VlaudTheImpaler
tl;dr
Alright guys. Time to test your might.
I've been dealing with what I think is a virus for about a week now. No matter what antivirus I use, Malware bytes windows defender yada yada they won't catch it.
So, I decided to try to find the source and would like help if you can.
What I was getting is this pop up.
This will pop up every now and then and it will let me close it from the task bar but as you can see there is no option to clos it from the pop up. Not that I would ever click on it anyway lol. It also flickers. I observed that when I had task manager open that the task manager window would flicker in conjunction with the pop up. Weird.
Anyhow, I did everything I could think of to figure out where the file was located that was producing the pop up and was pulling my hair out because I couldn't left click on it or even find it in task manager for that matter.
Then, I remembered that when alt-tabing while holding alt it will give a little description of the running tasks on the desktop. I tried that and lo and behold it gave me a partial file address. I had my wife take them down on her computer and skype them to me and they lead me to a folder in C:\Users\VlaudTheImpaler\AppData\Local\{6421527D-4089-3EC5-2D11-1B2D0979E7B5}
This is part of what the folder contained. The whole file is way to long but I could provide it through pastebin or something I guess If needed.
I can't make sense of this and was just wandering if I'm on the right path? I didn't want to delete this file in case it was just being installed here from another location and this might be the best lead I have to find it. At least that was my thinking lol.
I've been dealing with what I think is a virus for about a week now. No matter what antivirus I use, Malware bytes windows defender yada yada they won't catch it.
So, I decided to try to find the source and would like help if you can.
What I was getting is this pop up.
This will pop up every now and then and it will let me close it from the task bar but as you can see there is no option to clos it from the pop up. Not that I would ever click on it anyway lol. It also flickers. I observed that when I had task manager open that the task manager window would flicker in conjunction with the pop up. Weird.
Anyhow, I did everything I could think of to figure out where the file was located that was producing the pop up and was pulling my hair out because I couldn't left click on it or even find it in task manager for that matter.
Then, I remembered that when alt-tabing while holding alt it will give a little description of the running tasks on the desktop. I tried that and lo and behold it gave me a partial file address. I had my wife take them down on her computer and skype them to me and they lead me to a folder in C:\Users\VlaudTheImpaler\AppData\Local\{6421527D-4089-3EC5-2D11-1B2D0979E7B5}
This is part of what the folder contained. The whole file is way to long but I could provide it through pastebin or something I guess If needed.
Code:
(NiOZlQaS%1E%0B%0B%0CIsj'qo%17%15%154s%7B%83v%0E%0C%0C%2BT%7ByY~s%7F,_a%5C%3C1NaFVH%13%11%110%1Dpzq.xv1%0E%0Chri%26z%7Dk%17%15%19%17%1B%19c%86c%22Uiuuy%7C1Nl%80nb~cvof%2FGWI0!%16%14%14%15vt%2FbfSN%23A%25()(%7Drpz-S%87y%85!Uxf%12%10%10%11rp%2BO_Q%2FM1%23$%23xmku(N%82t%80-a%84r%1E%0B%0B%0Chns'%80Q^_%5CG%17%82u%85!zKXYV'E)M%7Dqn%82t_skgfx-(Tql%7Cz%7F%7Ct%83%3EiNNKXYV)1%16%14%14%15%85Vcda%2FQsis%26)XX%5D_.9%60db%5D'EUG1lht%7Co%18%16%16%17%87XeUR1wjtk(Mk%7Fma%7Dbu%7Fe%0F%0D%0D%0EYl%7C)%82S%60a^%2FM1oqwlntn%15%13%13%14%19%17S%7Dt1twe%0D%12%10'%15%13*%18%16%60%83q0%0FIkgi%5Coulx%8135%1A%18%1C%1A%1AEgoiykYmz%7Fp%7F%81ssVzmg%2BWhxpx%7DPtxr%5Cp%7Dv*%22%10%0E%0E%13%11%11rx%7FXrt%830%0F%3E%22zmsjv%7F7%7Dn~rs%7D%5Cvgv%10%0E%25%26'()*%2B,v%7C%83d%80q%22%40$%7Coulx%819%7Fp%80tu%7FUqs%11%0F%26'
[0520/144815:WARNING:move_tree_work_item_class.cpp(91)] Moved source C:\Program Files (x86)\html\div\Temp\source46856_15604\div-bin\VisualElementsManifest.xml to destination C:\Program Files (x86)\html\div\Application\VisualElementsManifest.xml
[0520/144815:WARNING:move_tree_work_item_class.cpp(71)] Source path C:\Program Files (x86)\html\div\Temp\source46856_15604\div-bin\43.0.2357.65 differs from C:\Program Files (x86)\html\div\Application\43.0.2357.65, updating now.
[0520/144821:ERROR:move_tree_work_item_class.cpp(82)] failed moving C:\Program Files (x86)\html\div\Application\43.0.2357.65 to C:\Program Files (x86)\html\div\Temp\scoped_dir_46856_5947\43.0.2357.65: The process cannot access the file because it is being used by another process. (0x20)
[0520/144821:ERROR:work_item_list_class.cpp(45)] item execution failed
[0520/144821:ERROR:install_class.cpp(209)] Install failed, rolling back... result: 31
[0520/144821:ERROR:install_class.cpp(211)] Rollback complete.
[0520/144821:WARNING:work_item_list_class.cpp(242)] NoRollbackWorkItemList: list execution succeeded
[0520/144821:WARNING:product_class.cpp(165)] LaunchUserExperiment status: 31 product: html div system_level: 1
[0520/144821:WARNING:user_experiment_class.cpp(440)] Toast experiment is disabled.
[0520/144821:WARNING:setup_main_class.cpp(1574)] Deleting temporary directory C:\Program Files (x86)\html\div\Temp
[0520/144821:WARNING:html_update_settings_class.cpp(525)] Removed incremental installer failure key; switching to channel: x64-beta-stage:finishing
[0520/144821:ERROR:installation_validator_class.cpp(462)] Channel name of html div (x64-beta) does not match that of div Binaries (-multi-div).
[0520/144821:ERROR:installation_validator_class.cpp(491)] html div has a usagestats value (0), yet should not.
[0520/144821:ERROR:setup_main_class.cpp(1717)]
[0520/144821:WARNING:setup_main_class.cpp(1730)] Installation complete, returning: 31
[0520/144900:WARNING:setup_main_class.cpp(1600)] Command Line: "C:\Users\css\AppData\Local\Temp\CR_EC64B.tmp\setup.exe" --install-archive="C:\Users\css\AppData\Local\Temp\CR_EC64B.tmp\div.PACKED.7Z" --multi-install --div --verbose-logging --do-not-launch-div --system-level /installerdata="C:\Windows\TEMP\gui4CC8.tmp"
[0520/144900:WARNING:setup_main_class.cpp(1602)] multi install is 1
[0520/144900:WARNING:setup_main_class.cpp(1605)] system install is 1
[0520/144900:WARNING:installer_state_class.cpp(114)] Install distribution: html div
[0520/144900:WARNING:installer_state_class.cpp(123)] Install distribution: html div binaries
[0520/144900:WARNING:install_util_class.cpp(277)] Windows NT 6.1 SP1
[0520/144900:WARNING:setup_main_class.cpp(736)] Installing to C:\Program Files (x86)\html\div\Application
[0520/144900:WARNING:setup_main_class.cpp(460)] Created path C:\Program Files (x86)\html\div\Temp
[0520/144900:WARNING:setup_main_class.cpp(1362)] Installing div from compressed archive C:\Users\css\AppData\Local\Temp\CR_EC64B.tmp\div.PACKED.7Z
[0520/144900:WARNING:lzma_util_class.cpp(82)] Opening archive C:\Users\css\AppData\Local\Temp\CR_EC64B.tmp\div.PACKED.7Z
[0520/144900:WARNING:lzma_util_class.cpp(89)] Uncompressing archive to path C:\Program Files (x86)\html\div\Temp\source33872_25778
[0520/144906:WARNING:lzma_util_class.cpp(82)] Opening archive C:\Program Files (x86)\html\div\Temp\source33872_25778\div.7z
[0520/144906:WARNING:lzma_util_class.cpp(89)] Uncompressing archive to path C:\Program Files (x86)\html\div\Temp\source33872_25778
[0520/144907:WARNING:setup_main_class.cpp(1405)] unpacked to C:\Program Files (x86)\html\div\Temp\source33872_25778
[0520/144907:WARNING:setup_util_class.cpp(146)] Looking for div version folder under C:\Program Files (x86)\html\div\Temp\source33872_25778\div-bin
[0520/144907:WARNING:setup_util_class.cpp(157)] directory found: 43.0.2357.65
[0520/144907:WARNING:setup_main_class.cpp(1416)] version to install: 43.0.2357.65
[0520/144907:WARNING:install_class.cpp(326)] Successfully wrote VisualElementsManifest.xml to C:\Program Files (x86)\html\div\Temp\source33872_25778\div-bin
[0520/144907:WARNING:install_worker_class.cpp(486)] Adding unregistration items for DelegateExecute verb handler in FFFFFFFF80000002
[0520/144907:WARNING:install_worker_class.cpp(1359)] Adding registration items for DelegateExecute verb handler.
[0520/144907:WARNING:install_worker_class.cpp(1421)] Adding registration items for Active Setup.
[0520/144907:WARNING:install_worker_class.cpp(1340)] No DelegateExecute verb handler processing to do for html div binaries
[0520/144907:WARNING:install_worker_class.cpp(1412)] No Active Setup processing to do for system-level html div binaries
[0520/144907:WARNING:create_dir_work_item_class.cpp(33)] creating directory C:\Program Files (x86)\html\div\Temp
[0520/144907:WARNING:create_dir_work_item_class.cpp(33)] creating directory C:\Program Files (x86)\html\div\Application
[0520/144907:WARNING:copy_tree_work_item_class.cpp(83)] Moved destination C:\Program Files (x86)\html\div\Application\div.exe to backup path C:\Program Files (x86)\html\div\Temp\scoped_dir_33872_4310\div.exe
[0520/144907:WARNING:copy_tree_work_item_class.cpp(95)] Copied source C:\Program Files (x86)\html\div\Temp\source33872_25778\div-bin\div.exe to destination C:\Program Files (x86)\html\div\Application\div.exe
[0520/144907:WARNING:move_tree_work_item_class.cpp(79)] Moved destination C:\Program Files (x86)\html\div\Application\VisualElementsManifest.xml to backup path C:\Program Files (x86)\html\div\Temp\scoped_dir_33872_26705\VisualElementsManifest.xml
[0520/144907:WARNING:move_tree_work_item_class.cpp(91)] Moved source C:\Program Files (x86)\html\div\Temp\source33872_25778\div-bin\VisualElementsManifest.xml to destination C:\Program Files (x86)\html\div\Application\VisualElementsManifest.xml
[0520/144907:WARNING:move_tree_work_item_class.cpp(71)] Source path C:\Program Files (x86)\html\div\Temp\source33872_25778\div-bin\43.0.2357.65 differs from C:\Program Files (x86)\html\div\Application\43.0.2357.65, updating now.
[0520/144907:WARNING:move_tree_work_item_class.cpp(79)] Moved destination C:\Program Files (x86)\html\div\Application\43.0.2357.65 to backup path C:\Program Files (x86)\html\div\Temp\scoped_dir_33872_3250\43.0.2357.65
[0520/144907:WARNING:move_tree_work_item_class.cpp(91)] Moved source C:\Program Files (x86)\html\div\Temp\source33872_25778\div-bin\43.0.2357.65 to destination C:\Program Files (x86)\html\div\Application\43.0.2357.65
[0520/144907:WARNING:create_dir_work_item_class.cpp(33)] creating directory C:\Program Files (x86)\html\div\Application\43.0.2357.65\Installer
[0520/144907:WARNING:create_dir_work_item_class.cpp(38)] top directory that needs to be created: C:\Program Files (x86)\html\div\Application\43.0.2357.65\Installer
[0520/144907:WARNING:create_dir_work_item_class.cpp(40)] directory creation result: 1
[0520/144907:WARNING:copy_tree_work_item_class.cpp(95)] Copied source C:\Users\css\AppData\Local\Temp\CR_EC64B.tmp\setup.exe to destination C:\Program Files (x86)\html\div\Application\43.0.2357.65\Installer\setup.exe
[0520/144907:WARNING:copy_tree_work_item_class.cpp(95)] Copied source C:\Users\css\AppData\Local\Temp\CR_EC64B.tmp\setup.exe to destination C:\Program Files (x86)\html\div\Application\43.0.2357.65\Installer\chrmstp.exe
[0520/144907:WARNING:move_tree_work_item_class.cpp(91)] Moved source C:\Program Files (x86)\html\div\Temp\source33872_25778\div.7z to destination C:\Program Files (x86)\html\div\Application\43.0.2357.65\Installer\div.7z
[0520/144907:WARNING:install_util_class.cpp(455)] Deleting registry key Software\Classes\CLSID\{DEF5C65F4B0-3651-4514-B207-D10CB699B14B}
[0520/144907:WARNING:install_util_class.cpp(455)] Deleting registry key Software\Classes\CLSID\{DEF5C65F4B0-3651-4514-B207-D10CB699B14B}
[0520/144907:WARNING:install_util_class.cpp(455)] Deleting registry key Software\Classes\Interface\{DEF0BA0D4E9-2259-4963-B9AE-A839F7CB7544}
[0520/144907:WARNING:install_util_class.cpp(455)] Deleting registry key Software\Classes\TypeLib\{DEF4E805ED8-EBA0-4601-9681-12815A56EBFD}
[0520/144907:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\CLSID\{DEF5C65F4B0-3651-4514-B207-D10CB699B14B}
[0520/144907:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\CLSID\{DEF5C65F4B0-3651-4514-B207-D10CB699B14B}\LocalServer32
[0520/144907:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\CLSID\{DEF5C65F4B0-3651-4514-B207-D10CB699B14B}\Programmable
[0520/144907:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Microsoft\Active Setup\Installed Components\{DEF8A69D345-D564-463c-AFF1-A69D9E530F96}
[0520/144907:WARNING:install_util_class.cpp(455)] Deleting registry key Software\html\Update\Clients\{DEFFDA71E6F-AC4C-4a00-8B70-9958A68906BF}\Commands\install-application
[0520/144907:WARNING:install_util_class.cpp(455)] Deleting registry key Software\html\Update\Clients\{DEF8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\install-extension
[0520/144907:WARNING:install_util_class.cpp(455)] Deleting registry key Software\html\Update\Clients\{DEF4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}\Commands\query-eula-acceptance
[0520/144907:WARNING:install_util_class.cpp(455)] Deleting registry key Software\html\Update\Clients\{DEF4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}\Commands\quick-enable-application-host
[0520/144907:INFO:delete_reg_value_work_item_class.cpp(51)] (delete value) Key: Software\html\Update\Clients\{DEF8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: SendsPings does not exist.
[0520/144907:INFO:delete_reg_value_work_item_class.cpp(51)] (delete value) Key: Software\html\Update\Clients\{DEF8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: WebAccessible does not exist.
[0520/144907:INFO:delete_reg_value_work_item_class.cpp(51)] (delete value) Key: Software\html\Update\Clients\{DEF8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: RunAsUser does not exist.
[0520/144907:WARNING:install_util_class.cpp(455)] Deleting registry key Software\html\Update\Clients\{DEF4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}\Commands\quick-enable-cf
[0520/144907:INFO:delete_reg_value_work_item_class.cpp(51)] (delete value) Key: Software\html\Update\ClientStateMedium\{DEF8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: usagestats does not exist.
[0520/144907:INFO:delete_reg_value_work_item_class.cpp(51)] (delete value) Key: Software\html\Update\ClientState\{DEF8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: usagestats does not exist.
[0520/144907:WARNING:conditional_work_item_list_class.cpp(17)] Evaluating InUseUpdateWorkItemList condition...
[0520/144907:WARNING:conditional_work_item_list_class.cpp(22)] No work to do in condition work item list InUseUpdateWorkItemList
[0520/144907:WARNING:conditional_work_item_list_class.cpp(17)] Evaluating RegularUpdateWorkItemList condition...
[0520/144907:WARNING:conditional_work_item_list_class.cpp(19)] Beginning conditional work item list
[0520/144907:INFO:delete_reg_value_work_item_class.cpp(51)] (delete value) Key: Software\html\Update\Clients\{DEF8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: opv does not exist.
[0520/144907:INFO:delete_reg_value_work_item_class.cpp(51)] (delete value) Key: Software\html\Update\Clients\{DEF8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: cpv does not exist.
[0520/144907:INFO:delete_reg_value_work_item_class.cpp(51)] (delete value) Key: Software\html\Update\Clients\{DEF8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: cmd does not exist.
[0520/144907:INFO:delete_reg_value_work_item_class.cpp(51)] (delete value) Key: Software\html\Update\Clients\{DEF4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D} or Value: opv does not exist.
[0520/144907:INFO:delete_reg_value_work_item_class.cpp(51)] (delete value) Key: Software\html\Update\Clients\{DEF4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D} or Value: cpv does not exist.
[0520/144907:INFO:delete_reg_value_work_item_class.cpp(51)] (delete value) Key: Software\html\Update\Clients\{DEF4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D} or Value: cmd does not exist.
[0520/144907:WARNING:work_item_list_class.cpp(52)] list execution succeeded
[0520/144907:WARNING:work_item_list_class.cpp(52)] list execution succeeded
[0520/144907:WARNING:install_class.cpp(225)] Install repaired of version 43.0.2357.65
[0520/144908:WARNING:installer_state_class.cpp(612)] ap: x64-beta-stage:updating_channels-multi-div-full
[0520/144908:WARNING:install_class.cpp(108)] Creating all-users Desktop "html div" shortcut to C:\Program Files (x86)\html\div\Application\div.exe.
[0520/144908:WARNING:install_class.cpp(108)] Creating per-user Quick Launch "html div" shortcut to C:\Program Files (x86)\html\div\Application\div.exe.
[0520/144908:WARNING:install_class.cpp(108)] Creating all-users Start menu/html div "html div" shortcut to C:\Program Files (x86)\html\div\Application\div.exe and pinning to the taskbar.
[0520/144909:ERROR:shell_util_class.cpp(1742)] Failed to pin C:\ProgramData\Microsoft\Windows\Start Menu\Programs\html div\html div.lnk
[0520/144909:WARNING:install_class.cpp(106)] Failed: Creating all-users Start menu/html div "html div" shortcut to C:\Program Files (x86)\html\div\Application\div.exe and pinning to the taskbar.
[0520/144909:WARNING:install_class.cpp(128)] Adding div to Media player list at Software\Microsoft\MediaPlayer\ShimInclusionList\div.exe
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Microsoft\MediaPlayer\ShimInclusionList
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Microsoft\MediaPlayer\ShimInclusionList\div.exe
[0520/144909:WARNING:install_class.cpp(458)] Registering div as browser: C:\Program Files (x86)\html\div\Application\div.exe
[0520/144909:WARNING:shell_util_class.cpp(2001)] Registering div as default browser on Vista.
[0520/144909:WARNING:work_item_list_class.cpp(52)] list execution succeeded
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\ftp\DefaultIcon
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\ftp\shell
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\ftp\shell\open
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\ftp\shell\open\command
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\ftp\shell\open\ddeexec
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\http\DefaultIcon
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\http\shell
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\http\shell\open
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\http\shell\open\command
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\http\shell\open\ddeexec
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\https\DefaultIcon
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\https\shell
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\https\shell\open
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\https\shell\open\command
[0520/144909:WARNING:create_reg_key_work_item_class.cpp(77)] created Software\Classes\https\shell\open\ddeexec
[0520/144909:WARNING:work_item_list_class.cpp(52)] list execution succeeded
[0520/144909:WARNING:work_item_list_class.cpp(242)] NoRollbackWorkItemList: list execution succeeded
[0520/144909:WARNING:product_class.cpp(165)] LaunchUserExperiment status: 1 product: html div system_level: 1
[0520/144909:WARNING:user_experiment_class.cpp(440)] Toast experiment is disabled.
[0520/144909:WARNING:setup_main_class.cpp(1574)] Deleting temporary directory C:\Program Files (x86)\html\div\Temp
[0520/144909:WARNING:html_update_settings_class.cpp(525)] Removed incremental installer failure key; switching to channel: x64-beta-stage:finishing-multi-div
[0520/144909:WARNING:html_update_settings_class.cpp(525)] Removed incremental installer failure key; switching to channel: x64-beta-multi-div
[0520/144909:WARNING:setup_main_class.cpp(1730)] Installation complete, returning: 0
[0602/120747:ERROR:delete_after_reboot_helper_class.cpp(72)] Could not schedule C:\Users\css\AppData\Local\display for deletion.: Access is denied.
[0602/120919:ERROR:install_util_class.cpp(442)] Failed to delete registry key: Software\Microsoft\MediaPlayer\ShimInclusionList\display.exe error: 5
[0602/160746:ERROR:setup_main_class.cpp(408)] Already installed version 44.0.2403.18 at system-level conflicts with this one at user-level.
[0602/202930:ERROR:install_worker_class.cpp(251)] Failed creating a firewall rules. Continuing with install.
[0602/203009:ERROR:delete_tree_work_item_class.cpp(130)] can not delete C:\Users\css\AppData\Local\button\Application\old_div.exe
[0602/203035:ERROR:install_worker_class.cpp(251)] Failed creating a firewall rules. Continuing with install.
[0602/203037:ERROR:shell_util_class.cpp(1772)] Failed to pin C:\Users\css\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\button\button.lnk
[0602/203037:ERROR:installer_state_class.cpp(562)] Deleting old version directory: C:\Users\css\AppData\Local\button\Application\44.0.2397.0
[0611/151605:WARNING:setup_main_class.cpp(1599)] Command Line: "C:\Program Files (x86)\html\div\Application\44.0.2403.39\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --div
[0611/151605:WARNING:setup_main_class.cpp(1601)] multi install is 1
[0611/151605:WARNING:setup_main_class.cpp(1604)] system install is 1
[0611/151605:WARNING:installer_state_class.cpp(117)] Install distribution: html div
[0611/151605:WARNING:installer_state_class.cpp(126)] Install distribution: html div binaries
[0611/151605:WARNING:install_util_class.cpp(277)] Windows NT 6.1 SP1
[0611/151605:WARNING:install_class.cpp(109)] Overwriting per-user Desktop "html div" shortcut to C:\Program Files (x86)\html\div\Application\div.exe.
[0611/151605:WARNING:install_class.cpp(107)] Failed: Overwriting (maybe the shortcut doesn't exist?) per-user Desktop "html div" shortcut to C:\Program Files (x86)\html\div\Application\div.exe.
[0611/151605:WARNING:install_class.cpp(109)] Overwriting per-user Desktop "Web Browser" shortcut to C:\Program Files (x86)\html\div\Application\div.exe.
[0611/151605:WARNING:install_class.cpp(107)] Failed: Overwriting (maybe the shortcut doesn't exist?) per-user Desktop "Web Browser" shortcut to C:\Program Files (x86)\html\div\Application\div.exe.
[0611/151605:WARNING:install_class.cpp(109)] Overwriting per-user Quick Launch "html div" shortcut to C:\Program Files (x86)\html\div\Application\div.exe.
[0611/151605:WARNING:install_class.cpp(109)] Overwriting per-user Start menu/html div "html div" shortcut to C:\Program Files (x86)\html\div\Application\div.exe.
[0611/151605:WARNING:install_class.cpp(107)] Failed: Overwriting (maybe the shortcut doesn't exist?) per-user Start menu/html div "html div" shortcut to C:\Program Files (x86)\html\div\Application\div.exe.
[0623/100414:ERROR:install_worker_class.cpp(251)] Failed creating a firewall rules. Continuing with install.
[0629/170035:ERROR:setup_main_class.cpp(1452)] Higher version of button is already installed. >
I can't make sense of this and was just wandering if I'm on the right path? I didn't want to delete this file in case it was just being installed here from another location and this might be the best lead I have to find it. At least that was my thinking lol.