversion/996887577/?random=1418391591441&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: VVV.googleadservices.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 302 Found
P3P: policyref="hXXp://VVV.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA IVD OTP OUR OTR IND OTC"
Date: Fri, 12 Dec 2014 13:39:51 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Location: hXXp://googleads.g.doubleclick.net/pagead/viewthroughconversion/996887577/?random=1793213668&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0
Content-Type: image/gif
X-Content-Type-Options: nosniff
Server: cafe
Content-Length: 42
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
GIF89a.............!.......,...........D.;HTTP/1.1 302 Found..P3P: pol
icyref="hXXp://VVV.googleadservices.com/pagead/p3p.xml", CP="NOI DEV P
SA PSD IVA IVD OTP OUR OTR IND OTC"..Date: Fri, 12 Dec 2014 13:39:51 G
MT..Pragma: no-cache..Expires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Co
ntrol: no-cache, must-revalidate..Location: hXXp://googleads.g.doublec
lick.net/pagead/viewthroughconversion/996887577/?random=1793213668&cv=
7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=f
fffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=
1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.dri
versupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2
52fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia
&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178
ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1&ctc_id=CAIVAgAAAB0C
AAAA&ct_cookie_present=false&convclickts=0..Content-Type: image/gif..X
-Content-Type-Options: nosniff..Server: cafe..Content-Length: 42..X-XS
S-Protection: 1; mode=block..Alternate-Protocol: 80:quic,p=0.002..GIF8
9a.............!.......,...........D.;
....

<<< skipped >>>

GET /pagead/conversion/933633792/?label=NtOJCPjf1hEQgL6YvQM&guid=ON&script=0&ord=3418199282196799 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: VVV.googleadservices.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 302 Found
P3P: policyref="hXXp://VVV.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA IVD OTP OUR OTR IND OTC"
Date: Fri, 12 Dec 2014 13:39:52 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Location: hXXp://googleads.g.doubleclick.net/pagead/viewthroughconversion/933633792/?label=NtOJCPjf1hEQgL6YvQM&guid=ON&script=0&ord=3418199282196799&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0&random=2010159716
Content-Type: image/gif
X-Content-Type-Options: nosniff
Server: cafe
Content-Length: 42
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
GIF89a.............!.......,...........D.;HTTP/1.1 302 Found..P3P: pol
icyref="hXXp://VVV.googleadservices.com/pagead/p3p.xml", CP="NOI DEV P
SA PSD IVA IVD OTP OUR OTR IND OTC"..Date: Fri, 12 Dec 2014 13:39:52 G
MT..Pragma: no-cache..Expires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Co
ntrol: no-cache, must-revalidate..Location: hXXp://googleads.g.doublec
lick.net/pagead/viewthroughconversion/933633792/?label=NtOJCPjf1hEQgL6
YvQM&guid=ON&script=0&ord=3418199282196799&ctc_id=CAIVAgAAAB0CAAAA&ct_
cookie_present=false&convclickts=0&random=2010159716..Content-Type: im
age/gif..X-Content-Type-Options: nosniff..Server: cafe..Content-Length
: 42..X-XSS-Protection: 1; mode=block..Alternate-Protocol: 80:quic,p=0
.002..GIF89a.............!.......,...........D.;..


GET /cd-rom.png HTTP/1.1
Host: 70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com
Connection: Close


HTTP/1.1 200 OK
Last-Modified: Fri, 24 Oct 2014 17:06:35 GMT
ETag: d6905b36ba69707b36406ffc24481aef
Content-Length: 36630
Accept-Ranges: bytes
X-Timestamp: 1414170394.61876
Content-Type: image/png
X-Trans-Id: tx90e6af58f6d5418891294-00544a89dford1
Cache-Control: public, max-age=617
Expires: Fri, 12 Dec 2014 13:50:02 GMT
Date: Fri, 12 Dec 2014 13:39:45 GMT
Connection: close
.PNG........IHDR.......,......i......PLTE.............................
...................................................................RMI
...............C>[email protected]?A@<=...FBC...PKH...NJFC>?....
.....=:;F>?............@>?::;...=<>IACDA?...KFC.........I@
?...JDA...777......:89...IDE...VUQ...USO.........OMHTNL...XWX...LJD...
.........RQL[Y]GB?.....................KIIVST?>;...FEE.............
...........RPR<<:......ZXTUTX...E@=.....L.....<431.....D.....
...............).....E<:6210......645`]a..5...........?LGE......$##
..K.........*((.....5..$..G......NLM.-... ...872...........<..2....
.......".....<..-...olk.....D..L1/)........., .........?{xv*....Sig
d...C>9vso...1%......D..3%........b_Y............4%.......=/......y
..8..VYK.../KJ>...I:...>..O...hZ.wj ..F..=RRC..W..7.|$.. ..=..:.
.P........O.....Z.x4..K%....IDATx....lSw..M......M......."Y.f.....U..r
...x..Y...=....... ...#9W..A.:.....l..--T..mHB...".mig``.0..NwzUU..N..
[email protected]..?....55.PC.5.PC.5.PC.5.PC.5.PC.5.PC.-_n.../.._...K
......K.....-.|..H.<C.m..&.FL..D...{.....o....I..nj....]/.j........
..,...I..D.7..=.?2.>.q.'.t....8$b...z...... ........|..%.M.I...._%.
.......lMtGR2.....F.a..pa.NF.E"....w.lm.....u..VC.Dl #i.?....C..<..
.p{...}1.......DN.a&$.jtV.q,...<.......A.V..w..K....o....]..6....8p
.w..p...#...#...."..Q..-syG".>.; ........b..~.!.X.W.L...z...... .=.
b........[....k[............q..a.....=.>........u..'.....<< .
1.!....=...k...B.{.=.n..l...55..$...h....r....rEb..=y)kj.s.fq...t,

<<< skipped >>>

GET /content/themes/reset.css?v=1.0.0.13 HTTP/1.1
Accept: text/css
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: text/css
Content-Length: 1092
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Mon, 10 Nov 2014 19:19:01 GMT
Accept-Ranges: bytes
ETag: "aa603a2f1bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Tue, 02 Dec 2014 21:23:07 GMT
Age: 3052
X-Cache: Hit from cloudfront
Via: 1.1 3d412ad301f6861db40352c43a580a9d.cloudfront.net (CloudFront)
X-Amz-Cf-Id: CzLxbEzwUp98Kq6a9Hp1y9NVjrahS9btP97vRUMEY-bhBXW18BWh5w==
/* hXXp://meyerweb.com/eric/tools/css/reset/ .   v2.0 | 20110126.   Li
cense: none (public domain).*/..html, body, div, span, applet, object,
iframe,.h1, h2, h3, h4, h5, h6, p, blockquote, pre,.a, abbr, acronym,
address, big, cite, code,.del, dfn, em, img, ins, kbd, q, s, samp,.sm
all, strike, strong, sub, sup, tt, var,.b, u, i, center,.dl, dt, dd, o
l, ul, li,.fieldset, form, label, legend,.table, caption, tbody, tfoot
, thead, tr, th, td,.article, aside, canvas, details, embed, .figure,
figcaption, footer, header, hgroup, .menu, nav, output, ruby, section,
summary,.time, mark, audio, video {..margin: 0;..padding: 0;..border:
0;..font-size: 100%;..font: inherit;..vertical-align: baseline;.}./*
HTML5 display-role reset for older browsers */.article, aside, details
, figcaption, figure, .footer, header, hgroup, menu, nav, section {..d
isplay: block;.}.body {..line-height: 1;.}.ol, ul {..list-style: none;
.}.blockquote, q {..quotes: none;.}.blockquote:before, blockquote:afte
r,.q:before, q:after {..content: '';..content: none;.}.table {..border
-collapse: collapse;..border-spacing: 0;.}
....

<<< skipped >>>

GET /bundles/TSUIScanResults?v=1.0.0.13 HTTP/1.1

Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: text/javascript; charset=utf-8
Content-Length: 14212
Connection: keep-alive
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Fri, 12 Dec 2014 13:39:50 GMT
X-Cache: Miss from cloudfront
Via: 1.1 3d412ad301f6861db40352c43a580a9d.cloudfront.net (CloudFront)
X-Amz-Cf-Id: momPaiQ6VhZJ247doafs26r_Z0SEcWSP8MRyEbSq52LYXVFjNLyxwg==
var UIControls,Model,UIObjects,__extends,Controllers;(function(n){var 
t=function(){function n(){this.animationTime=300;this.tileSelected=new
Common.UIActionEvent}return n.prototype.Initialize=function(){this.pa
rentController.dataBound&&(this.scanData=this.parentController.data,th
is.BindDomObjects(),$(this.tileHolder).width(0),this.animationBlockers
=[this.tileHolder,this.carrot],this.tiles=[])},n.prototype.slideLeft=f
unction(){var t=this,i=parseInt($(this.tileHolder.jQueryObject).css("l
eft"),10),n,r,u;i<0?(this.SelectPreviousTile(!1),n=i this.tileWidth
this.tileMargin,$(this.tileHolder.jQueryObject).animate({left:n "px"}
,this.animationTime)):(r=this.tileHolder.jQueryObject,this.tiles[0].cu
rrentlySelected?(u=Math.round(this.tileViewportWidth/this.tileWidth),n
=(this.tiles.length-u)*(this.tileWidth this.tileMargin),$(r).animate({
left:"-" n "px"},this.animationTime,function(){t.SelectTile(t.tiles[t.
tiles.length-1],!0)})):this.SelectPreviousTile(!0))},n.prototype.slide
Right=function(){var n=this,r=$(this.tileHolder.jQueryObject).width()
parseInt($(this.tileHolder.jQueryObject).css("left"),10),u=parseInt($(
this.tileHolder.jQueryObject).css("left"),10),t,i;r>this.tileViewpo
rtWidth?(this.SelectNextTile(!1),t=u-this.tileWidth-this.tileMargin,$(
this.tileHolder.jQueryObject).animate({left:t "px"},this.animationTime
)):(i=this.tileHolder.jQueryObject,this.tiles[this.tiles.length-1].cur
rentlySelected?$(i).animate({left:"0px"},this.animationTime,function()
{n.SelectTile(n.tiles[0],!0)}):this.SelectNextTile(!0))},n.prototy

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEApfEU0DWxeRF9Lv1AOMPzs= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=510512
Content-Type: application/ocsp-response
Date: Fri, 12 Dec 2014 13:39:53 GMT
Etag: "548ac533-1d7"
Expires: Fri, 19 Dec 2014 01:39:53 GMT
Last-Modified: Fri, 12 Dec 2014 10:36:35 GMT
Server: ECS (ams/D1A6)
X-Cache: HIT
Content-Length: 471
0..........0..... .....0......0...0.......>.i...G...&....cd ...2014
1211200000Z0s0q0I0... ............([email protected]....>.i...G...&...
.cd ...._.M.[........?;....20141211200000Z....20141218200000Z0...*.H..
...........Mf.......X.!0...8..............hl~e.D.[..e.._>zi...~.7..
...W S0H...jl./z]5#.ey...k#G.#x..7a....d..q(..u.Etm.. ..F..NY.NCq....$
w....,....I.c...4Tb.....~5.]...0.M...,.j..,.aL.. ..&..n.......#.L.Z..1
...../..JYG...%.OM*.1Q....E}|.4.BY_nb.?. 8...]G./1./;.?.:.W.
...
.



GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEApfEU0DWxeRF9Lv1AOMPzs= HTTP/1.1

Cache-Control: max-age = 510512
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Fri, 12 Dec 2014 10:36:35 GMT
If-None-Match: "548ac533-1d7"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com


HTTP/1.1 304 Not Modified
Accept-Ranges: bytes
Cache-Control: max-age=510512
Date: Fri, 12 Dec 2014 13:39:53 GMT
Etag: "548ac533-1d7"
Expires: Fri, 19 Dec 2014 01:39:53 GMT
Last-Modified: Fri, 12 Dec 2014 10:36:35 GMT
Server: ECS (ams/D1A6)
X-Cache: HIT
....



GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTtSK3dy3sA4g6EKqm0CfGsMDTPlgQUUOpzidsp+xCPnuUBINTeeZlIg/cCEAJwu3i4ZpYdN6xM1SVvBys= HTTP/1.1

Cache-Control: max-age = 507985
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Fri, 12 Dec 2014 10:04:48 GMT
If-None-Match: "548abdc0-1d7"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com


HTTP/1.1 304 Not Modified
Accept-Ranges: bytes
Cache-Control: max-age=511587
Date: Fri, 12 Dec 2014 13:39:53 GMT
Etag: "548abdc0-1d7"
Expires: Fri, 19 Dec 2014 01:39:53 GMT
Last-Modified: Fri, 12 Dec 2014 10:04:48 GMT
Server: ECS (ams/49CD)
X-Cache: HIT
HTTP/1.1 304 Not Modified..Accept-Ranges: bytes..Cache-Control: max-ag
e=511587..Date: Fri, 12 Dec 2014 13:39:53 GMT..Etag: "548abdc0-1d7"..E
xpires: Fri, 19 Dec 2014 01:39:53 GMT..Last-Modified: Fri, 12 Dec 2014
10:04:48 GMT..Server: ECS (ams/49CD)..X-Cache: HIT..


GET /input.png HTTP/1.1
Host: 70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com
Connection: Close


HTTP/1.1 200 OK
Last-Modified: Fri, 24 Oct 2014 17:06:36 GMT
ETag: 184d022e56c9b162d6d5fc95e91951c3
X-Trans-Id: txb288ded5eff44a7480eb6-00546d18ebord1
Content-Length: 20915
Accept-Ranges: bytes
X-Timestamp: 1414170395.91873
Content-Type: image/png
Cache-Control: public, max-age=337
Expires: Fri, 12 Dec 2014 13:45:22 GMT
Date: Fri, 12 Dec 2014 13:39:45 GMT
Connection: close
.PNG........IHDR.......,......i......PLTE...///'''   YYY...PPPNNNEEETT
TIII```GGG[[[VVVccc...BBB111333###@@@555<<<>>>fffhhh
888jjj:::...LLL...llluuu............~~~......RRRKKK{{{nnn...pppxxxrrr.
...........]]].........^^^.........---eee777..........................
.......................................bB..PlIDATx..|.{.......7v$.B. G
$..A.0..........%;........y:3.7.u.RIuN..DN2d..!C...2d..!C...2d..!C...
2d..!C...2d..!C...2d..!C...2d..!C...2d..!C...2d....?..~9.....Co.r.....
] Z....'.~.|zZ{......d.%py.a..Y.|..$......./..R.3..........8>......
.>.....p:.1..........,...H.....|.....t...~:.(.u}...|..^...d..*B....
.Gh.Z!/...}...#.m-n......6.'....@&.?.s<X.#.YNU.o......[..o......#'.
.;..W.....g.s"I.R.:..g..D..U...3.{...!....:..d.K...9=....'..NG.......j
.......3..0.v.m..z..Y...K.........].N...>...........A.. u..e.j.....
,...$...R.\.].c:..WZ..bdtWk\AK ....'.].....nv../._S\....nw...I.?../TKN
...G.....m....?.A|.u.o..?.wp&....4...0...q.0p...$...I>}.X`.....u.d{
.....Z.G_N ....O_.....b.8<..v...o../=v..g.....}.....S....*.Kum....V
..0._.\g4'.!.O.Bx...7............}...z..-......jQ..b......F......f.."A
fD..^".$D.f....P.F.XqF......O_....oInt./^.R.2..U.7_..?g..............K
v..K......./.b..ECx..o.L..M....).|......]~...w-..&.;h....o..../G......
."9....tx|9.4./....~.;.<K..$Z.wW=....HF...~!........d...q~..u{l....
.p....>}...................u.Yo._.2... G........W.0.....B....9..-..
^..u^..W.......o/......=..-.r...j.i....$h.6......f..{.....[.....b...k.
..^~...........M...o.=...G.......d.\.*..m&..._....4..6{..o...Ud.ec

<<< skipped >>>

GET /cm/w/out HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d.adroll.com
DNT: 1
Connection: Keep-Alive
Cookie: __adroll=e65dac886a3b760d94806f5afd818c65


HTTP/1.1 302 Moved Temporarily
Cache-Control: no-store, no-cache, must-revalidate
Date: Fri, 12 Dec 2014 13:39:52 GMT
Location: hXXps://analytics.twitter.com/i/adsct?p_user_id=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU&p_id=823423
P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Pragma: no-cache
Server: nginx/1.6.2
Set-Cookie: __adroll=e65dac886a3b760d94806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max-Age=157680000; Path=/
Content-Length: 109
Connection: keep-alive
Go to hXXps://analytics.twitter.com/i/adsct?p_user_id=ZTY1ZGFjODg2YTNi
NzYwZDk0ODA2ZjVhZmQ4MThjNjU&p_id=823423HTTP/1.1 302 Moved Temporarily.
.Cache-Control: no-store, no-cache, must-revalidate..Date: Fri, 12 Dec
2014 13:39:52 GMT..Location: hXXps://analytics.twitter.com/i/adsct?p_
user_id=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU&p_id=823423..P3P:
CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"..Pragma: no-cache..Serve
r: nginx/1.6.2..Set-Cookie: __adroll=e65dac886a3b760d94806f5afd818c65;
Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max-Age=157680000;
Path=/..Content-Length: 109..Connection: keep-alive..Go to hXXps://ana
lytics.twitter.com/i/adsct?p_user_id=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZ
mQ4MThjNjU&p_id=823423
....



GET /cm/r/in?xid=KBgCC6FUe9PSyWP2DG4.yWXZ HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: d.adroll.com
Cookie: __adroll=e65dac886a3b760d94806f5afd818c65


HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate
Content-Type: image/gif
Date: Fri, 12 Dec 2014 13:39:53 GMT
P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Pragma: no-cache
Server: nginx/1.6.2
Set-Cookie: __adroll=e65dac886a3b760d94806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max-Age=157680000; Path=/
Content-Length: 35
Connection: keep-alive
GIF87a.............,............Q.;HTTP/1.1 200 OK..Cache-Control: no-
store, no-cache, must-revalidate..Content-Type: image/gif..Date: Fri,
12 Dec 2014 13:39:53 GMT..P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NA
V STA"..Pragma: no-cache..Server: nginx/1.6.2..Set-Cookie: __adroll=e6
5dac886a3b760d94806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13
:39:52 GMT; Max-Age=157680000; Path=/..Content-Length: 35..Connection:
keep-alive..GIF87a.............,............Q.;..


GET /MFQwUjBQME4wTDAJBgUrDgMCGgUABBSfAP5wz6TZE9AhTecbrorIUEieTwQU3Igt2WxNPQBQM/EVuXj7weahJK8CExkAAAlE5E3bN0hKjHcAAQAACUQ= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.msocsp.com


HTTP/1.1 200 OK
Date: Fri, 12 Dec 2014 13:40:54 GMT
Content-Type: application/ocsp-response
Content-Length: 1501
Connection: keep-alive
Set-Cookie: __cfduid=d80ce67dfc61b3f5f84fa26c0ef5120dd1418391654; expires=Sat, 12-Dec-15 13:40:54 GMT; path=/; domain=.msocsp.com; HttpOnly
Last-Modified: Thu, 11 Dec 2014 04:49:18 GMT
Expires: Tue, 16 Dec 2014 13:40:53 GMT
ETag: "b06006aa3364d120beea3a1c8e835ba1bad366bd"
Cache-Control: public, max-age=345599
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 197a5621f12c05c3-WAW
0..........0..... .....0......0...0.......j.....N ...#c........2014121
1044918Z0..0..0L0... ...........p.....!M.....PH.O....-.lM=.P3...x....$
.......D.M.7HJ.w.....D....20141211044918Z....20141215044918Z."0 0... .
....0......20131211044918Z0...*.H..............k..A.iu l....n`.....$_.
2{..Q.V*W.....D.n0K...K...F.aE............*.!..u....(,...d.....s.W(.N
.KPl...T.0.T......F`?.7.....5.p........Q..]ef.>. ........C...n..kq.
..p.jo'c..Cf....f''...m....Z.l.,/m......o%..%......i..{.".......?.:..~
../).`.......s[CD<.u.........0...0...0................y#....y......
0...*.H........0..1.0...U....US1.0...U....Washington1.0...U....Redmond
1.0...U....Microsoft Corporation1.0...U....Microsoft IT1.0...U....Micr
osoft IT SSL SHA10...141023182318Z..150106182318Z0!1.0...U....Should b
e ignore by CA0.."0...*.H.............0.........1._G....#.L;!>Q.z.m
?e8.-1\...Scf....0.....E(/F.(..nN...U....3"&M./[email protected];...j.k.
.\.d'...s2D...W6.g.9...xk................Q.GZK.1.\-.E.......l.h.]%i4..
..v.....J.-. O. ?.*...A3...h.#..."..c....PhV.>..;...Y...._.".t....|
c......3.l.YUZ."p.r..C.U-[y..........0..0...U.......j.....N ...#c.....
.0...U.#..0.....-.lM=.P3...x....$.0...U...........0...U.%..0... ......
.0... .....7....0.0... .......0... .....0......0...*.H...............a
.F7Z.A..,.N.^.W..;....m<........l....\..........ar....B......V....n
X/[email protected]/..L...1.'..SF..Qd.........e<.[....z..`..^wB?.p0,.2....R.`.
>..E?6Ppw....5.6.Q..?.?....."9..,[email protected] :`
...B......E....1*8.~J.U.D...zs..sw.,..V.G.d.#z...n.n..

<<< skipped >>>

GET /ipte/iPTE.1.0.4.7683.msi HTTP/1.1
Host: cdn.driversupport.com
Connection: Close


HTTP/1.1 200 OK
Content-Length: 11792896
Content-Type: application/octet-stream
Content-MD5: 4z vSdVB7S0Y0okpNT6V5w==
Last-Modified: Mon, 24 Nov 2014 20:32:05 GMT
ETag: 0x8D1D63CD85013B3
Server: Windows-Azure-Blob/1.0 Microsoft-HTTPAPI/2.0
x-ms-request-id: fdb5b678-0001-0072-574a-7538cb000000
x-ms-version: 2009-09-19
x-ms-meta-CbModifiedTime: Thu, 20 Nov 2014 15:59:38 GMT
x-ms-lease-status: unlocked
x-ms-blob-type: BlockBlob
Date: Fri, 12 Dec 2014 13:39:12 GMT
Connection: close
........................>..........................................
..6...................................................................
......................................................................
......................................................................
............................................................ ... ...!.
..!..."..."...#...#...$...$...%...%...&...&...'...'...(...(...)...)...
*...*... ... ...,...,...-...-.........../.../...0...0...1...1...2...2.
..3...3...4...4...5...5..............................................h
Y.....................................................................
......... ...!..."...#...$...%...&...'...(...)...*... ...,...-......./
...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?
...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P..
.Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b
...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s..
.t...u...v...w...x...y...z...{...|...}...~...........R.o.o.t. .E.n.t.r
.y....................................................................
[email protected].;;B&F7B.B4FhD&B.......
......................................................................
[email protected].?.?(E8B.A(H.......................
...........................,..........................................
.........<[email protected](?(E8B.A(H............................
..................................................................

<<< skipped >>>

GET /Scripts/custom.js?v=1.0.0.13 HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: application/javascript
Content-Length: 449
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Mon, 10 Nov 2014 19:19:03 GMT
Accept-Ranges: bytes
ETag: "7d359301bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Tue, 02 Dec 2014 21:23:07 GMT
Age: 3052
X-Cache: Hit from cloudfront
Via: 1.1 4959f7132ae6b3fce773418bff3f76bd.cloudfront.net (CloudFront)
X-Amz-Cf-Id: qd94IcvHeVkALyYyDrl_Kk2CX3MoUtdi2RRIC1zo5cpmgw5HcI8tNg==
.....function getParameterByName(name) {..    try {..        name = na
me.replace(/[\[]/, "\\\[").replace(/[\]]/, "\\\]");.. var regex
S = "[\\?&]" name "=([^&#]*)";.. var regex = new RegExp(reg
exS);.. var results = regex.exec(window.location.search);..
if (results == null).. return "";.. else..
return decodeURIComponent(results[1].replace(/\ /g, " "));..
} catch (e) { return ""; }..}HTTP/1.1 200 OK..Content-Type: applicatio
n/javascript..Content-Length: 449..Connection: keep-alive..Cache-Contr
ol: public,max-age=3600..Last-Modified: Mon, 10 Nov 2014 19:19:03 GMT.
.Accept-Ranges: bytes..ETag: "7d359301bfdcf1:0"..Server: Microsoft-IIS
/8.0..X-Powered-By: ASP.NET..Date: Tue, 02 Dec 2014 21:23:07 GMT..Age:
3052..X-Cache: Hit from cloudfront..Via: 1.1 4959f7132ae6b3fce773418b
ff3f76bd.cloudfront.net (CloudFront)..X-Amz-Cf-Id: qd94IcvHeVkALyYyDrl
_Kk2CX3MoUtdi2RRIC1zo5cpmgw5HcI8tNg==.......function getParameterByNam
e(name) {.. try {.. name = name.replace(/[\[]/, "\\\[").repl
ace(/[\]]/, "\\\]");.. var regexS = "[\\?&]" name "=([^&#]*
)";.. var regex = new RegExp(regexS);.. var results = re
gex.exec(window.location.search);.. if (results == null)..
return "";.. else.. return decodeURIComponent
(results[1].replace(/\ /g, " "));.. } catch (e) { return ""; }..}font>....

<<< skipped >>>

GET /content/themes/UI/Argon/images/upcarrot.png HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: image/png
Content-Length: 1230
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Mon, 10 Nov 2014 19:19:03 GMT
Accept-Ranges: bytes
ETag: "e0e223301bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Thu, 13 Nov 2014 16:41:44 GMT
Age: 2113
X-Cache: Hit from cloudfront
Via: 1.1 4959f7132ae6b3fce773418bff3f76bd.cloudfront.net (CloudFront)
X-Amz-Cf-Id: fCTZJfjuc4z39S-_m4uC52rmKZXG239M0g-BDWjwjWcwngMXC6Drww==
.PNG........IHDR...>.................tEXtSoftware.Adobe ImageReadyq
.e<..."iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0M
pCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmp
tk="Adobe XMP Core 5.0-c061 64.140949, 2010/12/07-10:57:01 ">
; <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"&
gt; <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xa
p/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="htt
p://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Ph
otoshop CS5.1 Windows" xmpMM:InstanceID="xmp.iid:17FFFBD50D3411E4A6619
04E1640E02A" xmpMM:DocumentID="xmp.did:17FFFBD60D3411E4A661904E1640E02
A"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:17FFFBD30D3411E
4A661904E1640E02A" stRef:documentID="xmp.did:17FFFBD40D3411E4A661904E1
640E02A"/> </rdf:Description> </rdf:RDF> </x:xmpmeta
> <?xpacket end="r"?>9P.K...BIDATx...?n.0..p.%..A,M .@.!#. .`
..S...E..........;...D(.......>.......... .'...?...


GET /driverdetective/dd.html?whitelabel=driversupport&utm_source=ddloc&utm_medium=en&utm_campaign=ddtracking HTTP/1.1
Host: downloads.drivershq.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Wed, 22 Apr 2009 18:24:34 GMT
Accept-Ranges: bytes
ETag: "05de39577c3c91:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Fri, 12 Dec 2014 13:39:29 GMT
Content-Length: 0
HTTP/1.1 200 OK..Content-Type: text/html..Last-Modified: Wed, 22 Apr 2
009 18:24:34 GMT..Accept-Ranges: bytes..ETag: "05de39577c3c91:0"..Serv
er: Microsoft-IIS/8.0..X-Powered-By: ASP.NET..Date: Fri, 12 Dec 2014 1
3:39:29 GMT..Content-Length: 0..


GET /AdServer/Pug?vcode=bz0yJnR5cGU9MSZqcz0xJmNvZGU9Mjk0NSZ0bD0xMjk2MDA=&piggybackCookie=f095a25f-0045-4490-8164-f197a9fa4acf HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: simage2.pubmatic.com


HTTP/1.1 200 OK
Date: Fri, 12 Dec 2014 13:39:53 GMT
Server: Apache/2.2.24 (Unix) mod_ssl/2.2.24 OpenSSL/1.0.1e-fips mod_fastcgi/2.4.6
Set-Cookie: KRTBCOOKIE_466=8233-f095a25f-0045-4490-8164-f197a9fa4acf&KRTB&14401-f095a25f-0045-4490-8164-f197a9fa4acf&KRTB&15149-f095a25f-0045-4490-8164-f197a9fa4acf; domain=pubmatic.com; expires=Thu, 12-Mar-2015 13:39:53 GMT; path=/
Set-Cookie: PUBRETARGET=dummy; domain=pubmatic.com; expires=Fri, 12-Dec-2014 13:39:53 GMT; path=/
Content-Length: 1
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=utf-8
 ..


GET /content/themes/UI/Argon/images/dsLogoNoCogWithBreak.png?v=1.0.0.13 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: image/png
Content-Length: 2851
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Mon, 10 Nov 2014 19:19:02 GMT
Accept-Ranges: bytes
ETag: "60e110301bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Tue, 02 Dec 2014 21:23:07 GMT
Age: 2113
X-Cache: Hit from cloudfront
Via: 1.1 8c79b62f48d3de38054fdcc1361128c3.cloudfront.net (CloudFront)
X-Amz-Cf-Id: 737pl0nROkWDsvesiJbz3cAQJ8DJAhBeFW_DEgY941zBM6sMkj6z5g==
.PNG........IHDR...............v.....tEXtSoftware.Adobe ImageReadyq.e&
lt;..."iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c061 64.140949, 2010/12/07-10:57:01 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CS5.1 Windows" xmpMM:InstanceID="xmp.iid:5A16CB5E0D1811E4BBA98899
D70A4A47" xmpMM:DocumentID="xmp.did:5A16CB5F0D1811E4BBA98899D70A4A47"&
gt; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:5A16CB5C0D1811E4BB
A98899D70A4A47" stRef:documentID="xmp.did:5A16CB5D0D1811E4BBA98899D70A
4A47"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
; <?xpacket end="r"?>.OBO....IDATx..\.n.F.^..J.*@..{@.t...1.&...
[email protected][email protected][email protected]<7C.)Q.).`a.".3........{.QG
.JA.|W.8y......=...c./X.?.....bx..b...........d.k...!G.....q....... F.
.[..../.z..0..........).U1..<G.....(r..XwL>...............B.I.C.
..t.>da,...J.......n.9..t..k.s.<M[......<..X......%....W.3.=.
.......F9>Z..`..\......E ;V-F...o..............X '......6!.Y...s.-
.r........LNw..).... .......>.....)...SC.......|Z.c.s,........Z...%
....9.~.....;.Y.......~.V.V,..t..q}..............^yqP]..z.R...5.&O..3.
..`.#K..<=.........7......z....w ....k..:A.x5.oDt.r.....D.d4...

<<< skipped >>>

GET /bundles/TSUIBase?v=1.0.0.13 HTTP/1.1

Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: text/javascript; charset=utf-8
Content-Length: 21489
Connection: keep-alive
Cache-Control: public
Expires: Wed, 02 Dec 2015 22:32:13 GMT
Last-Modified: Tue, 02 Dec 2014 22:32:13 GMT
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Tue, 02 Dec 2014 23:36:31 GMT
Age: 828198
X-Cache: Hit from cloudfront
Via: 1.1 8c79b62f48d3de38054fdcc1361128c3.cloudfront.net (CloudFront)
X-Amz-Cf-Id: 0HvA-H0N1jevUeAMmFu-Z5lGD3nVCJcHjei9QVKqXB0cuI-ZEIJxxw==
var Communication,Common,UIObjects,Controllers,ErrorHandling,UIMarkups
;(function(n,t){typeof define=="function"&&define.amd?define(t):typeof
exports=="object"?module.exports=t():n.returnExports=t()})(this,funct
ion(){function v(n){return n= n,n!==n?n=0:n!==0&&n!==1/0&&n!==-(1/0)&&
(n=(n>0||-1)*Math.floor(Math.abs(n))),n}function k(n){var t=typeof
n;return n===null||t==="undefined"||t==="boolean"||t==="number"||t==="
string"}function si(n){var t,i,u;if(k(n))return n;if((i=n.valueOf,r(i)
&&(t=i.call(n),k(t)))||(u=n.toString,r(u)&&(t=u.call(n),k(t))))return
t;throw new TypeError;}function d(){}var t=Array.prototype,u=Object.pr
ototype,ft=Function.prototype,o=String.prototype,et=Number.prototype,l
=t.slice,ot=t.splice,rr=t.push,fi=t.unshift,h=ft.call,a=u.toString,r=f
unction(n){return u.toString.call(n)==="[object Function]"},ei=functio
n(n){return u.toString.call(n)==="[object RegExp]"},b=function(n){retu
rn a.call(n)==="[object Array]"},f=function(n){return a.call(n)==="[ob
ject String]"},st=function(n){var i=a.call(n),t=i==="[object Arguments
]";return t||(t=!b(i)&&n!==null&&typeof n=="object"&&typeof n.length==
"number"&&n.length>=0&&r(n.callee)),t},oi=Object.defineProperty&&fu
nction(){try{return Object.defineProperty({},"x",{}),!0}catch(n){retur
n!1}}(),ht,i,e,ct,y,hi,ci,li,ai,vi,lt,at,vt,g,nt,pt,wt,kt,tt,it,ni,n,r
t,ut,ii,ri,ui;ht=oi?function(n,t,i,r){!r&&t in n||Object.definePropert
y(n,t,{configurable:!0,enumerable:!1,writable:!0,value:i})}:function(n
,t,i,r){!r&&t in n||(n[t]=i)};i=function(n,t,i){for(var r in t)u.h

<<< skipped >>>

GET /content/themes/UI/Argon/images/bigFixit.png HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: image/png
Content-Length: 10563
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Mon, 10 Nov 2014 19:19:02 GMT
Accept-Ranges: bytes
ETag: "929310301bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Thu, 13 Nov 2014 16:41:45 GMT
Age: 2113
X-Cache: Hit from cloudfront
Via: 1.1 8c79b62f48d3de38054fdcc1361128c3.cloudfront.net (CloudFront)
X-Amz-Cf-Id: VtrX4hTVgLyBvkaTaq0D3i0_SF7h_9qFnxKdbbg0NquzobeqaDrZ6A==
.PNG........IHDR...\............1....tEXtSoftware.Adobe ImageReadyq.e&
lt;..."iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c061 64.140949, 2010/12/07-10:57:01 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CS5.1 Windows" xmpMM:InstanceID="xmp.iid:98314EA32D4811E4B73FCE31
8E2CCA23" xmpMM:DocumentID="xmp.did:98314EA42D4811E4B73FCE318E2CCA23"&
gt; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:98314EA12D4811E4B7
3FCE318E2CCA23" stRef:documentID="xmp.did:98314EA22D4811E4B73FCE318E2C
CA23"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
; <?xpacket end="r"?>..G...%.IDATx..].x\.u.g..%K..-.....l..i...@
.%R...D.|m..Hi.}}%[email protected] .. <.^..6..l.b.?.....
;..V..>f......9.wm...sf...s..s.D.......DDDDD&i#.......'..3'..2...4.
.nA.....1y.[..`a.0*..w....\..O..D..Rw?3B)Z......_M...T....s..=....k...
..G>...33.3U).6.!.#....-_......< ...s=".sw..py..r...kh...d..4.pC
s....x...v...S...Fcu.......<..)..t........!,...Q...H &..I..6.om.H..
_.q]......&..<_x6...7....<P... ....H......W..W......RG?Fs..)..t&
|.PA...rq.P..C../....k.7?h<.M.. ......y.....f0....t%y@......=...H.M
.[h2)p..M....]-$.-.......j.I{....w......f5)x.!).H3BB_;.....m.5.x..

<<< skipped >>>

GET /content/themes/UI/Argon/images/fititButtonSprite.gif HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: image/gif
Content-Length: 8284
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Mon, 10 Nov 2014 19:19:02 GMT
Accept-Ranges: bytes
ETag: "df2719301bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Thu, 13 Nov 2014 16:41:45 GMT
Age: 2113
X-Cache: Hit from cloudfront
Via: 1.1 8c79b62f48d3de38054fdcc1361128c3.cloudfront.net (CloudFront)
X-Amz-Cf-Id: yVUTP1_XxwsgX8XYpP4D4aWYVuLdIFiaIGBdCRnDIwlnkyQe1PdSXQ==
GIF89a..h.......y.`V..D....P2..<..g.@,[email protected]. .....`..p...:..L..
3..K..`....`...C..X.....T..............<..R. z.Pl.@r.@...,|.I..A..Q
.....:.....2.....3.....|.@B........=....`E..`.0L..j.0K. ^.0...A..c.0^.
@>..E..=.....]. A..K..U.0..`Z.0>..5z./..d.0=..S..9.....4~.;.....
N. K..H..>..h. N.0N..3..U..*u.6.....].0D..H..A..Q..F..>..L.....E
[email protected].......`.....pp.0...U.0...8....p...:..Q..&p.N..E..8.
.V.....L..V........Y..... ..G..P..7..7..5..F..J..O..N..A..E..[..R..B..
4..T..5..7..>..K..\..I.....@..:..Y..G..M..P..;..Z..3..6..D..C..Q..V
..L..?..H..U..]..?..6..H..Y..<..Q..1..C.._..D..^..2..P..7..Z..0..M.
.V..G..>..^..@..]..I..3..5..K..1../..R..<..X.._..9..O..[..E..a..
I..F..A..E..D.....7..E....`Z..G..4..[..?....ps.Pk. _. ...G..S....P..pR
..............I..Y..m.PX..=..S..9..8..W..!..XMP DataXMP<?xpacket be
gin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="ad
obe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c061 64.140949, 2010/12/07-1
0:57:01 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/
22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="htt
p://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm
/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:Cr
eatorTool="Adobe Photoshop CS5.1 Windows" xmpMM:InstanceID="xmp.iid:31
A34351111B11E4A1A4F2EF6A48CBC6" xmpMM:DocumentID="xmp.did:31A34352111B
11E4A1A4F2EF6A48CBC6"> <xmpMM:DerivedFrom stRef:instanceID="xmp.
iid:31A3434F111B11E4A1A4F2EF6A48CBC6" stRef:documentID="xmp.did:31

<<< skipped >>>

GET /content/themes/base/images/favicon.ico?v=1.0.0.13 HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: image/x-icon
Content-Length: 1150
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Mon, 10 Nov 2014 19:19:02 GMT
Accept-Ranges: bytes
ETag: "72c832f1bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Tue, 02 Dec 2014 21:23:16 GMT
Age: 2115
X-Cache: Hit from cloudfront
Via: 1.1 8c79b62f48d3de38054fdcc1361128c3.cloudfront.net (CloudFront)
X-Amz-Cf-Id: VDdav1iMCTnBEwDjetcXmBb3RU9regPPedf4mXBw7MYLr41Tuuv57Q==
............ .h.......(....... ..... .................................
.......F.......j.......5...$..........................................
...~|..~|......................................................~|...}.
......~..~|..~|....M...........................p.~|..~|........8......
.&.....~|........>.......................>..}........$..........
...........~|...~....&...................D.~|.........................
...u.~|........(.....................~|............................~}{
y....y.........................~|........$...........................T
..b...L................3.....~|........>.......*.......y...........
.......L....Z...........".....~|..~|...............N.......z....B..x..
..........5.............~|.....}{y.......f.......t...............n....
...."...............P.......T......l........B...............F......x..
..............................(......~...............|.......F........
........................>...........n...0...p......D...............
.........................|.......................W....................
..........................,...F....Z...e.....................?........
.......'...........9...|...8...9............

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEApfEU0DWxeRF9Lv1AOMPzs= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=510512
Content-Type: application/ocsp-response
Date: Fri, 12 Dec 2014 13:39:53 GMT
Etag: "548ac533-1d7"
Expires: Fri, 19 Dec 2014 01:39:53 GMT
Last-Modified: Fri, 12 Dec 2014 10:36:35 GMT
Server: ECS (ams/D1A6)
X-Cache: HIT
Content-Length: 471
0..........0..... .....0......0...0.......>.i...G...&....cd ...2014
1211200000Z0s0q0I0... ............([email protected]....>.i...G...&...
.cd ...._.M.[........?;....20141211200000Z....20141218200000Z0...*.H..
...........Mf.......X.!0...8..............hl~e.D.[..e.._>zi...~.7..
...W S0H...jl./z]5#.ey...k#G.#x..7a....d..q(..u.Etm.. ..F..NY.NCq....$
w....,....I.c...4Tb.....~5.]...0.M...,.j..,.aL.. ..&..n.......#.L.Z..1
...../..JYG...%.OM*.1Q....E}|.4.BY_nb.?. 8...]G./1./;.?.:.W.
...
.



GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTtSK3dy3sA4g6EKqm0CfGsMDTPlgQUUOpzidsp+xCPnuUBINTeeZlIg/cCEAJwu3i4ZpYdN6xM1SVvBys= HTTP/1.1

Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=507985
Content-Type: application/ocsp-response
Date: Fri, 12 Dec 2014 13:39:53 GMT
Etag: "548abdc0-1d7"
Expires: Fri, 19 Dec 2014 01:39:53 GMT
Last-Modified: Fri, 12 Dec 2014 10:04:48 GMT
Server: ECS (ams/D1CA)
X-Cache: HIT
Content-Length: 471
0..........0..... .....0......0...0......P.s..)...... ..y.H....2014121
2095000Z0s0q0I0... .........H...{....*.....04....P.s..)...... ..y.H...
..p.x.f..7.L.%o. ....20141212095000Z....20141219100500Z0...*.H........
.....h..mr.....B..#....s\.......).G...8~;.........P.w...B.......Q.Y...
f.M}...... .7..9SB.....6D4.....:2j^..i.W.;...7...7.7.6..G.t.8(.."..g.
r.t...j...E~#....0=...c_Z....Z.n\.'....F...3..U.....f......1*3...0f[.m
.k....b.Y.9...s.E.g.Q.pJD..z...u.i.50...0J......MV.HTTP/1.1 200 OK..Ac
cept-Ranges: bytes..Cache-Control: max-age=507985..Content-Type: appli
cation/ocsp-response..Date: Fri, 12 Dec 2014 13:39:53 GMT..Etag: "548a
bdc0-1d7"..Expires: Fri, 19 Dec 2014 01:39:53 GMT..Last-Modified: Fri,
12 Dec 2014 10:04:48 GMT..Server: ECS (ams/D1CA)..X-Cache: HIT..Conte
nt-Length: 471..0..........0..... .....0......0...0......P.s..)......
..y.H....20141212095000Z0s0q0I0... .........H...{....*.....04....P.s..
)...... ..y.H.....p.x.f..7.L.%o. ....20141212095000Z....20141219100500
Z0...*.H.............h..mr.....B..#....s\.......).G...8~;.........P.w.
..B.......Q.Y...f.M}...... .7..9SB.....6D4.....:2j^..i.W.;...7...7.7.6
..G.t.8(.."..g. r.t...j...E~#....0=...c_Z....Z.n\.'....F...3..U.....f.
.....1*3...0f[.m.k....b.Y.9...s.E.g.Q.pJD..z...u.i.50...0J......MV...

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=575407, public, no-transform, must-revalidate
Last-Modified: Fri, 12 Dec 2014 05:33:31 GMT
Expires: Fri, 19 Dec 2014 05:33:31 GMT
Date: Fri, 12 Dec 2014 13:43:24 GMT
Connection: keep-alive
0..........0..... .....0......0...0........6?s....V....OlL".O..2014121
2053331Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5......
.A..2.....:...:......20141212053331Z....20141219053331Z0...*.H........
.....!......VV^.Fv.#.....<........../...=..G.`.S...c....P...X4C....
.l...?.d.s.....l.."...N..[[email protected].?..A..VD...&*....]
.%...d.....35..D....L.k...n......A..#..<Q7j...rT1`t>J.k.....b...
....BJ.K............=i.`..C...O.ve,%.h.y\C\.V{...3HH.IR..#.....#0...0.
..0..........<o&S.-S..}...e.30...*.H........0..1.0...U....US1.0...U
....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of
use at hXXps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3
Code Signing 2009-2 CA0...141205000000Z..150305235959Z0..1.0...U....US
1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2T
erms of use at hXXps://VVV.verisign.com/rpa (c)091<0:..U...


POST /postinstall/LogUIPageLoaded HTTP/1.1
Accept: */*
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Host: apps.driversupport.com
Content-Length: 65
DNT: 1
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: optimizelySegments={"176773665":"false","176809951":"direct","176875026":"ie"}; optimizelyEndUserId=oeu1418391590776r0.8981213483012467; optimizelyBuckets={}; optimizelyPendingLogEvents=[]; __utma=164611050.148068296.1418391591.1418391591.1418391591.1; __utmb=164611050.1.10.1418391591; __utmc=164611050; __utmz=164611050.1418391591.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

uuid=13682300-b037-44d0-9742-3c77ad4178ee×tamp=1418391591478
HTTP/1.1 200 OK
Cache-Control: private
Server: Microsoft-IIS/8.0
X-AspNetMvc-Version: 5.2
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Fri, 12 Dec 2014 13:39:51 GMT
Content-Length: 0
HTTP/1.1 200 OK..Cache-Control: private..Server: Microsoft-IIS/8.0..X-
AspNetMvc-Version: 5.2..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP
.NET..Date: Fri, 12 Dec 2014 13:39:51 GMT..Content-Length: 0..


GET /cm/f/out HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d.adroll.com
DNT: 1
Connection: Keep-Alive
Cookie: __adroll=e65dac886a3b760d94806f5afd818c65


HTTP/1.1 302 Moved Temporarily
Cache-Control: no-store, no-cache, must-revalidate
Date: Fri, 12 Dec 2014 13:39:52 GMT
Location: hXXp://VVV.facebook.com/fr/u.php?t=2592000&p=443937282305007&m=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU
P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Pragma: no-cache
Server: nginx/1.6.2
Set-Cookie: __adroll=e65dac886a3b760d94806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max-Age=157680000; Path=/
Content-Length: 112
Connection: keep-alive
Go to hXXp://VVV.facebook.com/fr/u.php?t=2592000&p=443937282305007&m=Z
TY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjUHTTP/1.1 302 Moved Temporari
ly..Cache-Control: no-store, no-cache, must-revalidate..Date: Fri, 12
Dec 2014 13:39:52 GMT..Location: hXXp://VVV.facebook.com/fr/u.php?t=25
92000&p=443937282305007&m=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU.
.P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"..Pragma: no-cache.
.Server: nginx/1.6.2..Set-Cookie: __adroll=e65dac886a3b760d94806f5afd8
18c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max-Age=15768
0000; Path=/..Content-Length: 112..Connection: keep-alive..Go to http:
//VVV.facebook.com/fr/u.php?t=2592000&p=443937282305007&m=ZTY1ZGFjODg2
YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU..


GET /cm/b/out HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d.adroll.com
DNT: 1
Connection: Keep-Alive
Cookie: __adroll=e65dac886a3b760d94806f5afd818c65


HTTP/1.1 302 Moved Temporarily
Cache-Control: no-store, no-cache, must-revalidate
Date: Fri, 12 Dec 2014 13:39:52 GMT
Location: hXXp://x.bidswitch.net/sync?dsp_id=44&user_id=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU
P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Pragma: no-cache
Server: nginx/1.6.2
Set-Cookie: __adroll=e65dac886a3b760d94806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max-Age=157680000; Path=/
Content-Length: 95
Connection: keep-alive
Go to hXXp://x.bidswitch.net/sync?dsp_id=44&user_id=ZTY1ZGFjODg2YTNiNz
YwZDk0ODA2ZjVhZmQ4MThjNjUHTTP/1.1 302 Moved Temporarily..Cache-Control
: no-store, no-cache, must-revalidate..Date: Fri, 12 Dec 2014 13:39:52
GMT..Location: hXXp://x.bidswitch.net/sync?dsp_id=44&user_id=ZTY1ZGFj
ODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU..P3P: CP="NON DSP COR CURa PSA PSD
OUR BUS NAV STA"..Pragma: no-cache..Server: nginx/1.6.2..Set-Cookie:
__adroll=e65dac886a3b760d94806f5afd818c65; Version=1; Expires=Wed, 11-
Dec-2019 13:39:52 GMT; Max-Age=157680000; Path=/..Content-Length: 95..
Connection: keep-alive..Go to hXXp://x.bidswitch.net/sync?dsp_id=44&us
er_id=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU
....



GET /cm/g/in?google_ula=1535926,0 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: d.adroll.com
Cookie: __adroll=e65dac886a3b760d94806f5afd818c65


HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate
Content-Type: image/gif
Date: Fri, 12 Dec 2014 13:39:53 GMT
P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Pragma: no-cache
Server: nginx/1.6.2
Set-Cookie: __adroll=e65dac886a3b760d94806f5afd818c65-g_1418391593; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max-Age=157680000; Path=/
X-Result: g.-1.-1.1535926.0.-1
Content-Length: 35
Connection: keep-alive
GIF87a.............,............Q.;HTTP/1.1 200 OK..Cache-Control: no-
store, no-cache, must-revalidate..Content-Type: image/gif..Date: Fri,
12 Dec 2014 13:39:53 GMT..P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NA
V STA"..Pragma: no-cache..Server: nginx/1.6.2..Set-Cookie: __adroll=e6
5dac886a3b760d94806f5afd818c65-g_1418391593; Version=1; Expires=Wed, 1
1-Dec-2019 13:39:52 GMT; Max-Age=157680000; Path=/..X-Result: g.-1.-1.
1535926.0.-1..Content-Length: 35..Connection: keep-alive..GIF87a......
.......,............Q.;..


GET /cm/l/out HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d.adroll.com
DNT: 1
Connection: Keep-Alive
Cookie: __adroll=e65dac886a3b760d94806f5afd818c65


HTTP/1.1 302 Moved Temporarily
Cache-Control: no-store, no-cache, must-revalidate
Date: Fri, 12 Dec 2014 13:39:52 GMT
Location: hXXp://idsync.rlcdn.com/377928.gif?partner_uid=e65dac886a3b760d94806f5afd818c65
P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Pragma: no-cache
Server: nginx/1.6.2
Set-Cookie: __adroll=e65dac886a3b760d94806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max-Age=157680000; Path=/
Content-Length: 85
Connection: keep-alive
Go to hXXp://idsync.rlcdn.com/377928.gif?partner_uid=e65dac886a3b760d9
4806f5afd818c65HTTP/1.1 302 Moved Temporarily..Cache-Control: no-store
, no-cache, must-revalidate..Date: Fri, 12 Dec 2014 13:39:52 GMT..Loca
tion: hXXp://idsync.rlcdn.com/377928.gif?partner_uid=e65dac886a3b760d9
4806f5afd818c65..P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"..P
ragma: no-cache..Server: nginx/1.6.2..Set-Cookie: __adroll=e65dac886a3
b760d94806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GM
T; Max-Age=157680000; Path=/..Content-Length: 85..Connection: keep-ali
ve..Go to hXXp://idsync.rlcdn.com/377928.gif?partner_uid=e65dac886a3b7
60d94806f5afd818c65..


GET /pagead/viewthroughconversion/996887577/?random=1793213668&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: googleads.g.doubleclick.net
DNT: 1
Connection: Keep-Alive
Cookie: id=caebd6253000002||t=1384780400|et=730|cs=002213fd480c4c2631f7c541a4


HTTP/1.1 302 Found
P3P: policyref="hXXp://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Fri, 12 Dec 2014 13:39:51 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Location: hXXp://VVV.google.com/ads/conversion/996887577/?random=1793213668&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&cdct=2&convclickts=0&random=3718956492
Content-Type: image/gif
X-Content-Type-Options: nosniff
Server: cafe
Content-Length: 42
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
GIF89a.............!.......,...........D.;HTTP/1.1 302 Found..P3P: pol
icyref="hXXp://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="C
URa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV O
TC NOI DSP COR"..Date: Fri, 12 Dec 2014 13:39:51 GMT..Pragma: no-cache
..Expires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache, mus
t-revalidate..Location: hXXp://VVV.google.com/ads/conversion/996887577
/?random=1793213668&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9
hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u
_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=
0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?c
art=https%3a%2f%2fsecure.driversupport.com%2fregistration%
2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b0
37-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vi
s=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&cdct=2&convclickts
=0&random=3718956492..Content-Type: image/gif..X-Content-Type-Options:
nosniff..Server: cafe..Content-Length: 42..X-XSS-Protection: 1; mode=
block..Alternate-Protocol: 80:quic,p=0.002..GIF89a.............!......
.,...........D.;
....

<<< skipped >>>

GET /pagead/viewthroughconversion/933633792/?label=xn2YCKKm-1UQgL6YvQM&guid=ON&script=0&ord=3418199282196799&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0&random=603867099 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: googleads.g.doubleclick.net
DNT: 1
Connection: Keep-Alive
Cookie: id=caebd6253000002||t=1384780400|et=730|cs=002213fd480c4c2631f7c541a4


HTTP/1.1 302 Found
P3P: policyref="hXXp://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Fri, 12 Dec 2014 13:39:52 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Location: hXXp://VVV.google.com/ads/user-lists/933633792/?label=xn2YCKKm-1UQgL6YvQM&script=0&ct_cookie_present=false&random=1583785290
Content-Type: image/gif
X-Content-Type-Options: nosniff
Server: cafe
Content-Length: 42
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
GIF89a.............!.......,...........D.;HTTP/1.1 302 Found..P3P: pol
icyref="hXXp://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="C
URa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV O
TC NOI DSP COR"..Date: Fri, 12 Dec 2014 13:39:52 GMT..Pragma: no-cache
..Expires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache, mus
t-revalidate..Location: hXXp://VVV.google.com/ads/user-lists/933633792
/?label=xn2YCKKm-1UQgL6YvQM&script=0&ct_cookie_present=false&random=15
83785290..Content-Type: image/gif..X-Content-Type-Options: nosniff..Se
rver: cafe..Content-Length: 42..X-XSS-Protection: 1; mode=block..Alter
nate-Protocol: 80:quic,p=0.002..GIF89a.............!.......,..........
.D.;..


GET /scsi.png HTTP/1.1
Host: 70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com
Connection: Close


HTTP/1.1 200 OK
Last-Modified: Fri, 24 Oct 2014 17:06:43 GMT
ETag: 5c2bcf85387ad7cddd68297ebf7ae2e9
Content-Length: 40592
Accept-Ranges: bytes
X-Timestamp: 1414170402.10987
Content-Type: image/png
X-Trans-Id: tx56f4a3f2d1a54e6ba9955-00544a882aord1
Cache-Control: public, max-age=302
Expires: Fri, 12 Dec 2014 13:44:48 GMT
Date: Fri, 12 Dec 2014 13:39:46 GMT
Connection: close
.PNG........IHDR.......,......i......PLTE......aUVQFF.................
....XLN...eYY...UJJ...LAA=jG.........\RR...[NR...DnLG<;...1,-# !<
;aCEtP)'(4433_>#..6gBLxV...SRP@569<5h]^ @....:/-...EDC[PJSyZwkjM
KK, .EcHnaa:W>0W9*2*EYC`_\...38)...pffK[L<rL...MpSaSO@N>2'%&
ZYV7J;...5E3JgP@D:j}j=<=btc...-L6...T._}.{......~po.%.n^[...a.e...
...Z|_fgb..._tYHPFXl[TbT.{xK.[f.mvfc}xsWnQ...JK=\_Nq.us.o......&X4....
..QeJuspC}T..s.=&....1.............(7"*c;..............zTTE...........
...P.2&[.g2oE......B<.{.wqqbi[N...o.k.%...v~..s.v..I...........H...
......lnj.......wePA8...s.|...giVe.q..@...!N,...........X.....j..S:E..
....y..F.....c.......u:.........8zO;P...Of.Z%..9QI........0..UHL*h]&.r
#.....L..825.R[3\L:.....9udQ.....dQ<&.nX.....`|.....TM....iX>C1.
{h/....................k...............jC....rm@twW....\......d.....k.
.t6......KIDATx..}]L[g...8.>...a|X.,c.W.'s....6.$...B...."V0qHl..&6
.S.a0....$..... c.....&.."E.pSE.^q......S..%..H.9.gH..G..?;3~..IZ.?~..
}...V......>..... ../. .<!yB..............y.' OH._.....yB.......
......x*(............C...(..:..zAI.@$.... ...........yB~.T.Y....#.."..
XT...y.p.!.*.r...1..UUUyB.'..#........"0".......p.AI.....n!...B.......
..b.^........1O.....h# O.....8G....uG.H[.....>.9....U...?Wy(o6~.h..
@G....J...0V...U.....H.-..n..R......yB...i;..|.s.#y...E.dw9..z]....H..
%.`$.<!.1.*.......BI^.......x..1.c.X.bY..././..8..'.{..........F67.
<.NEl.g.. .My.q.o`.....52Ry. ...E....A.%..\|.......}...<...P..bX
o<...[,...Be%....w..3..".E.PT.F..h.!...........~..6...h4......F

<<< skipped >>>

GET /j/roundtrip.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: a.adroll.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
x-amz-id-2: faWcDW2Or4K/MxJu6HBovpddkEjKhZjg1MDJesq20bn5qCKJfFyqnWIny1eRnkpi
x-amz-request-id: CAAD8BD6A496BEB4
Last-Modified: Tue, 14 Oct 2014 18:17:00 GMT
ETag: "7fe20f624c256dfa94db3f8fd2a8c04b"
Accept-Ranges: bytes
Content-Type: text/javascript
Server: AmazonS3
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 4804
Cache-Control: must-revalidate, max-age=238
Date: Fri, 12 Dec 2014 13:39:52 GMT
Connection: keep-alive
...........;k..6... $..I..#.. .....m\..]{RW[.Y......THj.s...v.$.>&.
.U]*e..F....X.c..(M,...O7..di.{..t.">.......?.....n...b... v..%A..l
. .C.'..~O.&a.3....'9.1..Yz#.g....."...,v....n2...nn.b..\....Z.M..1.N.
..%..1K..(..C<. vQ>....Hy.[6.........A..{...P......?./Y....Ep..O
.....W.....*?.....]..,:..gO.,...i ... ]....8......3...n..*.{.^d.y.6..y
.qa.....`.....G.3...[........e/ .8...2..S%BS....".$..(..d..A..![..0d..
.......nI.......l.7.f...~..?S..... ...p...g..Hl.......i.#Kr...^.. ...&
lt;Mo"q.0?.A.D...R.l..b.....nPr...P...tR.(..K.,\X..K.bBp:1.......Ea.M!
6.....%.......a/.[..W=t...d<...T'j...w.F..h.m..8S..\..E-^.>YK.Z.
V........f..?..|^..O.....rKh]....[r.s.YV_..G{Y..6.r....l...f....Cr....
.j..`.....S......K........}....J....,8.....u..a..)...{.{$O....J...X..,
*...\do.m*?.... ..p.....f.0..... v. ../..~..b1..(..%...i~.#`...._.p.`.
..z.1..t....S..gq...8..v..f..3P.$....)>.....u....jfQN.U.....`.....\
..3.....{<N.6GH ...,.[.e";..K..Q%..T..2T...Z..X.9..H.i.....[..i..Bj
...HN...G?/.(...)..gc..*...].9.#4.Tab..4..F....4.O. ...qy..._.5.lB<
...q.b^{h...H.b7Y.4.Q...l.b.." pLM.i......8..T.`)7...D......&....i@.:.
pG.x........../9.v,.%.n._..T............|.........."......;.!.......#.
n..{ .`Q...vs......L..w;..$.&..O..*.7#...`....m#.........md{"28.&.....
.(..Y.d..$..tKC.h.........K...7Z[..bC..5.Q.....F..3.......(.-..l......
.4.vB.%..dpm;rB..P.............$T..>A&@. .{....ZR.=.a.../...J.=)...
.".e....."M.~..a..y....FE....q....{...V2 ." .....L...E>.*..../=.D8.
.e.rW..{p..o.T.S{!WL..Z........0......%.........@Y.....;..qt.6 ...

<<< skipped >>>

GET /pixel/ID6YJCUG4BA7BHFUIYCHOX/MJDFCCTA3JETLDLZWCFYDD/IBURATUZTNHBFDLWQBB66R.js HTTP/1.1

Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: a.adroll.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
x-amz-id-2: SUN/ukBa1WvDj4rZgMbrJHo7MGPcefQdv4rDyPRe0ITeWerukSCPXKYVaULl5EBh
x-amz-request-id: 65C7DD73B30BFEF0
Last-Modified: Mon, 17 Nov 2014 18:36:37 GMT
ETag: "56cd4083f0fe771e2ca4e10370446b91"
Accept-Ranges: bytes
Content-Type: text/javascript
Server: AmazonS3
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 927
Cache-Control: must-revalidate, max-age=300
Date: Fri, 12 Dec 2014 13:39:52 GMT
Connection: keep-alive
...........W{o.6..?.B.`Xn.....na....[.m.d....M.$.4)P..`.w...8n....y..[
&....y...f.......?v,kF.....`.,..cc...m...S4..4m.(.u..VFQ%Z..V)i[/...zY
Y#L....)..m6S...vAnS5m....TL.a.B?.....)...-.......~f..6g..rJ/..f....}.
.O.Ql.....je..ZP..b.H@>[email protected]'...sfb...l/Y...1.(6.q.O.A.J6..K..
.P%....LBJI.N..S>...Ni...F....I....b..2Q....(D*...R...P..i5.......P
.u.FM !...t.jWe.E......6x.v..l7..v.[l7<.=.6..G[..5......@3...!.0Q.c
.....r....{.^..{.......Q.....7\.(...~.^_.^]..:?..~u...p..].8..{..Q..S"
(...7 w9R*./....S(..nB"[email protected].
L...{s.....>..H.F.n.....=.Qq4...V ..J......i$..}...AB...F.^..u}.Q..
....q.................._........3....NN.....9.w.L...w...3..8.o]>>
;.XAP.......;.r6pn:....-..e&.V......&.O..... ....-..h.......Z.2......D
.......y..jP...05)8.......n..Y..U.:..F..|]m=...:./.X5........z........
.!N%X..\J..Wg....... .|tZm.$ .(..9 [email protected].`...O&...b..kzT.
).......).(RL......-w.N....L938|...HTTP/1.1 200 OK..x-amz-id-2: SUN/uk
Ba1WvDj4rZgMbrJHo7MGPcefQdv4rDyPRe0ITeWerukSCPXKYVaULl5EBh..x-amz-requ
est-id: 65C7DD73B30BFEF0..Last-Modified: Mon, 17 Nov 2014 18:36:37 GMT
..ETag: "56cd4083f0fe771e2ca4e10370446b91"..Accept-Ranges: bytes..Cont
ent-Type: text/javascript..Server: AmazonS3..Vary: Accept-Encoding..Co
ntent-Encoding: gzip..Content-Length: 927..Cache-Control: must-revalid
ate, max-age=300..Date: Fri, 12 Dec 2014 13:39:52 GMT..Connection: kee
p-alive.............W{o.6..?.B.`Xn.....na....[.m.d....M.$.4)P..`.w...8
n....y..[&....y...f.......?v,kF.....`.,..cc...m...S4..4m.(.u..VFQ%

<<< skipped >>>

GET /content/themes/UI/Argon/ScanResults.css?v=1.0.0.13 HTTP/1.1
Accept: text/css
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: text/css
Content-Length: 13665
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Tue, 02 Dec 2014 20:43:09 GMT
Accept-Ranges: bytes
ETag: "3447e59470ed01:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Tue, 02 Dec 2014 21:23:07 GMT
Age: 2114
X-Cache: Hit from cloudfront
Via: 1.1 6afe85420fda9e3e25f861dba6a40bab.cloudfront.net (CloudFront)
X-Amz-Cf-Id: x8QMeTRS4dx7BYkZKC8EvcM1uAbuL53s61z-t1yGNSbGOHm7CtTE4Q==
.../*General*/..html{min-width:100%; min-height:100%; margin:0px; padd
ing:0px;}..body {.background: #747473; /* Old browsers */..background:
-moz-linear-gradient(top, #747473 0%, #9d9e9e 100%); /* FF3.6 */..b
ackground: -webkit-gradient(linear, left top, left bottom, color-stop(
0%,#747473), color-stop(100%,#9d9e9e)); /* Chrome,Safari4 */..backgro
und: -webkit-linear-gradient(top, #747473 0%,#9d9e9e 100%); /* Chrome
10 ,Safari5.1 */..background: -o-linear-gradient(top, #747473 0%,#9d
9e9e 100%); /* Opera 11.10 */..background: -ms-linear-gradient(top,
#747473 0%,#9d9e9e 100%); /* IE10 */..background: linear-gradient(to
bottom, #747473 0%,#9d9e9e 100%); /* W3C */..filter: progid:DXImageTr
ansform.Microsoft.gradient( startColorstr='#747473', endColorstr='#9d9
e9e',GradientType=0 ); /* IE6-9 */..min-height:100%;..min-width:100%;.
.position:relative;..margin:0px;..padding:0px;..}..#wrapper {width: 98
0px; margin: 0px auto; height:100%; padding:0px; box-shadow:0px 0px 20
px #555;}..#header {height: 55px;.width: 100%; background-color:#eeeee
e;}..#footer {height:75px; width:940px; background-color:#eeeeee; posi
tion:relative; min-height:100px;padding: 20px;}...logo-disclaimer{ wid
th:100%; display:inline-block;padding: 5px 0;}...logo-disclaimer p{ co
lor:#777; font-size:12px; text-align:center; line-height: 16px;}...pri
ce-disclaimer{ width:100%; display:inline-block;padding: 5px 0;}...pr
ice-disclaimer p{ color:#777; font-size:12px; text-align:center; line-
height: 16px;}..#content { width: 940px; background: #f6f6f6; padd

<<< skipped >>>

GET /content/themes/UI/Argon/images/severityIcon.png HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: image/png
Content-Length: 1223
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Mon, 10 Nov 2014 19:19:03 GMT
Accept-Ranges: bytes
ETag: "de7d1e301bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Thu, 13 Nov 2014 16:41:45 GMT
Age: 2113
X-Cache: Hit from cloudfront
Via: 1.1 6afe85420fda9e3e25f861dba6a40bab.cloudfront.net (CloudFront)
X-Amz-Cf-Id: SfqhbXZjYra1dT7kbyLdewrgZsehI-HaziezgSNFnQqbyB8Tg6b_Ug==
.PNG........IHDR.............X.......tEXtSoftware.Adobe ImageReadyq.e&
lt;..."iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c061 64.140949, 2010/12/07-10:57:01 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CS5.1 Windows" xmpMM:InstanceID="xmp.iid:7602415B111E11E4B60CEC86
9B22D92B" xmpMM:DocumentID="xmp.did:7602415C111E11E4B60CEC869B22D92B"&
gt; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:76024159111E11E4B6
0CEC869B22D92B" stRef:documentID="xmp.did:7602415A111E11E4B60CEC869B22
D92B"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
; <?xpacket end="r"?>..?....;IDATx..U...0......c...v./.v.V.V.V.O
[email protected]#b.vo...i<S.E1D...$I...... D.3..6?.M.....*....
0...(.>s.7?e.6..M.f`U:3"...L{K..L*.hf.T..L....#d..G.Q.%.e....<..
.v....*Dr0.WN.v P.a6...I.1f.y..l.k.4;sB..fT.F.c.,D.o.;..B..K:....w..f.
V..hg..Nw.t ...05Ix....`......bd....................T..E....U..[...=..
_....S...J4t....D....IEND.B`...

<<< skipped >>>

GET /custom/drivershq.jsp HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: VVV.upsellit.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: nginx
Date: Fri, 12 Dec 2014 13:39:52 GMT
Content-Type: application/x-javascript
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Set-Cookie: JSESSIONID=52B2CC7EBC5C5801C8CA16072CC9EBFA; Path=/
Pragma: No-cache
Cache-Control: no-cache,no-store
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: uid=CgoKBlSK8CglWUCswlCMAg==; expires=Sat, 12-Dec-15 13:39:52 GMT; domain=VVV.upsellit.com; path=/
P3P: policyref="/w3c/p3p.xml", CP="NON DSP LAW CUR ADMi TAIi PSAi PSD TELi OUR SAMi IND PHY DEM ONL STA NAV UNI LOC COM CNT"
Content-Encoding: gzip
6c7.............Xms.F..,.........^.0...4..eZ..d%..$.# .a.S..w.8.@..:m&
3.....gwo...5.Y.|tCB.r.4.<....Hg:....,(..R.N..* Z.....v.....$.$..f.
...w..a.Y.3Xj....4........Ln.V...`.4.E.......FAp.:*.9jKHa....?g4.fB..S
ReQ.....$b.'[email protected]....}.1....gJO.....:.B.....
.v,#M..i.H..Lc.qd.......#[email protected],.AH........f..."U.AF.].....
O.*|..A.....Z~d.9.2uD..hTa...."......N.e..;B...E....$t=.....I.D.... .:
y"..E...dFn.A.2..xu4QZ.J.....&............SH...4...... 7....\./.0.\n.1
.d.r.i .<".^..(e.J.......W.....\...}.0...J.xEn....u..........R9;...
...S7.9Yb........BxD....Sm.L.......4.....D..!b....U.P.x..&....1...L.k.
..g.G.....R..A/.....'........M].P.w.Z"....03..e..U..].. ......R.4.&4..
Z>.......A..H...tD.U..N>.-[...).:.k..E=R........Q-X..../........
....o.....8.,.......yQ.).T...}.C..].".......E.(....H......;..S.Eu...i.
c.lf~.OR..*Z......-....(.D....i.u,0.. .....F....J.G.A...D!..T.x..x...w
.%ILyg\..9.........d......w.dIJB......!....V7..[/....J...ge..B-..Bww[.
. ~..'~...B%I....t.......n.....=Zz...Ed..\..a..u...x.h....0..k........
....w..k.>..l..mu...m....P.........9...l....>N..V..2.~G>.A..*
...!..y....u..^.-`PuHX..<^. Y..^..(..9h..)...e...}lNFU~.6:.h...(..f
DJ.S.@^.r/.....k.S.e.o...g.....k.r.....R.C.v{.\...D.)6?.w.Oi..s.....-.
(.......#..........t.w.4^.oTj.^.YU\......_..ZJ......"$.O.m..*^......?.
z.......|Fp....Q>.~C.z-.........$ ...m.6$.l....s..........j....j.T.
HA .......||.=>....wx.m.....;-..'..JF1-9....4 ...0.JC...&.n..m^....
C...mvm...!..0 ...P...Y.~...f..9 ...v... .........t.u..2^.(X......

<<< skipped >>>

GET /hound/monitor.jsp?qs=222263239272274311291323337332321338325289311328311346277328329&siteID=10238 HTTP/1.1

Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: VVV.upsellit.com
DNT: 1
Connection: Keep-Alive
Cookie: JSESSIONID=52B2CC7EBC5C5801C8CA16072CC9EBFA; uid=CgoKBlSK8CglWUCswlCMAg==


HTTP/1.1 200 OK
Server: nginx
Date: Fri, 12 Dec 2014 13:39:52 GMT
Content-Type: application/x-javascript
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Pragma: No-cache
Cache-Control: no-cache,no-store
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Encoding: gzip
afc..............kw.F.sr..Ah.A.6J.m......6.@)...M.9.4.....Fy....;..i.(
.|[.r..}.}..m>..|.y.UNS......sTUEu^7........=..4y..".`5..}...o.z:..
M...Y...._.*p.|...N....i..._&...5....q1w....y..<z.t.A..S]..X......-
....b0...D..G..3.%.{.bR....8."..!..~}s.M.Es.....N...lJ.(....$..E.q*.WS
./..-.....p=......2..V.............U..p......(.z..P.G%.{...'..........
.)......,...%..].......\5..`..|V..q.pV....uZ.. J...Kw..`.....3P..9F.HP
#|...H..e....R?.m.:.d.9..n.c.W.&..Y.m.......6!>[email protected].\[email protected]|
w...|..$...G...'.....I.0.....x6J.......!...r....c.]....d...... [email protected]
.....0.....R;|q..<`C..M......c.-.....o....\...AY...V...........Q...
.A....!(v...J...4..........hP9.;....^,..C....*IOV.7.........._..}.....
..r....,....[U.a.~.(>...C.yX....:..O..`as.=..S..b.Y.8."C.L..`.s..w.
[email protected]....?.=>.U.O9}[email protected]..%.<JsBQ....s
[n.0@b._iL.....Q ..#.^RB|...'.K.V.u=...E*b..........?..YT...v0.{..0...
...gg.sz..bY.....n..::...LRV....)..y..3b.?.#...x%[email protected]
.I.%$99W..Qh.rB..h..%[email protected].=......u....I.e.j$..
....Y*..!.i..I.Z6..ZU...|c....C.....<.n.~.......$.vH.. ....F...5n&.
.\.D2..D/..dv..F.k.,]KH....Y=-...1...d.n......f.W.w.........<|.....
~8:.....:.wt.CTLg..l.... ..........XZ8....F>."Po......6..>,.m_..
9.....N..2#..H....ia$...1.".D.0BtH..v..R...m......R...n2.&...........
.......L.-.)!..z4a'.. ..3..5..(..#Uy.U^...!.Q........$..(H\0.LC8.mS.T.
.....].*.9...5..]J.%.oU....>m.U9k..e.......-.v^....}....r.9yH..s.q]
.......{5;..V..&...O....SL'. ...(....=........C..B.....G..........

<<< skipped >>>

GET /baltimoreroot/MEUwQzBBMD8wPTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom/nYB45SPUEwQU5Z1ZMIJHWMys+ghUNoZ7OrUETfACBAcnqkY= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.omniroot.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: application/ocsp-response
Date: Fri, 12 Dec 2014 13:40:54 GMT
Last-Modified: Thu, 11 Dec 2014 15:29:57 GMT
Server: ECS (ams/49BB)
X-Cache: HIT
Content-Length: 1406
0..z......s0..o.. .....0.....`0..\0......`;.l.uZ..k.F..^|A.Tb..2014121
1094629Z0g0e0=0... ........./Ev..Y..].....x.#......Y0.GX....T6.{:..M..
..'.F....20141203203011Z....20150303203511Z0...*.H....................
..L..f.Y......C\x....Z....X^....f..Z...u.q..r.(dVv....P..E~j;..PL.C...
Rf..[.......r.Y&/.P.d...0......T...{...(........W..$..^.lP3pZ6...PQ`..
......J~...=..55..D...P.\?8.N..v....(..$y.~y...z../0....V.\.\@E.lG..W=
o1V.kxF.xR.......}$...............W{..v....0...0...0...........'..0...
*.H........0Z1.0...U....IE1.0...U....Baltimore1.0...U....CyberTrust1"0
..U....Baltimore CyberTrust Root0...140122184236Z..150122184140Z0G1.0
...U....US1.0...U....Cybertrust1#0!..U....Cybertrust-Validation-20110.
."0...*.H.............0.........?....(Fb....G... ..=..(L..wK...04..I..
....C...1.Z......U.$b.f..Pa.....S...#..B.........^T..IP8..........h8GM
..*.4.MP..../[email protected]....
$..@@....q2...Uby.e......D....lf...C....ZP}O......7...mM..c.g..j.\.>
;.O....G.A........0..0... .....0......0...U.......0.0...U...........0.
..U.%..0... .......0...U.#..0.....Y0.GX....T6.{:..M.0...U......`;.l.uZ
..k.F..^|A.Tb0...*.H.............. .p.)...09W..Z.......]....}.:..Vr...
..c..U..:V^.O.....<...b*5.c.\.fF./....5'.>./ iS..R0..)..*.!..q.h
.T..ul.}&.......`.1".~.U....rB.BR.s..x..o..Y.......).4:.[.9.=....x...'
.f..\ [email protected]:J!.hRH..!z2DtL.s2.r.....Yi~..E..AzO..i.."N.$j...
b...o..i."{(3....

<<< skipped >>>

GET /pki/crl/products/MicCodSigPCA_08-31-2010.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com


HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Thu, 13 Nov 2014 06:02:42 GMT
Accept-Ranges: bytes
ETag: "88cab6f7ffcf1:0"
Server: Microsoft-IIS/8.5
VTag: 791936916300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 554
Cache-Control: max-age=900
Date: Fri, 12 Dec 2014 13:43:23 GMT
Connection: keep-alive
0..&0......0...*.H........0y1.0...U....US1.0...U....Washington1.0...U.
...Redmond1.0...U....Microsoft Corporation1#0!..U....Microsoft Code Si
gning PCA..141112173206Z..150211055206Z.a0_0...U.#..0..........X..7.3.
..L...0... .....7.........0...U......W0... .....7......150210174206Z0.
..*.H................].`...D..9.>LO.ey...Qx%.^.P.& ...D.......b}.K.
.[.....5.m....).....H..6R....G/ju.........:..A.#.9!......D5...|".w.x..
=.u..X6.7{..).XN....g......B.8.!&...........<7fS$..........t<X)%
.b([email protected]... ,...K\....U1cp).........y.T..?rm.t..Y.}.E..
-@...


GET /seg?add=1602123&t=2 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: ib.adnxs.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 302 Found
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="hXXp://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
X-XSS-Protection: 0
Set-Cookie: uuid2=0; path=/; expires=Thu, 12-Mar-2015 13:39:52 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: sess=1; path=/; expires=Sat, 13-Dec-2014 13:39:52 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=1752085521283445628; path=/; expires=Thu, 12-Mar-2015 13:39:52 GMT; domain=.adnxs.com; HttpOnly
Location: hXXp://ib.adnxs.com/bounce?/seg?add=1602123&t=2
Content-Type: text/html; charset=utf-8
Date: Fri, 12 Dec 2014 13:39:52 GMT
Content-Length: 0
....



GET /pxj?bidder=172&seg=802787&action=setuid('ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU') HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: ib.adnxs.com


HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: policyref="hXXp://cdn.adnxs.com/w3c/policy/p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NAV DEM STA PRE"
X-XSS-Protection: 0
Set-Cookie: uuid2=0; path=/; expires=Thu, 12-Mar-2015 13:39:53 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: sess=1; path=/; expires=Sat, 13-Dec-2014 13:39:53 GMT; domain=.adnxs.com; HttpOnly
Content-Length: 43
Content-Type: image/gif
Date: Fri, 12 Dec 2014 13:39:53 GMT
GIF89a.............!.......,[email protected]..;HTTP/1.1 200 OK..Cache-Cont
rol: no-store, no-cache, private..Pragma: no-cache..Expires: Sat, 15 N
ov 2008 16:00:00 GMT..P3P: policyref="hXXp://cdn.adnxs.com/w3c/policy/
p3p.xml", CP="NOI DSP COR ADM PSAo PSDo OURo SAMo UNRo OTRo BUS COM NA
V DEM STA PRE"..X-XSS-Protection: 0..Set-Cookie: uuid2=0; path=/; expi
res=Thu, 12-Mar-2015 13:39:53 GMT; domain=.adnxs.com; HttpOnly..Set-Co
okie: sess=1; path=/; expires=Sat, 13-Dec-2014 13:39:53 GMT; domain=.a
dnxs.com; HttpOnly..Content-Length: 43..Content-Type: image/gif..Date:
Fri, 12 Dec 2014 13:39:53 GMT..GIF89a.............!.......,........@.
.L..;..


GET /bat.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: bat.bing.com
DNT: 1
Connection: Keep-Alive
Cookie: SRCHD=MS=3187714&SM=1&D=3093912&AF=MSN005; SRCHUSR=AUTOREDIR=0&GEOVAR=&DOB=20131118; MUID=1785AC2FD94664211AC0A9A6DD466620


HTTP/1.1 200 OK
Content-Type: application/javascript
Content-Encoding: gzip
Last-Modified: Tue, 04 Nov 2014 20:07:51 GMT
Accept-Ranges: bytes
ETag: "805d926bf8cf1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/8.0
Access-Control-Allow-Origin: *
Date: Fri, 12 Dec 2014 13:39:50 GMT
Content-Length: 2542
............ko.8..(.`HkZ..n.;;..M.mp..m.(...lQ2.2.R.. [email protected].
....[.r.}.....I.X..R0.^=.R....y.$.....d....T....X...>b..M$..`..|..Q
I.9.#.x...p_r..............p}K~...?...Rz.G..A.T/,..*e..'...<.......
.xL..i<[email protected]....|%...._...@.........=-......f...~.
....^X.)./.... 2^..z..B)..k........y...C...h...}O>...a.[.m...'.....
.....J...9.de.....Am.....8.....y/e....h)[email protected]%b.K........8..X.
.'.w.F...p@}Tm7.....]....!..'.H.=.S.j.V^......|.}pm."..I...5.... .....
OW.....$...q...5..r......_....Ac6X.?).:...I...|.).a!r.o.. ....L.0..THV
Rq....'..Z.y)...9E.^....`#...mn. .}[email protected]..#${...=....o..u.t.j^...
....:.,..rb#........l...:.HFj...^...,....J...%;.^eYo.......T.U..u.&...
..."...,....S.........^....^........X......XG~?...h.^.k..A.{......4.Y.
x......,....!\...R..R...@?......)....1x.(..C...O......,X......v.h.V...
..........2.B......V...cA}..4.8.| A.M%..J..Q.!&.r.... oGY...[..,z\....
..`......!~.P.Y..U..O..k..Q.>..0*......b........d..C...P......1Hj.&
LP#..>..4z|...,Fl.*~X.j..%sP..'|J.x....[....."[email protected]<0..",...A..
*..2x.}...........}..T..2....W...s.s..U....<..Q2.y../...p.nPW.9....
N.....:s|.....f.....jf....<.Q.2...%..e.A.e.9C.b....A.....]$...R..$.
<?.#.......Z..y>gU..%TJ.I....(s*.....W...EXh.. Jb...WU.)..#..8..
U.$,...............5.s..-....L.}...<.jq....Tw.p[5...~jC..5...2G.C..
P{u4..Pu..-...V.(o".VP.<?..3{.r.H'5J....).....Sh)|.a..>/...W..wm
@[email protected].....|.....s.v^u..:...nw][email protected].]..B..L....E
./ ..l..e...I.*.@....}......f......a..YrVS.y...}>...". .}$.. .

<<< skipped >>>

GET /action/0?ti=4002897&Ver=2&mid=d2180211-1d49-87f4-90bc-7a999623f1d5&evt=pageLoad&pi=0&lg=en-US&sw=1683&sh=901&sc=24&tl=DriverSupport - Available Driver Updates&p=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&r=&rn=122091 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: bat.bing.com
DNT: 1
Connection: Keep-Alive
Cookie: SRCHD=MS=3187714&SM=1&D=3093912&AF=MSN005; SRCHUSR=AUTOREDIR=0&GEOVAR=&DOB=20131118; MUID=1785AC2FD94664211AC0A9A6DD466620


HTTP/1.1 204 No Content
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Length: 0
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Server: Microsoft-IIS/8.0
Access-Control-Allow-Origin: *
Date: Fri, 12 Dec 2014 13:39:50 GMT
HTTP/1.1 204 No Content..Cache-Control: no-cache, must-revalidate..Pra
gma: no-cache..Content-Length: 0..Expires: Fri, 01 Jan 1990 00:00:00 G
MT..Server: Microsoft-IIS/8.0..Access-Control-Allow-Origin: *..Date: F
ri, 12 Dec 2014 13:39:50 GMT..


GET /cm/x/out HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d.adroll.com
DNT: 1
Connection: Keep-Alive
Cookie: __adroll=e65dac886a3b760d94806f5afd818c65


HTTP/1.1 302 Moved Temporarily
Cache-Control: no-store, no-cache, must-revalidate
Date: Fri, 12 Dec 2014 13:39:52 GMT
Location: hXXp://ib.adnxs.com/pxj?bidder=172&seg=802787&action=setuid('ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU')
P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Pragma: no-cache
Server: nginx/1.6.2
Set-Cookie: __adroll=e65dac886a3b760d94806f5afd818c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max-Age=157680000; Path=/
Content-Length: 112
Connection: keep-alive
Go to hXXp://ib.adnxs.com/pxj?bidder=172&seg=802787&action=setuid('ZTY
1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU')HTTP/1.1 302 Moved Temporari
ly..Cache-Control: no-store, no-cache, must-revalidate..Date: Fri, 12
Dec 2014 13:39:52 GMT..Location: hXXp://ib.adnxs.com/pxj?bidder=172&se
g=802787&action=setuid('ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU').
.P3P: CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"..Pragma: no-cache.
.Server: nginx/1.6.2..Set-Cookie: __adroll=e65dac886a3b760d94806f5afd8
18c65; Version=1; Expires=Wed, 11-Dec-2019 13:39:52 GMT; Max-Age=15768
0000; Path=/..Content-Length: 112..Connection: keep-alive..Go to http:
//ib.adnxs.com/pxj?bidder=172&seg=802787&action=setuid('ZTY1ZGFjODg2YT
NiNzYwZDk0ODA2ZjVhZmQ4MThjNjU')..


GET /postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults HTTP/1.1
Accept: text/html, application/xhtml xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: apps.driversupport.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/8.0
X-AspNetMvc-Version: 5.2
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Fri, 12 Dec 2014 13:39:48 GMT
Content-Length: 15598
<!DOCTYPE HTML PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "htt
p://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xm
lns="hXXp://VVV.w3.org/1999/xhtml">..<head>.. <title>
;DriverSupport - Available Driver Updates</title>.. <meta
http-equiv="X-UA-Compatible" content="IE=edge" />.. <link hre
f="hXXp://d1pmrmlzxdx671.cloudfront.net/content/themes/reset.css?v=1.0
.0.13" rel="stylesheet" type="text/css" />.. .. <link href
="hXXp://d1pmrmlzxdx671.cloudfront.net/content/themes/UI/Argon/ScanRes
ults.css?v=1.0.0.13" rel="stylesheet" type="text/css" />.. <l
ink href="hXXp://d1pmrmlzxdx671.cloudfront.net/content/themes/UI/Argon
/AltHeader.css?v=1.0.0.13" rel="stylesheet" type="text/css" />..
.. .. <link rel="shortcut icon" href="hXXp://d1p
mrmlzxdx671.cloudfront.net/content/themes/base/images/favicon.ico?v=1.
0.0.13" type="image/x-icon" />.. <link rel="icon" href="http:
//d1pmrmlzxdx671.cloudfront.net/content/themes/base/images/favicon.ico
?v=1.0.0.13" type="image/x-icon" />.. <script src="//asse
ts.adobedtm.com/359eb7b28b26c98a238e6cdedc877947afb6a2ef/satelliteLib-
6d2ff207543454d05c23a4bcb6934a30b796a147.js"></script>.. &
lt;!--Optimizely testing support scripts and variables-->.. <
script src="hXXp://d1pmrmlzxdx671.cloudfront.net/Scripts/custom.js?v=1
.0.0.13" type="text/javascript"></script>.. <script typ
e="text/javascript">.. var machineName = "Custom built m

<<< skipped >>>

GET /content/themes/base/images/win7_compatible.png HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: apps.driversupport.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Cache-Control: public,max-age=3600
Content-Type: image/png
Last-Modified: Mon, 10 Nov 2014 19:19:02 GMT
Accept-Ranges: bytes
ETag: "b68c82f1bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Fri, 12 Dec 2014 13:39:50 GMT
Content-Length: 7444
.PNG........IHDR...I...I.....qs......sRGB.........gAMA......a.....pHYs
..........o.d....tEXtSoftware.Paint.NET v3.5.11G.B7....IDATx^...X.i..{
.P.E.^..cI...v...%.(.P..JR.}_.E.6.&.e.../c...Y.......y.O.b....}.}..8..
s..s..u^.....u.....HJJ....KJII...4h...........o'......I..:.B^^..H.. YY
.Kd..f..~........5......]....:Q.......!C.l...?R....u.S..6({...x'.w....
.NH...HKKCVV..M....{[email protected]..;..
....NP...G.............555.3 ..9.....&....#....=7xv.._~.SSS...s..{..
.....mmm.......;.... .s......!M.:.vvv..e}...1.f.G....3z.h...`...\.....
.8^W.!EEE.....k.6mBXX.BBB....777...a..5hii...K.o.>............puu..
.s.p.B...p........=......q#.V\\\7$................\.1....'"!!......m.6
l...c``...F.\......2e....1....?5...o6.....$6p."6H.[jj*7.l..9sNtt4<&
lt;<...L6..... . 1.l.............J||<.;.........9.......$...r...
.sN.....w=..cH.N..0W...o...q.8.3(....;.)##.{.99..T[[..z..E...@qq1.....
.~....R.......\.....e.................X............J6.]5i.........f...
........$n0.n........Y.`.7xVs..2.18....6..8.:22...O...9...9JGG..ml..1b
.....g_O..'K{[email protected]|.p8;;s..M.k... 1w....<.g.$........W.?.....g....
*....s ....X...Ca.WP.1....P......P....naPu...g.T...M.......y........P.
^.%..P.........fSQ.....?Q._H.....(.ZBi.2.,....Cm.a.'\.F..h.}..\.g.A..k
/.)4RnA-...!.PY...9.P.b..Q.....x....IA....E..P.I....PM.`...Z....T..A5.
.....4g..&.~..g.D..B..N...v.........J[[email protected].]^....P..#..I../
.vM....!....f..2..p[W....e..h.....V...Bp....QVPM..$J ..a.....-7.......
8..F.(.Mc......C..rh./..I$=y4...........%.......>...i...<$..

<<< skipped >>>

GET /imagefactory.ashx?rguid=c5f07e3a-a197-4627-9438-974b57fd6373&catid=4d36e972-e325-11ce-bfc1-08002be10318 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: apps.driversupport.com
DNT: 1
Connection: Keep-Alive
Cookie: optimizelySegments={"176773665":"false","176809951":"direct","176875026":"ie"}; optimizelyEndUserId=oeu1418391590776r0.8981213483012467; optimizelyBuckets={}; optimizelyPendingLogEvents=[]; __utma=164611050.148068296.1418391591.1418391591.1418391591.1; __utmb=164611050.1.10.1418391591; __utmc=164611050; __utmz=164611050.1418391591.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)


HTTP/1.1 200 OK
Cache-Control: private
Content-Type: image/png
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Fri, 12 Dec 2014 13:39:51 GMT
Content-Length: 19586
.PNG........IHDR...................LIIDATx....t[g.-..........3.....;ff
.. .23.2.....8..ff..9q.an.R.6M..I..}^Y......i..u".H.........A0...Y.=..
.&..6....&.`..`.L0.l..&.M0....&.`....L0.l..&.M0....&.`....L..`..&.M0..
..&..6...L..`..`.L0....&..6....&.`..`.L0.l..&..6....&.`....L0.l..&.M0.
...&.`....L..`.....[OO.;...O........m...k.S?..w.......5..6.\..........
.......?..K.p..m.....\...?..u3pusl.o....v...=...?.==...l..}..~7{aW7.=.
/.}|?...)......<~.._}..>..c.<y..7o..5k.z.j.......{.}....&.O.f
.h..~....'..W.]...W.a.^]<.3Z...`..\..u`S....o8....d.....e.0}.t..?..
V.....[q..y.....l.f...c5.......I....c...<.b.....`l...=...9.~o..W%#.
.......r..<x.okii.....t.Rl....m..9X.b...J..@.)...,....>.M.yw'.$.
......=.<...%..K.........x.N&?.}...._.H:......m..;|.0..=........]..
..c..yX.h.v...........S\._I.7..y'.z.........)....S9...}. [email protected]{..gM
..........d......^$.k....lo.C...{.4..{.......{.n.....'9I~....9...1....
.s...|k`E.....}..bWg;..^2.1f#X..dl...l...1.......0y.L....9..fb.h;.a...
".Sq..E<c|'.....o.{.U1.2.A2.d".m....`t{..!.9r..6l..F,[email protected]&f..._..g
.q....D..O.:.........\/....../q..I,..........s..h:.CUd.5'C.......jnF..
.C......=....g?.nr.l....2.O...s'..=.7.<...8q..I...W#...G.F...^.x...
.ft...>.[.......!..s.c..._.=..<.B.../...g7....T..ATa,.....[b4c.1
"..:..[=.v..j/..:.A...CD.0..av.b.._p.| .~c.._..:::.N.../_....8mmm\F...
.F,F..2e../^..H@..(..&...r....7aL.u.:{..........c..u..=.....<..x...
I................vu..7LCLy.\..`.`.1.z..6.{s....H;C..3..'c.s2....tD&..t
<...f.qB.,$.p........$......)......X.`..L......._~..F #p).%....

<<< skipped >>>

GET /content/themes/UI/Argon/AltHeader.css?v=1.0.0.13 HTTP/1.1
Accept: text/css
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: text/css
Content-Length: 2254
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Mon, 10 Nov 2014 19:19:02 GMT
Accept-Ranges: bytes
ETag: "9710301bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Tue, 02 Dec 2014 21:23:07 GMT
Age: 2114
X-Cache: Hit from cloudfront
Via: 1.1 7b8a7488445561e0573f89a1f8dc5d44.cloudfront.net (CloudFront)
X-Amz-Cf-Id: ptYsnUSbdFGnsCSCEOpVVvCJ-FtmmoPLI_fWiuHYZ6z5yg3l_0NOhQ==
.....        #introWrapper {..            padding: 20px 30px;..       
background-color: #bbb;.. }.. #intro {..
text-align: left;.. padding: 20px;.. background
-color: #fff;.. text-align: center;.. border: 1p
x solid #888;.. width: 880px;.. box-shadow: 3px
3px 3px #aaa;.. height: auto;.. }.. #intr
o h1 {.. font-size: 30px;.. margin-botto
m: 5px;.. line-height: 1.4em;.. text-ali
gn: center;.. }.. #intro h2 {.. f
ont-size: 27px;.. }.. #productDescription {..
color: #666;.. text-align: center;.. font-s
ize: 12px;.. }.. #machineImageTop {.. float:
left;.. text-align: center;.. width: 280px;..
margin: 10px 20px 10px 0;.. }.. #machineIma
geTop img {.. display: inline-block;.. m
ax-width: 280px;.. width: auto;.. }..
#marketingSubText {.. float: left;.. width: 580
px;.. }.. #marketingSubText h2 {.. ma
rgin: 5px 0 15px 0;.. font-size: 18px;..
line-height: 1.2em;.. text-align: left;.. }
.. #PartnerLogo {.. height: 40px;.. }..
#updateCount {.. color: #d25647;.. font-we

<<< skipped >>>

GET /content/themes/UI/Argon/images/leftArrow.png HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: image/png
Content-Length: 731
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Mon, 10 Nov 2014 19:19:03 GMT
Accept-Ranges: bytes
ETag: "b6821a301bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Thu, 13 Nov 2014 16:41:44 GMT
Age: 2113
X-Cache: Hit from cloudfront
Via: 1.1 7b8a7488445561e0573f89a1f8dc5d44.cloudfront.net (CloudFront)
X-Amz-Cf-Id: cagnhiAhr01m2LNbNMLgcJX0xisd4jTS2JFXxa_eOr3WM8lgv2XBuQ==
.PNG........IHDR...%...G........R....pHYs................ cHRM........
...|..y...V.......9=.."^.Ph....aIDATx....m.0.@_.....{.m..\...... .....
_?..@....#d.......X..tG.`..e.......;.......-.............i..;X.......y
n.*..e.....U.....b..B......E..%'T.f....9.X..jF.}[email protected]
A...5..1.p.Z.J...=.y@-n../j`.....%..u............../.:...A..F..G.1e...
&Uy..n.M.R.(...P*[email protected].,..@
es.X......1fw....Z........r..4S...{k.k.'.Q..d.C...........!...&.k..U)a
.r.(E*y....R$...H.}.x..C..'..7.j.zt.P.......m...X.b.qx....8dw..-VV.I6
...&..gq..*..4. w.i.f....^ts..F...,Z....j..:.....a.Pf..>Z3q..!..a..
v/(..r...r..i..ax..k.V{/..a.....9.V..#....}}..sX...!.n?...3'.Y..E.x.^p
.<..........;.S..t..[W....IEND.B`.HTTP/1.1 200 OK..Content-Type: im
age/png..Content-Length: 731..Connection: keep-alive..Cache-Control: p
ublic,max-age=3600..Last-Modified: Mon, 10 Nov 2014 19:19:03 GMT..Acce
pt-Ranges: bytes..ETag: "b6821a301bfdcf1:0"..Server: Microsoft-IIS/8.0
..X-Powered-By: ASP.NET..Date: Thu, 13 Nov 2014 16:41:44 GMT..Age: 211
3..X-Cache: Hit from cloudfront..Via: 1.1 7b8a7488445561e0573f89a1f8dc
5d44.cloudfront.net (CloudFront)..X-Amz-Cf-Id: cagnhiAhr01m2LNbNMLgcJX
0xisd4jTS2JFXxa_eOr3WM8lgv2XBuQ==...PNG........IHDR...%...G........R..
..pHYs................ cHRM...........|..y...V.......9=.."^.Ph....aIDA
Tx....m.0.@_.....{.m..\...... ....._?..@....#d.......X..tG.`..e.......
;.......-.............i..;X.......yn.*..e.....U.....b..B......E..%'T.f
....9.X..jF.}[email protected]...=.y@-n../j`...

<<< skipped >>>

GET /dc.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: stats.g.doubleclick.net
DNT: 1
Connection: Keep-Alive
Cookie: id=caebd6253000002||t=1384780400|et=730|cs=002213fd480c4c2631f7c541a4


HTTP/1.1 200 OK
Date: Fri, 12 Dec 2014 12:44:52 GMT
Expires: Fri, 12 Dec 2014 14:44:52 GMT
Last-Modified: Thu, 13 Nov 2014 21:10:00 GMT
X-Content-Type-Options: nosniff
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Server: Golfe2
Content-Length: 15853
Cache-Control: public, max-age=7200
Age: 3299
Alternate-Protocol: 80:quic,p=0.02
X-Google-Cookies-Blocked: id=
...........={_.:...)....'.$..&.......-..Ms..e9..'...B.g.3#..........3z
?F........z....n.h..@&b.....v.W.A"...<8H.^.....A*......3....~..X?8.
...<..t..)d.......Hf.Q...._. .,`.....a....>...?...v.Aq.G........
.p.........a$y&.....sX7p........ ..M.d..l.K.....t...8..i6....C..XO....
.@....!.....RG.l .}....b$c..B|8..C}!.8..=.e.K....{..K.9..a..nx......%.
.;..F...J...v..n!.L.....g.C@...~..|...=....q.9n_...P.....Tw.o.........
..k.....^:.....O!..b......=...B..,..j8......k.b./.Y..JE...({k.........
(.L..@. ...b;...s.f...k../--..\..A.M..he.q..u.u.$..<.....$......eBf
....,...r{.[.....h....Tup..$?F?2.... .qk...x..;.......}.Y.[)jL........
.}.4.'..Z_...bms.._..I4.r=...f....U}...|......].FG..\.[9...hp......"..
L..J...a..l.=.C..c.............i..2&.......{....T*w..%#ey....A..`.T..Q
.w.....f2...,....J...y.qqA.........BTo....5.W..9]...]b$K%Z.V..b..x1t..
..]..&.P.Qo.A?..W.R..l.........'".. ..D. ..EA.......$US.t...w?.u*rn.:.
.....?...a,.(..0....`.GL....Z...j[8.[.2k8N...4(.x..4j&..V..p.N)0.;k...
....C..= .].;M.|..&..;........M'....Vy.6*..[J.7`n*...Q..O.%4T ...;....
.'J.........xKK.&..^A...;...........a<.783[X......p...c...3j$.....Z
....c.D.....BW................*.1]KQ].zb.... .?~....V>&."..Q$.....&
.sS..Kq........).....{y.V....T...L.09.-.KK:..yH.....4./..Ni.oaM..X..X.
R...l...[...n2.....6.v.Q.......v.C.0........55..z]__.a.j...fJh.....r.6
a.6v3..!.}^0...,...I.w........i.......Q..q ..c;2.p2 .%..:0..14....z...
.b.*Z..*..>...v].....H...V...kVT.]....I ...._..}.f.....^U..a.V]..wd
.N.....9....n1-0..`...B..Q.MB...7...%.!.L~.."H..xNV`?||.H.........

<<< skipped >>>

GET /__utm.gif?utmwv=5.6.1dc&utms=1&utmn=527317186&utmhn=apps.driversupport.com&utmcs=utf-8&utmsr=1683x901&utmvp=1667x779&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=-&utmdt=DriverSupport - Available Driver Updates&utmhid=146776347&utmr=-&utmp=/postinstall/ScanResultsMedia?cart=https%253a%252f%252fsecure.driversupport.com%252fregistration%252fcart%253faf%253dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&utmht=1418391591398&utmac=UA-2010741-4&utmcc=__utma=164611050.148068296.1418391591.1418391591.1418391591.1;+__utmz=164611050.1418391591.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmu=qB~ HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: stats.g.doubleclick.net
DNT: 1
Connection: Keep-Alive
Cookie: id=caebd6253000002||t=1384780400|et=730|cs=002213fd480c4c2631f7c541a4


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 19 Apr 2000 11:43:00 GMT
Last-Modified: Wed, 21 Jan 2004 19:51:30 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Wed, 10 Dec 2014 13:16:41 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 174190
Alternate-Protocol: 80:quic,p=0.02
GIF89a.............,...........D..;HTTP/1.1 200 OK..Pragma: no-cache..
Expires: Wed, 19 Apr 2000 11:43:00 GMT..Last-Modified: Wed, 21 Jan 200
4 19:51:30 GMT..X-Content-Type-Options: nosniff..Content-Type: image/g
if..Date: Wed, 10 Dec 2014 13:16:41 GMT..Server: Golfe2..Content-Lengt
h: 35..Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-re
validate..Age: 174190..Alternate-Protocol: 80:quic,p=0.02..GIF89a.....
........,...........D..;..


GET /printer.png HTTP/1.1
Host: e49b30b1dab19bb21dcf-bce5d432a4997ec4ca1b037336914d84.r88.cf1.rackcdn.com
Connection: Close


HTTP/1.1 200 OK
Last-Modified: Tue, 15 Apr 2014 19:21:18 GMT
ETag: dc0beab565f8b8f6e8376f434c0d793c
Content-Length: 60685
Content-Disposition: attachment; filename=printer.png
Accept-Ranges: bytes
X-Timestamp: 1397589677.22478
Content-Type: image/png
X-Trans-Id: tx6a925c8b676843e490454-0053f3c065dfw1
Cache-Control: public, max-age=33920
Expires: Fri, 12 Dec 2014 23:05:06 GMT
Date: Fri, 12 Dec 2014 13:39:46 GMT
Connection: close
.PNG........IHDR.......,.....b.r.....tEXtSoftware.Adobe ImageReadyq.e&
lt;..."iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c061 64.140949, 2010/12/07-10:57:01 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CS5.1 Windows" xmpMM:InstanceID="xmp.iid:DE5B71AB7E3211E387FDB964
610F7B6B" xmpMM:DocumentID="xmp.did:DE5B71AC7E3211E387FDB964610F7B6B"&
gt; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:DE5B71A97E3211E387
FDB964610F7B6B" stRef:documentID="xmp.did:DE5B71AA7E3211E387FDB964610F
7B6B"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
; <?xpacket end="r"?>]nsz....IDATx...Y.%Wz&vN....=....U\........
-k i$x...1.h..1..~3....".....lk..c./..<...[3c.jQ#.Zl...f.l..T...YK.
.w....v.s"nV.m.5..8.J...7n..s../....9g.Q.jT.,.[.V5.Q....Q.jT...jT...`U
....F.X..F5.Q.V5.Q....Q.jT...jT.........F.X..F5.Q.V5.Q.jT.U.jT...jT...
......F5*..F5.Q.V5.Q.jT.U.jT...`U.........F5*..F5.Q....Q.jT.U.jT...`U.
...F.X..F5*..F5.Q....Q.jT...jT...`U....F.X..F5*.......F.X..F5.Q.V5.Q..
..Q.jT...jT.........F.X..F5.Q.V5.Q.jT.U.jT...jT.........F5*..F5.Q.V5.Q
.jT.U.jT...`U.......gm.........Q.......J...<R`.....<.......jT.U.
..N.En.....UaV5*..........>. ..1.CU.U.....=C.zj...?.4a....?(..l

<<< skipped >>>

GET /monitor.png HTTP/1.1
Host: 70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com
Connection: Close


HTTP/1.1 200 OK
Last-Modified: Fri, 24 Oct 2014 17:06:39 GMT
ETag: 33d0ab2f164ede0bc598921a89635534
Content-Length: 25481
Accept-Ranges: bytes
X-Timestamp: 1414170398.07988
Content-Type: image/png
X-Trans-Id: tx7c26630b6eae425fab4b5-00544a8929ord1
Cache-Control: public, max-age=581
Expires: Fri, 12 Dec 2014 13:49:26 GMT
Date: Fri, 12 Dec 2014 13:39:45 GMT
Connection: close
.PNG........IHDR.......,......i......PLTE...&&&(((***!!!%%%)))###"""$$
$''' 000///... ,,,...111666777---333222444555...888999<<<
;;;:::===...>>>......???BBB.........SSSCCC...@@@..!...EEE...D
DDFFF......AAAGGGHHHRRR... "VVVJJJIII...PPP...UUU.. LLL......KKK[[[TT
TNNN...OOOZZZQQQMMMWWW.....#.........YYY\\\XXX...... .$........ ......
!!#...QQS...........! .%......PPR...LLO.........SSU........ ]]].......
.....NNPNOR...JKM"!%TTVVVX...IIL......GGJUUW..........................
0...RSW...CCE.."......((,.........""#.........bcdjjj...,,.==?...335$$&
.........89<..."#)ffg...//[email protected]...)''@@A''*WW\__`...224mno.
..DDF......]]`...458.........* - ) FFIvwxppr...9;?;>B;<>137..
.&%'ttt111113) 1...789YY\<99$(.}}}...,.3$% &$$NLK77:>>B36; ((
ZZ]=AG..&\\^RRT@?>wz},07#$#ECBAEJ/04/0/DHL#.!((&GED...422?<<W
USC?>GEFS^eUSS723.Q.b..`DIDATx....t.....$3.L.2..d&.....CH...W....1@
...@..%.....e!.)...*...G........V.h-..k..........,.s..N......g...:k.{.
=.....g.{.....7...{.{....*....*....*....*....*....*....*....*....*..T.
}..{... .~...|...?{^V..u..?.D...c........}....O}......................
..U...uu5.U.xYY...3..}.l..............^=....<.......O...[.[......u.
5U.?....?w...W6w..........R...D..". [email protected].......
.s7...-......w...OL.\Q2UVY[S]...'..6<A..GZ&.L.:m.T.....n..b...p....
7e....^N.1:..E.HK..........).L.!.9s.<.3fL...56.O...n..^..S.|.{Y....
..;......xmm]z|..i.......g..G..(..x.f..;.....O.z....'O~a..3.D.........
.H.....X.,B.L.6.4.0f..4.................o..}.vAK.,.7......O...}.u.

<<< skipped >>>

GET /js/176561969.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: cdn.optimizely.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
x-amz-id-2: idnnh fvK1xlnS0BLOQOzeLlYiJ 2ifTj41LhJrb2MUre1bV1Z5tYw lSOeAaVn0
x-amz-request-id: 285BDCF73930BC43
Content-Encoding: gzip
ETag: "8f79e2277c84675a130114b4c4a9f496"
Accept-Ranges: bytes
Content-Type: text/javascript
Content-Length: 55336
Server: AmazonS3
Vary: Accept-Encoding
Timing-Allow-Origin: *
Cache-Control: max-age=120
Date: Fri, 12 Dec 2014 13:39:50 GMT
Connection: keep-alive
Timing-Allow-Origin: *
......}T.....c.6.0........5-...#...mv.&[...._..D[..Q......... A...4}..
.{X$.s0.......S..f.2.ge}}p0..I.2|/......T.....-..C;......u0,...lQ.l(..
.j....7....J.'......o.Qw..n.....##......k.4..ne..F....yh.N%.y..7......
4..?.........K........l..]]..].2_.W...Y.;....p..pQvK....^e..77...p./..
P...U..h\.gn..?...Y8..3..|=.l.8...w...u.m.....U......o]..:v......&~...
..........{6...f...9Pr......:......P."w.....e........qyz.>0..>..
v...&<[email protected].,...q0.t...^.........ET.A ?........%.L.m.
?..`....Y.V..M...8..Z.. I..-S..F!.\....?..|.u....Uk.f.^.:}...x..G.....
...\\T.^.......".6..|......^\..c...W.pJ.t. _\.*_C._../...5...3...Q3^x
3......t'.{....e'...i.C......NE.u.U3....ug>.t...rZgu.aY5.....2w..|.
-......Z..2b.Q8..Z.<.Y-....~.FO{.....V.-3.;g9....[g.Y.A_..G.I......
I..Os6.c...P.U.3.M.s...Q...z...$ir..S...P.. Z...../...X....K>3....o
....f.....s..P...f5.fl...->.F.l..Fu.t....M......sPo....qv....D..u..
'..u..%[email protected] !....i{.tC.....gMh..c.-bC.eX.r.Z.@.}.,f.^.
V.X.....`IT..[.....[....6\.P4k....c...)....).[..*..j.F..m.O.4.Z8*.j...
..JB..`Z.V.f...y%D.*.N....n4...Zq.....4.pN.L....a.....5.Yk4..........e
`.F.....>.......2..v.j.y.yQ.qqQ.]...03............!(....>.......
..k..iQz.#..J..C.......a [email protected].
.........t2?..S>........:...jJ5....s&.w.....["9MX.f.L..7...=.n..j6.
..j.Y7a...j..0.&.=|jY..I/.......M..a.....F..pO.8,j...i...........us...
.k.m..3.LZ..........;..X.`.{..2......e....1....ZbQ.......}.<.N....L
.[.J..4K...o......?...B.b...P...`.u..U..VU.....Z=.. .($...{.x..7z.

<<< skipped >>>

GET /action-uic/0?ti=4002897&Ver=2&mid=d2180211-1d49-87f4-90bc-7a999623f1d5&evt=pageLoad&pi=0&lg=en-US&sw=1683&sh=901&sc=24&tl=DriverSupport - Available Driver Updates&p=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&r=&rn=26480 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: bat.r.msn.com
DNT: 1
Connection: Keep-Alive
Cookie: mh=MSFT; CC=UA; CULTURE=EN-US; SRCHD=SM=1&MS=3093912&D=3093912&AF=NOFORM; SRCHUSR=AUTOREDIR=0&GEOVAR=&DOB=20131118; MC1=V=3&GUID=373863f57d114b0289364f6434076125; brdSample=0; MUID=1785AC2FD94664211AC0A9A6DD466620; cbus=subint:1:138479115


HTTP/1.1 204 No Content
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Length: 0
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Server: Microsoft-IIS/8.0
Access-Control-Allow-Origin: *
Date: Fri, 12 Dec 2014 13:39:50 GMT
HTTP/1.1 204 No Content..Cache-Control: no-cache, must-revalidate..Pra
gma: no-cache..Content-Length: 0..Expires: Fri, 01 Jan 1990 00:00:00 G
MT..Server: Microsoft-IIS/8.0..Access-Control-Allow-Origin: *..Date: F
ri, 12 Dec 2014 13:39:50 GMT..


GET /ads/user-lists/996887577/?fmt=1&num=2&cv=7&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&random=2059655862 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: VVV.google.com


HTTP/1.1 302 Found
Location: hXXp://VVV.google.com.ua/ads/user-lists/996887577/?fmt=1&num=2&cv=7&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&random=2059655862&ipr=y
Cache-Control: private, max-age=43200
Date: Fri, 12 Dec 2014 13:39:51 GMT
Expires: Fri, 12 Dec 2014 13:39:51 GMT
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Server: adclick_server
Content-Length: 594
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
<HTML><HEAD><meta http-equiv="content-type" content="te
xt/html;charset=utf-8">.<TITLE>302 Moved</TITLE></HE
AD><BODY>.<H1>302 Moved</H1>.The document has mov
ed.<A HREF="hXXp://VVV.google.com.ua/ads/user-lists/996887577/?fmt=
1&num=2&cv=7&frm=0&url=http://apps.driversupport.com
/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driv
ersupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media
&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=
9.1.4.66&ddsrc=ScanResults&random=2059655862&ipr=y">her
e</A>...</BODY></HTML>..HTTP/1.1 302 Found..Location
: hXXp://VVV.google.com.ua/ads/user-lists/996887577/?fmt=1&num=2&cv=7&
frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia
?cart=https%3a%2f%2fsecure.driversupport.com%2fregistratio
n%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=1368230
0-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResult
s&random=2059655862&ipr=y..Cache-Control: private, max-age=43200..Date
: Fri, 12 Dec 2014 13:39:51 GMT..Expires: Fri, 12 Dec 2014 13:39:51 GM
T..Content-Type: text/html; charset=UTF-8..X-Content-Type-Options: nos
niff..Server: adclick_server..Content-Length: 594..X-XSS-Protection: 1
; mode=block..Alternate-Protocol: 80:quic,p=0.002..<HTML><HEA
D><meta http-equiv="content-type" content="text/html;charset=utf
-8">.<TITLE>302 Moved</TITLE></HEAD><BODY&

<<< skipped >>>

GET /ads/user-lists/933633792/?label=xn2YCKKm-1UQgL6YvQM&script=0&ct_cookie_present=false&random=1583785290 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: VVV.google.com


HTTP/1.1 302 Found
Location: hXXp://VVV.google.com.ua/ads/user-lists/933633792/?label=xn2YCKKm-1UQgL6YvQM&script=0&ct_cookie_present=false&random=1583785290&ipr=y
Cache-Control: private, max-age=43200
Date: Fri, 12 Dec 2014 13:39:52 GMT
Expires: Fri, 12 Dec 2014 13:39:52 GMT
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Server: adclick_server
Content-Length: 346
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
<HTML><HEAD><meta http-equiv="content-type" content="te
xt/html;charset=utf-8">.<TITLE>302 Moved</TITLE></HE
AD><BODY>.<H1>302 Moved</H1>.The document has mov
ed.<A HREF="hXXp://VVV.google.com.ua/ads/user-lists/933633792/?labe
l=xn2YCKKm-1UQgL6YvQM&script=0&ct_cookie_present=false&ran
dom=1583785290&ipr=y">here</A>...</BODY></HTML&g
t;..HTTP/1.1 302 Found..Location: hXXp://VVV.google.com.ua/ads/user-li
sts/933633792/?label=xn2YCKKm-1UQgL6YvQM&script=0&ct_cookie_present=fa
lse&random=1583785290&ipr=y..Cache-Control: private, max-age=43200..Da
te: Fri, 12 Dec 2014 13:39:52 GMT..Expires: Fri, 12 Dec 2014 13:39:52
GMT..Content-Type: text/html; charset=UTF-8..X-Content-Type-Options: n
osniff..Server: adclick_server..Content-Length: 346..X-XSS-Protection:
1; mode=block..Alternate-Protocol: 80:quic,p=0.002..<HTML><H
EAD><meta http-equiv="content-type" content="text/html;charset=u
tf-8">.<TITLE>302 Moved</TITLE></HEAD><BODY>
;.<H1>302 Moved</H1>.The document has moved.<A HREF="ht
tp://VVV.google.com.ua/ads/user-lists/933633792/?label=xn2YCKKm-1UQgL6
YvQM&script=0&ct_cookie_present=false&random=1583785290&am
p;ipr=y">here</A>...</BODY></HTML>....

<<< skipped >>>

GET /imagefactory.ashx?modelid=0 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: apps.driversupport.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Cache-Control: private
Content-Type: image/png
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Fri, 12 Dec 2014 13:39:49 GMT
Content-Length: 46066
.PNG........IHDR................b....tEXtSoftware.Adobe ImageReadyq.e&
lt;....IDATx...y.e.u.v......z......... .......R;.he.YvJ.[..l%*G...r..R
..........%)..d..GJ....E.".$Hl.`0...~....}9.|...w....,Y....._...{.~~.w
.C.....\ H.......&....*..x........$)L&.......,....4..X.....g .. |.....
........a..Z......7.Rx,&....d..*.{-.....9....k.....q..x...g.}Z'.<wl
...f4.A.~.N..........h4........L..$.../[email protected]`...Y.Y..}.4.@.(>
....c...9i.@..)..z...V..I...W..o.......=../.7........9....O.}.}.....x.
..%x...........?...N.;...m>g.Z.F..*^.....O..Z..w.ZZ|.O].....?../.Y\
.F.4z..c.Oj...%...B.Z..l...$0.....P..y.d(Kx....z...j.L...Fx.U..:..<
.{{{P.V...Q&'....?7....9..5...c......Q<....YIn...co8.......F.>.f
.s..cuc.....)..........Dc.L.$'Q..Zi/?.i..o7.si.....{O<..k?...;...2.
L^B..*...x{.o;(j.(.c...\.S..._dq'.<K~..U.Ok.{............YaR.>Z.
..n..]^Z.......//.....i.....$S...a.y..$..U~Ai.|.$........S.{_...0...X.
.{(..w.....,-?....*5V....\.z.V..`.....=..l...=.o{.#...._{..X......V0.K
.....1.}...7....#.7....K...wf:.ax|...5.._...C.yO1.}.i~uP.....S*I.c...c
.V....r<O.................u..,,,a....W..../pL.......7.N9..&..Z...2.
......K.`4.c...aXv......p...:y.......C...-/.<7;.......^....[3.y..).
......W.o...O.$y:.U...>.....t...x<......I....'.....`...".%....#.
2L........E~.].$t.7....|...../`o...V...........k...}....a..v.}|~~..'N.
..O...;sfp....'.......F...|.K.Z.f.V..[.....{.q..[..E#{..?............8
.A..;.......A[(.....kT..du...`.U..X.....Ru..j|?Uw.KT..T.c..u.>....p
...CK0..69.#..V.6AQ5.......{..x..W...L..Y..j3.....{....g...S;...y.

<<< skipped >>>

POST /postinstall/LogUIDOMReady HTTP/1.1

Accept: */*
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Host: apps.driversupport.com
Content-Length: 65
DNT: 1
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: optimizelySegments={"176773665":"false","176809951":"direct","176875026":"ie"}; optimizelyEndUserId=oeu1418391590776r0.8981213483012467; optimizelyBuckets={}; optimizelyPendingLogEvents=[]; __utma=164611050.148068296.1418391591.1418391591.1418391591.1; __utmb=164611050.1.10.1418391591; __utmc=164611050; __utmz=164611050.1418391591.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

uuid=13682300-b037-44d0-9742-3c77ad4178ee×tamp=1418391591456
HTTP/1.1 200 OK
Cache-Control: private
Server: Microsoft-IIS/8.0
X-AspNetMvc-Version: 5.2
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Fri, 12 Dec 2014 13:39:51 GMT
Content-Length: 0
HTTP/1.1 200 OK..Cache-Control: private..Server: Microsoft-IIS/8.0..X-
AspNetMvc-Version: 5.2..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP
.NET..Date: Fri, 12 Dec 2014 13:39:51 GMT..Content-Length: 0..


GET /content/themes/base/images/ms-certified-partner.png?v=1.0.0.13 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: image/png
Content-Length: 5258
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Mon, 10 Nov 2014 19:19:02 GMT
Accept-Ranges: bytes
ETag: "4ab6ac2f1bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Tue, 02 Dec 2014 21:23:07 GMT
Age: 3049
X-Cache: Hit from cloudfront
Via: 1.1 3d412ad301f6861db40352c43a580a9d.cloudfront.net (CloudFront)
X-Amz-Cf-Id: xJ5CGhk0WMjLRQGpNqIx2DZgkRYWJnAyz9z-bMmPJIo6LGHjqYtlVw==
.PNG........IHDR.......E.............tEXtSoftware.Adobe ImageReadyq.e&
lt;...,IDATx..].xUU.^[email protected]..~...Q?..O...d...a.P.a.
[email protected]......;$...W.....0.0..H.8..ii8....C...pg.r79...)
O..322...~.`......W.XQ........cr..........L.........C.<..n.....)[..
....}KOOW?...#...w.).z....-[f......}>?...W.....U.T1...k....e|..W..9
s..........i...F....z.... W6.....^z);.^.....e.....-.~....O>.D......
@.......^..7nx.5i..Qu.}..w..O...f*V.....O^~.e...P.Xg..qR.n..w.;w..X...
..../.~.....*TPf...z.......%4h.....n..)c...b>.~.f.........Z...KO.,.
...;...8...6.,..f...'[email protected]...........$....J....~.n5...
.}...._|Q&L..~_.n..z. W............k....i......:uJI..Pr3.6l(.<.....
3gd..E.b..9z...C&.=."..M..]...g{..u.7.V,[email protected]#.?..t..M.M.c..O.V.F.*Y.
....C.x..eb..|.r.qd.....X.?.9>>^z..%...R..J..../..B..]*g..U.E..)
SF.y...0`..L..:....m.p.S.LQ....'.2......D....wo..q.\.|E.F\\.;..X.....L
Z.......%.|...m....M0........I.FD......muXN ....*..._>pK.,.g..v....
...>m..5..;.i.A4&M.d ....u......A.i.@O..=U_PD......y...!....#......
..];`."E...l.....&...m.b...>..b...}5..m~......y...!.....Az...l...F.
.-.z.e.O.e1.{...............'..2J..ByaA.N.Z.j.t..s...~.m.z0G........3.
..=....60i.....l..z...../_6:w..p\Z..;....w.U..........y5.R.J..J!&.....
E....G..../nL.>].IM.*...>h.........tok..n.....^e......X.v.......
-[...d.a`P.._1../o[.|....S.*.g.....Q..].v...F........}j"..&n.......L.U
Sk..i{O.........X..W..-[..Z..|.\.p..]..Q.i-g..i.s(.....(mt.p.Q.pa.>
.V.Zek..3.x..eX..=.....Ce..D... ...w.U.H!))I.. .m...~.z.A.z.....Jo

<<< skipped >>>

GET /content/themes/UI/Argon/images/rightArrow.png HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: d1pmrmlzxdx671.cloudfront.net
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: image/png
Content-Length: 1557
Connection: keep-alive
Cache-Control: public,max-age=3600
Last-Modified: Mon, 10 Nov 2014 19:19:03 GMT
Accept-Ranges: bytes
ETag: "86f61e301bfdcf1:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Thu, 13 Nov 2014 16:41:44 GMT
Age: 2113
X-Cache: Hit from cloudfront
Via: 1.1 3d412ad301f6861db40352c43a580a9d.cloudfront.net (CloudFront)
X-Amz-Cf-Id: q1cRAKTlatoxABn4oS4fDVKl5CyClnkFC-349JSSu4j3C8UhyRESHQ==
.PNG........IHDR...%...G........R....tEXtSoftware.Adobe ImageReadyq.e&
lt;..."iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c061 64.140949, 2010/12/07-10:57:01 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CS5.1 Windows" xmpMM:InstanceID="xmp.iid:B1CFBE1C0D1E11E493398B82
5AF7DEE9" xmpMM:DocumentID="xmp.did:B1CFBE1D0D1E11E493398B825AF7DEE9"&
gt; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:B1CFBE1A0D1E11E493
398B825AF7DEE9" stRef:documentID="xmp.did:B1CFBE1B0D1E11E493398B825AF7
DEE9"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
; <?xpacket end="r"?>.h.T....IDATx....m.0.FSO.....E.P.A.A3.0A...
.,....`.F...T.).Br..w...Q.....;........z.S.......es....1a........u.-..
.{.z..:...zQz...7...7KF*..i.....:Q:v.m.,.z...(.&.6cn....(....i......'t
P$...F.5...N..=...`M......J..........S)m ..k.c... .OJU..'y............
.M.X.[.,O!.0..i..5.aA.).;,H.y;,H.z:, ......5wXP.ES.i.L..f.D.0I.6.*.H..
........6V....x7..#..%T..;l.pI...a..T..hEk(........0 .Y...j...g*k..".-
.1.zuTP.v..Zq...}s.i...4.....TZ*........P...Zm..39......^....G.?...i..
h.g..pM.<.....Y...R.H..k.`.!9..*...Aq.......P.....':.A..r.......v."
..Aq.......P.d."m.L].Cq.j."...Eb(O....]4....F..r.(.P..."..*.._d...

<<< skipped >>>

GET /MEQwQjBAMD4wPDAJBgUrDgMCGgUABBQ/m36Fj2BE19VBYXRO62zrgIYp0gQUQnlUG2HNVSs+Y9U8SFf1n/tFzkoCAwJ35A== HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: gtssl-ocsp.geotrust.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1359
content-transfer-encoding: binary
Cache-Control: max-age=557207, public, no-transform, must-revalidate
Last-Modified: Fri, 12 Dec 2014 00:23:04 GMT
Expires: Fri, 19 Dec 2014 00:23:04 GMT
Date: Fri, 12 Dec 2014 13:39:54 GMT
Connection: keep-alive
0..K......D0..@.. .....0.....10..-0...,0*1(0&..U....GeoTrust SSL TGV O
CSP Responder..20141212002304Z0f0d0<0... ........?.~..`D..AatN.l...
)...ByT.a.U >c.<HW...E.J...w.....20141212002304Z....201412190023
04Z0...*.H.............y..'..wRG&.tZn....r.^ [email protected]=Fy..
.....Ds..p.H.b...".o....hilm96....E.4Y.n.j\.!.pp...... [email protected]. z?.Z
T.c...O...{[email protected]......<x....^..F.]..2........D
T...d..-$B.....Py..|.....-...J..(...v..D$..<..4.9....O.. .2b.*..h3.
..x_....k0..g0..c0..K..........0...*[email protected]..
..GeoTrust, Inc.1.0...U....GeoTrust SSL CA0...140502165328Z..150522165
328Z0*1(0&..U....GeoTrust SSL TGV OCSP Responder0.."0...*.H...........
..0...........S.O.].&...4.......PU.HE..L....P.AH(l...o.V...b*....c.r.5
^...'.79.e<N]^n......<p....\H..0.#[".....B.A....K%?"...Q...z.\X.
~.b....X{.R..d.e..3.p.1...]!xX?.N.X.O...`v!39..V..VK9U....|.fV.7v.....
F.3..^.E'....C..M..4Ur......B ...>..d... ...w.....p..9$....y{......
..|0z0...U.#..0...ByT.a.U >c.<HW...E.J0... .....0......0...U.%..
0... .......0...U...........0!..U....0...0.1.0...U....TGV-B-1210...*.H
.............]E...n...a..b.M.(B....S......H~...h.2....{pK..#...0......
...A...L).....).f|d:[email protected];r....B.$..1.LH...`....S.<.y..$..N./!.....
e?z2T.'.....0..h.,b.D..... ....d.G..*[R`2J...g....6.!.........#.......
T.LF:q,...2..S.9....5..u!.y.RP..;H`.....S..}.F..$3Se...N.....5..

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTtSK3dy3sA4g6EKqm0CfGsMDTPlgQUUOpzidsp+xCPnuUBINTeeZlIg/cCEAJwu3i4ZpYdN6xM1SVvBys= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=513388
Content-Type: application/ocsp-response
Date: Fri, 12 Dec 2014 13:39:53 GMT
Etag: "548abdc0-1d7"
Expires: Fri, 19 Dec 2014 01:39:53 GMT
Last-Modified: Fri, 12 Dec 2014 10:04:48 GMT
Server: ECS (ams/D18C)
X-Cache: HIT
Content-Length: 471
0..........0..... .....0......0...0......P.s..)...... ..y.H....2014121
2095000Z0s0q0I0... .........H...{....*.....04....P.s..)...... ..y.H...
..p.x.f..7.L.%o. ....20141212095000Z....20141219100500Z0...*.H........
.....h..mr.....B..#....s\.......).G...8~;.........P.w...B.......Q.Y...
f.M}...... .7..9SB.....6D4.....:2j^..i.W.;...7...7.7.6..G.t.8(.."..g.
r.t...j...E~#....0=...c_Z....Z.n\.'....F...3..U.....f......1*3...0f[.m
.k....b.Y.9...s.E.g.Q.pJD..z...u.i.50...0J......MV.HTTP/1.1 200 OK..Ac
cept-Ranges: bytes..Cache-Control: max-age=513388..Content-Type: appli
cation/ocsp-response..Date: Fri, 12 Dec 2014 13:39:53 GMT..Etag: "548a
bdc0-1d7"..Expires: Fri, 19 Dec 2014 01:39:53 GMT..Last-Modified: Fri,
12 Dec 2014 10:04:48 GMT..Server: ECS (ams/D18C)..X-Cache: HIT..Conte
nt-Length: 471..0..........0..... .....0......0...0......P.s..)......
..y.H....20141212095000Z0s0q0I0... .........H...{....*.....04....P.s..
)...... ..y.H.....p.x.f..7.L.%o. ....20141212095000Z....20141219100500
Z0...*.H.............h..mr.....B..#....s\.......).G...8~;.........P.w.
..B.......Q.Y...f.M}...... .7..9SB.....6D4.....:2j^..i.W.;...7...7.7.6
..G.t.8(.."..g. r.t...j...E~#....0=...c_Z....Z.n\.'....F...3..U.....f.
.....1*3...0f[.m.k....b.Y.9...s.E.g.Q.pJD..z...u.i.50...0J......MV...

<<< skipped >>>

GET /377928.gif?partner_uid=e65dac886a3b760d94806f5afd818c65 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: idsync.rlcdn.com


HTTP/1.1 302 Found
Cache-Control: no-cache, no-store
Date: Fri, 12 Dec 2014 13:39:53 GMT
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Location: hXXp://idsync.rlcdn.com/377928.gif?partner_uid=e65dac886a3b760d94806f5afd818c65&redirect=1
P3P: CP: "NON DSP COR PSDo SAMo BUS IND UNI COM NAV INT POL PRE"
Set-Cookie: ck1=ck1;Domain=.rlcdn.com;Expires=Wed, 10-Jun-2015 13:39:51 GMT
Content-Length: 0
Connection: keep-alive
....



GET /377928.gif?partner_uid=e65dac886a3b760d94806f5afd818c65&redirect=1 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Cookie: ck1=ck1
DNT: 1
Connection: Keep-Alive
Host: idsync.rlcdn.com


HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Content-Type: image/gif; charset=ISO-8859-1
Date: Fri, 12 Dec 2014 13:39:53 GMT
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: CP: "NON DSP COR PSDo SAMo BUS IND UNI COM NAV INT POL PRE"
Set-Cookie: rlas3="1 4FcSkJnHnTH7HehYJ8f5htVoZnGDEpVCwF0YmBRDY=";Version=1;Domain=.rlcdn.com;Expires=Wed, 10-Jun-2015 13:39:52 GMT;Max-Age=15551999
Set-Cookie: rtn1=2b66616c37ccd4faf86b12932f97ce18;Domain=.rlcdn.com;Expires=Wed, 10-Jun-2015 13:39:53 GMT
Set-Cookie: dids1312211055=1189d6f58aedcaebea60ec1845c665bc414134aff914a4ce8bfd52bb2886b3ffd3fbddb074101510c3a58506664e6d67;Domain=.rlcdn.com;Expires=Wed, 10-Jun-2015 13:39:49 GMT
Content-Length: 43
Connection: keep-alive
GIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Cache-Cont
rol: no-cache, no-store..Content-Type: image/gif; charset=ISO-8859-1..
Date: Fri, 12 Dec 2014 13:39:53 GMT..Expires: Thu, 01 Jan 1970 00:00:0
0 GMT..P3P: CP: "NON DSP COR PSDo SAMo BUS IND UNI COM NAV INT POL PRE
"..Set-Cookie: rlas3="1 4FcSkJnHnTH7HehYJ8f5htVoZnGDEpVCwF0YmBRDY=";Ve
rsion=1;Domain=.rlcdn.com;Expires=Wed, 10-Jun-2015 13:39:52 GMT;Max-Ag
e=15551999..Set-Cookie: rtn1=2b66616c37ccd4faf86b12932f97ce18;Domain=.
rlcdn.com;Expires=Wed, 10-Jun-2015 13:39:53 GMT..Set-Cookie: dids13122
11055=1189d6f58aedcaebea60ec1845c665bc414134aff914a4ce8bfd52bb2886b3ff
d3fbddb074101510c3a58506664e6d67;Domain=.rlcdn.com;Expires=Wed, 10-Jun
-2015 13:39:49 GMT..Content-Length: 43..Connection: keep-alive..GIF89a
.............!.......,...........L..;..


GET /pagead/viewthroughconversion/933633792/?label=NtOJCPjf1hEQgL6YvQM&guid=ON&script=0&ord=3418199282196799&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&convclickts=0&random=2010159716 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: googleads.g.doubleclick.net
DNT: 1
Connection: Keep-Alive
Cookie: id=caebd6253000002||t=1384780400|et=730|cs=002213fd480c4c2631f7c541a4


HTTP/1.1 302 Found
P3P: policyref="hXXp://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Fri, 12 Dec 2014 13:39:52 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Location: hXXp://VVV.google.com/ads/user-lists/933633792/?label=NtOJCPjf1hEQgL6YvQM&script=0&ct_cookie_present=false&random=3244418699
Content-Type: image/gif
X-Content-Type-Options: nosniff
Server: cafe
Content-Length: 42
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
GIF89a.............!.......,...........D.;HTTP/1.1 302 Found..P3P: pol
icyref="hXXp://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="C
URa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV O
TC NOI DSP COR"..Date: Fri, 12 Dec 2014 13:39:52 GMT..Pragma: no-cache
..Expires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache, mus
t-revalidate..Location: hXXp://VVV.google.com/ads/user-lists/933633792
/?label=NtOJCPjf1hEQgL6YvQM&script=0&ct_cookie_present=false&random=32
44418699..Content-Type: image/gif..X-Content-Type-Options: nosniff..Se
rver: cafe..Content-Length: 42..X-XSS-Protection: 1; mode=block..Alter
nate-Protocol: 80:quic,p=0.002..GIF89a.............!.......,..........
.D.;..


GET /crls/secureca.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.geotrust.com


HTTP/1.1 200 OK
Server: Apache
ETag: "81093c70dd26bf892cee0e67a6d372ac:1418390421"
Last-Modified: Fri, 12 Dec 2014 13:20:21 GMT
Date: Fri, 12 Dec 2014 13:39:50 GMT
Content-Length: 966
Connection: keep-alive
Content-Type: application/pkix-crl
0...0.. 0...*.H........0N1.0...U....US1.0...U....Equifax1-0 ..U...$Equ
ifax Secure Certificate Authority..141212130300Z..141222130300Z0...0..
..X...140427081922Z0....v...140618150003Z0........140429180917Z0......
..140709194633Z0........140416233935Z0........140521155053Z0.....)..14
0617185515Z0....Bf..120627171053Z0.....3..020515130611Z0........140811
090836Z0.....#..140606204021Z0........100729164439Z0....x...1405072040
01Z0........140606222139Z0....%...020514181157Z0....S...140423105438Z0
........120627171058Z0........140725020038Z0........100729164732Z0....
M\..140430000442Z0.....-..140617185011Z0....V...140624123102Z0....t6..
140425041720Z0........120627171025Z0........100301134531Z0........1406
18143256Z0........120627171017Z0.....>..140711125531Z0....[...10073
0213120Z0........120627171058Z0....j...140226123519Z0...*.H...........
.Qa..[H.r`x...u..v,.x.EvQ.^L...w..:.`#....K.m.=..S.......8OV....Z.pA..
...b..a...\...2z&U..A9tj..$............7.;..M...G.eZ..Xd.!8HTTP/1.1 20
0 OK..Server: Apache..ETag: "81093c70dd26bf892cee0e67a6d372ac:14183904
21"..Last-Modified: Fri, 12 Dec 2014 13:20:21 GMT..Date: Fri, 12 Dec 2
014 13:39:50 GMT..Content-Length: 966..Connection: keep-alive..Content
-Type: application/pkix-crl..0...0.. 0...*.H........0N1.0...U....US1.0
...U....Equifax1-0 ..U...$Equifax Secure Certificate Authority..141212
130300Z..141222130300Z0...0....X...140427081922Z0....v...140618150003Z
0........140429180917Z0........140709194633Z0........140416233935Z0...
.....140521155053Z0.....)..140617185515Z0....Bf..120627171053Z0...

<<< skipped >>>

GET /MFQwUjBQME4wTDAJBgUrDgMCGgUABBSfAP5wz6TZE9AhTecbrorIUEieTwQU3Igt2WxNPQBQM/EVuXj7weahJK8CExkAAAlE5E3bN0hKjHcAAQAACUQ= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.msocsp.com


HTTP/1.1 200 OK
Date: Fri, 12 Dec 2014 13:40:54 GMT
Content-Type: application/ocsp-response
Content-Length: 1501
Connection: keep-alive
Set-Cookie: __cfduid=db552f003d15cd6380d065309bd616f8b1418391654; expires=Sat, 12-Dec-15 13:40:54 GMT; path=/; domain=.msocsp.com; HttpOnly
Last-Modified: Thu, 11 Dec 2014 04:49:18 GMT
Expires: Tue, 16 Dec 2014 13:40:53 GMT
ETag: "b06006aa3364d120beea3a1c8e835ba1bad366bd"
Cache-Control: public, max-age=345599
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 197a56218cb405db-WAW
0..........0..... .....0......0...0.......j.....N ...#c........2014121
1044918Z0..0..0L0... ...........p.....!M.....PH.O....-.lM=.P3...x....$
.......D.M.7HJ.w.....D....20141211044918Z....20141215044918Z."0 0... .
....0......20131211044918Z0...*.H..............k..A.iu l....n`.....$_.
2{..Q.V*W.....D.n0K...K...F.aE............*.!..u....(,...d.....s.W(.N
.KPl...T.0.T......F`?.7.....5.p........Q..]ef.>. ........C...n..kq.
..p.jo'c..Cf....f''...m....Z.l.,/m......o%..%......i..{.".......?.:..~
../).`.......s[CD<.u.........0...0...0................y#....y......
0...*.H........0..1.0...U....US1.0...U....Washington1.0...U....Redmond
1.0...U....Microsoft Corporation1.0...U....Microsoft IT1.0...U....Micr
osoft IT SSL SHA10...141023182318Z..150106182318Z0!1.0...U....Should b
e ignore by CA0.."0...*.H.............0.........1._G....#.L;!>Q.z.m
?e8.-1\...Scf....0.....E(/F.(..nN...U....3"&M./[email protected];...j.k.
.\.d'...s2D...W6.g.9...xk................Q.GZK.1.\-.E.......l.h.]%i4..
..v.....J.-. O. ?.*...A3...h.#..."..c....PhV.>..;...Y...._.".t....|
c......3.l.YUZ."p.r..C.U-[y..........0..0...U.......j.....N ...#c.....
.0...U.#..0.....-.lM=.P3...x....$.0...U...........0...U.%..0... ......
.0... .....7....0.0... .......0... .....0......0...*.H...............a
.F7Z.A..,.N.^.W..;....m<........l....\..........ar....B......V....n
X/[email protected]/..L...1.'..SF..Qd.........e<.[....z..`..^wB?.p0,.2....R.`.
>..E?6Ppw....5.6.Q..?.?....."9..,[email protected] :`
...B......E....1*8.~J.U.D...zs..sw.,..V.G.d.#z...n.n..

<<< skipped >>>

GET /pki/crl/products/microsoftrootcert.crl HTTP/1.1
Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Thu, 23 Oct 2014 05:05:32 GMT
If-None-Match: "a2f3ff97eeecf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com


HTTP/1.1 304 Not Modified
Content-Type: application/pkix-crl
Last-Modified: Thu, 23 Oct 2014 05:05:32 GMT
ETag: "a2f3ff97eeecf1:0"
Cache-Control: max-age=900
Date: Fri, 12 Dec 2014 13:39:33 GMT
Connection: keep-alive
....



GET /pki/crl/products/WinPCA.crl HTTP/1.1

Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Mon, 06 Oct 2014 05:06:02 GMT
If-None-Match: "3e1c83923e1cf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com


HTTP/1.1 304 Not Modified
Content-Type: application/pkix-crl
Last-Modified: Mon, 06 Oct 2014 05:06:02 GMT
ETag: "3e1c83923e1cf1:0"
Cache-Control: max-age=900
Date: Fri, 12 Dec 2014 13:39:34 GMT
Connection: keep-alive
....



GET /pki/crl/products/MicrosoftTimeStampPCA.crl HTTP/1.1

Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Sat, 04 Oct 2014 05:06:12 GMT
If-None-Match: "58cddbea90dfcf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com


HTTP/1.1 304 Not Modified
Content-Type: application/pkix-crl
Last-Modified: Sat, 04 Oct 2014 05:06:12 GMT
ETag: "58cddbea90dfcf1:0"
Cache-Control: max-age=900
Date: Fri, 12 Dec 2014 13:39:34 GMT
Connection: keep-alive
HTTP/1.1 304 Not Modified..Content-Type: application/pkix-crl..Last-Mo
dified: Sat, 04 Oct 2014 05:06:12 GMT..ETag: "58cddbea90dfcf1:0"..Cach
e-Control: max-age=900..Date: Fri, 12 Dec 2014 13:39:34 GMT..Connectio
n: keep-alive..


GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CECMkFlOTkMQ5KGdSAcojyz8= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1725
content-transfer-encoding: binary
Cache-Control: max-age=525804, public, no-transform, must-revalidate
Last-Modified: Thu, 11 Dec 2014 15:38:01 GMT
Expires: Thu, 18 Dec 2014 15:38:01 GMT
Date: Fri, 12 Dec 2014 13:39:03 GMT
Connection: keep-alive
0..........0..... .....0......0...0......u\..3Oo?U...H.....O!..2014121
1153801Z0s0q0I0... ...................F....0.yV......{&.K......&......
.#$.S...9(gR..#.?....20141211153801Z....20141218153801Z0...*.H........
.....K..<.Z...0.'?.o}..p..V..1N_...D.w.F"X.....&`=...:.....[=.6l...
x.nk..N......!i...qf..Dx.......K...... /.....w....._R=..\r.. v...u...Z
Gb.....2).h.C..&.....o....h.;.........^5kU.\..j ...h...........E.x.6hr
ei.r.......U.......2....7..U.....V...>....l.)'...._.......0...0...0
........../...nj0...}..i..0...*.H........0..1.0...U....US1.0...U....Ve
riSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use a
t hXXps://VVV.verisign.com/rpa (c)101.0,..U...%VeriSign Class 3 Code S
igning 2010 CA0...141204000000Z..150304235959Z0..1.0...U....US1.0...U.
...VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1VeriSign
Class 3 Code Signing 2010 OCSP Responder0.."0...*.H.............0.....
....4.4...........o....?..f.........I.!.b.L...L..U.........rM.,.....=.
.cR4d.~*..k..x......=.WT.<.A2n1.qZyM.M..Q_...8....9....d.... ...'..
.......h..Z..I...(.b.jK..DO.ra..gb..j..A.(....mrzU.w.......Bv...l.:s..
L....y.....u..n.)W......Y!....Q...,.i|.....:.Mu..DD1.........0...0...U
....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.veris
ign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS incor
p. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U...
.....0... .....0......0"..U....0...0.1.0...U....TGV-B-24600...*.H.....
[email protected].=.. ...........hi.......>....

<<< skipped >>>

GET /$(KGrHqF,!iMFD)meJw 1BRF!H4Mw !~~60_35.JPG HTTP/1.1
Host: efd765d1ec5992c99482-0705b69156f5fc427c1a0e8338e226b8.r32.cf1.rackcdn.com
Connection: Close


HTTP/1.1 200 OK
Last-Modified: Mon, 07 Apr 2014 14:02:29 GMT
ETag: 859a1260264517c2a504c49f291df7f9
X-Trans-Id: tx646e321446c24fceb8a56-0054724553dfw1
Content-Length: 16899
Content-Disposition: attachment; filename=$(KGrHqF,!iMFD)meJw 1BRF!H4Mw !~~60_35.JPG
Accept-Ranges: bytes
X-Timestamp: 1396879348.75573
Content-Type: image/jpeg
Cache-Control: public, max-age=78843
Expires: Sat, 13 Dec 2014 11:33:49 GMT
Date: Fri, 12 Dec 2014 13:39:46 GMT
Connection: close
......JFIF.....H.H.....2Processed By eBay with ImageMagick, z1.1.0. ||
B2...C.....................................%...#... , #&')*)..-0-(0%()
(...C...........(...((((((((((((((((((((((((((((((((((((((((((((((((((
........,.."........................................@.................
........!.1."AQa.2Bq...#Rb..3r$......LDcs...........................
......,........................!1A."Q.aq2...#................?...T....
G4.Zp...&...i.M*.@.(..N..x^).P.Q.p..8.i.F(@.).q.O.(.P..{.P>i.....H.
.F;b..P(...K..p_.J..N....~..(.0H.QN...zsB.Rc.s.Efr.@.$..X}w....L..s...
v..[......S....5...IMAe.n...Pk.-..b..\.nW.....G.....W.x..Z..R..A.3...;
....H.bO../|.....".:2..&.-..H.$...;.;O..X..ts.S..7~"...s.......A.....A
... .....R._T.u........'..%^8p~.9..H....as,. ..h...(.`..m.K.A>.....
I...<........S*J.Y.q.-.j..K...I.....rb..2.....x...VyU.^...lO ..=...
.....u...%.7R]...I..M..~.$..w<.{s.^........).0.*..%|....>9.w\..N
.\.........h.R......WA.3..4.k.%..s.7.5.m&..4C'2)0s.]1A..."../...Rm.*.S
..g...0qPH*..".?.u.P........(....8R.)qB....(..N(H...R..P*H..)q.N.....n
>i.JR3FE2FD........ZG...k.....U\....9?..7..jW7.?...4.Lq{....$y"..s.
....W.......xo.....]:....a..O.I\*....W....K9.Z....<....c..3........
....-KQ.uk.{..... q9;6...Gb1... S..H4.Qa..i.!.I.h....\y...A.........R.
....#.u.n.\..q ...g0['........$...M....B%ay..e....).^Ab..;p3..sU..,.w
\t...\".#.....;...qP>.iZ&.......V'*...;<..9.....|..z...V.c..V...
"...<.c..X.$..$s.B"..Yd.7..^.......F........c.k.....eV.t..`.......;
. ..H....Q.(uM#..A ...BT.L....#..K.dry8....re....4\G.[..w.....dKMB

<<< skipped >>>

GET /sync?dsp_id=44&user_id=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: x.bidswitch.net


HTTP/1.1 302 Moved Temporarily
Server: nginx/1.7.2
Date: Fri, 12 Dec 2014 13:39:53 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 0
Connection: keep-alive
Set-Cookie: tuuid=f095a25f-0045-4490-8164-f197a9fa4acf; path=/; expires=Sun, 11-Dec-2016 13:39:53 GMT; domain=.bidswitch.net
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Location: hXXp://x.bidswitch.net/ul_cb/sync?dsp_id=44&user_id=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
....



GET /ul_cb/sync?dsp_id=44&user_id=ZTY1ZGFjODg2YTNiNzYwZDk0ODA2ZjVhZmQ4MThjNjU HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Cookie: tuuid=f095a25f-0045-4490-8164-f197a9fa4acf
DNT: 1
Connection: Keep-Alive
Host: x.bidswitch.net


HTTP/1.1 302 Moved Temporarily
Server: nginx/1.7.2
Date: Fri, 12 Dec 2014 13:39:53 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 0
Connection: keep-alive
Set-Cookie: tuuid=f095a25f-0045-4490-8164-f197a9fa4acf; path=/; expires=Sun, 11-Dec-2016 13:39:53 GMT; domain=.bidswitch.net
Set-Cookie: c=1418391593; path=/; expires=Sun, 11-Dec-2016 13:39:53 GMT; domain=.bidswitch.net
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Location: //simage2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZqcz0xJmNvZGU9Mjk0NSZ0bD0xMjk2MDA=&piggybackCookie=f095a25f-0045-4490-8164-f197a9fa4acf
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
HTTP/1.1 302 Moved Temporarily..Server: nginx/1.7.2..Date: Fri, 12 Dec
2014 13:39:53 GMT..Content-Type: text/html; charset=UTF-8..Content-Le
ngth: 0..Connection: keep-alive..Set-Cookie: tuuid=f095a25f-0045-4490-
8164-f197a9fa4acf; path=/; expires=Sun, 11-Dec-2016 13:39:53 GMT; doma
in=.bidswitch.net..Set-Cookie: c=1418391593; path=/; expires=Sun, 11-D
ec-2016 13:39:53 GMT; domain=.bidswitch.net..P3P: CP="NOI DSP COR NID
CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"..Location: //sim
age2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZqcz0xJmNvZGU9Mjk0N
SZ0bD0xMjk2MDA=&piggybackCookie=f095a25f-0045-4490-8164-f197a9fa4acf..
Cache-Control: no-cache, no-store, must-revalidate..Expires: Mon, 26 J
ul 1997 05:00:00 GMT..Pragma: no-cache..


GET /bootstrap/v5/tp.widget.bootstrap.min.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
Host: widget.trustpilot.com
DNT: 1
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 2443
Connection: keep-alive
Cache-Control: public, max-age=3600
Content-Encoding: gzip
Date: Fri, 12 Dec 2014 12:54:20 GMT
Expires: Fri, 12 Dec 2014 13:54:21 GMT
Last-Modified: Fri, 12 Dec 2014 12:54:21 GMT
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 5.1
X-Powered-By: ASP.NET
Age: 2734
X-Cache: Hit from cloudfront
Via: 1.1 622b39b22357e70fa8da7e1f171019f3.cloudfront.net (CloudFront)
X-Amz-Cf-Id: EHqz1rWGKOB7fNfkRHY-rj4FBW-MkHPl0IaHO4EXxfENcC_OcdK7Zg==
............ks.6..0.\.<.t.....e.7..&n{.s...3..I.)..@;...~....z....d
db..b........<N6F=m....F..SIE...1O..z...y_k.8S....#y.c.f.5.(.. &...
...u.Y.......xL..e.T*..#..mc.}.v;.s.*fZ..S4-......`.m..M.Y,.... {.../Y
............M.k....n..v.......?.....H..u#LZ.U...~..\.}M.f....1Y.#...y%
.v..I.QZY....R4.kO5..SB..fr.8..3-c.F\.:......~..........Dj.o..X..BULM_
R..x.Q...P..OS.: T.J4M..S..,.S..t3....B...YQ./.hyu!..p...!...l..v.w.'T
<05.3..uU1N......Y..f9}..9.....-.W..Z.)..-r.2.tm..... V..........S\
3..R.......)..OV.@.[:k.'....7...z..'.5.Td.....Gk(.H>..\*2"..fQ.9[F.
.d.1oj..J.k..D......l....No.\u......zf...m.Y].$...1k5..nym......P...o.
a..........\|.yi....?(......u.tJ.<....o....".l.. Iv...P.....,K.....
g.f.U...td...........*Y.%....O.]1Y.....'.,v....?], l.Si.a.X...?.....}P
.....h..$.....|.f...._....B.i.Y...\..M..Kj.N..EL..C....(..^.......L&l
t;....o.8m..p.E.....H.....*!..bJ...w.n.s......9..j.8..~.}.C[G8.~@.....
....m.o.U.1.q{N......O.<...`....F.q.XH. .3..d.idz.|...o.;[...>.
.....;V.<...j....bU`..{...W..w...{z..]:.&....w.d.C.'S............S.
...t..{:[email protected]$B..E../Z..8.......
..)&..P...<f....!..a(hW).#@./).z..NR...2S...h5.......l.@.%....]....
m...l..."..N2.......d.-.I.[q.I.......P......I.....K..n.#....q o....y..
`..l/AW...ko..q5.j...9...Xck@<.~..&..g. ..<.j '9...L.o......B.$.
d.p.[~.L..(....|.|.d.y......d......i.Cz.$.^.E.IbT...h...,I.3.....w...m
&%D...n.X`.....A..6]..`k..aKN}..E.T.R.?.....v.(T..t8....C....x4.....I.
.N's..d}... .....'.&....~r.......z.). fTF...&7...W.j...V..P.m.#`.G

<<< skipped >>>

GET /MEQwQjBAMD4wPDAJBgUrDgMCGgUABBSxtDkXkBa3l3lQEfFgudSiPNvt7gQUAPkqw0GRtsnCuD5V8sCXEROgByACAwI20A== HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.geotrust.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1363
content-transfer-encoding: binary
Cache-Control: max-age=571549, public, no-transform, must-revalidate
Last-Modified: Fri, 12 Dec 2014 04:23:11 GMT
Expires: Fri, 19 Dec 2014 04:23:11 GMT
Date: Fri, 12 Dec 2014 13:39:53 GMT
Connection: keep-alive
0..O......H0..D.. .....0.....50..10......7).nj./P(.3.\\.;.B....2014121
2042311Z0f0d0<0... ..........9.....yP..`...<.......*.A.....>U
....... ...6.....20141212042311Z....20141219042311Z0...*.H............
.;..#.p.oH.. ..(?A.5...k...)...KW.....x...!VL/.....y.\ ....k..y.F..C..
J_U.........`e.X......H`..m.I.....%..mH.....W....P....B,;.l.j.\.......
.._....D.['l ..{.0....y.$m.=n......n...y..I...~...... .Z.H.s....Z....1
[email protected] ....1.....4.."[email protected]*...&Q.'X.g......0...0..}0..e.......
.:}0...*.H........0B1.0...U....US1.0...U....GeoTrust Inc.1.0...U....Ge
oTrust Global CA0...141201130534Z..151216130534Z02100...U...'GeoTrust
Global CA TGV OCSP Responder 30.."0...*.H.............0............\.h
pc..J.a.j-.t......F`Aw...)L.YE.2..~..-...2.Y(.".CZ.w..T..Y. syd.....x.
.YE..<....lwv.:J.76>U....uF.a.|8N.. ..1p...`f.X...B>x........
......6..m.&...'..W.plK....[.m.V..h..lI.........?~.....>.|'....o...
A!.Pm.*.N ...<.....3...*|.x._..1..m.W<*....._S.............0..0.
..U.#..0....z.h.....d..}.}e...N0... .....0......0...U.%..0... .......0
...U...........0...U.......0.0!..U....0...0.1.0...U....TGV-B-2830...*.
H.............~....2!...V..0...Y....L..k....z}~a.3Y.x..dS.L...Dk$a...n
R9_......B......m....Y....U.5....'.....<{....v&=.2].....j*.r(7...=.
.w.I...z....\.#.J.ac.....I.[.[....6.X....0...g.3d...z.i.H..f...v.....\
.....^.N..1.J<.)`Z.....4.-.E..n.E.~t....v.e.T...?. ......i..%....

<<< skipped >>>

GET /video.png HTTP/1.1
Host: 70bd7761b4e8398ed5ec-bf80855baf7f0a78e1035933491d3dca.r98.cf2.rackcdn.com
Connection: Close


HTTP/1.1 200 OK
Last-Modified: Fri, 24 Oct 2014 17:06:44 GMT
ETag: 1a5883daf427181232acbcfb26aaf4b7
Content-Length: 15399
Accept-Ranges: bytes
X-Timestamp: 1414170403.72059
Content-Type: image/png
X-Trans-Id: tx1000dd2267d54152a04bf-00544a89f1ord1
Cache-Control: public, max-age=577
Expires: Fri, 12 Dec 2014 13:49:22 GMT
Date: Fri, 12 Dec 2014 13:39:45 GMT
Connection: close
.PNG........IHDR.......,......i......PLTE...8p.8u.8r.8y.#. 8{.......8w
[email protected].;..8..D..7|....8..>.....=..<..
7..8..*..<{.@..<}.8..:..8..;..A..8..C..<..!..E..8...Z.8..8...
.....H..'..?.....nnp.O.1..=.....G..SSU...>..c...c.;y.....T....8...^
..E..j.C...}.:.....@..?.....'%&302- ,...<..~..o..M.........J.Bp.Z..
{|.;...........H...x..q.E...j..B....N...s.968f...........|..[.....wx{.
......K.............Q.....8.....H...........V...Q....^{."..YXZ2.......
.t..*......}.J..-..>p.A.....Et.;....._^`:.........Y..........ddfM..
............SbuMMOiik...>=?...rsv...&......c....5.........\..?.Q..
..DCDIHJ............W.....:..\....W......t....zAb...p.....Z..U.....d..
..6K........t..0..Q\...%Y..}.....f..(&Mwk.....w.Z..J.?q\....5...}.....
n....a.......!:C...d'....*D...u.......&..u.~cm..F..........L.L.4l...3`
..8.IDATx....lV....]....(S`2E../H0.2..X.....m.6B%Y.2.e. ......H.\....1
w:6(e..m.J.m.... .. .......4...>......p..|.s...d.O........i..I.&M.4
i..I.&M.4i..I.&M.4i..I.&M.4i..I.&M.4i..I.&M.4i..I.&M.4i..I..B...'0....
5I..../'1/>..CQ..._yy`.7........>*...L.o...(_$........$.|=.....F
@B..%...\. ?K....aP..Pp...r.H2=.d4ro\m......o2A.. ...LMG...w...\....H
B@.....,....={...q..%I..._/...0..<....N......{:z.B...kt..\...m.....
..grg<..3.tK...K.0.........P...=q"..........,.r.E..01J..*........2.
[email protected];.l... C........z.:[email protected],N(.%".[.....?\..]^^
...y=a.ftm...:..hI..%i.".0".#....P...t....=t.a...|...D..G... .....q"Y%
!......9..c.A.v0...5..9.Hm^^.0....SV.^*.....j...x.2 !..!.....1.I..

<<< skipped >>>

GET /repository/gd_intermediate.crt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: certificates.godaddy.com


HTTP/1.1 200 OK
Date: Fri, 12 Dec 2014 13:39:11 GMT
Server: Apache
Last-Modified: Thu, 23 Oct 2014 23:14:10 GMT
ETag: "4e2-5061f38c8f480"
Accept-Ranges: bytes
Content-Length: 1250
P3P: CP="IDC DSP COR LAW CUR ADM DEV TAI PSA PSD IVA IVD HIS OUR SAM PUB LEG UNI COM NAV STA"
Connection: close
Content-Type: application/x-x509-ca-cert
0...0............0...*.H........0c1.0...U....US1!0...U....The Go Daddy
Group, Inc.110/..U...(Go Daddy Class 2 Certification Authority0...061
116015437Z..261116015437Z0..1.0...U....US1.0...U....Arizona1.0...U....
Scottsdale1.0...U....GoDaddy.com, Inc.1301..U...*hXXp://certificates.g
odaddy.com/repository100...U...'Go Daddy Secure Certification Authorit
y1.0...U....079692870.."0...*.H.............0.........-....&L.25._.Y.Z
.a.Y;pc...=.*..3.y.:.<0#...0.....=.T......%.!.e)~5..T...29.&U.....X
.......*..B...?.......R.if....].,f..k...QJ./H..u..)...fm.....x|.......
.z....%.....enj..DSp0... X =.tJ..Q....L'Xk.5....1......6.....:.%..I...
g.E....9.6..~.7...q..t0.....?..O........20...0...U........a2.lE...._..
.v.h..0...U.#..0.........L.q.a.=....j..0...U.......0.......03.. ......
..'0%0#.. .....0...hXXp://ocsp.godaddy.com0F..U...?0=0;.9.7.5hXXp://ce
rtificates.godaddy.com/repository/gdroot.crl0K..U. [email protected]. .0806..
........*hXXp://certificates.godaddy.com/repository0...U...........0..
.*.H.....................g.f...:.P..r.Jt.S.7.DI...k3....V..0.<.2!{.
...$...F.%#..g...o.]{z...X*...!.Z...F...c./..))..r,).7.'.O.h.!........
..S....Y..;...$I.....H..E.:6o.E.E.A...DN>.tv...U,..........u....L..
n..=..q...Q@"(I..K..4.....Z..6d.5oown...P.^..S..#c.......c:..h...5.S..
.

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEApfEU0DWxeRF9Lv1AOMPzs= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=510512
Content-Type: application/ocsp-response
Date: Fri, 12 Dec 2014 13:39:53 GMT
Etag: "548ac533-1d7"
Expires: Fri, 19 Dec 2014 01:39:53 GMT
Last-Modified: Fri, 12 Dec 2014 10:36:35 GMT
Server: ECS (ams/D1A6)
X-Cache: HIT
Content-Length: 471
0..........0..... .....0......0...0.......>.i...G...&....cd ...2014
1211200000Z0s0q0I0... ............([email protected]....>.i...G...&...
.cd ...._.M.[........?;....20141211200000Z....20141218200000Z0...*.H..
...........Mf.......X.!0...8..............hl~e.D.[..e.._>zi...~.7..
...W S0H...jl./z]5#.ey...k#G.#x..7a....d..q(..u.Etm.. ..F..NY.NCq....$
w....,....I.c...4Tb.....~5.]...0.M...,.j..,.aL.. ..&..n.......#.L.Z..1
...../..JYG...%.OM*.1Q....E}|.4.BY_nb.?. 8...]G./1./;.?.:.W.HTTP/1.1 2
00 OK..Accept-Ranges: bytes..Cache-Control: max-age=510512..Content-Ty
pe: application/ocsp-response..Date: Fri, 12 Dec 2014 13:39:53 GMT..Et
ag: "548ac533-1d7"..Expires: Fri, 19 Dec 2014 01:39:53 GMT..Last-Modif
ied: Fri, 12 Dec 2014 10:36:35 GMT..Server: ECS (ams/D1A6)..X-Cache: H
IT..Content-Length: 471..0..........0..... .....0......0...0.......>
;.i...G...&....cd ...20141211200000Z0s0q0I0... ............(..A...B..G
@B.X....>.i...G...&....cd ...._.M.[........?;....20141211200000Z...
.20141218200000Z0...*.H.............Mf.......X.!0...8..............hl~
e.D.[..e.._>zi...~.7.....W S0H...jl./z]5#.ey...k#G.#x..7a....d..q(.
.u.Etm.. ..F..NY.NCq....$w....,....I.c...4Tb.....~5.]...0.M...,.j..,.a
L.. ..&..n.......#.L.Z..1...../..JYG...%.OM*.1Q....E}|.4.BY_nb.?. 8...
]G./1./;.?.:.W...

<<< skipped >>>

GET /baltimoreroot/MEUwQzBBMD8wPTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom/nYB45SPUEwQU5Z1ZMIJHWMys+ghUNoZ7OrUETfACBAcnqkY= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.omniroot.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: application/ocsp-response
Date: Fri, 12 Dec 2014 13:40:54 GMT
Last-Modified: Thu, 11 Dec 2014 15:29:57 GMT
Server: ECS (ams/49BB)
X-Cache: HIT
Content-Length: 1406
0..z......s0..o.. .....0.....`0..\0......`;.l.uZ..k.F..^|A.Tb..2014121
1094629Z0g0e0=0... ........./Ev..Y..].....x.#......Y0.GX....T6.{:..M..
..'.F....20141203203011Z....20150303203511Z0...*.H....................
..L..f.Y......C\x....Z....X^....f..Z...u.q..r.(dVv....P..E~j;..PL.C...
Rf..[.......r.Y&/.P.d...0......T...{...(........W..$..^.lP3pZ6...PQ`..
......J~...=..55..D...P.\?8.N..v....(..$y.~y...z../0....V.\.\@E.lG..W=
o1V.kxF.xR.......}$...............W{..v....0...0...0...........'..0...
*.H........0Z1.0...U....IE1.0...U....Baltimore1.0...U....CyberTrust1"0
..U....Baltimore CyberTrust Root0...140122184236Z..150122184140Z0G1.0
...U....US1.0...U....Cybertrust1#0!..U....Cybertrust-Validation-20110.
."0...*.H.............0.........?....(Fb....G... ..=..(L..wK...04..I..
....C...1.Z......U.$b.f..Pa.....S...#..B.........^T..IP8..........h8GM
..*.4.MP..../[email protected]....
$..@@....q2...Uby.e......D....lf...C....ZP}O......7...mM..c.g..j.\.>
;.O....G.A........0..0... .....0......0...U.......0.0...U...........0.
..U.%..0... .......0...U.#..0.....Y0.GX....T6.{:..M.0...U......`;.l.uZ
..k.F..^|A.Tb0...*.H.............. .p.)...09W..Z.......]....}.:..Vr...
..c..U..:V^.O.....<...b*5.c.\.fF./....5'.>./ iS..R0..)..*.!..q.h
.T..ul.}&.......`.1".~.U....rB.BR.s..x..o..Y.......).4:.[.9.=....x...'
.f..\ [email protected]:J!.hRH..!z2DtL.s2.r.....Yi~..E..AzO..i.."N.$j...
b...o..i."{(3....

<<< skipped >>>

GET /ads/conversion/996887577/?random=1793213668&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&cdct=2&convclickts=0&random=3718956492 HTTP/1.1
Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: VVV.google.com


HTTP/1.1 302 Found
Location: hXXp://VVV.google.com.ua/ads/conversion/996887577/?random=1793213668&cv=7&fst=1418391591441&num=1&fmt=3&value=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistration%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=false&cdct=2&convclickts=0&random=3718956492&ipr=y
Cache-Control: private, max-age=43200
Date: Fri, 12 Dec 2014 13:39:51 GMT
Expires: Fri, 12 Dec 2014 13:39:51 GMT
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Server: adclick_server
Content-Length: 944
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
<HTML><HEAD><meta http-equiv="content-type" content="te
xt/html;charset=utf-8">.<TITLE>302 Moved</TITLE></HE
AD><BODY>.<H1>302 Moved</H1>.The document has mov
ed.<A HREF="hXXp://VVV.google.com.ua/ads/conversion/996887577/?rand
om=1793213668&cv=7&fst=1418391591441&num=1&fmt=3&v
alue=0&label=9hZ5CJeizAcQmZit2wM&bg=ffffff&hl=en&guid=
ON&u_h=901&u_w=1683&u_ah=857&u_aw=1683&u_cd=24&
;u_his=1&u_tz=120&u_java=true&u_nplug=0&u_nmime=0&
frm=0&url=http://apps.driversupport.com/postinstall/ScanResultsM
edia?cart=https%3a%2f%2fsecure.driversupport.com%2fregistr
ation%2fcart%3faf%3dmedia&aff=media&wlID=30&uuid=136
82300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanRe
sults&vis=1&ctc_id=CAIVAgAAAB0CAAAA&ct_cookie_present=fals
e&cdct=2&convclickts=0&random=3718956492&ipr=y">her
e</A>...</BODY></HTML>..
....

<<< skipped >>>

GET /ads/user-lists/933633792/?label=NtOJCPjf1hEQgL6YvQM&script=0&ct_cookie_present=false&random=3244418699 HTTP/1.1

Accept: image/png, image/svg xml, image/*;q=0.8, */*;q=0.5
Referer: hXXp://apps.driversupport.com/postinstall/ScanResultsMedia?cart=https://secure.driversupport.com/registration/cart?af=media&aff=media&wlID=30&uuid=13682300-b037-44d0-9742-3c77ad4178ee&appVer=9.1.4.66&ddsrc=ScanResults
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
Accept-Encoding: gzip, deflate
DNT: 1
Connection: Keep-Alive
Host: VVV.google.com


HTTP/1.1 302 Found
Location: hXXp://VVV.google.com.ua/ads/user-lists/933633792/?label=NtOJCPjf1hEQgL6YvQM&script=0&ct_cookie_present=false&random=3244418699&ipr=y
Cache-Control: private, max-age=43200
Date: Fri, 12 Dec 2014 13:39:52 GMT
Expires: Fri, 12 Dec 2014 13:39:52 GMT
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Server: adclick_server
Content-Length: 346
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0.002
<HTML><HEAD><meta http-equiv="content-type" content="te
xt/html;charset=utf-8">.<TITLE>302 Moved</TITLE></HE
AD><BODY>.<H1>302 Moved</H1>.The document has mov
ed.<A HREF="hXXp://VVV.google.com.ua/ads/user-lists/933633792/?labe
l=NtOJCPjf1hEQgL6YvQM&script=0&ct_cookie_present=false&ran
dom=3244418699&ipr=y">here</A>...</BODY></HTML&g
t;..HTTP/1.1 302 Found..Location: hXXp://VVV.google.com.ua/ads/user-li
sts/933633792/?label=NtOJCPjf1hEQgL6YvQM&script=0&ct_cookie_present=fa
lse&random=3244418699&ipr=y..Cache-Control: private, max-age=43200..Da
te: Fri, 12 Dec 2014 13:39:52 GMT..Expires: Fri, 12 Dec 2014 13:39:52
GMT..Content-Type: text/html; charset=UTF-8..X-Content-Type-Options: n
osniff..Server: adclick_server..Content-Length: 346..X-XSS-Protection:
1; mode=block..Alternate-Protocol: 80:quic,p=0.002..<HTML><H
EAD><meta http-equiv="content-type" content="text/html;charset=u
tf-8">.<TITLE>302 Moved</TITLE></HEAD><BODY>
;.<H1>302 Moved</H1>.The document has moved.<A HREF="ht
tp://VVV.google.com.ua/ads/user-lists/933633792/?label=NtOJCPjf1hEQgL6
YvQM&script=0&ct_cookie_present=false&random=3244418699&am
p;ipr=y">here</A>...</BODY></HTML>....

<<< skipped >>>

The Trojan connects to the servers at the folowing location(s):

IEXPLORE.EXE_3712:

.text
`.data
.idata
.rsrc
@.reloc
u\j.Xf9
j.Xf9
USER32.dll
api-ms-win-downlevel-shell32-l1-1-0.dll
IEFRAME.dll
SHELL32.dll
iexplore.pdb
api-ms-win-downlevel-shlwapi-l1-1-0.dll
iertutil.dll
api-ms-win-downlevel-advapi32-l1-1-0.dll
KERNEL32.dll
msvcrt.dll
_wcmdln
_amsg_exit
RegOpenKeyExW
RegCloseKey
<!-- Note: This manifest needs to be kept in sync with iexplore.exe.manifest -->
<assemblyIdentity version="5.1.0.0"
name="Microsoft.InternetExplorer"
<windowsSettings>
<dpiAware xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
<!--The ID below indicates application support for Windows 8 -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
KEYW
.ENNNG.
a.ry.v
l.igM4
?1%SGf
xh.JW^
.97777"7" " " !
3.... )) 
8888888888888
8888888888
.lPV)
úW1
.ApX/
H.ZAf
ð[U
%s!FK
1YYYY1YY9GEAA=77YRNNNW:.VT1
888777777
Y.hilkRROMLK=C,
..(((($$
3...((((%
3....(.''$
3.2...((((%
33.2....(,'
55323222...
(%&'00443445?
00.,,,4(
000.,,9(
0020..9(
003200;(
(#'( (''''!'!
Microsoft.InternetExplorer.Default
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe
{28fb17e0-d393-439d-9a21-9474a070473a}
imm32.dll
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}
Kernel32.dll
"%s" %s
kernel32.dll
IEXPLORE.EXE
{00000000-0000-0000-0000-000000000000}
\\?\Volume
Imaging_CreateWebPagePreview_Perftrack
Browseui_Tabs_Tearoff_BetweenWindows
Browseui_Tabs_Tearoff_BetweenWindows_TabProc
Frame_URLEntered
Imaging_CreateWebPagePreview
WS_ExecuteQuery
Shdocvw_BaseBrowser_FireEvent_WindowStateChanged
IdleTask_Execution_Time
Shdocvw_BaseBrowser_FireEvent_BeforeScriptExecute
IMTravelLogMVC_TravelURL
10.00.9200.16521 (win8_gdr_soc_ie.130216-2100)
Windows
10.00.9200.16521

DriverSupportAOsvc.exe_3832:

.text
`.rdata
@.data
.rsrc
FSShg$@
%s error: %d
@usage: ReportStatus(STATE[, WAITHINT])
PerlSvc::ReportStatus
PerlSvc::ReportEvent
PerlSvc.cpp
Cannot read license file '%s'
License file '%s' does not exist
ActiveState.lic
Could not create directory '%s'
Directory '%s' does not exist
shell32.dll
shfolder.dll
X.inf
Error: Can't locate %s
%sPATH=%s
Panic: Some symbols not resolvable from %s
Panic: Can't create %s
Panic: Can't extract %s
Panic: Can't allocate memory for %s
Panic: Can't extract MD5 checksum for %s
Panic: Can't malloc name (%d)
perl.md5
dyndll loaded %s
Already loaded %s
perl510.dll
Perl_hv_common_key_len
mkdir("%s") failed, errno=%d
chmod("%s", 0755) failed, errno=%d
TEMP path need more than %d characters
Panic: Can't alloc %lu bytes for %s
\/:*?<>|
advapi32.dll
PerlApp::exe
Error: cannot load shared library '%s'
Panic: Can't find bfs section in '%s'
-e#line 1 "%s"
PERL5DB=BEGIN { $PerlApp::P=$^P; $^P=0; delete %s; PerlApp::_init(%ld); eval %s('%s'); die $@ if $@; $^P=$PerlApp::P;}BEGIN { require 'perl5db.pl' }
-eBEGIN { PerlApp::_init(%ld); eval %s('%s'); die $@ if $@ }
/perl510.dll
PDK-%d.%d.%d
inflate 1.1.4 Copyright 1995-2002 Mark Adler
KERNEL32.dll
USER32.dll
ReportEventA
RegCloseKey
RegOpenKeyExA
ADVAPI32.dll
MSVCRT.dll
1.1.4
<assemblyIdentity version="0.0.0.0" processorArchitecture="X86" name="Perl" type="win32" />
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0"
processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" />
po%?c
Uy.UF
;Úw
L:"9%c}
f\%DY2
.ziKT
N:\}n
d.UIA
\.wD-
R!$p%c
x4!û
1%fh!2
-3a1W7A}
.Vx"xV
%ULv5
6Uu.AI
.esf 
];.yhm
"%u04_
G#?.CX
.xlGF
.Yu,b\A
xm.Ol
h!2.Ht
hX%c.
).Esg
q!".vR
3YO_%x
k.Rd'
C`}.EX
.xo)3xobq
%S^UA
%f?Q*-)
-t".BK
I'&.reu
ov.nO
i{7.hzg
S"'.vK
g}F.qaX
%u#ha@
sm%Dp
:s.Qb
J.DjJ
V=.Zy
XfI%f
sm%.nI
a.rGUr-
-{.Tt
3.HSx
[K.jZ
 q_%S
zy%uC6
.OY*P
q %S27|
9 1.db
0YD.Dw
;I%F>
TX8%Uct
xZ.RU
%SIR<
e1J(t.jIm
.tD_J
:%8xR
Q1.RWC;9
U,%Uz
7j.qi#"
;E.Ba
<>%SA
D.nV%
Sn
3.OP.;
,O.Cy
6"%C;
R.ljMTR
n.Ls%
X=^5%c
N{.vu
>D5%D?
*V.ls>Q
&%fSn>
TO%U:
6%fi6
*bÍ
.wQ=!
N.lY4
b-YbvW}
%XC#L
W&V%cX
uo%.X
.oe[=
8%.jX
cI.BD
lHGM%D
|TCpi
ko%Sj
.CJ'V
-J}6f<
s.ZSQ{
.PwQ:B>
t.*.fd
4fw%Ut
.ch!D
a.iJhf
|.xtU
>.HygKr_
Driver Support Active Optimization Service
1.0.4.7683

DriverSupportAOsvc.exe_3832_rwx_00270000_0000A000:

.text
`.rdata
@.data
.reloc
.t.Ht$
userenv.dll
advapi32.dll
Cannot load functions from advapi32.dll library
Cannot load advapi32.dll library
shell32.dll
usage: Win32::MsgBox($message [, $flags [, $title]]);
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
shfolder.dll
%d.%d.%d.%d
netapi32.dll
usage: Win32::Spawn($cmdName, $args, $PID)
Win32::LoginName
Win32::MsgBox
Win32.xs
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
KERNEL32.dll
USER32.dll
RegCloseKey
RegOpenKeyExA
ADVAPI32.dll
ole32.dll
VERSION.dll
MSVCRT.dll
Win32.dll

DriverSupportAOsvc.exe_3832_rwx_00280000_00008000:

.text
`.rdata
@.data
.reloc
Win32::API::Call: parameter %d must be a Win32::API::Callback object!
Win32::API::Call: parameter %d must be an array reference!
Wrong number of parameters: expected %d, got %d.
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
perl510.dll
KERNEL32.dll
MSVCRT.dll
API.dll

DriverSupportAO.exe_3856:

.text
`.rdata
@.data
.rsrc
Panic: Cannot determine full path of '%s'
Cannot read license file '%s'
License file '%s' does not exist
ActiveState.lic
Could not create directory '%s'
Directory '%s' does not exist
shell32.dll
shfolder.dll
X.inf
Error: Can't locate %s
%sPATH=%s
Panic: Some symbols not resolvable from %s
Panic: Can't create %s
Panic: Can't extract %s
Panic: Can't allocate memory for %s
Panic: Can't extract MD5 checksum for %s
Panic: Can't malloc name (%d)
perl.md5
dyndll loaded %s
Already loaded %s
perl510.dll
Perl_hv_common_key_len
mkdir("%s") failed, errno=%d
chmod("%s", 0755) failed, errno=%d
TEMP path need more than %d characters
Panic: Can't alloc %lu bytes for %s
\/:*?<>|
advapi32.dll
PerlApp::exe
Error: cannot load shared library '%s'
Panic: Can't find bfs section in '%s'
-e#line 1 "%s"
PERL5DB=BEGIN { $PerlApp::P=$^P; $^P=0; delete %s; PerlApp::_init(%ld); eval %s('%s'); die $@ if $@; $^P=$PerlApp::P;}BEGIN { require 'perl5db.pl' }
-eBEGIN { PerlApp::_init(%ld); eval %s('%s'); die $@ if $@ }
/perl510.dll
PDK-%d.%d.%d
inflate 1.1.4 Copyright 1995-2002 Mark Adler
KERNEL32.dll
USER32.dll
ADVAPI32.dll
MSVCRT.dll
1.1.4
<assemblyIdentity version="0.0.0.0" processorArchitecture="X86" name="Perl" type="win32" />
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0"
processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" />
m.gnA.
.MgB(
>$%C,$
Jz.WJ
.TB%T
.lUFe
R%L.xO
%sEy\
fN>w%D
%sa>2
c.PH!
!A%Ue,/0
y_%%S
j.eUv
)&ÊWa)
a.BZ\
o÷7
%c"'5
%u.Y%
%x!#$
%s$,?
s9.mj
`.ViM
U%X@s
:.eGe
o7`%u
LV%UqjR3
%fLAz
-.RP ~
z4_%x
%FMWpv~
%SI#},)
^_.RX
[G};>*%x
$.gjn
LÝL
IXq>.NU
xw.Fo
.Zx]Tx
-vr}n0
.WJMW
9%Xesi:
`j|.hq
8%Xtu
Ds;d.Ul
m.XLxA
.ssL%I
q{XH.kFX
_.Uw O
%F-Mw"
-.SW[
V&.hg
tTD%d
/.oTi
_^e.xS
Ee.sY
s3.iC~
.qh;2yk
'8%xe
.tlSYc
2&.ez
7q.YZ[
*-.Rk
rA%sSj
.YNUm
&%CSv
.ewh/H
<.JVc
Ce.Na
UkH@n%X
,.Dn<
N.gNn>u|
.nL#yI
td.Et
xt %X
<Qs.jf
O)b&4.mfo
k.cV*
p.OD|
DI.Kz
~7.Xg
J3CO%U
}.asF
p".CKj
nT.FM
;.USD
.uY(/
.WYih
iCsQlHJ
15.oK
h.rRvt
Hin5;i.zpn
udPR=p^
`i%x1h&b
(}OY
kEYv
!.LT}
.HVx n&V
WHt 9l.Vx
}O.kwR
d2l.eN
6A.Jt
LD8.sd
.Aeg$=T
.XY"b\
.MMTs
%UN/s
]|L%u
%d;9,
W%s;E
fA4.zU|
.qYWY'E
.EF)9
.zt@nI
u-t}).O
]I.lU0
:6M.Zx
=.Eh#=
mK$b%X
.knS$
.FUDK
.AtVv^
L]1.gg
R.ILrN
iD.Tu
K.EI9
.Zm F
p.MNT
sWt%x
wg1.gV
D8R^.jv&
x.FBp
I.Vm~
D,.RV
\jT.tOK[
.NPZM
bp[%x
rÖO
%X8Fn
ND.sY
.Wy">=>
*6D%S`
`f.lCC6
x%u'(R
.HL;\
^5L/X%XM
kO.xH
Oc*}RS.ci
.ppf3
tW.sR
.FT|Yl
Ik.lG-
N.zZ#c
c*N<%x
x.GMj
{J.DD2I
].Qi$x
ww.bR
rq.kP
@&F1.KQ1
4"õ
|fTPSDv
R.ui4o
q%DMh
G.kqk
H.mZ}
.dY%PH
.KVe}
*.sRS{
$.bKA
A95%S]
!H.ws
.Bf""D
2%u0{|M
&t\%x
:.qFYx
(S_%f
.utc|
!4 .lt<`&(
]>.yNx/
.PZT3}
#%;9bO%d
{TCpx$%
(2uDP
.nOW8s
Q..qC
&%C%M
y%fM>
.s.qdO
6`.lPs
KSM%D`
'.iU_)
/!.Kzl
xDi.tx
ejE.UH
Z.FZE-52
u|j%x
v9S%S]pV
.zgJI
%3'.%f&-
-q.Fw
.sirg(e:A
.BFEc
U.pxq 
ed1.Ir
7^.mGy
XEI2%S
 8FsqL
M#.Dt>
.eouu
M%CWS
J\.PnBx
7.JiY
*.lZ..j
{.Yy9
O|Msgq
AxT.Cx
F?%s?
FON%u
%uP"`
YO.Lh
6P[%d
\.wrK 
~.cZ!
VFk.ec
Jz.dK
u.iEu.
.(V.FM47
'kp1.Edo
04.ND
o4.yb
.uh(v
f{w.gb
=%d&Z
.HBxt
<.MMa
M%x|/
udP@ta
.Dq3?{
T%xP,
.Ung1
W.GK8<
1..lZX
.Fn9;LS
[e
:?}X.in
WEBo
?.SD$
:kz%cY5M\#<
l0q%f
.LH=J
p.Kh^
wh3.sm
]Hg
%6S)r
DEm:$%ft :
%F{s,
@P^.Fr
SJG.aw!9
%s_xk
Ao.Ph
zI.Iy?oYu:<R
S&>`.tY
u,=*ou%X/Sa
a-f3}
?os%d
0?ÿ
b.CQ\
K%U^F?
^%uM%N
$i.LSJ)
.QkPI
-4d}5
RYB%CS
8.ans
k .vJ
-y0}e
gQ.JqPw]
(R?
.Nf%<
Ez.lr
Udp$U
Ë.Fs.
Q4q|%F
7ÜkR
|4{%fu
f%dy'
f;Mw*
z%s:w
Zo.yz
.Ae$%"O3
c.VCg
^.bzj,
.fTs1
okQ%X
.go'ngeO
.drrc
.rm e$:
VzR%S
7\:*-E}
86U^c.gT8
%SVA't
.Cg4-
[4.GJ
8^u%D
 ]V%C<wG*
N4OD.Hq]
%XLai
=aZ%U|
BV3%x
ðTKh
.cA,J
%U&i}
aX.UB!
%S#=Z.*y
.xn.g
}h'.fUY
op.rk
 u6(.Ba
.BjQD
.BzQd
1uj%cI
\|%u0
.Uu=~P
%S9*5S
O7%d"
jykn:hh.HX&
Driver Support Active Optimization
1.0.4.7683

DriverSupportAOsvc.exe_3832_rwx_002A0000_00006000:

.text
`.rdata
@.data
.reloc
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Usage: CODE(0x%lx)(%s)
Usage: %s(%s)
Usage: %s::%s(%s)
No filehandle passed
Bad conversion type (%d)
&Digest::MD5::%s function %s
perl510.dll
MSVCRT.dll
KERNEL32.dll
MD5.dll

DriverSupportAOsvc.exe_3832_rwx_002B0000_00008000:

.text
`.rdata
@.data
.reloc
sortkeys
quotekeys
Sortkeys subroutine did not return ARRAYREF
Usage: CODE(0x%lx)(%s)
Usage: %s(%s)
Usage: %s::%s(%s)
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
Perl_hv_iterkeysv
perl510.dll
MSVCRT.dll
KERNEL32.dll
Dumper.dll

DriverSupportAOsvc.exe_3832_rwx_003E0000_00015000:

.text
`.rdata
@.data
.reloc
OLE_E_ADVISENOTSUPPORTED
@RPC_S_UNSUPPORTED_TYPE
@RPC_S_UNSUPPORTED_TRANS_SYN
@RPC_S_UNSUPPORTED_NAME_SYNTAX
@RPC_S_UNSUPPORTED_AUTHN_LEVEL
@RPC_S_PROTSEQ_NOT_SUPPORTED
@RPC_S_NOT_ALL_OBJS_UNEXPORTED
@RPC_S_NOTHING_TO_EXPORT
@RPC_S_CANNOT_SUPPORT
REGDB_E_KEYMISSING
CO_E_SERVER_EXEC_FAILURE
CO_E_INIT_SCM_EXEC_FAILURE
ACACHE_S_FORMATETC_NOTSUPPORTED
@ERROR_WRONG_PASSWORD
@ERROR_UNKNOWN_PORT
@ERROR_TRANSFORM_NOT_SUPPORTED
L@ERROR_TOO_MANY_CMDS
a@ERROR_SUBST_TO_JOIN
@ERROR_PORT_UNREACHABLE
m@ERROR_PIPE_NOT_CONNECTED
@ERROR_PIPE_LISTENING
@ERROR_PIPE_CONNECTED
l@ERROR_PIPE_BUSY
@ERROR_PASSWORD_RESTRICTION
@ERROR_PASSWORD_MUST_CHANGE
@ERROR_PASSWORD_EXPIRED
@ERROR_OPERATION_ABORTED
@ERROR_NULL_LM_PASSWORD
@ERROR_NO_USER_SESSION_KEY
I@ERROR_NOT_SUPPORTED
a@ERROR_NOT_JOINED
@ERROR_METAFILE_NOT_SUPPORTED
@ERROR_LOGIN_WKSTA_RESTRICTION
@ERROR_LOGIN_TIME_RESTRICTION
@ERROR_LOCAL_USER_SESSION_KEY
@ERROR_KEY_HAS_CHILDREN
@ERROR_KEY_DELETED
a@ERROR_JOIN_TO_SUBST
@a@ERROR_JOIN_TO_JOIN
`@ERROR_IS_JOIN_TARGET
`b@ERROR_IS_JOIN_PATH
`@ERROR_IS_JOINED
@ERROR_INVALID_PASSWORDNAME
U@ERROR_INVALID_PASSWORD
@ERROR_INVALID_MSGBOX_STYLE
g@ERROR_INVALID_EXE_SIGNATURE
@ERROR_ILL_FORMED_PASSWORD
@ERROR_HOTKEY_NOT_REGISTERED
@ERROR_HOTKEY_ALREADY_REGISTERED
h@ERROR_EXE_MARKED_INVALID
q@ERROR_EAS_NOT_SUPPORTED
@ERROR_DISK_OPERATION_FAILED
@ERROR_CLIPPING_NOT_SUPPORTED
@ERROR_CLASS_HAS_WINDOWS
@[@ERROR_BROKEN_PIPE
l@ERROR_BAD_PIPE
h@ERROR_BAD_EXE_FORMAT
@ERROR_BADKEY
e@ERROR_ATOMIC_LOCKS_NOT_SUPPORTED
@FACILITY_WINDOWS
MK_E_INTERMEDIATEINTERFACENOTSUPPORTED
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
MSVCRT.dll
KERNEL32.dll
WinError.dll

DriverSupportAOsvc.exe_3832_rwx_00660000_00028000:

.text
`.rdata
@.data
.reloc
hKey
sComputer, hRootKey, ohKey
swComputer, hRootKey, ohKey
hKey, sSubKey, ohSubKey
hKey, swSubKey, ohSubKey
hKey, sSubKey, uZero, sClass, uOpts, uAccess, pSecAttr, ohNewKey, ouDisp
hKey, swSubKey, uZero, swClass, uOpts, uAccess, pSecAttr, ohNewKey, ouDisp
hKey, sSubKey
hKey, swSubKey
hKey, sValueName
hKey, swValueName
hKey, uIndex, osName, ilNameSize
hKey, uIndex, oswName, ilwNameSize
hKey, uIndex, osName, iolName, pNull, osClass, iolClass, opftLastWrite
hKey, uIndex, oswName, iolwName, pNull, oswClass, iolwClass, opftLastWrite
hKey, uIndex, osName, iolName, pNull, ouType, opData, iolData
hKey, uIndex, oswName, iolwName, pNull, ouType, opData, iolData
hKey, uSecInfo, opSecDesc, iolSecDesc
hKey, sSubKey, sFileName
hKey, swSubKey, swFileName
hKey, bWatchSubtree, uNotifyFilter, hEvent, bAsync
hKey, sSubKey, uOptions, uAccess, ohSubKey
hKey, swSubKey, uOptions, uAccess, ohSubKey
hKey, osClass, iolClass, pNull, ocSubKeys, olSubKey, olSubClass, ocValues, olValName, olValData, olSecDesc, opftTime
hKey, oswClass, iolwClass, pNull, ocSubKeys, olwSubKey, olwSubClass, ocValues, olwValName, olValData, olSecDesc, opftTime
%s: %s (%d bytes < %d * %d)
hKey, ioarValueEnts, icValueEnts, opBuffer, iolBuffer
hKey, sSubKey, osValueData, iolValueData
hKey, swSubKey, oswValueData, iolValueData
hKey, sName, pNull, ouType, opData, iolData
hKey, swName, pNull, ouType, opData, iolData
hKey, sSubKey, sNewFile, sOldFile
hKey, swSubKey, swNewFile, swOldFile
hKey, sFileName, uFlags
hKey, swFileName, uFlags
hKey, sFileName, pSecAttr
hKey, swFileName, pSecAttr
hKey, uSecInfo, pSecDesc
hKey, sSubKey, uType, sValueData, lValueData
hKey, swSubKey, uType, swValueData, lValueData
hKey, sName, uZero, uType, pData, lData
hKey, swName, uZero, uType, pData, lData
Win32API::Registry::RegUnLoadKeyW
Win32API::Registry::RegUnLoadKeyA
Win32API::Registry::RegSetKeySecurity
Win32API::Registry::RegSaveKeyW
Win32API::Registry::RegSaveKeyA
Win32API::Registry::RegRestoreKeyW
Win32API::Registry::RegRestoreKeyA
Win32API::Registry::RegReplaceKeyW
Win32API::Registry::RegReplaceKeyA
Win32API::Registry::_RegQueryInfoKeyW
Win32API::Registry::_RegQueryInfoKeyA
Win32API::Registry::RegOpenKeyExW
Win32API::Registry::RegOpenKeyExA
Win32API::Registry::RegOpenKeyW
Win32API::Registry::RegOpenKeyA
Win32API::Registry::RegNotifyChangeKeyValue
Win32API::Registry::RegLoadKeyW
Win32API::Registry::RegLoadKeyA
Win32API::Registry::_RegGetKeySecurity
Win32API::Registry::RegFlushKey
Win32API::Registry::_RegEnumKeyExW
Win32API::Registry::_RegEnumKeyExA
Win32API::Registry::_RegEnumKeyW
Win32API::Registry::_RegEnumKeyA
Win32API::Registry::RegDeleteKeyW
Win32API::Registry::RegDeleteKeyA
Win32API::Registry::RegCreateKeyExW
Win32API::Registry::RegCreateKeyExA
Win32API::Registry::RegCreateKeyW
Win32API::Registry::RegCreateKeyA
Win32API::Registry::RegCloseKey
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
KERNEL32.dll
RegCloseKey
RegCreateKeyA
RegCreateKeyW
RegCreateKeyExA
RegCreateKeyExW
RegDeleteKeyA
RegDeleteKeyW
RegEnumKeyA
RegEnumKeyW
RegEnumKeyExA
RegEnumKeyExW
RegFlushKey
RegGetKeySecurity
RegLoadKeyA
RegLoadKeyW
RegNotifyChangeKeyValue
RegOpenKeyA
RegOpenKeyW
RegOpenKeyExA
RegOpenKeyExW
RegQueryInfoKeyA
RegQueryInfoKeyW
RegReplaceKeyA
RegReplaceKeyW
RegRestoreKeyA
RegRestoreKeyW
RegSaveKeyA
RegSaveKeyW
RegSetKeySecurity
RegUnLoadKeyA
RegUnLoadKeyW
ADVAPI32.dll
MSVCRT.dll
Registry.dll

DriverSupportAOsvc.exe_3832_rwx_00690000_00006000:

.text
`.rdata
@.data
.reloc
?456789:;<=
!"#$%&'()* ,-./0123
=X
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
MSVCRT.dll
KERNEL32.dll
Base64.dll

DriverSupportAOsvc.exe_3832_rwx_006A0000_00006000:

.text
`.rdata
@.data
.reloc
%s is not a valid Time::HiRes macro
Your vendor has not defined Time::HiRes macro %s, used
Unexpected return type %d while processing Time::HiRes macro %s, used
.Auseconds
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
perl510.dll
KERNEL32.dll
MSVCRT.dll
HiRes.dll

DriverSupportAOsvc.exe_3832_rwx_02260000_00007000:

.text
`.rdata
@.data
.reloc
cP, appname, cmdline, inherit, flags, curdir
kernel32.dll
%s: %s is not a reference
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
KERNEL32.dll
MSVCRT.dll
Process.dll

DriverSupportAOsvc.exe_3832_rwx_10000000_0000C000:

.text
`.rdata
@.data
.reloc
KEY_EVENT
ENHANCED_KEY
Win32::Console::_SetConsoleOutputCP
Win32::Console::_GetConsoleOutputCP
Win32::Console::_GetLargestConsoleWindowSize
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
GetLargestConsoleWindowSize
GetConsoleOutputCP
SetConsoleOutputCP
KERNEL32.dll
USER32.dll
MSVCRT.dll
Console.dll

DriverSupportAOsvc.exe_3832_rwx_28000000_000DB000:

.text
`.rdata
@.data
.rsrc
@.reloc
Y}.Sh
SWSSh
PPj.PSV
9Q4t.RRj
@tCPV
.YYu6
Wj.VS
98t%9x
'udPV
t.HHt
t.IIt
[291086]
Filehandle STDIN reopened as %s only for output
Filehandle STD%s reopened as %s only for input
Can't open bidirectional pipe
piped open
Missing command in piped open
More than one argument to '<%c' open
More than one argument to '%c&' open
More than one argument to '>%c' open
Warning: unable to close filehandle %s properly.
Can't open %s: %s
Can't do inplace edit on %s: %s
Can't do inplace edit: %s is not a regular file
Use of -l on filehandle %s
Can't exec "%s": %s
Unrecognized signal name "%s"
panic: do_trans_simple line %d
panic: do_trans_count line %d
panic: do_trans_complex line %d
panic: do_trans_simple_utf8 line %d
panic: do_trans_complex_utf8 line %d
panic: do_vop called for op %u (%s)
nkeys(k)
(xsub 0x%lx %d)
SUB %s =
FORMAT %s =
%cx{%lx}
%co
[UTF8 "%s"]
CV(%s)
<%lu%s>
PMFLAGS = (%s)
PMf_PRE %c%s%c%s
PRIVATE = (%s)
FLAGS = (%s)
LABEL = "%s"
PACKAGE = "%s"
(was %s)
%*sTYPE = %s ===>
-> %s
GV_NAME = %s
=> HEf_SVKEY
MG_TYPE = PERL_MAGIC_%s
PAT = %s
MG_FLAGS = 0xX
MG_PRIVATE = %d
MG_VIRTUAL = &PL_vtbl_%s
nkeys
%s = 0x%lx
%s" :: "
UNKNOWN(0x%lx) %s
FILE = "%s"
RARE = %u
FLAGS = %u
TYPE = %c
FLAGS = (%s)
[UTF8 "%s"]
Elt %s
NAME = "%s"
KEYS = %ld
%d%s:%d
OUTSIDE = 0x%lx (%s)
FILE = "%s"
TYPE = '%c'
BOTTOM_NAME = "%s"
FMT_NAME = "%s"
TOP_NAME = "%s"
( %s . )
IMPORT
SHAREKEYS,
PCS_IMPORTED,
cmd /x /c
Use of uninitialized value%s%s%s
Unquoted string "%s" may clash with future reserved word
Unsuccessful %s on filename containing newline
Can't use %s ref as %s ref
Can't use string ("%.32s") as %s ref while "strict refs" in use
Can't use string ("%-32p") as %s ref while "strict refs" in use
Can't use an undefined value as %s reference
Modification of non-creatable array value attempted, subscript %d
Insecure dependency in %s%s
Unsupported socket function "%s" called
Unsupported directory function "%s" called
The %s function is unimplemented
"%s" variable %s can't be in a package
!"#$%&'()* ,-./0123456789:;<=>?
unknown custom operator
getservbyport
pipe
join or string
undef operator
defined operator
append I/O operator
quoted execution (``, qx)
reference-type operator
null operation
getlogin
gsbyport
msgrcv
msgsnd
msgctl
msgget
ftpipe
fteexec
ftrexec
pipe_op
join
keys
PIPE
Bad symbol for %s
Cannot convert a reference to %s to typeglob
Can't locate package %-p for @%s::ISA
unimport
import
%s::SUPER
Use of inherited AUTOLOAD for non-method %s::%.*s() is deprecated
$%c is no longer supported
XPORT
Had to create %s unexpectedly
Global symbol "%s%s" requires explicit package name
(Did you mean &%s instead?)
Variable "%c%s" is not imported
panic: Can't use %%%c because %-p does not support method %s
panic: Can't use %%%c because %-p is not available
Name "%s::%s" used only once: possible typo
%s::_GEN_%ld
%s method "%.256s" overloading "%s" in package "%.256s"
Operation "%s": no method found,%sargument %s%s%s%s
panic: hv_store() failed in set_mro_private_data() for '%.*s' %d
panic: hv_store() failed in mro_register() for '%.*s' %d
Recursive inheritance detected in package '%s'
Cannot modify shared string table in hv_%s
Attempt to access disallowed key '%-p' in a restricted hash
Attempt to delete disallowed key '%-p' from a restricted hash
Attempt to delete readonly key '%-p' from a restricted hash
Attempt to free non-existent shared string '%s'%s, Perl interpreter: 0x%p
panic: refcounted_he_value bad flags %x
Can't fix broken locale name "%s"
are supported and installed on your system.
LANG = %c%s%c
%.*s = "%s",
LC_ALL = %c%s%c,
No such signal: SIG%s
No such hook: %s
FIRSTKEY
NEXTKEY
SIG%s handler "%s" not defined.
Signal SIG%s received, but no signal handler set.
ABinary number > 0b11111111111111111111111111111111 non-portable
AIllegal binary digit '%c' ignored
Hexadecimal number > 0xffffffff non-portable
Illegal hexadecimal digit '%c' ignored
Octal number > 037777777777 non-portable
Illegal octal digit '%c' ignored
Can't declare class for non-scalar %s in "%s"
Can't use global %c^%c%s in "%s"
Can't use global %s in "%s"
Useless use of %s in void context
Useless localization of %s
Can't modify %s in %s
Can't localize lexical variable %s
That use of $[ is unsupported
Can't declare %s in "%s"
attributes.pm
Applying %s to %s will act on scalar(%s)
Parentheses missing around "%s" list
panic: fold_constants JMPENV_PUSH returned %d
'%s' trapped by operation mask
&`'123456789 -
Value of %s%s can be "0"; test with defined()
() operator
Can't use %s for loop variable
%s:%ld-%ld
Subroutine %s redefined
Constant subroutine %s redefined
%s[%s:%ld]
panic: no address for '%s' in '%s'
Possible precedence problem on bitwise %c operator
%s argument is not a HASH or ARRAY element or slice
%s argument is not a HASH or ARRAY element or a subroutine
%s argument is not a subroutine name
Can't use bareword ("%-p") as %s ref while "strict refs" in use
Constant is not %s reference
Array @%-p missing the @ in argument %ld of %s()
Useless use of %s with no values
Hash %%%-p missing the %% in argument %ld of %s()
%s%c...%c
Missing comma after first argument to %s function
Not enough arguments for %s
Too many arguments for %s
Type of arg %d to %s must be %s (not %s)
Malformed prototype for %s: %-p
(Maybe you meant system() when you said exec()?)
No such class field "%s" in variable %s of type %s
"our" variable %s redeclared
"%s" variable %s masks earlier declaration in same %s
Variable "%s" is not available
Variable "%s" will not stay shared
-. 0x%lx<%lu>
-. 0x%lx<%lu> (%lu,%lu) "%s"
-. 0x%lx<%lu> FAKE "%s" flags=0x%lx index=%lu
-V[:variable] print configuration summary (or a single Config.pm variable)
-v print version, subversion (includes VERY IMPORTANT perl info)
-U allow unsafe operations
-[mM][-]module execute "use/no module..." before executing program
-f don't do $sitelib/sitecustomize.pl at startup
v5.10.1
Unbalanced string table refcount: (%ld) for "%s"
Execution of %s aborted due to compilation errors.
%s had compilation errors.
PERL_SIGNALS illegal: "%s"
Can't chdir to %s
Illegal switch in PERL5OPT: -%c
BEGIN { do '%s/sitecustomize.pl' }
5.10.1
No code specified for -%c
Unrecognized switch: -%s (-h will show valid options)
Config::config_vars(qw%c%s%c)
; $"="\n "; @env = map { "$_=\"$ENV{$_}\"" } sort grep {/^PERL/} keys %ENV;
" Built under %s\n
$_ = join ' ', sort qw( PERL_DONT_CREATE_GVSV PERL_MALLOC_WRAP USE_SITECUSTOMIZE
%s syntax OK
require q%c%s%c
Internet, point your browser at hXXp://VVV.perl.org/, the Perl Home Page.
Binary build 1006 [291086] provided by ActiveState hXXp://VVV.ActiveState.com
(with %d registered patch%s, see perl -V for more detail)
This is perl, %-p built for %s
Missing argument to -%c
Can't use '%c' after -mname
Invalid module name %.*s with -%c option: contains single ':'
Module name required with -%c option
split(/,/,q{%s});
"-%c" is on the #! line, it must also be used on the command line%s
Usage: %s [switches] [--] [programfile] [arguments]
dump is not supported
$0s
Can't open perl script "%s": %s
Can't open nul: %s
%s -ne%s%s%s %s | %-p %s %-p %s
C:\WINNT\TEMP\perl-dnjvrgkrkqrtrykitgvqcoxgyxozxpsgcwltzssxnkepx\bin
Wrong syntax (suid) fd script name "%s"
No %s allowed with (suid) fdscript
/5.10.1
/5.10.1/MSWin32-x86-multi-thread
%s/%s
%s failed--call queue aborted
Can't find an opnumber for "%s"
?$@@%&*$
Constant subroutine %s undefined
?Can't take %s of %g
panic: avhv_delete no longer supported
panic: unimplemented op %s (#%d) called
%*.*f
%#*.*f
%0*.*f
%#0*.*f
Apanic: bad gimme: %d
%sCompilation failed in require
Label not found for "last %s"
Exiting %s via %s
Label not found for "next %s"
Label not found for "redo %s"
Can't find label %s
_<(%.10seval %lu)[%s:%ld]
%sCompilation failed in regexp
Can't locate %s
%s in @INC%s%s (@INC contains:
(change .h to .ph maybe?)
%s: %s
/loader/0x%lx/%s
Attempt to reload %s aborted.
v%d.%d.%d
_<(eval %lu)[%s:%ld]
Can't return %s to lvalue scalar context
Not %s reference
glob failed (child exited with status %d%s)
utf8 "\xX" does not map to Unicode
$&*(){}[]'";\|?<>~`
glob failed (can't start child: %s)
Can't return a %s from lvalue subroutine
%s returned from lvalue subroutine in scalar context
Can't return %s from lvalue subroutine
Can't locate object method "%s" via package "%.*s" (perhaps you forgot to load "%.*s"?)
Can't locate object method "%s" via package "%.*s"
Can't call method "%s" %s
Can't call method "%s" on unblessed reference
Can't call method "%s" on an undefined value
Invalid type '%c' in unpack
0000000000
Character in '%c' format wrapped in unpack
Malformed UTF-8 string in '%c' format in unpack
Character(s) in '%c' format wrapped in %s
'/' does not take a repeat count in %s
Malformed integer in [] in %s
Duplicate modifier '%c' after '%c' in %s
Can't use '%c' in a group with different byte-order in %s
Can't use both '<' and '>' after type '%c' in %s
'%c' allowed only after types %s in %s
Too deeply nested ()-groups in %s
()-group starts with a count in %s
Invalid type ',' in %s
'X' outside of string in %s
Within []-length '%c' not allowed in %s
Invalid type '%c' in %s
Within []-length '*' not allowed in %s
No group ending character '%c' found in template
'%c' outside of string in pack
Invalid type '%c' in pack
...caught
...propagated
Opening dirhandle %s also as a file
Can't locate object method "%s" via package "%-p"
Self-ties of arrays and hashes are not supported
AnyDBM_File.pm
.ANon-string passed as bitmask
Undefined format "%s" called
Undefined top format "%s" called
%s_TOP
Wide character in %s
Possible memory corruption: %s overflowed 3rd argument
lstat() on filehandle %s
Opening filehandle %s also as a directory
readdir() attempted on invalid dirhandle %s
telldir() attempted on invalid dirhandle %s
seekdir() attempted on invalid dirhandle %s
rewinddir() attempted on invalid dirhandle %s
closedir() attempted on invalid dirhandle %s
%s %s - d:d:d %d
&'( /01,*)854
CURLY_B_max_fail
CURLY_B_max
CURLY_B_min_fail
CURLY_B_min
CURLY_B_min_known_fail
CURLY_B_min_known
CURLYM_B_fail
CURLYM_B
CURLYM_A_fail
CURLYM_A
CURLYX_end_fail
CURLYX_end
CURLYX
CURLYM
CURLYN
CURLY
%s in regex m/%.*s%s/
Lookbehind longer than %lu not implemented in regex m/%.*s%s/
%s in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
panic: Unknown flags %d in named_buff
panic: Unknown flags %d in named_buff_iter
panic: Unknown flags %d in named_buff_scalar
Sequence (?%c... not terminated
Useless (%s%c) - %suse /%c modifier in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Useless (%sc) - %suse /gc modifier in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Sequence (?%c...) not implemented
Sequence (?(%c... not terminated
in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
%.*s matches null string many times in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Quantifier in {,} bigger than %d
Unrecognized escape \%c passed through in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Missing right brace on \%c{}
Ignoring zero length \N{%s} in character class in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Ignoring excess chars from \N{%s} in character class in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Constant(\N{%s}): Call to &{$^H{charnames}} did not return a defined value
Constant(\N{%s}): $^H{charnames} is not defined
Constant(\N{%s}) unknown: (possibly a missing "use charnames ...")
%cutf8::Is%s
False [] range "%*.*s" in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Unrecognized escape \%c in character class passed through in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
%cutf8::%.*s
Empty \%c{}
Invalid [] range "%*.*s"
POSIX syntax [%c %c] is reserved for future extensions
POSIX syntax [%c %c] belongs inside character classes in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
panic: reg_node overrun trying to emit %d
panic: regfree data code '%c'
panic: re_dup unknown data code '%c'
panic: unknown regstclass %d
%lx %d
%s limit (%d) exceeded
sv_upgrade from type %d down to type %d
Can't upgrade %s (%lu) to %lu
Can't coerce %s to integer in %s
Can't coerce %s to number in %s
Argument "%s" isn't numeric
Argument "%s" isn't numeric in %s
Cannot copy to %s
Cannot copy to %s in %s
Bizarre copy of %s
Bizarre copy of %s in %s
Subroutine %s::%s redefined
Constant subroutine %s::%s redefined
DESTROY created new reference to dead object '%s'
Bad filehandle: %s
Can't coerce %s to string in %s
Can't coerce readonly %s to string
Can't coerce readonly %s to string in %s
"%%%c"
Invalid conversion in %sprintf:
vector argument not supported with alpha versions
Integer overflow in format string for %s
Insecure $ENV{%s}%s
Insecure directory in %s%s
Insecure %s%s
%%ENV is aliased to %%%s%s
%%ENV is aliased to %s%s
037777777777
Use of %s is deprecated
([{< )]}> )]}>
Ambiguous use of %c resolved as operator %c
Operator or semicolon missing before %c%s
Ambiguous use of -%s resolved as -&%s()
Bareword "%s" refers to nonexistent package
Bad name after %s%s
Illegal character in prototype for %-p : %s
$@%*;[]&\_
|&* -=!?:.
Can't use \%c to mean $%c in expression
Invalid separator character %c%c%c in attribute list
Unmatched right curly bracket
You need to quote "%s"
Multidimensional syntax %.*s not supported
Missing right curly or square bracket
Unrecognized character \xX in column %d
%s::DATA
CORE::%s is not a keyword
Ambiguous call resolved as CORE::%s(), %s
Reversed %c= operator
 -*/%.^&|<
Can't exec %s
our @F=split(%s);
BEGIN { require 'perl5db.pl' };
(Missing operator before %.*s?)
%s found where operator expected
Can't find string terminator %c%s%c anywhere before EOF
\%c better written as $%c
Unrecognized escape \%c passed through
Ambiguous range in transliteration operator
Invalid range "%c-%c" in transliteration operator
[#!%*<>()-=
readpipe
"%s" not allowed in expression
Possible unintended interpolation of %s in string
Can't use "my %s" in sort comparison
No package name allowed for variable %s in "our"
No comma allowed after %s
%s (...) interpreted as function
Constant(%s) unknown: %s
Constant(%s): %s%s%s
Ambiguous use of %c{%s} resolved to %c%s
Ambiguous use of %c{%s%s} resolved to %c%s%s
Search pattern not terminated or ternary operator parsed as search pattern
Unterminated <> operator
Excessively long <> operator
 -0123456789_
%s number > %s non-portable
Integer overflow in %s number
Illegal binary digit '%c'
Illegal octal digit '%c'
%s has too many errors.
%-p%s has too many errors.
(Might be a runaway multi-line %c%c string starting on line %ld)
at %s line %ld,
Unsupported script encoding UTF32-BE
Unsupported script encoding UTF32-LE
Tie::Hash::NamedCapture::NEXTKEY
Tie::Hash::NamedCapture::FIRSTKEY
\[$%@];$
Usage: CODE(0x%lx)(%s)
Usage: %s(%s)
Usage: %s::%s(%s)
%s version %-p required--this is only version %-p
%s defines neither package nor VERSION--version check failed
%s does not define $%s::VERSION--version check failed
operation not supported with version object
get_layers: unknown argument '%s'
$key, $flags
$key, $value, $flags
$lastkey
%s in %s
(overflow at 0x%lx, byte 0xx, after start byte 0xlx)
(%d byte%s, need %d, after start byte 0xlx)
(unexpected non-continuation byte 0xlx, %d byte%s after start byte 0xlx, expected %d bytes)
%s: illegal mapping '%s'
, <%s> %s %ld
at %s line %ld
List form of piped open not implemented
Can't %s %s%s%s
Filehandle opened only for %sput
Filehandle %s opened only for %sput
(Are you trying to call %s%s on dirhandle?)
%s%s on %s %s
(Are you trying to call %s%s on dirhandle %s?)
%s%s on %s %s %s
v.Inf
Integer overflow in version %d
Version string '%s' contains invalid data; ignoring: '%s'
%0*d_%d
Unknown Unicode option letter '%c'
msvcrt.dll
Destruct popping %s
PerlIO_pop f=%p %s
warning:%s
define %s %p
Invalid separator character %c%c%c in PerlIO layer specification %s
Pushing %s
Layer %ld is %s
PerlIO_push f=%p %s %s %p
:raw f=%p :%s
PerlIO_binmode f=%p %s %c %x %s
openn(%s,'%s','%s',%d,%x,%o,%p,%d,%p)
More than one argument to open(,':%s')
PerlIOBase_dup %s f=%p o=%p param=%p
refcnt_inc: fd %d < 0
refcnt_inc: fd %d refcnt=%d
refcnt_inc: fd %d: %d <= 0
Zeroing %p, %d
More fds - old=%d, need %d, new=%d
refcnt_dec: fd %d < 0
refcnt_dec: fd %d refcnt=%d
refcnt_dec: fd %d: %d <= 0
refcnt_dec: fd %d >= refcnt_size %d
%d _is_ a regular file
%d is not regular file
kernel32.dll
%s-%s
%d.%d
%s/lib
%s/%s/lib
Can't spawn "%s": %s
command.com /c
cmd.exe /x/d/c
Can't %s "%s": %s
unknown(0x%x)
Build %d
Windows
Windows NT
Terminating on signal SIG%s(%d)
List form of pipe open not implemented
command.com
cmd.exe
ntdll.dll
load_file:%s
unload_file:%s
find_symbol:%s
Win32::LoginName
WS2_32.dll
KERNEL32.dll
CallMsgFilterA
MsgWaitForMultipleObjects
SetWindowsHookExA
USER32.dll
RegCloseKey
RegOpenKeyExA
ADVAPI32.dll
_pipe
_execl
_execv
_execvp
MSVCRT.dll
perl510.dll
PL_vtbl_nkeys
PerlIO_exportFILE
PerlIO_importFILE
Perl_Gthr_key_ptr
Perl_ICmd_ptr
Perl_Ilast_swash_key_ptr
Perl_do_aexec
Perl_do_join
Perl_hv_common_key_len
Perl_hv_iterkey
Perl_hv_iterkeysv
Perl_pregexec
Perl_reg_named_buff_firstkey
Perl_reg_named_buff_nextkey
Perl_regexec_flags
Perl_repeatcpy
Perl_report_uninit
Perl_sv_report_used
win32_execv
win32_execvp
win32_getservbyport
win32_pipe
!"#$% !"#$%&'()* ,-./0123456789:;<=>?
C:/Windows/system32/perl510.dll
8?86????8
<????8,<???0
(?8.6?$0????#
6???<#?0
$;??.?0(<???24
#2<?;4????8
8?;( ??0
&???:??,
1??.4)?:
=???8.&%)1:???8)
 ???=42=?..1
)<<:45< (
66666666666666
666666666666666
6666666666666
01383>3`3
9œ9^9m9
3 3'3-334:4@4
:&:-:7:>:
8#8'8 8/83878
4 4$4(4,4044484<4@4
!"#$%&'()* 
'()* !,-.
9>?@>?@=>
!>?@%&'()
5,10,1,1006
perl58.dll
Copyright 1987-2007, Larry Wall, Binary build by ActiveState, hXXp://VVV.ActiveState.com

DriverSupportAO.exe_3856_rwx_001D0000_00006000:

.text
`.rdata
@.data
.reloc
S_IEXEC
FD_CLOEXEC
Couldn't add key '%s' to missing_hash
Couldn't add key '%s' to %üntl::
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
perl510.dll
MSVCRT.dll
KERNEL32.dll
Fcntl.dll

DriverSupportAO.exe_3856_rwx_003A0000_00010000:

.text
`.rdata
@.data
.reloc
Can't determine type of %s(0x%lx)
Hash %p inconsistent - expected %d keys, %dth is NULL
No magic '%c' found while storing tied %s
You lost %s(0x%lx)%c
Can't store item %s(0x%lx)
Can't store %s items
No magic '%c' found while storing ref to tied %s with hook
Could not serialize item #%d from hook in %s
Item #%d returned by STORABLE_freeze for %s is not a reference
Freeze cannot return references if %s class is using STORABLE_attach
Too late to ignore hooks for %s class "%s"
Unexpected object type (%d) in store_hook()
Corrupted storable %s (binary v%d.%d)
Corrupted storable %s (binary v%d.%d), current is v%d.%d
Forgot to deal with extra type %d
No STORABLE_thaw defined for objects of class %s (even after a "require %s;")
STORABLE_attach did not return a %s object
Cannot restore overloading on %s(0x%lx) (package %s) (even after a "require %s;")
Cannot restore overloading on %s(0x%lx) (package <unknown>)
code %s did not evaluate to a subroutine reference
code %s caused an error: %s
Unexpected type %d in retrieve_code
Storable binary image v%d.%d contains data of type %d. This Storable is v%d.%d and can only handle data types up to %d
Magic number checking on storable %s failed
Storable binary image v%d.%d more recent than I am (v%d.%d)
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_iterkeysv
Perl_hv_common_key_len
perl510.dll
MSVCRT.dll
KERNEL32.dll
Storable.dll

DriverSupportAO.exe_3856_rwx_003B0000_00007000:

.text
`.rdata
@.data
.reloc
MSG_PEEK
MSG_OOB
MSG_DONTROUTE
IPPROTO_UDP
IPPROTO_TCP
TCP_NODELAY
MSG_WAITALL
MSG_MAXIOVLEN
MSG_PROXY
MSG_CTRUNC
TCP_MD5SIG
TCP_CONGESTION
TCP_QUICKACK
TCP_INFO
TCP_WINDOW_CLAMP
TCP_DEFER_ACCEPT
TCP_LINGER2
TCP_SYNCNT
TCP_KEEPCNT
TCP_KEEPINTVL
TCP_KEEPIDLE
TCP_CORK
TCP_STDURG
TCP_MAXSEG
TCP_MAXRT
TCP_KEEPALIVE
SO_SECURITY_ENCRYPTION_TRANSPORT
SO_REUSEPORT
SO_PASSIFNAME
SO_PASSCRED
PF_KEY
MSG_WIRE
MSG_URG
MSG_TRUNC
MSG_SYN
MSG_RST
MSG_NOSIGNAL
MSG_MCAST
MSG_FIN
MSG_ETAG
MSG_ERRQUEUE
MSG_EOR
MSG_EOF
MSG_DONTWAIT
MSG_CTLIGNORE
MSG_CTLFLAGS
MSG_BTAG
MSG_BCAST
AI_PASSIVE
AF_KEY
Couldn't add key '%s' to missing_hash
Couldn't add key '%s' to %%Socket::
%s object version %-p does not match %s%s%s%s %-p
%s::%s
%-p is not a valid Socket macro at %s line %d
Your vendor has not defined Socket macro %-p, used at %s line %d
Usage: CODE(0x%lx)(%s)
Usage: %s(%s)
Usage: %s::%s(%s)
%d.%d.%d.%d
Bad arg length for %s, length is %lu, should be %lu
Wide character in %s
Bad arg length for %s, length is %lu, should be at least %lu
Socket::%s not implemented on this architecture
port, ip_address_sv
Bad address family for %s, got %d, should be %d
port, sin6_addr, scope_id=0, flowinfo=0
Perl_hv_common_key_len
perl510.dll
MSVCRT.dll
KERNEL32.dll
Socket.dll
11n1s1z1

DriverSupportAO.exe_3856_rwx_003C0000_00008000:

.text
`.rdata
@.data
.reloc
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
perl510.dll
MSVCRT.dll
KERNEL32.dll
Util.dll

DriverSupportAO.exe_3856_rwx_003D0000_00006000:

.text
`.rdata
@.data
.reloc
?456789:;<=
!"#$%&'()* ,-./0123
=X
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
MSVCRT.dll
KERNEL32.dll
Base64.dll

DriverSupportAO.exe_3856_rwx_003E0000_0000A000:

.text
`.rdata
@.data
.reloc
.t.Ht$
userenv.dll
advapi32.dll
Cannot load functions from advapi32.dll library
Cannot load advapi32.dll library
shell32.dll
usage: Win32::MsgBox($message [, $flags [, $title]]);
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
shfolder.dll
%d.%d.%d.%d
netapi32.dll
usage: Win32::Spawn($cmdName, $args, $PID)
Win32::LoginName
Win32::MsgBox
Win32.xs
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
KERNEL32.dll
USER32.dll
RegCloseKey
RegOpenKeyExA
ADVAPI32.dll
ole32.dll
VERSION.dll
MSVCRT.dll
Win32.dll

DriverSupportAO.exe_3856_rwx_003F0000_00008000:

.text
`.rdata
@.data
.reloc
Win32::API::Call: parameter %d must be a Win32::API::Callback object!
Win32::API::Call: parameter %d must be an array reference!
Wrong number of parameters: expected %d, got %d.
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
perl510.dll
KERNEL32.dll
MSVCRT.dll
API.dll

DriverSupportAO.exe_3856_rwx_008D0000_00006000:

.text
`.rdata
@.data
.reloc
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Usage: CODE(0x%lx)(%s)
Usage: %s(%s)
Usage: %s::%s(%s)
No filehandle passed
Bad conversion type (%d)
&Digest::MD5::%s function %s
perl510.dll
MSVCRT.dll
KERNEL32.dll
MD5.dll

DriverSupportAO.exe_3856_rwx_008E0000_00008000:

.text
`.rdata
@.data
.reloc
sortkeys
quotekeys
Sortkeys subroutine did not return ARRAYREF
Usage: CODE(0x%lx)(%s)
Usage: %s(%s)
Usage: %s::%s(%s)
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
Perl_hv_iterkeysv
perl510.dll
MSVCRT.dll
KERNEL32.dll
Dumper.dll

DriverSupportAO.exe_3856_rwx_008F0000_00028000:

.text
`.rdata
@.data
.reloc
hKey
sComputer, hRootKey, ohKey
swComputer, hRootKey, ohKey
hKey, sSubKey, ohSubKey
hKey, swSubKey, ohSubKey
hKey, sSubKey, uZero, sClass, uOpts, uAccess, pSecAttr, ohNewKey, ouDisp
hKey, swSubKey, uZero, swClass, uOpts, uAccess, pSecAttr, ohNewKey, ouDisp
hKey, sSubKey
hKey, swSubKey
hKey, sValueName
hKey, swValueName
hKey, uIndex, osName, ilNameSize
hKey, uIndex, oswName, ilwNameSize
hKey, uIndex, osName, iolName, pNull, osClass, iolClass, opftLastWrite
hKey, uIndex, oswName, iolwName, pNull, oswClass, iolwClass, opftLastWrite
hKey, uIndex, osName, iolName, pNull, ouType, opData, iolData
hKey, uIndex, oswName, iolwName, pNull, ouType, opData, iolData
hKey, uSecInfo, opSecDesc, iolSecDesc
hKey, sSubKey, sFileName
hKey, swSubKey, swFileName
hKey, bWatchSubtree, uNotifyFilter, hEvent, bAsync
hKey, sSubKey, uOptions, uAccess, ohSubKey
hKey, swSubKey, uOptions, uAccess, ohSubKey
hKey, osClass, iolClass, pNull, ocSubKeys, olSubKey, olSubClass, ocValues, olValName, olValData, olSecDesc, opftTime
hKey, oswClass, iolwClass, pNull, ocSubKeys, olwSubKey, olwSubClass, ocValues, olwValName, olValData, olSecDesc, opftTime
%s: %s (%d bytes < %d * %d)
hKey, ioarValueEnts, icValueEnts, opBuffer, iolBuffer
hKey, sSubKey, osValueData, iolValueData
hKey, swSubKey, oswValueData, iolValueData
hKey, sName, pNull, ouType, opData, iolData
hKey, swName, pNull, ouType, opData, iolData
hKey, sSubKey, sNewFile, sOldFile
hKey, swSubKey, swNewFile, swOldFile
hKey, sFileName, uFlags
hKey, swFileName, uFlags
hKey, sFileName, pSecAttr
hKey, swFileName, pSecAttr
hKey, uSecInfo, pSecDesc
hKey, sSubKey, uType, sValueData, lValueData
hKey, swSubKey, uType, swValueData, lValueData
hKey, sName, uZero, uType, pData, lData
hKey, swName, uZero, uType, pData, lData
Win32API::Registry::RegUnLoadKeyW
Win32API::Registry::RegUnLoadKeyA
Win32API::Registry::RegSetKeySecurity
Win32API::Registry::RegSaveKeyW
Win32API::Registry::RegSaveKeyA
Win32API::Registry::RegRestoreKeyW
Win32API::Registry::RegRestoreKeyA
Win32API::Registry::RegReplaceKeyW
Win32API::Registry::RegReplaceKeyA
Win32API::Registry::_RegQueryInfoKeyW
Win32API::Registry::_RegQueryInfoKeyA
Win32API::Registry::RegOpenKeyExW
Win32API::Registry::RegOpenKeyExA
Win32API::Registry::RegOpenKeyW
Win32API::Registry::RegOpenKeyA
Win32API::Registry::RegNotifyChangeKeyValue
Win32API::Registry::RegLoadKeyW
Win32API::Registry::RegLoadKeyA
Win32API::Registry::_RegGetKeySecurity
Win32API::Registry::RegFlushKey
Win32API::Registry::_RegEnumKeyExW
Win32API::Registry::_RegEnumKeyExA
Win32API::Registry::_RegEnumKeyW
Win32API::Registry::_RegEnumKeyA
Win32API::Registry::RegDeleteKeyW
Win32API::Registry::RegDeleteKeyA
Win32API::Registry::RegCreateKeyExW
Win32API::Registry::RegCreateKeyExA
Win32API::Registry::RegCreateKeyW
Win32API::Registry::RegCreateKeyA
Win32API::Registry::RegCloseKey
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
KERNEL32.dll
RegCloseKey
RegCreateKeyA
RegCreateKeyW
RegCreateKeyExA
RegCreateKeyExW
RegDeleteKeyA
RegDeleteKeyW
RegEnumKeyA
RegEnumKeyW
RegEnumKeyExA
RegEnumKeyExW
RegFlushKey
RegGetKeySecurity
RegLoadKeyA
RegLoadKeyW
RegNotifyChangeKeyValue
RegOpenKeyA
RegOpenKeyW
RegOpenKeyExA
RegOpenKeyExW
RegQueryInfoKeyA
RegQueryInfoKeyW
RegReplaceKeyA
RegReplaceKeyW
RegRestoreKeyA
RegRestoreKeyW
RegSaveKeyA
RegSaveKeyW
RegSetKeySecurity
RegUnLoadKeyA
RegUnLoadKeyW
ADVAPI32.dll
MSVCRT.dll
Registry.dll

DriverSupportAO.exe_3856_rwx_00920000_00015000:

.text
`.rdata
@.data
.reloc
OLE_E_ADVISENOTSUPPORTED
@RPC_S_UNSUPPORTED_TYPE
@RPC_S_UNSUPPORTED_TRANS_SYN
@RPC_S_UNSUPPORTED_NAME_SYNTAX
@RPC_S_UNSUPPORTED_AUTHN_LEVEL
@RPC_S_PROTSEQ_NOT_SUPPORTED
@RPC_S_NOT_ALL_OBJS_UNEXPORTED
@RPC_S_NOTHING_TO_EXPORT
@RPC_S_CANNOT_SUPPORT
REGDB_E_KEYMISSING
CO_E_SERVER_EXEC_FAILURE
CO_E_INIT_SCM_EXEC_FAILURE
ACACHE_S_FORMATETC_NOTSUPPORTED
@ERROR_WRONG_PASSWORD
@ERROR_UNKNOWN_PORT
@ERROR_TRANSFORM_NOT_SUPPORTED
L@ERROR_TOO_MANY_CMDS
a@ERROR_SUBST_TO_JOIN
@ERROR_PORT_UNREACHABLE
m@ERROR_PIPE_NOT_CONNECTED
@ERROR_PIPE_LISTENING
@ERROR_PIPE_CONNECTED
l@ERROR_PIPE_BUSY
@ERROR_PASSWORD_RESTRICTION
@ERROR_PASSWORD_MUST_CHANGE
@ERROR_PASSWORD_EXPIRED
@ERROR_OPERATION_ABORTED
@ERROR_NULL_LM_PASSWORD
@ERROR_NO_USER_SESSION_KEY
I@ERROR_NOT_SUPPORTED
a@ERROR_NOT_JOINED
@ERROR_METAFILE_NOT_SUPPORTED
@ERROR_LOGIN_WKSTA_RESTRICTION
@ERROR_LOGIN_TIME_RESTRICTION
@ERROR_LOCAL_USER_SESSION_KEY
@ERROR_KEY_HAS_CHILDREN
@ERROR_KEY_DELETED
a@ERROR_JOIN_TO_SUBST
@a@ERROR_JOIN_TO_JOIN
`@ERROR_IS_JOIN_TARGET
`b@ERROR_IS_JOIN_PATH
`@ERROR_IS_JOINED
@ERROR_INVALID_PASSWORDNAME
U@ERROR_INVALID_PASSWORD
@ERROR_INVALID_MSGBOX_STYLE
g@ERROR_INVALID_EXE_SIGNATURE
@ERROR_ILL_FORMED_PASSWORD
@ERROR_HOTKEY_NOT_REGISTERED
@ERROR_HOTKEY_ALREADY_REGISTERED
h@ERROR_EXE_MARKED_INVALID
q@ERROR_EAS_NOT_SUPPORTED
@ERROR_DISK_OPERATION_FAILED
@ERROR_CLIPPING_NOT_SUPPORTED
@ERROR_CLASS_HAS_WINDOWS
@[@ERROR_BROKEN_PIPE
l@ERROR_BAD_PIPE
h@ERROR_BAD_EXE_FORMAT
@ERROR_BADKEY
e@ERROR_ATOMIC_LOCKS_NOT_SUPPORTED
@FACILITY_WINDOWS
MK_E_INTERMEDIATEINTERFACENOTSUPPORTED
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
MSVCRT.dll
KERNEL32.dll
WinError.dll

DriverSupportAO.exe_3856_rwx_00940000_00007000:

.text
`.rdata
@.data
.reloc
%%%%%d
SYSTEM\CurrentControlSet\Services\EventLog\%s\%s
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
KERNEL32.dll
ReportEventA
RegCloseKey
RegOpenKeyExA
ADVAPI32.dll
MSVCRT.dll
EventLog.dll

DriverSupportAO.exe_3856_rwx_00950000_00009000:

.text
`.rdata
@.data
.reloc
%ld running and unjoined
%ld finished and unjoined
Invalid context: %s
Usage: threads->create(\%%specs, function, ...)
PANIC: underlying join failed
Cannot join self
Thread already joined
Cannot join a detached thread
Usage: $thr->join()
Cannot detach a joined thread
Unrecognized signal name: %s
Usage: $thr->is_joinable()
threads::is_joinable
threads::join
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
perl510.dll
KERNEL32.dll
MSVCRT.dll
threads.dll

DriverSupportAO.exe_3856_rwx_00960000_00009000:

.text
`.rdata
@.data
.reloc
shared.xs
obj, oldkey
Argument to share needs to be passed as ref
cond_wait lock needs to be passed as ref
Argument to cond_wait needs to be passed as ref
cond_timedwait lock needs to be passed as ref
Argument to cond_timedwait needs to be passed as ref
Argument to cond_signal needs to be passed as ref
Argument to cond_broadcast needs to be passed as ref
\[$@%]$;\[$@%]
\[$@%];\[$@%]
threads::shared::tie::NEXTKEY
threads::shared::tie::FIRSTKEY
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
Perl_hv_iterkey
perl510.dll
KERNEL32.dll
MSVCRT.dll
shared.dll

DriverSupportAO.exe_3856_rwx_00970000_00006000:

.text
`.rdata
@.data
.reloc
%s is not a valid Time::HiRes macro
Your vendor has not defined Time::HiRes macro %s, used
Unexpected return type %d while processing Time::HiRes macro %s, used
.Auseconds
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
perl510.dll
KERNEL32.dll
MSVCRT.dll
HiRes.dll

DriverSupportAO.exe_3856_rwx_02040000_00016000:

.text
`.rdata
@.data
.reloc
Win32::OLE(0.1709): SetLastOleError: couldnot create variable %s
Win32::OLE(0.1709) error 0xx
OLE exception from "%s":
%s(): DESTROY must be a method name or a CODE reference
Win32::OLE(0.1709): GetOleObject() Not a %s object
Win32::OLE(0.1709): GetOleEnumObject() Not a %s object
Win32::OLE(0.1709): GetOleVariantObject() Not a %s object
Win32::OLE(0.1709): GetOleTypeLibObject() Not a %s object
Win32::OLE(0.1709): GetOleTypeInfoObject() Not a %s object
Win32::OLE(0.1709)FindIID: Interface '%s' not found
AWin32::OLE(0.1709) AssignVariantFromSV() cannot assign to vt=0x%x
END { %s->Uninitialize(%d); }
Win32::OLE->%s must be called as class method
Win32::OLE->new: for DCOM use ['Machine', 'Prog.Id']
argument %d
argument "%s"
%sPROPERTYPUTREF
%sPROPERTYPUT
%sPROPERTYGET
in GetIDsOfNames for "%s"
A in GetIDsOfNames of "%s"
Win32::OLE->Dispatch: named arguments not supported for PROPERTYPUT
after character %lu in "%s"
in GetIDsOfNames "%s"
in METHOD/PROPERTYGET "%s"
self, key, def
in PROPERTYPUT%s "%s"
self, key, value, def
HHCTRL.OCX
Win32::OLE(0.1709): Win32::OLE::Variant->Copy() indices mismatch: specified %d vs. required %d
Win32::OLE(0.1709): Win32::OLE::Variant->Copy(): %d %s specified, but variant is not a SAFEARRYA
Win32::OLE(0.1709): Win32::OLE::Variant->_Clone doesn't support array elements
Usage: Win32::OLE::Variant::%s(SELF [, FORMAT [, LCID]])
%.*s.%s
%.*s0.%.*s%s
Win32::OLE(0.1709): Win32::OLE::Variant->Dim(): Variant type (0x%x) is not an array
Win32::OLE(0.1709): Win32::OLE::Variant->%s(): Wrong number of indices; dimension of SafeArray is %d
Win32::OLE(0.1709): Win32::OLE::Variant->%s(): Wrong number of arguments
Win32::OLE::Tie::FIRSTKEY
Win32::OLE::Tie::NEXTKEY
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
Perl_hv_iterkey
perl510.dll
KERNEL32.dll
USER32.dll
RegCloseKey
RegOpenKeyExA
RegEnumKeyExA
ADVAPI32.dll
ole32.dll
OLEAUT32.dll
WS2_32.dll
MSVCRT.dll
OLE.dll
5 5$5(5,5
0!1,111#272
8 8$8(8,8084888

DriverSupportAO.exe_3856_rwx_02060000_00012000:

.text
`.rdata
@.data
.reloc
Yt.Wh(
_POSIX_PIPE_BUF
MSG_WAITALL
MSG_PEEK
MSG_OOB
MSG_DONTROUTE
ESPIPE
EPIPE
ENOEXEC
EAFNOSUPPORT
_PC_PIPE_BUF
SIGPIPE
PIPE_BUF
MSG_TRUNC
MSG_EOR
MSG_CTRUNC
ESOCKTNOSUPPORT
EPROTONOSUPPORT
EPFNOSUPPORT
EMSGSIZE
POSIX::%s not implemented on this architecture
%s: %s is not a reference
%s: %s is not of type %s
Illegal alias %d for POSIX::W*
%s: %s is not a hash reference
TZ=%s
Couldn't add key '%s' to missing_hash
Couldn't add key '%s' to %%POSIX::
POSIX::pipe
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
perl510.dll
MSVCRT.dll
KERNEL32.dll
POSIX.dll
9(:-:2:@:
2"2F2S2g2t2

DriverSupportAO.exe_3856_rwx_028C0000_000B9000:

.text
`.rdata
@.data
.reloc
.EOWSU
3|$43|$$
3|$<3|$$
3|$(3|$,
6-9'6-9'
$6.:$6.:
*?#1*?#1
>8$4,8$4,
Montgomery Multiplication for x86, CRYPTOGAMS by <[email protected]>
Crypt::SSLeay::Conn::get_peer_certificate
Crypt::SSLeay::CTX::check_private_key
Crypt::SSLeay::CTX::use_PrivateKey_file
Crypt::SSLeay::CTX::use_certificate_file
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Usage: CODE(0x%lx)(%s)
Usage: %s(%s)
Usage: %s::%s(%s)
ctx, filename, password
HTTPS_CA_DIR
HTTPS_CA_FILE
%s:error in %s
%s:failed in %s
SSL3 alert %s:%s:%s
%s:%s
cert is not an Crypt::SSLeay::X509
cert
OpenSSL 0.9.8k 25 Mar 2009
SSLv3 read certificate verify B
SSLv3 read certificate verify A
SSLv3 read client key exchange B
SSLv3 read client key exchange A
SSLv3 read client certificate B
SSLv3 read client certificate A
SSLv3 write certificate request B
SSLv3 write certificate request A
SSLv3 write key exchange B
SSLv3 write key exchange A
SSLv3 write certificate B
SSLv3 write certificate A
SSLv2 X509 read server certificate
SSLv2 write request certificate D
SSLv2 write request certificate C
SSLv2 write request certificate B
SSLv2 write request certificate A
SSLv2 read client master key B
SSLv2 read client master key A
SSLv3 write certificate verify B
SSLv3 write certificate verify A
SSLv3 write client key exchange B
SSLv3 write client key exchange A
SSLv3 write client certificate D
SSLv3 write client certificate C
SSLv3 write client certificate B
SSLv3 write client certificate A
SSLv3 read server certificate request B
SSLv3 read server certificate request A
SSLv3 read server key exchange B
SSLv3 read server key exchange A
SSLv3 read server certificate B
SSLv3 read server certificate A
SSLv2 X509 read client certificate
SSLv2 write client certificate D
SSLv2 write client certificate C
SSLv2 write client certificate B
SSLv2 write client certificate A
SSLv2 write client master key B
SSLv2 write client master key A
export restriction
certificate unknown
certificate expired
certificate revoked
unsupported certificate
bad certificate
no certificate
%-23s %s Kx=%-8s Au=%-4s Enc=%-9s Mac=%-4s%s
EXPORT56
EXPORT40
EXPORT
.\ssl\ssl_cert.c
SSLv2 part of OpenSSL 0.9.8k 25 Mar 2009
s->session->master_key_length >= 0 && s->session->master_key_length < (int)sizeof(s->session->master_key)
c->iv_len <= (int)sizeof(s->session->key_arg)
s->s2->key_material_length <= sizeof s->s2->key_material
SSLv3 part of OpenSSL 0.9.8k 25 Mar 2009
TLSv1 part of OpenSSL 0.9.8k 25 Mar 2009
wrong number of key bits
unsupported status type
unsupported ssl version
unsupported protocol
unsupported elliptic curve
unsupported compression algorithm
unsupported cipher
unknown pkey type
unknown key exchange type
unknown certificate type
unable to find public key parameters
unable to extract public key
unable to decode ecdh certs
unable to decode dh certs
tried to use unsupported cipher
tls peer did not respond with certificate list
tls client cert req with anon cipher
tlsv1 alert export restriction
sslv3 alert unsupported certificate
sslv3 alert no certificate
sslv3 alert certificate unknown
sslv3 alert certificate revoked
sslv3 alert certificate expired
sslv3 alert bad certificate
signature for non signing certificate
reuse cert type not zero
reuse cert length not zero
public key not rsa
public key is not rsa
public key encrypt error
peer error unsupported certificate type
peer error no certificate
peer error certificate
peer did not return a certificate
null ssl method passed
no publickey
no private key assigned
no privatekey
no client cert received
no client cert method
no ciphers passed
no certificate specified
no certificate set
no certificate returned
no certificate assigned
no certificates returned
missing tmp rsa pkey
missing tmp rsa key
missing tmp ecdh key
missing tmp dh key
missing rsa signing cert
missing rsa encrypting cert
missing rsa certificate
missing export tmp rsa key
missing export tmp dh key
missing dsa signing cert
missing dh rsa cert
missing dh key
missing dh dsa cert
krb5 server rd_req (keytab perms?)
key arg too long
invalid ticket keys length
http request
https proxy request
error generating tmp rsa key
cert length mismatch
certificate verify failed
bad ecc cert
bad dh pub key length
TLS1_SETUP_KEY_BLOCK
SSL_VERIFY_CERT_CHAIN
SSL_use_RSAPrivateKey_file
SSL_use_RSAPrivateKey_ASN1
SSL_use_RSAPrivateKey
SSL_use_PrivateKey_file
SSL_use_PrivateKey_ASN1
SSL_use_PrivateKey
SSL_use_certificate_file
SSL_use_certificate_ASN1
SSL_use_certificate
SSL_SET_PKEY
SSL_SET_CERT
SSL_SESS_CERT_NEW
SSL_GET_SIGN_PKEY
SSL_GET_SERVER_SEND_CERT
SSL_CTX_use_RSAPrivateKey_file
SSL_CTX_use_RSAPrivateKey_ASN1
SSL_CTX_use_RSAPrivateKey
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_PrivateKey_ASN1
SSL_CTX_use_PrivateKey
SSL_CTX_use_certificate_file
SSL_CTX_use_certificate_chain_file
SSL_CTX_use_certificate_ASN1
SSL_CTX_use_certificate
SSL_CTX_set_client_cert_engine
SSL_CTX_check_private_key
SSL_check_private_key
SSL_CERT_NEW
SSL_CERT_INSTANTIATE
SSL_CERT_INST
SSL_CERT_DUP
SSL_add_file_cert_subjects_to_stack
SSL_add_dir_cert_subjects_to_stack
SSL3_SETUP_KEY_BLOCK
SSL3_SEND_SERVER_KEY_EXCHANGE
SSL3_SEND_SERVER_CERTIFICATE
SSL3_SEND_CLIENT_KEY_EXCHANGE
SSL3_SEND_CLIENT_CERTIFICATE
SSL3_SEND_CERTIFICATE_REQUEST
SSL3_OUTPUT_CERT_CHAIN
SSL3_GET_SERVER_CERTIFICATE
SSL3_GET_KEY_EXCHANGE
SSL3_GET_CLIENT_KEY_EXCHANGE
SSL3_GET_CLIENT_CERTIFICATE
SSL3_GET_CERT_VERIFY
SSL3_GET_CERT_STATUS
SSL3_GET_CERTIFICATE_REQUEST
SSL3_GENERATE_KEY_BLOCK
SSL3_CHECK_CERT_AND_ALGORITHM
SSL2_SET_CERTIFICATE
SSL2_GENERATE_KEY_MATERIAL
REQUEST_CERTIFICATE
GET_CLIENT_MASTER_KEY
DTLS1_SEND_SERVER_KEY_EXCHANGE
DTLS1_SEND_SERVER_CERTIFICATE
DTLS1_SEND_CLIENT_KEY_EXCHANGE
DTLS1_SEND_CLIENT_CERTIFICATE
DTLS1_SEND_CERTIFICATE_REQUEST
DTLS1_OUTPUT_CERT_CHAIN
CLIENT_MASTER_KEY
CLIENT_CERTIFICATE
client write key
server write key
key expansion
%lu:%s:%s:%d:%s
error:lX:%s:%s:%s
value.bag
value.safes
value.shkeybag
value.keybag
value.sdsicert
value.x509cert
value.other
cert_info
Stack part of OpenSSL 0.9.8k 25 Mar 2009
%s(%d): OpenSSL internal error, assertion failed: %s
lhash part of OpenSSL 0.9.8k 25 Mar 2009
crlUrl
certStatus
certId
OCSP_CERTSTATUS
value.unknown
value.revoked
value.good
value.byKey
value.byName
reqCert
OCSP_CERTID
issuerKeyHash
certs
Microsoft Local Key set
LocalKeySet
id-Gost28147-89-None-KeyMeshing
id-Gost28147-89-CryptoPro-KeyMeshing
password based MAC
id-PasswordBasedMAC
X509v3 Certificate Issuer
certificateIssuer
certicom-arc
Proxy Certificate Information
proxyCertInfo
Microsoft Smartcardlogin
msSmartcardLogin
joint-iso-itu-t
JOINT-ISO-ITU-T
set-rootKeyThumb
setAttr-Cert
setCext-cCertRequired
setCext-certType
setct-CertResTBE
setct-CertReqTBEX
setct-CertReqTBE
setct-AcqCardCodeMsgTBE
setct-CertInqReqTBS
setct-CertResData
setct-CertReqTBS
setct-CertReqData
setct-PCertResTBS
setct-PCertReqData
setct-AcqCardCodeMsg
certificate extensions
set-certExt
set-msgExt
id-ecPublicKey
id-cmc-confirmCertAcceptance
id-cmc-getCert
id-regInfo-certReq
id-regCtrl-protocolEncrKey
id-regCtrl-oldCertID
id-it-revPassphrase
id-it-keyPairParamRep
id-it-keyPairParamReq
id-it-unsupportedOIDs
id-it-caKeyUpdateInfo
id-it-encKeyPairTypes
id-it-signKeyPairTypes
id-it-caProtEncCert
id-mod-attribute-cert
id-mod-qualified-cert-93
id-mod-qualified-cert-88
id-smime-aa-ets-certCRLTimestamp
id-smime-aa-ets-certValues
id-smime-aa-ets-CertificateRefs
id-smime-aa-ets-otherSigCert
id-smime-aa-smimeEncryptCerts
id-smime-aa-signingCertificate
id-smime-aa-encrypKeyPref
id-smime-aa-msgSigDigest
id-smime-ct-publishCert
id-smime-mod-msg-v3
sdsiCertificate
x509Certificate
localKeyID
certBag
pkcs8ShroudedKeyBag
keyBag
pbeWithSHA1And2-KeyTripleDES-CBC
pbeWithSHA1And3-KeyTripleDES-CBC
TLS Web Client Authentication
TLS Web Server Authentication
X509v3 Extended Key Usage
extendedKeyUsage
X509v3 Authority Key Identifier
authorityKeyIdentifier
X509v3 Certificate Policies
certificatePolicies
X509v3 Private Key Usage Period
privateKeyUsagePeriod
X509v3 Key Usage
keyUsage
X509v3 Subject Key Identifier
subjectKeyIdentifier
Netscape Certificate Sequence
nsCertSequence
Netscape CA Policy Url
nsCaPolicyUrl
Netscape Renewal Url
nsRenewalUrl
Netscape CA Revocation Url
nsCaRevocationUrl
Netscape Revocation Url
nsRevocationUrl
Netscape Base Url
nsBaseUrl
Netscape Cert Type
nsCertType
Netscape Certificate Extension
nsCertExt
extendedCertificateAttributes
challengePassword
dhKeyAgreement
Diffie-Hellman part of OpenSSL 0.9.8k 25 Mar 2009
EC part of OpenSSL 0.9.8k 25 Mar 2009
.\crypto\ec\ec_key.c
Big Number part of OpenSSL 0.9.8k 25 Mar 2009
RSA part of OpenSSL 0.9.8k 25 Mar 2009
.\crypto\dh\dh_key.c
priv_key
pub_key
.\crypto\engine\eng_pkey.c
CERTIFICATE
CERTIFICATE REQUEST
NEW CERTIFICATE REQUEST
RSA PRIVATE KEY
DSA PRIVATE KEY
EC PRIVATE KEY
.\crypto\pem\pem_pkey.c
ENCRYPTED PRIVATE KEY
PRIVATE KEY
ANY PRIVATE KEY
X.509 part of OpenSSL 0.9.8k 25 Mar 2009
OPENSSL_ALLOW_PROXY_CERTS
EVP part of OpenSSL 0.9.8k 25 Mar 2009
len>=0 && len<=(int)sizeof(ctx->key)
j <= (int)sizeof(ctx->key)
ASN.1 part of OpenSSL 0.9.8k 25 Mar 2009
RAND part of OpenSSL 0.9.8k 25 Mar 2009
You need to read the OpenSSL FAQ, hXXp://VVV.openssl.org/support/faq.html
unsupported requestorname type
signer certificate not found
private key does not match certificate
no public key
no certificates in chain
error parsing url
certificate verify error
PARSE_HTTP_LINE1
OCSP_parse_url
OCSP_cert_id_new
invalid cmd number
invalid cmd name
failed loading public key
failed loading private key
cmd not executable
ENGINE_UNLOAD_KEY
ENGINE_load_ssl_client_cert
ENGINE_load_public_key
ENGINE_load_private_key
ENGINE_ctrl_cmd_string
ENGINE_ctrl_cmd
ENGINE_cmd_is_executable
functionality not supported
WIN32_JOINER
prng seed must not match key
prng not rekeyed
prng keyed
no key set
unsupported pkcs12 mode
key gen error
PKCS8_add_keyusage
PKCS12_PBE_keyivgen
PKCS12_newpass
PKCS12_MAKE_SHKEYBAG
PKCS12_MAKE_KEYBAG
PKCS12_key_gen_uni
PKCS12_key_gen_asc
PKCS12_add_localkeyid
unsupported option
unable to get issuer keyid
policy syntax not currently supported
operation not defined
no proxy cert policy language defined
no issuer certificate
extension setting not supported
V2I_EXTENDED_KEY_USAGE
V2I_AUTHORITY_KEYID
S2I_SKEY_ID
S2I_ASN1_SKEY_ID
R2I_CERTPOL
unsupported content type
unsupported cipher type
unknown operation
unable to find certificate
operation not supported on this type
no recipient matches key
no recipient matches certificate
decrypted key is wrong length
PKCS7_add_certificate
unsupported method
no port specified
no port defined
no accept port specified
broken pipe
BIO_get_port
ECDH_compute_key
data too large for key size
unsupported field
passed null parameter
not a supported NIST prime
missing private key
invalid private key
o2i_ECPublicKey
i2o_ECPublicKey
i2d_ECPrivateKey
EC_KEY_print_fp
EC_KEY_print
EC_KEY_new
EC_KEY_generate_key
EC_KEY_copy
EC_KEY_check_key
d2i_ECPrivateKey
unsupported type
unsupported public key type
unsupported encryption algorithm
unsupported any defined by type
unknown public key type
unable to decode rsa private key
unable to decode rsa key
streaming not supported
private key header missing
bad password read
X509_PKEY_new
i2d_RSA_PUBKEY
i2d_PublicKey
i2d_PrivateKey
i2d_EC_PUBKEY
i2d_DSA_PUBKEY
d2i_X509_PKEY
d2i_PublicKey
d2i_PrivateKey
unsupported algorithm
unknown key type
unable to get certs public key
no cert set for us to verify
loading cert dir
key values mismatch
key type mismatch
cert already in hash table
cant check dh key
X509_verify_cert
X509_STORE_add_cert
X509_REQ_check_private_key
X509_PUBKEY_set
X509_PUBKEY_get
X509_load_cert_file
X509_load_cert_crl_file
X509_get_pubkey_parameters
X509_check_private_key
GET_CERT_BY_SUBJECT
ADD_CERT_DIR
operation not allowed in fips mode
key size too small
DSA_BUILTIN_KEYGEN
unsupported encryption
read key
public key no rsa
problems getting password
error converting private key
PEM_READ_PRIVATEKEY
PEM_READ_BIO_PRIVATEKEY
PEM_PK8PKEY
PEM_F_PEM_WRITE_PKCS8PRIVATEKEY
DO_PK8PKEY_FP
DO_PK8PKEY
d2i_PKCS8PrivateKey_fp
d2i_PKCS8PrivateKey_bio
wrong public key type
unsupported salt type
unsupported private key algorithm
unsupported prf
unsupported key size
unsupported key derivation function
unsupported keylength
unsuported number of rounds
seed key setup failed
keygen failure
invalid key length
fips mode not supported
expecting a ec key
expecting a ecdsa key
expecting a dsa key
expecting a dh key
expecting an rsa key
different key types
ctrl operation not implemented
camellia key setup failed
bn pubkey error
bad key length
aes key setup failed
PKCS5_v2_PBE_keyivgen
PKCS5_PBE_keyivgen
EVP_PKEY_new
EVP_PKEY_get1_RSA
EVP_PKEY_get1_EC_KEY
EVP_PKEY_GET1_ECDSA
EVP_PKEY_get1_DSA
EVP_PKEY_get1_DH
EVP_PKEY_encrypt
EVP_PKEY_decrypt
EVP_PKEY_copy_parameters
EVP_PKEY2PKCS8_broken
EVP_PKCS82PKEY
EVP_CIPHER_CTX_set_key_length
ECKEY_PKEY2PKCS8
ECDSA_PKEY2PKCS8
DSA_PKEY2PKCS8
DSAPKEY2PKCS8
D2I_PKEY
CAMELLIA_INIT_KEY
AES_INIT_KEY
invalid public key
GENERATE_KEY
DH_generate_key
DH_compute_key
COMPUTE_KEY
rsa operations not supported
digest too big for rsa key
data too small for key size
RSA_generate_key
RSA_check_key
RSA_BUILTIN_KEYGEN
passed a null parameter
DSO support routines
x509 certificate routines
value.single
value.set
PKCS8_PRIV_KEY_INFO
pkey
pkeyalg
enc_key
key_enc_algor
d.encrypted
d.digest
d.signed_and_enveloped
d.enveloped
d.sign
d.data
d.other
X509_PUBKEY
public_key
.\crypto\asn1\x_pubkey.c
AUTHORITY_KEYID
keyid
X509_CERT_PAIR
X509_CERT_AUX
ECDSA part of OpenSSL 0.9.8k 25 Mar 2009
DSA part of OpenSSL 0.9.8k 25 Mar 2009
\X
.\crypto\evp\evp_pkey.c
d.registeredID
d.iPAddress
d.uniformResourceIdentifier
d.ediPartyName
d.directoryName
d.dNSName
d.rfc822Name
d.otherName
PROXY_CERT_INFO_EXTENSION
Load certs from files in a directory
%s%clx.%s%d
SHA1 part of OpenSSL 0.9.8k 25 Mar 2009
ECDH part of OpenSSL 0.9.8k 25 Mar 2009
SHA-256 part of OpenSSL 0.9.8k 25 Mar 2009
SHA-512 part of OpenSSL 0.9.8k 25 Mar 2009
DlMD5 part of OpenSSL 0.9.8k 25 Mar 2009
MD2 part of OpenSSL 0.9.8k 25 Mar 2009
RC2 part of OpenSSL 0.9.8k 25 Mar 2009
RC4 part of OpenSSL 0.9.8k 25 Mar 2009
IDEA part of OpenSSL 0.9.8k 25 Mar 2009
PEM part of OpenSSL 0.9.8k 25 Mar 2009
phrase is too short, needs to be at least %d chars
Enter PEM pass phrase:
TRUSTED CERTIFICATE
X509 CERTIFICATE
pubkey
EC_PRIVATEKEY
publicKey
privateKey
value.implicitlyCA
value.parameters
value.named_curve
p.char_two
p.prime
p.ppBasis
p.tpBasis
p.onBasis
p.other
NETSCAPE_CERT_SEQUENCE
ddddddZ
ddddddZ
USER32.DLL
NETAPI32.DLL
KERNEL32.DLL
ADVAPI32.DLL
EVP_CIPHER_key_length(cipher) <= (int)sizeof(md_tmp)
d.usernotice
d.cpsuri
CERTIFICATEPOLICIES
%*sCPS: %s
%*sExplicit Text: %s
%*sNumber%s:
%*sOrganization: %s
%s - d:d:d %d%s
- %-15s
'() ,-./:=?
.\crypto\pkcs12\p12_key.c
%d.%d.%d.%d
<unsupported>
IP Address:%d.%d.%d.%d
URI:%s
DNS:%s
email:%s
EdiPartyName:<unsupported>
X400Name:<unsupported>
othername:<unsupported>
C:/cpanfly/var/libs/ssl/certs
C:/cpanfly/var/libs/ssl/cert.pem
SSL_CERT_DIR
SSL_CERT_FILE
%'%1$=%C%K%O%s%
.%.-.3.7.9.?.W.[.o.y.
C%C'C3C7C9COCWCiC
.\crypto\evp\evp_key.c
nkey <= EVP_MAX_KEY_LENGTH
RIPE-MD160 part of OpenSSL 0.9.8k 25 Mar 2009
SHA part of OpenSSL 0.9.8k 25 Mar 2009
MD4 part of OpenSSL 0.9.8k 25 Mar 2009
keylen <= sizeof key
CAST part of OpenSSL 0.9.8k 25 Mar 2009
Blowfish part of OpenSSL 0.9.8k 25 Mar 2009
%*s%s:
keylength
keyfunc
%d.%d.%d.%d/%d.%d.%d.%d
%*sPolicy Text: %s
%*scrlUrl:
EXTENDED_KEY_USAGE
%*sZone: %s, User:
certificateHold
Certificate Hold
cessationOfOperation
Cessation Of Operation
keyCompromise
Key Compromise
name.relativename
name.fullname
<UNSUPPORTED>
.\crypto\x509v3\v3_akey.c
PKEY_USAGE_PERIOD
keyCertSign
Certificate Sign
keyAgreement
Key Agreement
keyEncipherment
Key Encipherment
.\crypto\x509v3\v3_skey.c
.\crypto\asn1\x_pkey.c
CONF part of OpenSSL 0.9.8k 25 Mar 2009
Verifying - %s
CONF_def part of OpenSSL 0.9.8k 25 Mar 2009
[[%s]]
[%s] %s=%s
%s.dll
perl510.dll
KERNEL32.dll
GetProcessWindowStation
USER32.dll
GDI32.dll
ReportEventA
ADVAPI32.dll
WS2_32.dll
MSVCRT.dll
SSLeay.dll
?456789:;<=
!"#$%&'()* ,-./0123
Operation not permitted
Inappropriate I/O control opera
Broken pipe
5 5$5(5,5054585
5!5'505!6(6
1$1(1,1014181
5 5$5(5,50545
: :$:(: ;';
3"4>4[4}4
< <$<(<,<0<4<
1 1$1(1,1014181<1
= =$=0=@=
1 1$1(1,101
= =(=,=0=8=<=

DriverSupportAO.exe_3856_rwx_03950000_00005000:

.text
`.rdata
@.data
.reloc
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
MSVCRT.dll
KERNEL32.dll
Cwd.dll

DriverSupportAO.exe_3856_rwx_03960000_0000C000:

.text
`.rdata
@.data
.reloc
KEY_EVENT
ENHANCED_KEY
Win32::Console::_SetConsoleOutputCP
Win32::Console::_GetConsoleOutputCP
Win32::Console::_GetLargestConsoleWindowSize
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
GetLargestConsoleWindowSize
GetConsoleOutputCP
SetConsoleOutputCP
KERNEL32.dll
USER32.dll
MSVCRT.dll
Console.dll

DriverSupportAO.exe_3856_rwx_03970000_0000D000:

.text
`.rdata
@.data
.reloc
blockcnt:%u
:x
%sx
alg:%d
%s object version %-p does not match %s%s%s%s %-p
%s::%s
%s: %s is not of type %s
Usage: CODE(0x%lx)(%s)
Usage: %s(%s)
Usage: %s::%s(%s)
perl510.dll
MSVCRT.dll
KERNEL32.dll
SHA.dll
2$2*20262

DriverSupportAO.exe_3856_rwx_03980000_00006000:

.text
`.rdata
@.data
.reloc
Don't know how to wait on $objects[%d]
Invalid object passed ($objects[%d])
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
KERNEL32.dll
MSVCRT.dll
IPC.dll

DriverSupportAO.exe_3856_rwx_03990000_00006000:

.text
`.rdata
@.data
.reloc
%s: %s is not a reference
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
KERNEL32.dll
MSVCRT.dll
Event.dll

DriverSupportAO.exe_3856_rwx_039A0000_00006000:

.text
`.rdata
@.data
.reloc
%s is not a valid File::Glob macro
Your vendor has not defined File::Glob macro %s, used
Unexpected return type %d while processing File::Glob macro %s, used
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
MSVCRT.dll
KERNEL32.dll
Glob.dll

DriverSupportAO.exe_3856_rwx_039B0000_00018000:

.Rich
.text
`.rdata
@.data
.reloc
Compress::Raw::Zlib::inflateStream::msg
Compress::Raw::Zlib::deflateStream::msg
%s object version %-p does not match %s%s%s%s %-p
%s::%s
%s is not a valid Zlib macro
Your vendor has not defined Zlib macro %s, used
Unexpected return type %d while processing Zlib macro %s, used
1.2.7
Usage: CODE(0x%lx)(%s)
Usage: %s(%s)
Usage: %s::%s(%s)
%s: buffer parameter is a reference to a reference
%s: buffer parameter is not a SCALAR reference
_deflateInit2 returned %d
in _deflateInit(level=%d, method=%d, windowBits=%d, memLevel=%d, strategy=%d, bufsize=%ld dictionary=%p)
in _inflateInit(windowBits=%d, bufsize=%lu, dictionary=%lu
%s: %s is not of type %s
LIMIT %s
CONSUME %s
ADLER32 %s
CRC32 %s
APPEND %s
flags 0x%x
adler32 0x%x
crc32 0x%x
zip_mode %d
msg %s
%s: buffer parameter is read-only
%s: %s is not a reference
in _createDeflateStream(level=%d, method=%d, windowBits=%d, memLevel=%d, strategy=%d, bufsize=%lu
deflate 1.2.7 Copyright 1995-2012 Jean-loup Gailly and Mark Adler
inflate 1.2.7 Copyright 1995-2012 Mark Adler
perl510.dll
MSVCRT.dll
KERNEL32.dll
Zlib.dll
=$>)>.>]?

DriverSupportAO.exe_3856_rwx_03B20000_00007000:

.text
`.rdata
@.data
.reloc
cP, appname, cmdline, inherit, flags, curdir
kernel32.dll
%s: %s is not a reference
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
KERNEL32.dll
MSVCRT.dll
Process.dll

DriverSupportAO.exe_3856_rwx_03B30000_00009000:

.text
`.rdata
@.data
.reloc
%s "\xlX" does not map to Unicode
"\x{lx}" does not map to %s
Usage: CODE(0x%lx)(%s)
Usage: %s(%s)
Usage: %s::%s(%s)
Unexpected code %d converting %s %s
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
perl510.dll
MSVCRT.dll
KERNEL32.dll
Encode.dll

DriverSupportAO.exe_3856_rwx_04210000_00007000:

.text
`.rdata
@.data
.reloc
%s object version %-p does not match %s%s%s%s %-p
%s::%s
perl510.dll
MSVCRT.dll
KERNEL32.dll
FastCalc.dll

DriverSupportAO.exe_3856_rwx_10000000_0000A000:

.text
`.rdata
@.data
.reloc
Bad argspec %d
Unknown boolean attribute (%d)
Can't report tag lists yet
Unknown tag-list attribute (%d)
No handler for %s events
Bad argspec: stuff after @{...} (%s)
Bad argspec (%s)
HTML::Entities::UNICODE_SUPPORT
HTML::Parser::report_tags
%s object version %-p does not match %s%s%s%s %-p
%s::%s
Perl_hv_common_key_len
perl510.dll
MSVCRT.dll
KERNEL32.dll
Parser.dll

DriverSupportAO.exe_3856_rwx_28000000_000DB000:

.text
`.rdata
@.data
.rsrc
@.reloc
Y}.Sh
SWSSh
PPj.PSV
9Q4t.RRj
@tCPV
.YYu6
Wj.VS
98t%9x
'udPV
t.HHt
t.IIt
[291086]
Filehandle STDIN reopened as %s only for output
Filehandle STD%s reopened as %s only for input
Can't open bidirectional pipe
piped open
Missing command in piped open
More than one argument to '<%c' open
More than one argument to '%c&' open
More than one argument to '>%c' open
Warning: unable to close filehandle %s properly.
Can't open %s: %s
Can't do inplace edit on %s: %s
Can't do inplace edit: %s is not a regular file
Use of -l on filehandle %s
Can't exec "%s": %s
Unrecognized signal name "%s"
panic: do_trans_simple line %d
panic: do_trans_count line %d
panic: do_trans_complex line %d
panic: do_trans_simple_utf8 line %d
panic: do_trans_complex_utf8 line %d
panic: do_vop called for op %u (%s)
nkeys(k)
(xsub 0x%lx %d)
SUB %s =
FORMAT %s =
%cx{%lx}
%co
[UTF8 "%s"]
CV(%s)
<%lu%s>
PMFLAGS = (%s)
PMf_PRE %c%s%c%s
PRIVATE = (%s)
FLAGS = (%s)
LABEL = "%s"
PACKAGE = "%s"
(was %s)
%*sTYPE = %s ===>
-> %s
GV_NAME = %s
=> HEf_SVKEY
MG_TYPE = PERL_MAGIC_%s
PAT = %s
MG_FLAGS = 0xX
MG_PRIVATE = %d
MG_VIRTUAL = &PL_vtbl_%s
nkeys
%s = 0x%lx
%s" :: "
UNKNOWN(0x%lx) %s
FILE = "%s"
RARE = %u
FLAGS = %u
TYPE = %c
FLAGS = (%s)
[UTF8 "%s"]
Elt %s
NAME = "%s"
KEYS = %ld
%d%s:%d
OUTSIDE = 0x%lx (%s)
FILE = "%s"
TYPE = '%c'
BOTTOM_NAME = "%s"
FMT_NAME = "%s"
TOP_NAME = "%s"
( %s . )
IMPORT
SHAREKEYS,
PCS_IMPORTED,
cmd /x /c
Use of uninitialized value%s%s%s
Unquoted string "%s" may clash with future reserved word
Unsuccessful %s on filename containing newline
Can't use %s ref as %s ref
Can't use string ("%.32s") as %s ref while "strict refs" in use
Can't use string ("%-32p") as %s ref while "strict refs" in use
Can't use an undefined value as %s reference
Modification of non-creatable array value attempted, subscript %d
Insecure dependency in %s%s
Unsupported socket function "%s" called
Unsupported directory function "%s" called
The %s function is unimplemented
"%s" variable %s can't be in a package
!"#$%&'()* ,-./0123456789:;<=>?
unknown custom operator
getservbyport
pipe
join or string
undef operator
defined operator
append I/O operator
quoted execution (``, qx)
reference-type operator
null operation
getlogin
gsbyport
msgrcv
msgsnd
msgctl
msgget
ftpipe
fteexec
ftrexec
pipe_op
join
keys
PIPE
Bad symbol for %s
Cannot convert a reference to %s to typeglob
Can't locate package %-p for @%s::ISA
unimport
import
%s::SUPER
Use of inherited AUTOLOAD for non-method %s::%.*s() is deprecated
$%c is no longer supported
XPORT
Had to create %s unexpectedly
Global symbol "%s%s" requires explicit package name
(Did you mean &%s instead?)
Variable "%c%s" is not imported
panic: Can't use %%%c because %-p does not support method %s
panic: Can't use %%%c because %-p is not available
Name "%s::%s" used only once: possible typo
%s::_GEN_%ld
%s method "%.256s" overloading "%s" in package "%.256s"
Operation "%s": no method found,%sargument %s%s%s%s
panic: hv_store() failed in set_mro_private_data() for '%.*s' %d
panic: hv_store() failed in mro_register() for '%.*s' %d
Recursive inheritance detected in package '%s'
Cannot modify shared string table in hv_%s
Attempt to access disallowed key '%-p' in a restricted hash
Attempt to delete disallowed key '%-p' from a restricted hash
Attempt to delete readonly key '%-p' from a restricted hash
Attempt to free non-existent shared string '%s'%s, Perl interpreter: 0x%p
panic: refcounted_he_value bad flags %x
Can't fix broken locale name "%s"
are supported and installed on your system.
LANG = %c%s%c
%.*s = "%s",
LC_ALL = %c%s%c,
No such signal: SIG%s
No such hook: %s
FIRSTKEY
NEXTKEY
SIG%s handler "%s" not defined.
Signal SIG%s received, but no signal handler set.
ABinary number > 0b11111111111111111111111111111111 non-portable
AIllegal binary digit '%c' ignored
Hexadecimal number > 0xffffffff non-portable
Illegal hexadecimal digit '%c' ignored
Octal number > 037777777777 non-portable
Illegal octal digit '%c' ignored
Can't declare class for non-scalar %s in "%s"
Can't use global %c^%c%s in "%s"
Can't use global %s in "%s"
Useless use of %s in void context
Useless localization of %s
Can't modify %s in %s
Can't localize lexical variable %s
That use of $[ is unsupported
Can't declare %s in "%s"
attributes.pm
Applying %s to %s will act on scalar(%s)
Parentheses missing around "%s" list
panic: fold_constants JMPENV_PUSH returned %d
'%s' trapped by operation mask
&`'123456789 -
Value of %s%s can be "0"; test with defined()
() operator
Can't use %s for loop variable
%s:%ld-%ld
Subroutine %s redefined
Constant subroutine %s redefined
%s[%s:%ld]
panic: no address for '%s' in '%s'
Possible precedence problem on bitwise %c operator
%s argument is not a HASH or ARRAY element or slice
%s argument is not a HASH or ARRAY element or a subroutine
%s argument is not a subroutine name
Can't use bareword ("%-p") as %s ref while "strict refs" in use
Constant is not %s reference
Array @%-p missing the @ in argument %ld of %s()
Useless use of %s with no values
Hash %%%-p missing the %% in argument %ld of %s()
%s%c...%c
Missing comma after first argument to %s function
Not enough arguments for %s
Too many arguments for %s
Type of arg %d to %s must be %s (not %s)
Malformed prototype for %s: %-p
(Maybe you meant system() when you said exec()?)
No such class field "%s" in variable %s of type %s
"our" variable %s redeclared
"%s" variable %s masks earlier declaration in same %s
Variable "%s" is not available
Variable "%s" will not stay shared
-. 0x%lx<%lu>
-. 0x%lx<%lu> (%lu,%lu) "%s"
-. 0x%lx<%lu> FAKE "%s" flags=0x%lx index=%lu
-V[:variable] print configuration summary (or a single Config.pm variable)
-v print version, subversion (includes VERY IMPORTANT perl info)
-U allow unsafe operations
-[mM][-]module execute "use/no module..." before executing program
-f don't do $sitelib/sitecustomize.pl at startup
v5.10.1
Unbalanced string table refcount: (%ld) for "%s"
Execution of %s aborted due to compilation errors.
%s had compilation errors.
PERL_SIGNALS illegal: "%s"
Can't chdir to %s
Illegal switch in PERL5OPT: -%c
BEGIN { do '%s/sitecustomize.pl' }
5.10.1
No code specified for -%c
Unrecognized switch: -%s (-h will show valid options)
Config::config_vars(qw%c%s%c)
; $"="\n "; @env = map { "$_=\"$ENV{$_}\"" } sort grep {/^PERL/} keys %ENV;
" Built under %s\n
$_ = join ' ', sort qw( PERL_DONT_CREATE_GVSV PERL_MALLOC_WRAP USE_SITECUSTOMIZE
%s syntax OK
require q%c%s%c
Internet, point your browser at hXXp://VVV.perl.org/, the Perl Home Page.
Binary build 1006 [291086] provided by ActiveState hXXp://VVV.ActiveState.com
(with %d registered patch%s, see perl -V for more detail)
This is perl, %-p built for %s
Missing argument to -%c
Can't use '%c' after -mname
Invalid module name %.*s with -%c option: contains single ':'
Module name required with -%c option
split(/,/,q{%s});
"-%c" is on the #! line, it must also be used on the command line%s
Usage: %s [switches] [--] [programfile] [arguments]
dump is not supported
$0s
Can't open perl script "%s": %s
Can't open nul: %s
%s -ne%s%s%s %s | %-p %s %-p %s
C:\WINNT\TEMP\perl-dnjvrgkrkqrtrykitgvqcoxgyxozxpsgcwltzssxnkepx\bin
Wrong syntax (suid) fd script name "%s"
No %s allowed with (suid) fdscript
/5.10.1
/5.10.1/MSWin32-x86-multi-thread
%s/%s
%s failed--call queue aborted
Can't find an opnumber for "%s"
?$@@%&*$
Constant subroutine %s undefined
?Can't take %s of %g
panic: avhv_delete no longer supported
panic: unimplemented op %s (#%d) called
%*.*f
%#*.*f
%0*.*f
%#0*.*f
Apanic: bad gimme: %d
%sCompilation failed in require
Label not found for "last %s"
Exiting %s via %s
Label not found for "next %s"
Label not found for "redo %s"
Can't find label %s
_<(%.10seval %lu)[%s:%ld]
%sCompilation failed in regexp
Can't locate %s
%s in @INC%s%s (@INC contains:
(change .h to .ph maybe?)
%s: %s
/loader/0x%lx/%s
Attempt to reload %s aborted.
v%d.%d.%d
_<(eval %lu)[%s:%ld]
Can't return %s to lvalue scalar context
Not %s reference
glob failed (child exited with status %d%s)
utf8 "\xX" does not map to Unicode
$&*(){}[]'";\|?<>~`
glob failed (can't start child: %s)
Can't return a %s from lvalue subroutine
%s returned from lvalue subroutine in scalar context
Can't return %s from lvalue subroutine
Can't locate object method "%s" via package "%.*s" (perhaps you forgot to load "%.*s"?)
Can't locate object method "%s" via package "%.*s"
Can't call method "%s" %s
Can't call method "%s" on unblessed reference
Can't call method "%s" on an undefined value
Invalid type '%c' in unpack
0000000000
Character in '%c' format wrapped in unpack
Malformed UTF-8 string in '%c' format in unpack
Character(s) in '%c' format wrapped in %s
'/' does not take a repeat count in %s
Malformed integer in [] in %s
Duplicate modifier '%c' after '%c' in %s
Can't use '%c' in a group with different byte-order in %s
Can't use both '<' and '>' after type '%c' in %s
'%c' allowed only after types %s in %s
Too deeply nested ()-groups in %s
()-group starts with a count in %s
Invalid type ',' in %s
'X' outside of string in %s
Within []-length '%c' not allowed in %s
Invalid type '%c' in %s
Within []-length '*' not allowed in %s
No group ending character '%c' found in template
'%c' outside of string in pack
Invalid type '%c' in pack
...caught
...propagated
Opening dirhandle %s also as a file
Can't locate object method "%s" via package "%-p"
Self-ties of arrays and hashes are not supported
AnyDBM_File.pm
.ANon-string passed as bitmask
Undefined format "%s" called
Undefined top format "%s" called
%s_TOP
Wide character in %s
Possible memory corruption: %s overflowed 3rd argument
lstat() on filehandle %s
Opening filehandle %s also as a directory
readdir() attempted on invalid dirhandle %s
telldir() attempted on invalid dirhandle %s
seekdir() attempted on invalid dirhandle %s
rewinddir() attempted on invalid dirhandle %s
closedir() attempted on invalid dirhandle %s
%s %s - d:d:d %d
&'( /01,*)854
CURLY_B_max_fail
CURLY_B_max
CURLY_B_min_fail
CURLY_B_min
CURLY_B_min_known_fail
CURLY_B_min_known
CURLYM_B_fail
CURLYM_B
CURLYM_A_fail
CURLYM_A
CURLYX_end_fail
CURLYX_end
CURLYX
CURLYM
CURLYN
CURLY
%s in regex m/%.*s%s/
Lookbehind longer than %lu not implemented in regex m/%.*s%s/
%s in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
panic: Unknown flags %d in named_buff
panic: Unknown flags %d in named_buff_iter
panic: Unknown flags %d in named_buff_scalar
Sequence (?%c... not terminated
Useless (%s%c) - %suse /%c modifier in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Useless (%sc) - %suse /gc modifier in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Sequence (?%c...) not implemented
Sequence (?(%c... not terminated
in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
%.*s matches null string many times in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Quantifier in {,} bigger than %d
Unrecognized escape \%c passed through in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Missing right brace on \%c{}
Ignoring zero length \N{%s} in character class in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Ignoring excess chars from \N{%s} in character class in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Constant(\N{%s}): Call to &{$^H{charnames}} did not return a defined value
Constant(\N{%s}): $^H{charnames} is not defined
Constant(\N{%s}) unknown: (possibly a missing "use charnames ...")
%cutf8::Is%s
False [] range "%*.*s" in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
Unrecognized escape \%c in character class passed through in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
%cutf8::%.*s
Empty \%c{}
Invalid [] range "%*.*s"
POSIX syntax [%c %c] is reserved for future extensions
POSIX syntax [%c %c] belongs inside character classes in regex; marked by <-- HERE in m/%.*s <-- HERE %s/
panic: reg_node overrun trying to emit %d
panic: regfree data code '%c'
panic: re_dup unknown data code '%c'
panic: unknown regstclass %d
%lx %d
%s limit (%d) exceeded
sv_upgrade from type %d down to type %d
Can't upgrade %s (%lu) to %lu
Can't coerce %s to integer in %s
Can't coerce %s to number in %s
Argument "%s" isn't numeric
Argument "%s" isn't numeric in %s
Cannot copy to %s
Cannot copy to %s in %s
Bizarre copy of %s
Bizarre copy of %s in %s
Subroutine %s::%s redefined
Constant subroutine %s::%s redefined
DESTROY created new reference to dead object '%s'
Bad filehandle: %s
Can't coerce %s to string in %s
Can't coerce readonly %s to string
Can't coerce readonly %s to string in %s
"%%%c"
Invalid conversion in %sprintf:
vector argument not supported with alpha versions
Integer overflow in format string for %s
Insecure $ENV{%s}%s
Insecure directory in %s%s
Insecure %s%s
%%ENV is aliased to %%%s%s
%%ENV is aliased to %s%s
037777777777
Use of %s is deprecated
([{< )]}> )]}>
Ambiguous use of %c resolved as operator %c
Operator or semicolon missing before %c%s
Ambiguous use of -%s resolved as -&%s()
Bareword "%s" refers to nonexistent package
Bad name after %s%s
Illegal character in prototype for %-p : %s
$@%*;[]&\_
|&* -=!?:.
Can't use \%c to mean $%c in expression
Invalid separator character %c%c%c in attribute list
Unmatched right curly bracket
You need to quote "%s"
Multidimensional syntax %.*s not supported
Missing right curly or square bracket
Unrecognized character \xX in column %d
%s::DATA
CORE::%s is not a keyword
Ambiguous call resolved as CORE::%s(), %s
Reversed %c= operator
 -*/%.^&|<
Can't exec %s
our @F=split(%s);
BEGIN { require 'perl5db.pl' };
(Missing operator before %.*s?)
%s found where operator expected
Can't find string terminator %c%s%c anywhere before EOF
\%c better written as $%c
Unrecognized escape \%c passed through
Ambiguous range in transliteration operator
Invalid range "%c-%c" in transliteration operator
[#!%*<>()-=
readpipe
"%s" not allowed in expression
Possible unintended interpolation of %s in string
Can't use "my %s" in sort comparison
No package name allowed for variable %s in "our"
No comma allowed after %s
%s (...) interpreted as function
Constant(%s) unknown: %s
Constant(%s): %s%s%s
Ambiguous use of %c{%s} resolved to %c%s
Ambiguous use of %c{%s%s} resolved to %c%s%s
Search pattern not terminated or ternary operator parsed as search pattern
Unterminated <> operator
Excessively long <> operator
 -0123456789_
%s number > %s non-portable
Integer overflow in %s number
Illegal binary digit '%c'
Illegal octal digit '%c'
%s has too many errors.
%-p%s has too many errors.
(Might be a runaway multi-line %c%c string starting on line %ld)
at %s line %ld,
Unsupported script encoding UTF32-BE
Unsupported script encoding UTF32-LE
Tie::Hash::NamedCapture::NEXTKEY
Tie::Hash::NamedCapture::FIRSTKEY
\[$%@];$
Usage: CODE(0x%lx)(%s)
Usage: %s(%s)
Usage: %s::%s(%s)
%s version %-p required--this is only version %-p
%s defines neither package nor VERSION--version check failed
%s does not define $%s::VERSION--version check failed
operation not supported with version object
get_layers: unknown argument '%s'
$key, $flags
$key, $value, $flags
$lastkey
%s in %s
(overflow at 0x%lx, byte 0xx, after start byte 0xlx)
(%d byte%s, need %d, after start byte 0xlx)
(unexpected non-continuation byte 0xlx, %d byte%s after start byte 0xlx, expected %d bytes)
%s: illegal mapping '%s'
, <%s> %s %ld
at %s line %ld
List form of piped open not implemented
Can't %s %s%s%s
Filehandle opened only for %sput
Filehandle %s opened only for %sput
(Are you trying to call %s%s on dirhandle?)
%s%s on %s %s
(Are you trying to call %s%s on dirhandle %s?)
%s%s on %s %s %s
v.Inf
Integer overflow in version %d
Version string '%s' contains invalid data; ignoring: '%s'
%0*d_%d
Unknown Unicode option letter '%c'
msvcrt.dll
Destruct popping %s
PerlIO_pop f=%p %s
warning:%s
define %s %p
Invalid separator character %c%c%c in PerlIO layer specification %s
Pushing %s
Layer %ld is %s
PerlIO_push f=%p %s %s %p
:raw f=%p :%s
PerlIO_binmode f=%p %s %c %x %s
openn(%s,'%s','%s',%d,%x,%o,%p,%d,%p)
More than one argument to open(,':%s')
PerlIOBase_dup %s f=%p o=%p param=%p
refcnt_inc: fd %d < 0
refcnt_inc: fd %d refcnt=%d
refcnt_inc: fd %d: %d <= 0
Zeroing %p, %d
More fds - old=%d, need %d, new=%d
refcnt_dec: fd %d < 0
refcnt_dec: fd %d refcnt=%d
refcnt_dec: fd %d: %d <= 0
refcnt_dec: fd %d >= refcnt_size %d
%d _is_ a regular file
%d is not regular file
kernel32.dll
%s-%s
%d.%d
%s/lib
%s/%s/lib
Can't spawn "%s": %s
command.com /c
cmd.exe /x/d/c
Can't %s "%s": %s
unknown(0x%x)
Build %d
Windows
Windows NT
Terminating on signal SIG%s(%d)
List form of pipe open not implemented
command.com
cmd.exe
ntdll.dll
load_file:%s
unload_file:%s
find_symbol:%s
Win32::LoginName
WS2_32.dll
KERNEL32.dll
CallMsgFilterA
MsgWaitForMultipleObjects
SetWindowsHookExA
USER32.dll
RegCloseKey
RegOpenKeyExA
ADVAPI32.dll
_pipe
_execl
_execv
_execvp
MSVCRT.dll
perl510.dll
PL_vtbl_nkeys
PerlIO_exportFILE
PerlIO_importFILE
Perl_Gthr_key_ptr
Perl_ICmd_ptr
Perl_Ilast_swash_key_ptr
Perl_do_aexec
Perl_do_join
Perl_hv_common_key_len
Perl_hv_iterkey
Perl_hv_iterkeysv
Perl_pregexec
Perl_reg_named_buff_firstkey
Perl_reg_named_buff_nextkey
Perl_regexec_flags
Perl_repeatcpy
Perl_report_uninit
Perl_sv_report_used
win32_execv
win32_execvp
win32_getservbyport
win32_pipe
!"#$% !"#$%&'()* ,-./0123456789:;<=>?
C:/Windows/system32/perl510.dll
8?86????8
<????8,<???0
(?8.6?$0????#
6???<#?0
$;??.?0(<???24
#2<?;4????8
8?;( ??0
&???:??,
1??.4)?:
=???8.&%)1:???8)
 ???=42=?..1
)<<:45< (
66666666666666
666666666666666
6666666666666
01383>3`3
9œ9^9m9
3 3'3-334:4@4
:&:-:7:>:
8#8'8 8/83878
4 4$4(4,4044484<4@4
!"#$%&'()* 
'()* !,-.
9>?@>?@=>
!>?@%&'()
5,10,1,1006
perl58.dll
Copyright 1987-2007, Larry Wall, Binary build by ActiveState, hXXp://VVV.ActiveState.com

DriverSupportAO.exe_3856_rwx_665C0000_00018000:

.text
P`.data
.rdata
`@.bss
.edata
[email protected]
.reloc
]f
L]f
Œ]f
Ü]f
%Xc]f
Ü]f
%xc]f
]f
M]f
]f
Ý]f
%xb]f
Û]f
\ux\ux
cannot encode reference to scalar '%s' unless the scalar is 0 or 1
encountered %s, but JSON can only represent references to arrays or hashes
encountered object '%s', but neither allow_blessed, convert_blessed nor allow_tags settings are enabled (or TO_JSON/FREEZE method missing)
encountered perl type (%s,0x%x) that JSON cannot handle, check your input data
%s::TO_JSON method returned same object as was passed instead of a new one
%s, at character offset %d (before "%s")
self, key, cb= &PL_sv_undef
JSON::XS::filter_json_single_key_object
%s::%s
%s object version %-p does not match %s%s%s%s %-p
../../gcc-3.4.5/gcc/config/i386/w32-shared-ptr.c
dll.exp.dll
perl510.dll
Perl_hv_iterkeysv
Perl_hv_common_key_len
KERNEL32.dll
msvcrt.dll
6&6.666`9
6 6$6(6,6
6 6$6(6,6064686

DriverSupportAO.exe_3856_rwx_68B00000_0000A000:

.text
P`.data
.rdata
[email protected]
.edata
[email protected]
.reloc
Invalid length key
Error creating key schedule
%s::%s
%s object version %-p does not match %s%s%s%s %-p
../../gcc-3.4.5/gcc/config/i386/w32-shared-ptr.c
dll.exp.dll
perl510.dll
KERNEL32.dll
msvcrt.dll

DriverSupportAO.exe_3856_rwx_6B280000_0000A000:

.text
P`.data
.rdata
[email protected]
.edata
[email protected]
.reloc
%s not implemented on this architecture
%s::%s
%s object version %-p does not match %s%s%s%s %-p
../../gcc-3.4.5/gcc/config/i386/w32-shared-ptr.c
dll.exp.dll
perl510.dll
Perl_hv_common_key_len
KERNEL32.dll
msvcrt.dll


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    DriverSupport.exe:3068
    viometer.exe:2616
    csc.exe:3920
    csc.exe:3824
    csc.exe:2716
    csc.exe:3908
    csc.exe:1836
    csc.exe:4024
    csc.exe:3388
    csc.exe:2948
    csc.exe:3148
    csc.exe:3040
    csc.exe:3684
    csc.exe:2820
    csc.exe:3652
    csc.exe:3452
    csc.exe:2132
    csc.exe:2544
    csc.exe:3512
    csc.exe:3340
    csc.exe:872
    csc.exe:3516
    csc.exe:1856
    csc.exe:3792
    csc.exe:2056
    csc.exe:3300
    csc.exe:3368
    csc.exe:3760
    csc.exe:3488
    csc.exe:2460
    csc.exe:2876
    csc.exe:3456
    csc.exe:3952
    csc.exe:3608
    csc.exe:3400
    csc.exe:3724
    csc.exe:3268
    csc.exe:2632
    csc.exe:2832
    csc.exe:3176
    csc.exe:3780
    csc.exe:3232
    csc.exe:3420
    csc.exe:3888
    csc.exe:1808
    csc.exe:3160
    csc.exe:2376
    csc.exe:2252
    %original file name%.exe:1120
    DriverSupportAOsvc.exe:3804
    cvtres.exe:1348
    cvtres.exe:1324
    cvtres.exe:3636
    cvtres.exe:3100
    cvtres.exe:980
    cvtres.exe:4004
    cvtres.exe:3944
    cvtres.exe:1200
    cvtres.exe:3324
    cvtres.exe:1856
    cvtres.exe:3676
    cvtres.exe:3292
    cvtres.exe:2940
    cvtres.exe:3476
    cvtres.exe:792
    cvtres.exe:1056
    cvtres.exe:3364
    cvtres.exe:3512
    cvtres.exe:3648
    cvtres.exe:4048
    cvtres.exe:3412
    cvtres.exe:3180
    cvtres.exe:2368
    cvtres.exe:3816
    cvtres.exe:3912
    cvtres.exe:3748
    cvtres.exe:2420
    cvtres.exe:3480
    cvtres.exe:1376
    cvtres.exe:3484
    cvtres.exe:3708
    cvtres.exe:3404
    cvtres.exe:3288
    cvtres.exe:2956
    cvtres.exe:3248
    cvtres.exe:3880
    cvtres.exe:3784
    cvtres.exe:3444
    cvtres.exe:3112
    cvtres.exe:3468
    cvtres.exe:3092
    cvtres.exe:3376
    cvtres.exe:3848
    cvtres.exe:3980
    ipterbg.exe:3336
    ipterbg.exe:3776
    netsh.exe:1608
    netsh.exe:2864
    netsh.exe:792
    netsh.exe:3472
    netsh.exe:2272
    netsh.exe:2548
    netsh.exe:3032
    netsh.exe:2632
    netsh.exe:2096
    netsh.exe:2368
    netsh.exe:2352
    netsh.exe:2504
    netsh.exe:1380
    netsh.exe:2372
    DriverSupportAO.exe:1200
    WmiApSrv.exe:3004
    WmiApSrv.exe:2412
    Agent.CPU.exe:2040

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ks81vfgg.0.cs (676 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\67f133336051498bae20d8a42c66cea0 (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scll4vkp.0.cs (676 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jowf_gms.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hgdi-q6i.0.cs (44948 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\54_uzr2d.cmdline (516 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ks81vfgg.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\c8xlzoj1.newcfg (6393 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hlrultwe.cmdline (460 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ghgvxgmj.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ckmtu3np.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ko37ladf.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wz3nllzp.out (807 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n9b-3a4i.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n8eqm2oz.cmdline (459 bytes)
    C:\ProgramData\Driver Support\Driver Support\RuleEngine\GlobalActions.dat (1100 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ql4ya16q.0.cs (196 bytes)
    C:\ProgramData\Driver Support\Driver Support\dd.lic (144 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ou5ph5wn.0.cs (196 bytes)
    C:\ProgramData\Driver Support\Driver Support\UXState.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\3n3dno5j.out (560 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\2saonv2b.newcfg (3846 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\majx6vcq.0.cs (196 bytes)
    C:\ProgramData\Driver Support\Driver Support\RuleEngine\GlobalEnvironmentEvents.dat (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\bstn2rrt.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\9s6fbgha.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rclvi9--.cmdline (704 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\0pemeuyw.out (560 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\3n3dno5j.cmdline (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hgdi-q6i.out (783 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rclvi9--.out (807 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pbifxxgm.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n8eqm2oz.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\egeu-bpl.0.cs (24148 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\fniuwqsj.newcfg (10420 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F6DEB9C1F3251400F7D6EB743CB14FB4 (452 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\k1l3ncvv.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ou5ph5wn.out (560 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wz3nllzp.cmdline (704 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hkkpqirm.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\fqvkndp7.cmdline (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n9b-3a4i.0.cs (37988 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rdyawuc6.out (623 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\xurbrp4o.newcfg (12988 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\7519e2ac1b724f779dde1e587bb60e49 (1506148 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\bstn2rrt.0.cs (37988 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n9b-3a4i.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ekilrb1z.out (508 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\39b7b31f79b5423fb1f9d8a46c900bd7 (1924 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rii4bvdv.out (560 bytes)
    C:\ProgramData\Driver Support\Driver Support\WL.dat (2 bytes)
    C:\ProgramData\Driver Support\Driver Support\RuleEngine\GlobalEnvironmentProperties.dat (1242 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jjnryppy.out (783 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wz3nllzp.0.cs (388 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hzgkbspj.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\egeu-bpl.out (783 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\f7d8eojk.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zvtxrn0a.cmdline (460 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\7hpnegaf.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mqbtijot.0.cs (676 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\5b0d7dtb.newcfg (16215 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\0pemeuyw.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xuiljsd9.out (602 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hkkpqirm.cmdline (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ugte--cj.out (563 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ghgvxgmj.0.cs (7332 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDSM\ScanManager.dat (33774 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pbifxxgm.cmdline (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mqbtijot.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\k1l3ncvv.cmdline (405 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\DownloadResourceManager.dat (5992 bytes)
    C:\ProgramData\Driver Support\Driver Support\RuleEngine\GlobalRules.dat (24016 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hgdi-q6i.cmdline (680 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\osgzrzst.0.cs (676 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nt5jn1ho.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\fqvkndp7.out (560 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zp_bzj6l.cmdline (459 bytes)
    C:\ProgramData\Driver Support\Driver Support\RuleEngine\RuleHistoryController.dat (986 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\osgzrzst.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F6DEB9C1F3251400F7D6EB743CB14FB4 (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n8eqm2oz.out (562 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\9a370d032c3b43ba9c16035637d5bdb6 (1444 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\exhkewak.newcfg (2519 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jwybd_jj.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\lg0bf1l_.cmdline (460 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ghgvxgmj.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rlyvchat.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\lg0bf1l_.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hkkpqirm.out (560 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ckmtu3np.0.cs (2500 bytes)
    %Program Files% (x86)\Driver Support\Common.dll (48 bytes)
    %Program Files% (x86)\Driver Support\ExceptionLogging.dll (32 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\k1l3ncvv.out (508 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\psmntriu.newcfg (10380 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ko37ladf.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\9s6fbgha.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_40F159D44D8C605036811A9D469F7AD9 (1504 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scll4vkp.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zvtxrn0a.out (563 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\fqvkndp7.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\f7d8eojk.out (562 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\14a11a95bc3d4011a82af56b5864fdb2 (5572 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\54_uzr2d.out (619 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rdyawuc6.cmdline (520 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\c319d7f190d649d3a4100511b6132314 (388 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jjnryppy.0.cs (40972 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pqis5zx7.out (560 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\54_uzr2d.0.cs (676 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rlyvchat.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xuiljsd9.0.cs (6740 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pqis5zx7.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\majx6vcq.out (560 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hzgkbspj.0.cs (676 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jowf_gms.out (560 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nt5jn1ho.0.cs (1444 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\7hpnegaf.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jwybd_jj.cmdline (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ekilrb1z.cmdline (405 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\7f804686e64f45cabd8107097dc688a3 (4708 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ql4ya16q.cmdline (704 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\0pemeuyw.cmdline (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jowf_gms.cmdline (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rii4bvdv.cmdline (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\bstn2rrt.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\024haam9.newcfg (1456 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\osgzrzst.cmdline (459 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\043835d9630e45e39f87449f3af42366 (5572 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_40F159D44D8C605036811A9D469F7AD9 (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hlrultwe.out (563 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\f0e18b584afe4b37b328737aebd980f9 (2500 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rlyvchat.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\majx6vcq.cmdline (457 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\4436b4f25b814365839a2bdcf97307fa (7332 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_lmw7aa4.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\f7d8eojk.0.cs (2500 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hlrultwe.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rdyawuc6.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\egeu-bpl.cmdline (680 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\8hcqdkos.newcfg (1854 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hzgkbspj.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ra-mrtty.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ckmtu3np.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ugte--cj.cmdline (460 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mqbtijot.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rii4bvdv.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_lmw7aa4.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_lmw7aa4.0.cs (2500 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xuiljsd9.cmdline (499 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nt5jn1ho.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rclvi9--.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\PC_Drivers_Headquarters\DriverSupport.exe_Url_jky4qfl0bb42zyjk05xwcsyp4qrtcets\9.1.4.66\ltb3ipvd.newcfg (6393 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zvtxrn0a.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zp_bzj6l.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\lg0bf1l_.out (563 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ugte--cj.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scll4vkp.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pbifxxgm.out (560 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pqis5zx7.cmdline (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ou5ph5wn.cmdline (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ra-mrtty.0.cs (388 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ql4ya16q.out (807 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\636258a27768481b92b8e563d2c198d8 (1444 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jjnryppy.cmdline (680 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ra-mrtty.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ekilrb1z.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ks81vfgg.cmdline (459 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\7hpnegaf.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ko37ladf.0.cs (676 bytes)
    C:\ProgramData\Driver Support\Driver Support\DDRM\7f816ca43b494c62bb80ee53ea76e10b (676 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zp_bzj6l.0.cs (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jwybd_jj.out (560 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\9s6fbgha.out (562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\3n3dno5j.0.cs (196 bytes)
    C:\Windows\SysWOW64\rnd_chunk.bin (166456 bytes)
    C:\Windows\SysWOW64\_tmp_total_results.txt (174705 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\7a965e8de7cc4fba744fa7016513e423\File.dll (12034 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\e790df575748f7ddfa6d074eefbd3af9\Dumper.dll (4744 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\perl510.dll (3645 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\cc6074bff1906afc872db1ac09b9f547\Process.dll (3204 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\eec708426f797e3eae1af772a856fdae\OLE.dll (12170 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\5a043c9ceeb6d93382986c196a4fafd4\API.dll (4744 bytes)
    C:\Windows\SysWOW64\_tmp_file.txt (5720758 bytes)
    C:\Windows\SysWOW64\_tmp_results.txt (138546 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\84c73e03b82ca27738913a411aab1a36\Win32.dll (6577 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\5bec2b7324c81f25bdf5c087fdf888e2\Util.dll (4744 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\bca7aac987d374edc35a6e36445e61af\Fcntl.dll (2528 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\1fb9e4724fa361b2039d7108d86facb1\IO.dll (4744 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\7fd1f1fe740136136caf3658edc53f83\FastCalc.dll (3204 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\baeb31b10de41e0fd6fecc1b786c31f3\SHA.dll (7045 bytes)
    C:\Windows\Temp\pdk-SYSTEM-2616\278e95d3c70d01bffd43d0d6f0a68d54\HiRes.dll (2528 bytes)
    C:\Windows\Temp\PFR6kZWcM5\_results.txt (29752 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC954C.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jwybd_jj.dll (3886 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC93A7.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rii4bvdv.dll (3694 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ko37ladf.dll (4740 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCBFB6.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC3294.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zvtxrn0a.dll (3614 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\f7d8eojk.dll (5228 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCC216.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nt5jn1ho.dll (4312 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCA044.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC79E0.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\egeu-bpl.dll (5166 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCCD9A.tmp (652 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wz3nllzp.dll (3600 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCA256.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\54_uzr2d.dll (3552 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4BAF.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hgdi-q6i.dll (5394 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pqis5zx7.dll (3726 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC89E7.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC450B.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\lg0bf1l_.dll (3662 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\majx6vcq.dll (3224 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC8979.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC7AD9.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hzgkbspj.dll (4230 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC515A.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jjnryppy.dll (4258 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCBF48.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\zp_bzj6l.dll (3534 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4F09.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n8eqm2oz.dll (3630 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC7905.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mqbtijot.dll (4950 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rclvi9--.dll (3742 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4845.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC1B2D.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rdyawuc6.dll (3646 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC5955.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ghgvxgmj.dll (4806 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC932A.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\jowf_gms.dll (3646 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC9423.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\0pemeuyw.dll (3790 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4DC1.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\7hpnegaf.dll (3646 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC7703.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ntgnb1p9.dll (4950 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ntgnb1p9.out (396 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCDA66.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\n9b-3a4i.dll (4662 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC92BD.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pbifxxgm.dll (3000 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_lmw7aa4.dll (5228 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC7F3D.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4E9C.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rlyvchat.dll (3518 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ekilrb1z.dll (3646 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCC293.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC1AA1.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ugte--cj.dll (3566 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC9626.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\fqvkndp7.dll (3192 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC85B2.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\3n3dno5j.dll (3032 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCDB41.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\k1l3ncvv.dll (3710 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hkkpqirm.dll (3304 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC8D9E.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kuwfyi5l.dll (4838 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kuwfyi5l.out (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC7638.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\bstn2rrt.dll (4662 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCC34E.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ra-mrtty.dll (3938 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCC199.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ckmtu3np.dll (3136 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4652.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\hlrultwe.dll (3614 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC2F2A.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCC12C.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scll4vkp.dll (4950 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC7A6C.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ks81vfgg.dll (4548 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC94CF.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ou5ph5wn.dll (3678 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4153.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\xuiljsd9.dll (4838 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSCC071.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\osgzrzst.dll (4548 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC477B.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ql4ya16q.dll (3854 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CSC4E2F.tmp (664 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\9s6fbgha.dll (3630 bytes)
    %Program Files% (x86)\Driver Support\ICSharpCode.SharpZipLib.dll (7192 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\nsDialogs.dll (21 bytes)
    %Program Files% (x86)\Driver Support\Agent.Common.XmlSerializers.dll (11344 bytes)
    %Program Files% (x86)\Driver Support\RuleEngine.dll (17848 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\modern-wizard.bmp (5520 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\modern-header.bmp (784 bytes)
    %Program Files% (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.Downloaders.dll (1552 bytes)
    %Program Files% (x86)\Driver Support\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.dll (2392 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\System.dll (23 bytes)
    %Program Files% (x86)\Driver Support\Agent.CPU.exe (1856 bytes)
    %Program Files% (x86)\Driver Support\ISUninstall.exe (784 bytes)
    %Program Files% (x86)\Driver Support\Interop.WUApiLib.dll (3312 bytes)
    %Program Files% (x86)\Driver Support\Agent.ExceptionLogging.XmlSerializers.dll (1552 bytes)
    %Program Files% (x86)\Driver Support\cpuidsdk.dll (28288 bytes)
    %Program Files% (x86)\Driver Support\Agent.Common.dll (13368 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Driver Support\Uninstall Driver Support.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\DotNetChecker.dll (1597 bytes)
    %Program Files% (x86)\Driver Support\Microsoft.Practices.EnterpriseLibrary.Common.dll (3312 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\UserInfo.dll (8 bytes)
    %Program Files% (x86)\Driver Support\DriverSupport.exe (190439 bytes)
    %Program Files% (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.dll (4992 bytes)
    %Program Files% (x86)\Driver Support\DriverSupport.Updater.exe.config (2 bytes)
    %Program Files% (x86)\Driver Support\Microsoft.Win32.TaskScheduler.dll (5064 bytes)
    %Program Files% (x86)\Driver Support\RuleEngine.XmlSerializers.dll (2392 bytes)
    %Program Files% (x86)\Driver Support\Microsoft.Practices.ObjectBuilder.dll (1856 bytes)
    %Program Files% (x86)\Driver Support\config.dat (2 bytes)
    %Program Files% (x86)\Driver Support\Uninstall.exe (2469 bytes)
    %Program Files% (x86)\Driver Support\Microsoft.ApplicationBlocks.Updater.ActivationProcessors.dll (3312 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Driver Support\Driver Support.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc9CDB.tmp (390115 bytes)
    %Program Files% (x86)\Driver Support\XPBurnComponent.dll (1856 bytes)
    %Program Files% (x86)\Driver Support\DriverSupport.chm (1552 bytes)
    %Program Files% (x86)\Driver Support\ThemePack.DriverSupport.dll (31856 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\LangDLL.dll (13 bytes)
    %Program Files% (x86)\Driver Support\Agent.ExceptionLogging.dll (1856 bytes)
    %Program Files% (x86)\Driver Support\Agent.Communication.dll (15536 bytes)
    %Program Files% (x86)\Driver Support\DriverSupport.exe.config (2 bytes)
    %Program Files% (x86)\Driver Support\Agent.Communication.XmlSerializers.dll (16288 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss9CEC.tmp\Linker.dll (16 bytes)
    %Program Files% (x86)\Veloxum\iPTE\ipte_svc.log (46 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES1B2E.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESBF49.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4BB0.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES85B3.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESC072.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4DC2.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES32A4.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES954D.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES5956.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES2F2B.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES7704.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4653.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES897A.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES7639.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESC217.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES7ADA.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESC294.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4846.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESBFB7.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES7906.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES7F4D.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4F0A.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESA045.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES79E1.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESA257.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4154.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES932B.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES94D0.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES8D9F.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES477C.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES1AA2.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES451B.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4E9D.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES89E8.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESDB42.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESCD9B.tmp (3666 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES515B.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESC34F.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES9424.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES92BE.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES7A6D.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESC12D.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES4E30.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESC19A.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RESDA67.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES93A8.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RES9627.tmp (3698 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3336\perl510.dll (3645 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3336\e790df575748f7ddfa6d074eefbd3af9\Dumper.dll (4744 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3336\cc6074bff1906afc872db1ac09b9f547\Process.dll (3204 bytes)
    %Program Files% (x86)\Veloxum\iPTE\DriverSupportAO.exe (485 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3776\perl510.dll (3645 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3776\e790df575748f7ddfa6d074eefbd3af9\Dumper.dll (4744 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-3776\cc6074bff1906afc872db1ac09b9f547\Process.dll (3204 bytes)
    %Program Files% (x86)\Veloxum\iPTE\DriverSupportAOsvc.exe (49 bytes)
    %Program Files% (x86)\Veloxum\iPTE\reg.dat (676 bytes)
    C:\Windows\Temp\pdk-SYSTEM-3856\XML\SAX\ParserDetails.ini (70 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pdk-SYSTEM-1200\XML\SAX\ParserDetails.ini (70 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\cpuz136\cpuz136_x64.sys (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kuwfyi5l.0.cs (6740 bytes)
    C:\ProgramData\Driver Support\Driver Support\CPUID.dat (856 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ntgnb1p9.0.cs (676 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ntgnb1p9.cmdline (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kuwfyi5l.cmdline (497 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "Driver Support" = "%Program Files% (x86)\Driver Support\DriverSupport.exe /applicationMode:systemTray /showWelcome:false"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now