This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Gogle Redirect Virus

42 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I believe I have the google redirect virus. When I try to enter a website I find through a search, I am redirected to other websites. I also get the following error message when I attempt to run certain programs or access links.
—————-
Insecure Internet activity. Threat of virus attack
Due to insecure Internet browsing your PC can easily get infected with viruses, worms and trojans without your knowledge, and that can lead to system slowdown, freezes and crashes.
Also insecure Internet activity can result in revealing your personal information.
To get full advanced real-time protection for PC and Internet activity, register Home Antivirus 2010.
We recommend you to protect your PC now and continue safe Internet browsing.
Click here to get full advanced real-time protection and continue browsing.
Continue to this website unprotected (not recommended).
——————

It seems to have installed a program called "Home Antivirus 2010" & tries to get me to register it. I can not delete it from my hard drive. It blocked my attampts to download new antivirus software. I managed to download the Malwarebytes' Anti-Malware program but my first scan was cut off & after that point I was denied access to the program. The same thing happened when I ran the Hijackthis program. The scan simply stopped. I believe the log below may be only a partial file. I hope this is enough information. I would appreciate any help I can get. I have never had a problem that caused this much trouble! Thanks in advance.


Hijack This Log:

=== Verbose logging started: 11/17/2006 18:16:47 Build type: SHIP UNICODE 3.01.4000.2435 Calling process: C:\WINDOWS\system32\msiexec.exe ===
MSI © (C4:5C) [18:16:47:484]: Resetting cached policy values
MSI © (C4:5C) [18:16:47:484]: Machine policy value 'Debug' is 0
MSI © (C4:5C) [18:16:47:484]: ******* RunEngine:
******* Product: c:\5a78a614ae0728d014fcdf\msxml.msi
******* Action:
******* CommandLine: **********
MSI © (C4:5C) [18:16:47:484]: Client-side and UI is none or basic: Running entire install on the server.
MSI © (C4:5C) [18:16:47:484]: Grabbed execution mutex.
MSI © (C4:5C) [18:16:48:218]: Cloaking enabled.
MSI © (C4:5C) [18:16:48:218]: Attempting to enable all disabled priveleges before calling Install on Server
MSI © (C4:5C) [18:16:48:218]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (F8:C4) [18:16:48:234]: Grabbed execution mutex.
MSI (s) (F8:64) [18:16:48:234]: Resetting cached policy values
MSI (s) (F8:64) [18:16:48:234]: Machine policy value 'Debug' is 0
MSI (s) (F8:64) [18:16:48:234]: ******* RunEngine:
******* Product: c:\5a78a614ae0728d014fcdf\msxml.msi
******* Action:
******* CommandLine: **********
MSI (s) (F8:64) [18:16:48:359]: Machine policy value 'DisableUserInstalls' is 0
MSI (s) (F8:64) [18:16:48:671]: File will have security applied from OpCode.
MSI (s) (F8:64) [18:16:48:734]: SOFTWARE RESTRICTION POLICY: Verifying package –> 'c:\5a78a614ae0728d014fcdf\msxml.msi' against software restriction policy
MSI (s) (F8:64) [18:16:48:734]: SOFTWARE RESTRICTION POLICY: c:\5a78a614ae0728d014fcdf\msxml.msi has a digital signature
MSI (s) (F8:64) [18:17:04:625]: SOFTWARE RESTRICTION POLICY: c:\5a78a614ae0728d014fcdf\msxml.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (F8:64) [18:17:04:640]: End dialog not enabled
MSI (s) (F8:64) [18:17:04:640]: Original package ==> c:\5a78a614ae0728d014fcdf\msxml.msi
MSI (s) (F8:64) [18:17:04:640]: Package we're running from ==> c:\WINDOWS\Installer\9dff401.msi
MSI (s) (F8:64) [18:17:04:750]: APPCOMPAT: looking for appcompat database entry with ProductCode '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (F8:64) [18:17:04:750]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (F8:64) [18:17:04:843]: MSCOREE not loaded loading copy from system32
MSI (s) (F8:64) [18:17:05:015]: Machine policy value 'TransformsSecure' is 0
MSI (s) (F8:64) [18:17:05:015]: User policy value 'TransformsAtSource' is 0
MSI (s) (F8:64) [18:17:05:031]: Machine policy value 'DisablePatch' is 0
MSI (s) (F8:64) [18:17:05:046]: Machine policy value 'AllowLockdownPatch' is 0
MSI (s) (F8:64) [18:17:05:046]: Machine policy value 'DisableLUAPatching' is 0
MSI (s) (F8:64) [18:17:05:046]: Machine policy value 'DisableFlyWeightPatching' is 0
MSI (s) (F8:64) [18:17:05:046]: APPCOMPAT: looking for appcompat database entry with ProductCode '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (F8:64) [18:17:05:046]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (F8:64) [18:17:05:046]: Transforms are not secure.
MSI (s) (F8:64) [18:17:05:046]: Command Line: REBOOT=ReallySuppress CURRENTDIRECTORY=c:\5a78a614ae0728d014fcdf CLIENTUILEVEL=3 CLIENTPROCESSID=3780
MSI (s) (F8:64) [18:17:05:046]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{2B27DCD9-53FA-4885-B6CD-698623819F4C}'.
MSI (s) (F8:64) [18:17:05:046]: Product Code passed to Engine.Initialize: ''
MSI (s) (F8:64) [18:17:05:046]: Product Code from property table before transforms: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (F8:64) [18:17:05:046]: Product Code from property table after transforms: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (F8:64) [18:17:05:046]: Product not registered: beginning first-time install
MSI (s) (F8:64) [18:17:05:046]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.
MSI (s) (F8:64) [18:17:05:046]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (F8:64) [18:17:05:046]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (F8:64) [18:17:05:046]: Adding new sources is allowed.
MSI (s) (F8:64) [18:17:05:046]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.
MSI (s) (F8:64) [18:17:05:046]: Package name extracted from package path: 'msxml.msi'
MSI (s) (F8:64) [18:17:05:046]: Package to be registered: 'msxml.msi'
MSI (s) (F8:64) [18:17:05:046]: Note: 1: 2729
MSI (s) (F8:64) [18:17:05:093]: Note: 1: 2729
MSI (s) (F8:64) [18:17:05:109]: Note: 1: 2262 2: AdminProperties 3: -2147287038
MSI (s) (F8:64) [18:17:05:109]: Machine policy value 'DisableMsi' is 0
MSI (s) (F8:64) [18:17:05:109]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (F8:64) [18:17:05:109]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (F8:64) [18:17:05:109]: Product installation will be elevated because user is admin and product is being installed per-machine.
MSI (s) (F8:64) [18:17:05:109]: Running product '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}' with elevated privileges: Product is assigned.
MSI (s) (F8:64) [18:17:05:109]: PROPERTY CHANGE: Adding REBOOT property. Its value is 'ReallySuppress'.
MSI (s) (F8:64) [18:17:05:109]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'c:\5a78a614ae0728d014fcdf'.
MSI (s) (F8:64) [18:17:05:109]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.
MSI (s) (F8:64) [18:17:05:109]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '3780'.
MSI (s) (F8:64) [18:17:05:109]: TRANSFORMS property is now:
MSI (s) (F8:64) [18:17:05:109]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '200'.
MSI (s) (F8:64) [18:17:05:109]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Application Data
MSI (s) (F8:64) [18:17:05:109]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Favorites
MSI (s) (F8:64) [18:17:05:109]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\NetHood
MSI (s) (F8:64) [18:17:05:109]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\My Documents
MSI (s) (F8:64) [18:17:05:109]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\PrintHood
MSI (s) (F8:64) [18:17:05:125]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Recent
MSI (s) (F8:64) [18:17:05:125]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\SendTo
MSI (s) (F8:64) [18:17:05:125]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Templates
MSI (s) (F8:64) [18:17:05:125]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Application Data
MSI (s) (F8:64) [18:17:05:125]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data
MSI (s) (F8:64) [18:17:05:125]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures
MSI (s) (F8:64) [18:17:05:171]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
MSI (s) (F8:64) [18:17:05:187]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs\Startup
MSI (s) (F8:64) [18:17:05:187]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs
MSI (s) (F8:64) [18:17:05:187]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu
MSI (s) (F8:64) [18:17:05:187]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Desktop
MSI (s) (F8:64) [18:17:05:187]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Administrative Tools
MSI (s) (F8:64) [18:17:05:203]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup
MSI (s) (F8:64) [18:17:05:203]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs
MSI (s) (F8:64) [18:17:05:203]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu
MSI (s) (F8:64) [18:17:05:203]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Desktop
MSI (s) (F8:64) [18:17:05:218]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Templates
MSI (s) (F8:64) [18:17:05:218]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\Fonts
MSI (s) (F8:64) [18:17:05:218]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16
MSI (s) (F8:64) [18:17:05:281]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
MSI (s) (F8:64) [18:17:05:281]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (F8:64) [18:17:05:281]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'Nancy'.
MSI (s) (F8:64) [18:17:05:281]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (F8:64) [18:17:05:281]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'c:\WINDOWS\Installer\9dff401.msi'.
MSI (s) (F8:64) [18:17:05:281]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'c:\5a78a614ae0728d014fcdf\msxml.msi'.
MSI (s) (F8:64) [18:17:05:281]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (F8:64) [18:17:05:281]: Machine policy value 'DisableRollback' is 0
MSI (s) (F8:64) [18:17:05:281]: User policy value 'DisableRollback' is 0
MSI (s) (F8:64) [18:17:05:281]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.
=== Logging started: 11/17/2006 18:17:05 ===
MSI (s) (F8:64) [18:17:05:296]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
MSI (s) (F8:64) [18:17:05:296]: Doing action: INSTALL
MSI (s) (F8:64) [18:17:05:312]: Running ExecuteSequence
MSI (s) (F8:64) [18:17:05:312]: Doing action: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901
Action start 18:17:05: INSTALL.
MSI (s) (F8:64) [18:17:05:328]: PROPERTY CHANGE: Adding DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Desktop\'.
Action start 18:17:05: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901.
MSI (s) (F8:64) [18:17:05:328]: Doing action: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901
Action ended 18:17:05: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901. Return value 1.
MSI (s) (F8:64) [18:17:05:328]: PROPERTY CHANGE: Adding ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Start Menu\Programs\'.
Action start 18:17:05: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901.
MSI (s) (F8:64) [18:17:05:328]: Doing action: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
Action ended 18:17:05: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901. Return value 1.
MSI (s) (F8:64) [18:17:05:343]: PROPERTY CHANGE: Adding WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 18:17:05: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537.
MSI (s) (F8:64) [18:17:05:343]: Doing action: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
Action ended 18:17:05: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (F8:64) [18:17:05:343]: PROPERTY CHANGE: Adding SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 18:17:05: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537.
MSI (s) (F8:64) [18:17:05:343]: Doing action: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537
Action ended 18:17:05: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (F8:64) [18:17:05:343]: PROPERTY CHANGE: Adding WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 18:17:05: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537.
MSI (s) (F8:64) [18:17:05:343]: Doing action: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537
Action ended 18:17:05: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (F8:64) [18:17:05:359]: PROPERTY CHANGE: Adding SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 18:17:05: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537.
MSI (s) (F8:64) [18:17:05:359]: Doing action: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
Action ended 18:17:05: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (F8:64) [18:17:05:359]: PROPERTY CHANGE: Adding WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 18:17:05: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537.
MSI (s) (F8:64) [18:17:05:359]: Doing action: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
Action ended 18:17:05: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (F8:64) [18:17:05:359]: PROPERTY CHANGE: Adding SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 18:17:05: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537.
MSI (s) (F8:64) [18:17:05:359]: Doing action: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB
Action ended 18:17:05: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (F8:64) [18:17:05:375]: PROPERTY CHANGE: Adding SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB property. Its value is 'C:\WINDOWS\system32\'.
Action start 18:17:05: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB.
MSI (s) (F8:64) [18:17:05:375]: Doing action: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1
Action ended 18:17:05: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB. Return value 1.
MSI (s) (F8:64) [18:17:05:375]: PROPERTY CHANGE: Adding SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 property. Its value is 'C:\WINDOWS\system32\'.
Action start 18:17:05: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1.
MSI (s) (F8:64) [18:17:05:375]: Doing action: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7
Action ended 18:17:05: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1. Return value 1.
MSI (s) (F8:64) [18:17:05:375]: PROPERTY CHANGE: Adding SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its value is 'C:\WINDOWS\system32\'.
Action start 18:17:05: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7.
MSI (s) (F8:64) [18:17:05:375]: Doing action: LaunchConditions
Action ended 18:17:05: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7. Return value 1.
Action start 18:17:05: LaunchConditions.
MSI (s) (F8:64) [18:17:05:375]: Doing action: FindRelatedProducts
Action ended 18:17:05: LaunchConditions. Return value 1.
Action start 18:17:05: FindRelatedProducts.
MSI (s) (F8:64) [18:17:05:375]: Doing action: AppSearch
Action ended 18:17:05: FindRelatedProducts. Return value 1.
Action start 18:17:05: AppSearch.
MSI (s) (F8:64) [18:17:05:375]: Note: 1: 2262 2: Signature 3: -2147287038
MSI (s) (F8:64) [18:17:05:375]: PROPERTY CHANGE: Adding WINHTTP_51 property. Its value is 'WinHttpRequest Component version 5.1'.
MSI (s) (F8:64) [18:17:05:375]: Skipping action: CCPSearch (condition is false)
MSI (s) (F8:64) [18:17:05:375]: Skipping action: RMCCPSearch (condition is false)
MSI (s) (F8:64) [18:17:05:375]: Doing action: ValidateProductID
Action ended 18:17:05: AppSearch. Return value 1.
Action start 18:17:05: ValidateProductID.
MSI (s) (F8:64) [18:17:05:390]: Doing action: CostInitialize
Action ended 18:17:05: ValidateProductID. Return value 1.
MSI (s) (F8:64) [18:17:05:390]: Machine policy value 'MaxPatchCacheSize' is 10
Action start 18:17:05: CostInitialize.
MSI (s) (F8:64) [18:17:05:437]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'c:\'.
MSI (s) (F8:64) [18:17:05:437]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.
MSI (s) (F8:64) [18:17:05:437]: Note: 1: 2205 2: 3: Patch
MSI (s) (F8:64) [18:17:05:437]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (F8:64) [18:17:05:437]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (F8:64) [18:17:05:437]: Note: 1: 2205 2: 3: __MsiPatchFileList
MSI (s) (F8:64) [18:17:05:437]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (F8:64) [18:17:05:437]: Note: 1: 2228 2: 3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId`
MSI (s) (F8:64) [18:17:05:437]: Doing action: FileCost
Action ended 18:17:05: CostInitialize. Return value 1.
MSI (s) (F8:64) [18:17:05:453]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 18:17:05: FileCost.
MSI (s) (F8:64) [18:17:05:453]: Doing action: CostFinalize
Action ended 18:17:05: FileCost. Return value 1.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.
MSI (s) (F8:64) [18:17:05:453]: Note: 1: 2205 2: 3: Patch
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'c:\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying WindowsFolder property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying CommonFilesFolder property. Its current value is 'C:\Program Files\Common Files\'. Its new value: 'c:\Program Files\Common Files\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 property. Its value is 'c:\Program Files\Common Files\Microsoft Shared\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 property. Its value is 'c:\Program Files\Common Files\Microsoft Shared\MSDN\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa692
0e9f98fc\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying DesktopFolder property. Its current value is 'C:\Documents and Settings\All Users\Desktop\'. Its new value: 'c:\Documents and Settings\All Users\Desktop\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying ProgramFilesFolder property. Its current value is 'C:\Program Files\'. Its new value: 'c:\Program Files\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding MSXML property. Its value is 'c:\Program Files\MSXML 4.0\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding INC.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\inc\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding LIB.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\lib\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding DOC.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\doc\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its current value is 'C:\Documents and Settings\All Users\Start Menu\Programs\'. Its new value: 'c:\Documents and Settings\All Users\Start Menu\Programs\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Adding MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\'.
MSI (s) (F8:64) [18:17:05:453]: PROPERTY CHANGE: Modifying DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its current value is 'C:\Documents and Settings\All Users\Desktop\'. Its new value: 'c:\Documents and Settings\All Users\Desktop\'.
MSI (s) (F8:64) [18:17:05:453]: Target path resolution complete. Dumping Directory table…
MSI (s) (F8:64) [18:17:05:453]: Note: target paths subject to change (via custom actions or browsing)
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: TARGETDIR , Object: c:\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WindowsFolder , Object: c:\WINDOWS\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: CommonFilesFolder , Object: c:\Program Files\Common Files\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\Program Files\Common Files\Microsoft Shared\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\Program Files\Common Files\Microsoft Shared\MSDN\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa692
0e9f98fc\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB , Object: c:\WINDOWS\system32\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 , Object: c:\WINDOWS\system32\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 , Object: c:\WINDOWS\system32\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: DesktopFolder , Object: c:\Documents and Settings\All Users\Desktop\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: ProgramFilesFolder , Object: c:\Program Files\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: MSXML , Object: c:\Program Files\MSXML 4.0\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: INC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\inc\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: LIB.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\lib\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: DOC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\doc\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Start Menu\Programs\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\
MSI (s) (F8:64) [18:17:05:453]: Dir (target): Key: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Desktop\
Action start 18:17:05: CostFinalize.
MSI (s) (F8:64) [18:17:05:593]: Doing action: SetODBCFolders
Action ended 18:17:05: CostFinalize. Return value 1.
MSI (s) (F8:64) [18:17:05:593]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (F8:64) [18:17:05:593]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `ComponentId`,`Description`,`Directory_`, `ActionRequest`, `Installed`, `Attributes` FROM `ODBCDriver`, `Component` WHERE `ODBCDriver`.`Component_` = `Component` AND (`ActionRequest` = 1 OR `ActionRequest` = 2)
MSI (s) (F8:64) [18:17:05:593]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (F8:64) [18:17:05:593]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `ComponentId`,`Description`,`Directory_`, `ActionRequest`, `Installed`, `Attributes` FROM `ODBCTranslator`, `Component` WHERE `ODBCTranslator`.`Component_` = `Component` AND (`ActionRequest` = 1 OR `ActionRequest` = 2)
Action start 18:17:05: SetODBCFolders.
MSI (s) (F8:64) [18:17:05:593]: Doing action: MigrateFeatureStates
Action ended 18:17:05: SetODBCFolders. Return value 0.
Action start 18:17:05: MigrateFeatureStates.
MSI (s) (F8:64) [18:17:05:593]: Doing action: InstallValidate
Action ended 18:17:05: MigrateFeatureStates. Return value 0.
MSI (s) (F8:64) [18:17:05:593]: Feature: MSXML; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Feature: MSXMLSYS; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Feature: MSXMLSUPP; Installed: Absent; Request: Null; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Feature: MSXMLSUPP2; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Feature: MSXMLSXS; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Feature: XMLSDK; Installed: Absent; Request: Null; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: RememberInstallFolder; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: QKBKEY; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: MSXML4_System.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: MSXML4_SystemRes.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: MSXML4_ANSI.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: WINHTTP50_COMPONENT.781A0624_31FF_4712_BFFD_31C829FFDBF1; Installed: Absent; Request: Null; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: PROXYCFG_COMPONENT.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB; Installed: Absent; Request: Local; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: uplevel.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: downlevel_manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: downlevel_payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: uplevel.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: downlevel_manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: downlevel_payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: uplevel.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: downlevel_manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: XMLSDK_Docs.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: XMLSDK_LIB.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: XMLSDK_INC.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: CookDoc_dll.3FB7DAB3_19E7_40A0_8730_4482CE77AC59; Installed: Absent; Request: Null; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: __uplevel.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: __uplevel.DA6654F6_456F_3658_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: __uplevel.0E9F98FC_A692_A6DF_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: __QKBKEY65; Installed: Null; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: __MSXML4_System.246EB7AD_459A_4FA8_83D1_4165; Installed: Null; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: __downlevel_payload.7B2FCEFF_0F22_B7E1_FF665; Installed: Null; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: __downlevel_manifest.7B2FCEFF_0F22_B7E1_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: __downlevel_payload.DA6654F6_456F_3658_FF665; Installed: Null; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: __downlevel_manifest.DA6654F6_456F_3658_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: __downlevel_manifest.0E9F98FC_A692_A6DF_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (F8:64) [18:17:05:593]: Component: __CookDoc_dll.3FB7DAB3_19E7_40A0_8730_448265; Installed: Null; Request: Null; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Component: __XMLSDK_Docs.4576A2F1_959E_4BCA_94A9_596565; Installed: Null; Request: Null; Action: Null
MSI (s) (F8:64) [18:17:05:593]: Note: 1: 2205 2: 3: BindImage
MSI (s) (F8:64) [18:17:05:593]: Note: 1: 2262 2: PublishComponent 3: -2147287038
MSI (s) (F8:64) [18:17:05:593]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F8:64) [18:17:05:593]: Note: 1: 2205 2: 3: Font
Action start 18:17:05: InstallValidate.
MSI (s) (F8:64) [18:17:05:625]: Note: 1: 2205 2: 3: _RemoveFilePath
MSI (s) (F8:64) [18:17:05:828]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F8:64) [18:17:05:828]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F8:64) [18:17:05:828]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F8:64) [18:17:05:828]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F8:64) [18:17:05:828]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F8:64) [18:17:05:828]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F8:64) [18:17:05:828]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F8:64) [18:17:05:828]: PROPERTY CHANGE: Modifying CostingComplete property. Its current value is '0'. Its new value: '1'.
MSI (s) (F8:64) [18:17:05:828]: Note: 1: 2205 2: 3: BindImage
MSI (s) (F8:64) [18:17:05:828]: Note: 1: 2262 2: PublishComponent 3: -2147287038
MSI (s) (F8:64) [18:17:05:828]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (F8:64) [18:17:05:828]: Note: 1: 2205 2: 3: Font
MSI (s) (F8:64) [18:17:05:828]: Note: 1: 2727 2:
MSI (s) (F8:64) [18:17:05:859]: Note: 1: 2727 2:
MSI (s) (F8:64) [18:17:05:859]: Doing action: InstallInitialize
Action ended 18:17:05: InstallValidate. Return value 1.
MSI (s) (F8:64) [18:17:05:859]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (F8:64) [18:17:05:859]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (F8:64) [18:17:05:859]: BeginTransaction: Locking Server
MSI (s) (F8:64) [18:17:05:859]: SRSetRestorePoint skipped for this transaction.
MSI (s) (F8:64) [18:17:05:859]: Server not locked: locking for product {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
Action start 18:17:05: InstallInitialize.
MSI (s) (F8:64) [18:17:07:265]: Doing action: SxsInstallCA
Action ended 18:17:07: InstallInitialize. Return value 1.
MSI (s) (F8:2C) [18:17:07:296]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI55.tmp, Entrypoint: CustomAction_SxsMsmInstall
MSI (s) (F8:C4) [18:17:07:343]: Generating random cookie.
MSI (s) (F8:C4) [18:17:07:390]: Created Custom Action Server with PID 2548 (0x9F4).
MSI (s) (F8:60) [18:17:07:562]: Running as a service.
MSI (s) (F8:58) [18:17:07:562]: Hello, I'm your 32bit Elevated custom action server.
Action start 18:17:07: SxsInstallCA.
1: sxsdelca 2: traceop 3: 1256 4: 0
1: sxsdelca 2: traceop 3: 1257 4: 0
1: sxsdelca 2: traceop 3: 1258 4: 0
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 1306 4: 0
1: sxsdelca 2: traceop 3: 1307 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 259
1: sxsdelca 2: SxsMsmInstall completed 3: 0 4: 0
MSI (s) (F8:64) [18:17:07:875]: Doing action: AllocateRegistrySpace
Action ended 18:17:07: SxsInstallCA. Return value 1.
Action start 18:17:07: AllocateRegistrySpace.
MSI (s) (F8:64) [18:17:07:875]: Doing action: ProcessComponents
Action ended 18:17:07: AllocateRegistrySpace. Return value 1.
MSI (s) (F8:64) [18:17:07:875]: Note: 1: 2205 2: 3: MsiPatchCertificate
MSI (s) (F8:64) [18:17:07:875]: LUA patching is disabled: missing MsiPatchCertificate table
MSI (s) (F8:64) [18:17:07:875]: Resolving source.
MSI (s) (F8:64) [18:17:07:875]: Resolving source to launched-from source.
MSI (s) (F8:64) [18:17:07:875]: Setting launched-from source as last-used.
MSI (s) (F8:64) [18:17:07:875]: PROPERTY CHANGE: Adding SourceDir property. Its value is 'c:\5a78a614ae0728d014fcdf\'.
MSI (s) (F8:64) [18:17:07:875]: PROPERTY CHANGE: Adding SOURCEDIR property. Its value is 'c:\5a78a614ae0728d014fcdf\'.
MSI (s) (F8:64) [18:17:07:875]: PROPERTY CHANGE: Adding SourcedirProduct property. Its value is '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (F8:64) [18:17:07:875]: SOURCEDIR ==> c:\5a78a614ae0728d014fcdf\
MSI (s) (F8:64) [18:17:07:875]: SOURCEDIR product ==> {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSI (s) (F8:64) [18:17:07:875]: Determining source type
MSI (s) (F8:64) [18:17:07:875]: Source type from package 'msxml.msi': 2
Action start 18:17:07: ProcessComponents.
MSI (s) (F8:64) [18:17:07:890]: Source path resolution complete. Dumping Directory table…
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: TARGETDIR , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WindowsFolder , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: CommonFilesFolder , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Microsoft Shared\ , ShortSubPath: MICROS~1\
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Microsoft Shared\MSDN\ , ShortSubPath: MICROS~1\MSDN\
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\system32\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\k0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\h0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\Manifests\ , ShortSubPath: Windows\winsxs\manifest\
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\Policies\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\Policies\i0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\j0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\system32\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\8n0mtfut.k85\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\Policies\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\Policies\6n0mtfut.k85\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\Manifests\ , ShortSubPath: Windows\winsxs\manifest\
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\5n0mtfut.k85\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\7n0mtfut.k85\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\system32\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\wl34x2va.rt8\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\Policies\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\Policies\ul34x2va.rt8\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\Manifests\ , ShortSubPath: Windows\winsxs\manifest\
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\tl34x2va.rt8\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: Windows\winsxs\vl34x2va.rt8\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: System\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: DesktopFolder , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: ProgramFilesFolder , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: MSXML , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: redist\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: INC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: redist\inc\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: LIB.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: redist\lib\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: DOC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: redist\doc\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: redist\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: redist\MSXML 4.0\ , ShortSubPath: redist\MSXML4\
MSI (s) (F8:64) [18:17:07:890]: Dir (source): Key: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\5a78a614ae0728d014fcdf\ , LongSubPath: redist\ , ShortSubPath:
MSI (s) (F8:64) [18:17:07:890]: Doing action: UnpublishComponents
Action ended 18:17:07: ProcessComponents. Return value 1.
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2262 2: PublishComponent 3: -2147287038
Action start 18:17:07: UnpublishComponents.
MSI (s) (F8:64) [18:17:07:890]: Doing action: MsiUnpublishAssemblies
Action ended 18:17:07: UnpublishComponents. Return value 1.
Action start 18:17:07: MsiUnpublishAssemblies.
MSI (s) (F8:64) [18:17:07:890]: Doing action: UnpublishFeatures
Action ended 18:17:07: MsiUnpublishAssemblies. Return value 1.
Action start 18:17:07: UnpublishFeatures.
MSI (s) (F8:64) [18:17:07:890]: Doing action: StopServices
Action ended 18:17:07: UnpublishFeatures. Return value 1.
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2205 2: 3: ServiceControl
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2228 2: 3: ServiceControl 4: SELECT `Name`,`Wait`,`Arguments`,`Event`, `Action` FROM `ServiceControl`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 2)
Action start 18:17:07: StopServices.
MSI (s) (F8:64) [18:17:07:890]: Doing action: DeleteServices
Action ended 18:17:07: StopServices. Return value 1.
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2205 2: 3: ServiceControl
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2228 2: 3: ServiceControl 4: SELECT `Name`,`Wait`,`Arguments`,`Event`, `Action` FROM `ServiceControl`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 2)
Action start 18:17:07: DeleteServices.
MSI (s) (F8:64) [18:17:07:890]: Doing action: UnregisterComPlus
Action ended 18:17:07: DeleteServices. Return value 1.
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2205 2: 3: Complus
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2228 2: 3: Complus 4: SELECT `ComponentId`, `FileName`, `Component`.`Directory_`, `ExpType`, `Component`.`Action`, `Component`.`Installed` FROM `Complus`, `Component`, `File` WHERE `Complus`.`Component_` = `Component` AND `Component`.`KeyPath` = `File`.`File` AND `Action` = 0
Action start 18:17:07: UnregisterComPlus.
MSI (s) (F8:64) [18:17:07:890]: Doing action: SelfUnregModules
Action ended 18:17:07: UnregisterComPlus. Return value 0.
Action start 18:17:07: SelfUnregModules.
MSI (s) (F8:64) [18:17:07:890]: Doing action: UnregisterTypeLibraries
Action ended 18:17:07: SelfUnregModules. Return value 1.
Action start 18:17:07: UnregisterTypeLibraries.
MSI (s) (F8:64) [18:17:07:890]: Doing action: RemoveODBC
Action ended 18:17:07: UnregisterTypeLibraries. Return value 1.
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND `Component`.`Action` = 0 AND `BinaryType` = ?
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND `Component`.`Action` = 0 AND `BinaryType` = ?
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCTranslator`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCTranslator`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCDriver`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCDriver`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2711 2: ODBCDriverManager
Action start 18:17:07: RemoveODBC.
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2711 2: ODBCDriverManager64
MSI (s) (F8:64) [18:17:07:890]: Doing action: UnregisterFonts
Action ended 18:17:07: RemoveODBC. Return value 1.
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2205 2: 3: Font
MSI (s) (F8:64) [18:17:07:890]: Note: 1: 2228 2: 3: Font 4: SELECT `FontTitle`, `FileName`, `Directory_`, `Installed`From `Font`, `FileAction` Where `Font`.`File_` = `FileAction`.`File` And `FileAction`.`Action` = 0 ORDER BY `FileAction`.`Directory_`
Action start 18:17:07: UnregisterFonts.
MSI (s) (F8:64) [18:17:07:890]: Doing action: RemoveRegistryValues
Action ended 18:17:07: UnregisterFonts. Return value 1.
Action start 18:17:07: RemoveRegistryValues.
MSI (s) (F8:64) [18:17:07:906]: Doing action: UnregisterClassInfo
Action ended 18:17:07: RemoveRegistryValues. Return value 1.
Action start 18:17:07: UnregisterClassInfo.
MSI (s) (F8:64) [18:17:07:906]: Doing action: UnregisterExtensionInfo
Action ended 18:17:07: UnregisterClassInfo. Return value 1.
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 18:17:07: UnregisterExtensionInfo.
MSI (s) (F8:64) [18:17:07:906]: Doing action: UnregisterProgIdInfo
Action ended 18:17:07: UnregisterExtensionInfo. Return value 1.
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 18:17:07: UnregisterProgIdInfo.
MSI (s) (F8:64) [18:17:07:906]: Doing action: UnregisterMIMEInfo
Action ended 18:17:07: UnregisterProgIdInfo. Return value 1.
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2262 2: MIME 3: -2147287038
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 18:17:07: UnregisterMIMEInfo.
MSI (s) (F8:64) [18:17:07:906]: Doing action: RemoveIniValues
Action ended 18:17:07: UnregisterMIMEInfo. Return value 1.
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2205 2: 3: IniFile
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2228 2: 3: IniFile 4: SELECT `FileName`,`IniFile`.`DirProperty`,`Section`,`IniFile`.`Key`,`IniFile`.`Value`,`IniFile`.`Action` FROM `IniFile`, `Component` WHERE `Component`=`Component_` AND `Component`.`Action`=0 ORDER BY `FileName`,`Section`
Action start 18:17:07: RemoveIniValues.
MSI (s) (F8:64) [18:17:07:906]: Doing action: RemoveShortcuts
Action ended 18:17:07: RemoveIniValues. Return value 1.
Action start 18:17:07: RemoveShortcuts.
MSI (s) (F8:64) [18:17:07:906]: Doing action: RemoveEnvironmentStrings
Action ended 18:17:07: RemoveShortcuts. Return value 1.
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2205 2: 3: Environment
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2228 2: 3: Environment 4: SELECT `Name`,`Value` FROM `Environment`,`Component` WHERE `Component_`=`Component` AND (`Component`.`Action` = 0)
Action start 18:17:07: RemoveEnvironmentStrings.
MSI (s) (F8:64) [18:17:07:906]: Doing action: RemoveDuplicateFiles
Action ended 18:17:07: RemoveEnvironmentStrings. Return value 1.
Action start 18:17:07: RemoveDuplicateFiles.
MSI (s) (F8:64) [18:17:07:906]: Doing action: RemoveFiles
Action ended 18:17:07: RemoveDuplicateFiles. Return value 1.
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2205 2: 3: RemoveFile
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2205 2: 3: RemoveFile
Action start 18:17:07: RemoveFiles.
MSI (s) (F8:64) [18:17:07:906]: Doing action: RemoveFolders
Action ended 18:17:07: RemoveFiles. Return value 0.
Action start 18:17:07: RemoveFolders.
MSI (s) (F8:64) [18:17:07:906]: Doing action: CreateFolders
Action ended 18:17:07: RemoveFolders. Return value 1.
Action start 18:17:07: CreateFolders.
MSI (s) (F8:64) [18:17:07:906]: Doing action: MoveFiles
Action ended 18:17:07: CreateFolders. Return value 1.
Action start 18:17:07: MoveFiles.
MSI (s) (F8:64) [18:17:07:906]: Doing action: InstallFiles
Action ended 18:17:07: MoveFiles. Return value 1.
Action start 18:17:07: InstallFiles.
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2205 2: 3: Patch
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2228 2: 3: Patch 4: SELECT `Patch`.`File_`, `Patch`.`Header`, `Patch`.`Attributes`, `Patch`.`Sequence`, `Patch`.`StreamRef_` FROM `Patch` WHERE `Patch`.`File_` = ? AND `Patch`.`#_MsiActive`=? ORDER BY `Patch`.`Sequence`
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2228 2: 3: MsiPatchHeaders 4: SELECT `Header` FROM `MsiPatchHeaders` WHERE `StreamRef` = ?
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (F8:64) [18:17:07:906]: Doing action: PatchFiles
Action ended 18:17:07: InstallFiles. Return value 1.
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2205 2: 3: Patch
MSI (s) (F8:64) [18:17:07:906]: Note: 1: 2228 2: 3: Patch 4: SELECT `File`,`FileName`,`FileSize`,`Directory_`,`PatchSize`,`File`.`Attributes`,`Patch`.`Attributes`,`Patch`.`Sequence`,`Component`.`Component`,`Component`.`ComponentId` FROM `File`,`Component`,`Patch` WHERE `Patch`.`#_MsiActive`=? AND `File`=`File_` AND `Component`=`Component_` ORDER BY `Patch`.`Sequence`
Action start 18:17:07: PatchFiles.
MSI (s) (F8:64) [18:17:07:906]: Doing action: DuplicateFiles
Action ended 18:17:07: PatchFiles. Return value 0.
Action start 18:17:07: DuplicateFiles.
MSI (s) (F8:64) [18:17:07:906]: Doing action: BindImage
Action ended 18:17:07: DuplicateFiles. Return value 1.
Action start 18:17:07: BindImage.
MSI (s) (F8:64) [18:17:07:906]: Doing action: CreateShortcuts
Action ended 18:17:07: BindImage. Return value 1.
Action start 18:17:07: CreateShortcuts.
MSI (s) (F8:64) [18:17:07:921]: Doing action: RegisterClassInfo
Action ended 18:17:07: CreateShortcuts. Return value 1.
Action start 18:17:07: RegisterClassInfo.
MSI (s) (F8:64) [18:17:07:921]: Doing action: RegisterExtensionInfo
Action ended 18:17:07: RegisterClassInfo. Return value 1.
MSI (s) (F8:64) [18:17:07:921]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 18:17:07: RegisterExtensionInfo.
MSI (s) (F8:64) [18:17:07:921]: Doing action: RegisterProgIdInfo
Action ended 18:17:07: RegisterExtensionInfo. Return value 1.
MSI (s) (F8:64) [18:17:07:921]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 18:17:07: RegisterProgIdInfo.
MSI (s) (F8:64) [18:17:07:921]: Doing action: RegisterMIMEInfo
Action ended 18:17:07: RegisterProgIdInfo. Return value 1.
MSI (s) (F8:64) [18:17:07:921]: Note: 1: 2262 2: MIME 3: -2147287038
MSI (s) (F8:64) [18:17:07:921]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 18:17:07: RegisterMIMEInfo.
MSI (s) (F8:64) [18:17:07:921]: Doing action: WriteRegistryValues
Action ended 18:17:07: RegisterMIMEInfo. Return value 1.
Action start 18:17:07: WriteRegistryValues.
MSI (s) (F8:64) [18:17:07:937]: Doing action: WriteIniValues
Action ended 18:17:07: WriteRegistryValues. Return value 1.
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2205 2: 3: IniFile
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2228 2: 3: IniFile 4: SELECT `FileName`,`IniFile`.`DirProperty`,`Section`,`IniFile`.`Key`,`IniFile`.`Value`,`IniFile`.`Action` FROM `IniFile`, `Component` WHERE `Component`=`Component_` AND (`Component`.`Action`=1 OR `Component`.`Action`=2) ORDER BY `FileName`,`Section`
Action start 18:17:07: WriteIniValues.
MSI (s) (F8:64) [18:17:07:937]: Doing action: WriteEnvironmentStrings
Action ended 18:17:07: WriteIniValues. Return value 1.
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2205 2: 3: Environment
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2228 2: 3: Environment 4: SELECT `Name`,`Value` FROM `Environment`,`Component` WHERE `Component_`=`Component` AND (`Component`.`Action` = 1 OR `Component`.`Action` = 2)
Action start 18:17:07: WriteEnvironmentStrings.
MSI (s) (F8:64) [18:17:07:937]: Doing action: RegisterFonts
Action ended 18:17:07: WriteEnvironmentStrings. Return value 1.
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2205 2: 3: Font
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2228 2: 3: Font 4: SELECT `FontTitle`, `FileName`, `Directory_`, `Action` From `Font`, `FileAction` Where `Font`.`File_` = `FileAction`.`File` And (`FileAction`.`Action` = 1 Or `FileAction`.`Action` = 2) ORDER BY `FileAction`.`Directory_`
Action start 18:17:07: RegisterFonts.
MSI (s) (F8:64) [18:17:07:937]: Doing action: InstallODBC
Action ended 18:17:07: RegisterFonts. Return value 1.
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2711 2: ODBCDriverManager
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2711 2: ODBCDriverManager64
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCDriver`, `File`, `Component` WHERE `File_` = `File` AND `ODBCDriver`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCDriver`, `File`, `Component` WHERE `File_` = `File` AND `ODBCDriver`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCTranslator`, `File`, `Component` WHERE `File_` = `File` AND `ODBCTranslator`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCTranslator`, `File`, `Component` WHERE `File_` = `File` AND `ODBCTranslator`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND (`Component`.`Action` = 1 OR `Component`.`Action` = 2) AND `BinaryType` = ?
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND (`Component`.`Action` = 1 OR `Component`.`Action` = 2) AND `BinaryType` = ?
Action start 18:17:07: InstallODBC.
MSI (s) (F8:64) [18:17:07:937]: Doing action: RegisterTypeLibraries
Action ended 18:17:07: InstallODBC. Return value 0.
Action start 18:17:07: RegisterTypeLibraries.
MSI (s) (F8:64) [18:17:07:937]: Doing action: SelfRegModules
Action ended 18:17:07: RegisterTypeLibraries. Return value 1.
Action start 18:17:07: SelfRegModules.
MSI (s) (F8:64) [18:17:07:937]: Doing action: RegisterComPlus
Action ended 18:17:07: SelfRegModules. Return value 1.
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2205 2: 3: Complus
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2228 2: 3: Complus 4: SELECT `ComponentId`, `FileName`, `Component`.`Directory_`, `ExpType`, `Component`.`Action`, `Component`.`Installed` FROM `Complus`, `Component`, `File` WHERE `Complus`.`Component_` = `Component` AND `Component`.`KeyPath` = `File`.`File` AND (`Action` = 1 OR `Action` = 2)
Action start 18:17:07: RegisterComPlus.
MSI (s) (F8:64) [18:17:07:937]: Doing action: InstallServices
Action ended 18:17:07: RegisterComPlus. Return value 0.
MSI (s) (F8:64) [18:17:07:937]: Detected older ServiceInstall table schema
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2205 2: 3: ServiceInstall
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2228 2: 3: ServiceInstall 4: SELECT `Name`,`DisplayName`,`ServiceType`,`StartType`,`ErrorControl`,`LoadOrderGroup`,`Dependencies`,`StartName`,`Password`,`ComponentId`,`Directory_`,`FileName`,`Arguments` FROM `ServiceInstall`, `Component`, `File` WHERE `ServiceInstall`.`Component_` = `Component`.`Component` AND (`Component`.`KeyPath` = `File`.`File`) AND (`Action` = 1 OR `Action` = 2)
Action start 18:17:07: InstallServices.
MSI (s) (F8:64) [18:17:07:937]: Doing action: StartServices
Action ended 18:17:07: InstallServices. Return value 1.
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2205 2: 3: ServiceControl
MSI (s) (F8:64) [18:17:07:937]: Note: 1: 2228 2: 3: ServiceControl 4: SELECT `Name`,`Wait`,`Arguments`,`Event`, `Action` FROM `ServiceControl`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 2)
Action start 18:17:07: StartServices.
MSI (s) (F8:64) [18:17:07:937]: Doing action: RegisterUser
Action ended 18:17:07: StartServices. Return value 1.
Action start 18:17:07: RegisterUser.
MSI (s) (F8:64) [18:17:07:937]: Doing action: RegisterProduct
Action ended 18:17:07: RegisterUser. Return value 1.
Action start 18:17:07: RegisterProduct.
MSI (s) (F8:64) [18:17:07:953]: PROPERTY CHANGE: Adding ProductToBeRegistered property. Its value is '1'.
MSI (s) (F8:64) [18:17:07:953]: Doing action: PublishComponents
Action ended 18:17:07: RegisterProduct. Return value 1.
MSI (s) (F8:64) [18:17:07:953]: Note: 1: 2262 2: PublishComponent 3: -2147287038
Action start 18:17:07: PublishComponents.
MSI (s) (F8:64) [18:17:07:953]: Doing action: MsiPublishAssemblies
Action ended 18:17:07: PublishComponents. Return value 1.
Action start 18:17:07: MsiPublishAssemblies.
MSI (s) (F8:64) [18:17:07:953]: Doing action: PublishFeatures
Action ended 18:17:07: MsiPublishAssemblies. Return value 1.
Action start 18:17:07: PublishFeatures.
MSI (s) (F8:64) [18:17:07:953]: Doing action: PublishProduct
Action ended 18:17:07: PublishFeatures. Return value 1.
Action start 18:17:07: PublishProduct.
MSI (s) (F8:64) [18:17:07:968]: Doing action: InstallFinalize
Action ended 18:17:07: PublishProduct. Return value 1.
MSI (s) (F8:64) [18:17:07:968]: Running Script: C:\WINDOWS\Installer\MSI56.tmp
MSI (s) (F8:64) [18:17:07:968]: PROPERTY CHANGE: Adding UpdateStarted property. Its value is '1'.
MSI (s) (F8:64) [18:17:07:968]: Machine policy value 'DisableRollback' is 0
MSI (s) (F8:64) [18:17:08:015]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (F8:64) [18:17:08:046]: Executing op: Header(Signature=1397708873,Version=301,Timestamp=896635428,LangId=1033,Platform
=0,ScriptType=1,ScriptMajorVersion=21,ScriptMinorVersion=4,ScriptAttributes=1)
Action start 18:17:07: InstallFinalize.
MSI (s) (F8:64) [18:17:08:046]: Executing op: ProductInfo(ProductKey={37477865-A3F1-4772-AD43-AAFC6BCFF99F},ProductName=MSXML 4.0 SP2 (KB927978),PackageName=msxml.msi,Language=1033,Version=68429425,Assignment=1,Obs
oleteArg=0,,,PackageCode={2B27DCD9-53FA-4885-B6CD-698623819F4C},,,InstanceType=0,LUASetting=0,RemoteURTInstalls=0)
MSI (s) (F8:64) [18:17:08:046]: Executing op: DialogInfo(Type=0,Argument=1033)
MSI (s) (F8:64) [18:17:08:046]: Executing op: DialogInfo(Type=1,Argument=MSXML 4.0 SP2 (KB927978))
MSI (s) (F8:64) [18:17:08:046]: Executing op: RollbackInfo(,RollbackAction=Rollback,RollbackDescription=Rolling back action:,RollbackTemplate=[1],CleanupAction=RollbackCleanup,CleanupDescription=Re
moving backup files,CleanupTemplate=File: [1])
MSI (s) (F8:64) [18:17:08:046]: Executing op: SetBaseline(Baseline=0,)
MSI (s) (F8:64) [18:17:08:046]: Executing op: SetBaseline(Baseline=1,)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ActionStart(Name=ProcessComponents,Description=Updating component registration,)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ProgressTotal(Total=5,Type=1,ByteEquivalent=24000)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentUnregister(ComponentId={E9BC82F6-AC0E-407C-8666-619D6D60DF2B},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (F8:64) [18:17:08:046]: Note: 1: 1402 2: UNKNOWN\Components\6F28CB9EE0CAC704686616D9D606FDB2 3: 2
MSI (s) (F8:64) [18:17:08:046]: Note: 1: 1402 2: UNKNOWN\Components\6F28CB9EE0CAC704686616D9D606FDB2 3: 2
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentUnregister(ComponentId={81754FFD-DA2B-49C6-9447-E1C1E1733BB6},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (F8:64) [18:17:08:046]: Note: 1: 1402 2: UNKNOWN\Components\DFF45718B2AD6C9449741E1C1E37B36B 3: 2
MSI (s) (F8:64) [18:17:08:046]: Note: 1: 1402 2: UNKNOWN\Components\DFF45718B2AD6C9449741E1C1E37B36B 3: 2
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentUnregister(ComponentId={5E6714E1-EA46-4B0F-B479-06D87058DC74},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (F8:64) [18:17:08:046]: Note: 1: 1402 2: UNKNOWN\Components\1E4176E564AEF0B44B97608D0785CD47 3: 2
MSI (s) (F8:64) [18:17:08:046]: Note: 1: 1402 2: UNKNOWN\Components\1E4176E564AEF0B44B97608D0785CD47 3: 2
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentUnregister(ComponentId={57E0F99D-E884-4BD0-B8CB-803CF9EA2066},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (F8:64) [18:17:08:046]: Note: 1: 1402 2: UNKNOWN\Components\D99F0E75488E0DB48BBC08C39FAE0266 3: 2
MSI (s) (F8:64) [18:17:08:046]: Note: 1: 1402 2: UNKNOWN\Components\D99F0E75488E0DB48BBC08C39FAE0266 3: 2
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentUnregister(ComponentId={C763CD13-6E1E-4166-8C78-D274B266E9B6},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (F8:64) [18:17:08:046]: Note: 1: 1402 2: UNKNOWN\Components\31DC367CE1E66614C8872D472B669E6B 3: 2
MSI (s) (F8:64) [18:17:08:046]: Note: 1: 1402 2: UNKNOWN\Components\31DC367CE1E66614C8872D472B669E6B 3: 2
MSI (s) (F8:64) [18:17:08:046]: Executing op: ProgressTotal(Total=14,Type=1,ByteEquivalent=24000)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentRegister(ComponentId={4075CDF6-D88F-4F57-AF1A-29A124755695},KeyPath=c:\Program Files\MSXML 4.0\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentRegister(ComponentId={D21D9CCD-C3FA-4D72-982F-C29A2DE361EC},KeyPath=02:\Software\Microsoft\Updates\MSXML4SP2\Q927978\Description,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentRegister(ComponentId={4B1F71A7-50C6-44B7-A3AD-B6C3574BB896},KeyPath=c:\WINDOWS\system32\msxml4.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentRegister(ComponentId={62846705-2671-4547-AB45-854DCC93B3C7},KeyPath=c:\WINDOWS\system32\msxml4r.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentRegister(ComponentId={3AAE95CD-F592-46E7-89A1-9B56717C4413},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentRegister(ComponentId={CCF8B6EF-5FB9-4DE1-A276-683008BA3485},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentRegister(ComponentId={7B2FCEFF-0F22-B7E1-A06B-D6B9ABF34537},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentRegister(ComponentId={7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\downlevel_manifest\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentRegister(ComponentId={7B2FCEFF-0F22-B7E1-B06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\downlevel_payload\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F8:64) [18:17:08:046]: Executing op: ComponentRegister(ComponentId={DA6654F6-456F-3658-A06B-D6B9ABF34537},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F8:64) [18:17:08:062]: Executing op: ComponentRegister(ComponentId={DA6654F6-456F-3658-C06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\downlevel_manifest\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F8:64) [18:17:08:062]: Executing op: ComponentRegister(ComponentId={DA6654F6-456F-3658-B06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\downlevel_payload\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F8:64) [18:17:08:062]: Executing op: ComponentRegister(ComponentId={0E9F98FC-A692-A6DF-A06B-D6B9ABF34537},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F8:64) [18:17:08:062]: Executing op: ComponentRegister(ComponentId={0E9F98FC-A692-A6DF-C06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\downlevel_manifest\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (F8:64) [18:17:08:062]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (F8:64) [18:17:08:062]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:062]: Executing op: ProgressTick()
MSI (s) (F8:64) [18:17:08:062]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (F8:64) [18:17:08:062]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:062]: Executing op: ProgressTick()
MSI (s) (F8:64) [18:17:08:062]: Executing op: ActionStart(Name=RemoveODBC,Description=Removing ODBC components,)
MSI (s) (F8:64) [18:17:08:062]: Executing op: ODBCDriverManager(,BinaryType=0)
MSI (s) (F8:64) [18:17:08:062]: Executing op: ODBCDriverManager(,BinaryType=1)
MSI (s) (F8:64) [18:17:08:062]: Executing op: ActionStart(Name=CreateFolders,Description=Creating folders,Template=Folder: [1])
MSI (s) (F8:64) [18:17:08:062]: Executing op: FolderCreate(Folder=c:\Program Files\MSXML 4.0\,Foreign=0,)
MSI (s) (F8:64) [18:17:08:062]: Executing op: ActionStart(Name=InstallFiles,Description=Copying new files,Template=File: [1], Directory: [9], Size: [6])
MSI (s) (F8:64) [18:17:08:062]: Executing op: ProgressTotal(Total=2521072,Type=0,ByteEquivalent=1)
MSI (s) (F8:64) [18:17:08:062]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\system32\)
MSI (s) (F8:64) [18:17:08:062]: Executing op: SetSourceFolder(Folder=1\System\)
MSI (s) (F8:64) [18:17:08:062]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,MediaCabinet=XML_Core.cab,BytesPerTick=32768,CopierType=2,ModuleFileName=c:\WINDOWS\Installer\9dff401.msi,,,,,IsFirstPhysicalMedia=1)
MSI (s) (F8:64) [18:17:08:062]: Executing op: FileCopy(SourceName=msxml4.dll,SourceCabKey=msxml4.dll.246EB7AD_459A_4FA8_83D1_4
1A46D7634B7,DestName=msxml4.dll,Attributes=512,FileSize=1245696,PerTick=32768,,Ve
rifyMedia=1,,,,,CheckCRC=0,Version=4.20.9841.0,Language=0,InstallMode=58982400,,,
,,,,)
MSI (s) (F8:64) [18:17:08:078]: File: c:\WINDOWS\system32\msxml4.dll; Overwrite; Won't patch; Existing file is a lower version
MSI (s) (F8:64) [18:17:08:078]: Source for file 'msxml4.dll.246EB7AD_459A_4FA8_83D1_41A46D7634B7' is compressed
MSI (s) (F8:64) [18:17:08:078]: Re-applying security from existing file.
MSI (s) (F8:64) [18:17:08:078]: Verifying accessibility of file: msxml4.dll
MSI (s) (F8:64) [18:17:08:093]: SOFTWARE RESTRICTION POLICY: Verifying object –> 'c:\WINDOWS\Installer\9dff401.msi' against software restriction policy
MSI (s) (F8:64) [18:17:08:093]: SOFTWARE RESTRICTION POLICY: c:\WINDOWS\Installer\9dff401.msi has a digital signature
MSI (s) (F8:64) [18:17:08:171]: SOFTWARE RESTRICTION POLICY: c:\WINDOWS\Installer\9dff401.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (F8:64) [18:17:08:203]: Note: 1: 2318 2: c:\WINDOWS\system32\msxml4.dll
MSI (s) (F8:64) [18:17:08:203]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:203]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:203]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:203]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:203]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:203]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:203]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:203]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:218]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:234]: Executing op: FileCopy(SourceName=msxml4r.dll,SourceCabKey=msxml4r.dll.246EB7AD_459A_4FA8_83D1
_41A46D7634B7,DestName=msxml4r.dll,Attributes=512,FileSize=82432,PerTick=32768,,V
erifyMedia=1,,,,,CheckCRC=0,Version=4.10.9404.0,Language=1033,InstallMode=5898240
0,,,,,,,)
MSI (s) (F8:64) [18:17:08:250]: File: c:\WINDOWS\system32\msxml4r.dll; Won't Overwrite; Won't patch; Existing file is of an equal version
MSI (s) (F8:64) [18:17:08:250]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\Manifests\)
MSI (s) (F8:64) [18:17:08:250]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\manifest\|Windows\winsxs\Manifests\)
MSI (s) (F8:64) [18:17:08:250]: Executing op: FileCopy(SourceName=xl34x2va.rt8|x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841
.0_x-ww_18171213.manifest,SourceCabKey=manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537,
DestName=x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest,,FileSize=3973,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,
,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-85909274,HashPart2=-393638470,HashPart3=495071453,HashPart4=945762879,,)
MSI (s) (F8:64) [18:17:08:250]: File: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest; To be installed; Won't patch; No existing file
MSI (s) (F8:64) [18:17:08:250]: Source for file 'manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537' is compressed
MSI (s) (F8:64) [18:17:08:250]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest
MSI (s) (F8:64) [18:17:08:265]: Executing op: FileCopy(SourceName=yl34x2va.rt8|x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841
.0_x-ww_18171213.cat,SourceCabKey=catalog.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537,DestNa
me=x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat,,FileSize=8347,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,,,Ch
eckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1679697816,HashPart2=1808584787,HashPart3=1425912084,HashPart4=629236904,,)
MSI (s) (F8:64) [18:17:08:265]: File: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat; To be installed; Won't patch; No existing file
MSI (s) (F8:64) [18:17:08:265]: Source for file 'catalog.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537' is compressed
MSI (s) (F8:64) [18:17:08:265]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat
MSI (s) (F8:64) [18:17:08:281]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\)
MSI (s) (F8:64) [18:17:08:281]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\tl34x2va.rt8\)
MSI (s) (F8:64) [18:17:08:281]: Executing op: FileCopy(SourceName=1m34x2va.rt8|msxml4.dll,SourceCabKey=msxml4.dll.7B2FCEFF_0F2
2_B7E1_FF6B_D6B9ABF34537,DestName=msxml4.dll,,FileSize=1245696,PerTick=32768,,Ver
ifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,Version=4.20.9841.0,Language=0,InstallMod
e=58982400,,,,,,,)
MSI (s) (F8:64) [18:17:08:281]: File: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\msxml4.dll; To be installed; Won't patch; No existing file
MSI (s) (F8:64) [18:17:08:281]: Source for file 'msxml4.dll.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537' is compressed
MSI (s) (F8:64) [18:17:08:296]: Note: 1: 2318 2: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\msxml4.dll
MSI (s) (F8:64) [18:17:08:296]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:296]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:296]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:296]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:296]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:296]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:296]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:296]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:296]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:296]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:312]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Note: 1: 2360
MSI (s) (F8:64) [18:17:08:328]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\Manifests\)
MSI (s) (F8:64) [18:17:08:328]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\manifest\|Windows\winsxs\Manifests\)
MSI (s) (F8:64) [18:17:08:328]: Executing op: FileCopy(SourceName=9n0mtfut.k85|x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_
x-ww_29c3ad6a.manifest,SourceCabKey=manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537,
DestName=x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.manifest,,FileSize=500,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,
,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-707213148,HashPart2=1938794768,HashPart3=-933075776,HashPart4=-843550219,,)
MSI (s) (F8:64) [18:17:08:343]: File: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.manifest; Won't Overwrite; Won't patch; Existing file is unversioned and unmodified - hash matches source file
MSI (s) (F8:64) [18:17:08:343]: Executing op: FileCopy(SourceName=an0mtfut.k85|x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_
x-ww_29c3ad6a.cat,SourceCabKey=catalog.DA6654F6_456F_3658_FF6B_D6B9ABF34537,DestNa
me=x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat,,FileSize=8349,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,,,Ch
eckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1336197992,HashPart2=-627824155,HashPart3=82633343,HashPart4=1105156543,,)
MSI (s) (F8:64) [18:17:08:343]: File: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat; Overwrite; Won't patch; Existing file is unversioned and unmodified - hash doesn't match source file
MSI (s) (F8:64) [18:17:08:343]: Source for file 'catalog.DA6654F6_456F_3658_FF6B_D6B9ABF34537' is compressed
MSI (s) (F8:64) [18:17:08:343]: Re-applying security from existing file.
MSI (s) (F8:64) [18:17:08:734]: Verifying accessibility of file: x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat
MSI (s) (F8:64) [18:17:08:734]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat
MSI (s) (F8:64) [18:17:08:765]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\)
MSI (s) (F8:64) [18:17:08:765]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\5n0mtfut.k85\)
MSI (s) (F8:64) [18:17:08:765]: Executing op: FileCopy(SourceName=dn0mtfut.k85|msxml4r.dll,SourceCabKey=msxml4r.dll.DA6654F6_4
56F_3658_FF6B_D6B9ABF34537,DestName=msxml4r.dll,,FileSize=82432,PerTick=32768,,Ve
rifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,Version=4.10.9404.0,Language=1033,Instal
lMode=58982400,,,,,,,)
MSI (s) (F8:64) [18:17:08:781]: File: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\msxml4r.dll; Won't Overwrite; Won't patch; Existing file is of an equal version
MSI (s) (F8:64) [18:17:08:781]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\)
MSI (s) (F8:64) [18:17:08:781]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\Policies\i0r1wg7y.dqe\)
MSI (s) (F8:64) [18:17:08:781]: Executing op: FileCopy(SourceName=l0r1wg7y.dqe|4.20.9841.0.policy,SourceCabKey=manifest.0E9F98
FC_A692_A6DF_FF6B_D6B9ABF34537,DestName=4.20.9841.0.policy,,FileSize=652,PerTick=
32768,,VerifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,,,InstallMode=58982400,HashOpti
ons=0,HashPart1=49613189,HashPart2=1139053242,HashPart3=-1699064514,HashPart4=-854272932,,)
MSI (s) (F8:64) [18:17:08:781]: File: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.policy; To be installed; Won't patch; No existing file
MSI (s) (F8:64) [18:17:08:781]: Source for file 'manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537' is compressed
MSI (s) (F8:64) [18:17:08:781]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.policy
MSI (s) (F8:64) [18:17:08:781]: Executing op: FileCopy(SourceName=m0r1wg7y.dqe|4.20.9841.0.cat,SourceCabKey=catalog.0E9F98FC_A
692_A6DF_FF6B_D6B9ABF34537,DestName=4.20.9841.0.cat,,FileSize=8359,PerTick=32768,
,VerifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,
HashPart1=-861819424,HashPart2=1423527147,HashPart3=-1146259424,HashPart4=2040409349,,)
MSI (s) (F8:64) [18:17:08:796]: File: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.cat; To be installed; Won't patch; No existing file
MSI (s) (F8:64) [18:17:08:796]: Source for file 'catalog.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537' is compressed
MSI (s) (F8:64) [18:17:08:796]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.cat
MSI (s) (F8:64) [18:17:08:843]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,MediaCabinet=XML_SDK.cab,BytesPerTick=32768,CopierType=2,ModuleFileName=c:\WINDOWS\Installer\9dff401.msi,,,,,IsFirstPhysicalMedia=1)
MSI (s) (F8:64) [18:17:08:843]: Executing op: CacheSizeFlush(,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: InstallProtectedFiles(AllowUI=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: ActionStart(Name=WriteRegistryValues,Description=Writing system registry values,Template=Key: [1], Name: [2], Value: [3])
MSI (s) (F8:64) [18:17:08:843]: Executing op: ProgressTotal(Total=112,Type=1,ByteEquivalent=13200)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=XML DOM Document 4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=Msxml2.DOMDocument.4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=XML DOM Document 4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=Msxml2.DOMDocument.4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=Msxml2.DOMDocument.4.0\CLSID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value={88D969C0-F192-11D4-A65F-0040963251E5},)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=Free Threaded XML DOM Document 4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=Msxml2.FreeThreadedDOMDocument.4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=Free Threaded XML DOM Document 4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=Msxml2.FreeThreadedDOMDocument.4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=Msxml2.FreeThreadedDOMDocument.4.0\CLSID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value={88D969C1-F192-11D4-A65F-0040963251E5},)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=XML Data Source Object 4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(Name=ThreadingModel,Value=Apartment,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=Msxml2.DSOControl.4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=XML Data Source Object 4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=Msxml2.DSOControl.4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=Msxml2.DSOControl.4.0\CLSID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value={88D969C4-F192-11D4-A65F-0040963251E5},)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=XML HTTP 4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(Name=ThreadingModel,Value=Apartment,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=Msxml2.XMLHTTP.4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=XML HTTP 4.0,)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:843]: Executing op: RegAddValue(,Value=Msxml2.XMLHTTP.4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=Msxml2.XMLHTTP.4.0\CLSID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value={88D969C5-F192-11D4-A65F-0040963251E5},)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=Server XML HTTP 4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(Name=ThreadingModel,Value=Apartment,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=Msxml2.ServerXMLHTTP.4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=Server XML HTTP 4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=Msxml2.ServerXMLHTTP.4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=Msxml2.ServerXMLHTTP.4.0\CLSID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value={88D969C6-F192-11D4-A65F-0040963251E5},)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C2-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=XML Schema Cache 4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=Msxml2.XMLSchemaCache.4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=XML Schema Cache 4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=Msxml2.XMLSchemaCache.4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=Msxml2.XMLSchemaCache.4.0\CLSID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value={88D969C2-F192-11D4-A65F-0040963251E5},)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C3-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=XSL Template 4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=Msxml2.XSLTemplate.4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=XSL Template 4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=Msxml2.XSLTemplate.4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=Msxml2.XSLTemplate.4.0\CLSID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value={88D969C3-F192-11D4-A65F-0040963251E5},)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=SAX XML Reader 4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=Msxml2.SAXXMLReader.4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=SAX XML Reader 4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\ProgID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=Msxml2.SAXXMLReader.4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\Version,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=Msxml2.SAXXMLReader.4.0\CLSID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value={7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F},)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=MX XML Reader 4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C8-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=MXXMLWriter 4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=Msxml2.MXXMLWriter.4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=MXXMLWriter 4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=Msxml2.MXXMLWriter.4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegOpenKey(,Key=Msxml2.MXXMLWriter.4.0\CLSID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:859]: Executing op: RegAddValue(,Value={88D969C8-F192-11D4-A65F-0040963251E5},)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=CLSID\{88D969C9-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=MXHTMLWriter 4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=Msxml2.MXHTMLWriter.4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=MXHTMLWriter 4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=Msxml2.MXHTMLWriter.4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=Msxml2.MXHTMLWriter.4.0\CLSID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value={88D969C9-F192-11D4-A65F-0040963251E5},)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=CLSID\{88D969CA-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=SAXAttributes 4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=Msxml2.SAXAttributes.4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=SAXAttributes 4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=Msxml2.SAXAttributes.4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=Msxml2.SAXAttributes.4.0\CLSID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value={88D969CA-F192-11D4-A65F-0040963251E5},)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=CLSID\{88D969D6-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=MXNamespaceManager 4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=Msxml2.MXNamespaceManager.4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=MXNamespaceManager 4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=Msxml2.MXNamespaceManager.4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(,Key=Msxml2.MXNamespaceManager.4.0\CLSID,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value={88D969D6-F192-11D4-A65F-0040963251E5},)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Updates\MSXML4SP2\Q927978,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(Name=Description,Value=FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(Name=InstalledDate,Value=11/17/2006,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(Name=InstalledBy,Value=Nancy,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(Name=IsInstalled,Value=#1,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(Name=ServicePack,Value=#1,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=Microsoft XML, v4.0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\0,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\0\win32,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\FLAGS,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,Value=0,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\HELPDIR,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\downlevel_payload,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\downlevel_manifest,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\downlevel_payload,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,,)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\downlevel_manifest,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:875]: Executing op: RegAddValue(,,)
MSI (s) (F8:64) [18:17:08:890]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\downlevel_manifest,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:890]: Executing op: RegAddValue(,,)
MSI (s) (F8:64) [18:17:08:890]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\SideBySide\PatchedComponents,,BinaryType=0)
MSI (s) (F8:64) [18:17:08:890]: Executing op: RegAddValue(Name={7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\Manifests\\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest[~]{7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Manifests\\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat[~]{7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Manifests\[~]{7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537},)
MSI (s) (F8:64) [18:17:08:890]: Executing op: RegAddValue(Name={7B2FCEFF-0F22-B7E1-B06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\\msxml4.dll[~]{7B2FCEFF-0F22-B7E1-B06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\[~]{7B2FCEFF-0F22-B7E1-B06B-D6B9ABF34537},)
MSI (s) (F8:64) [18:17:08:890]: Executing op: RegAddValue(Name={DA6654F6-456F-3658-C06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\Manifests\\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.manifest[~]{DA6654F6-456F-3658-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Manifests\\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat[~]{DA6654F6-456F-3658-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Manifests\[~]{DA6654F6-456F-3658-C06B-D6B9ABF34537},)
MSI (s) (F8:64) [18:17:08:890]: Executing op: RegAddValue(Name={DA6654F6-456F-3658-B06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\\msxml4r.dll[~]{DA6654F6-456F-3658-B06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\[~]{DA6654F6-456F-3658-B06B-D6B9ABF34537},)
MSI (s) (F8:64) [18:17:08:890]: Executing op: RegAddValue(Name={0E9F98FC-A692-A6DF-C06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\\4.20.9841.0.policy[~]{0E9F98FC-A692-A6DF-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\\4.20.9841.0.cat[~]{0E9F98FC-A692-A6DF-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\[~]{0E9F98FC-A692-A6DF-C06B-D6B9ABF34537},)
MSI (s) (F8:64) [18:17:08:890]: Executing op: ActionStart(Name=RegisterTypeLibraries,Description=Registering type libraries,Template=LibID: [1])
MSI (s) (F8:64) [18:17:08:890]: Executing op: TypeLibraryRegister(,,FilePath=c:\WINDOWS\system32\msxml4.dll,LibID={F5078F18-C551-11D3-89B9-0000F81FE221},Version=1024,,Language=0,,BinaryType=0,IgnoreRegistrationFailure=0
)
MSI (s) (F8:64) [18:17:08:953]: QueryPathOfRegTypeLib returned 0 in local context. Path is 'c:\WINDOWS\system32\msxml4.dll'
MSI (s) (F8:64) [18:17:08:953]: Note: 1: 1402 2: UNKNOWN\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\400.0\0\win32 3: 2
MSI (s) (F8:64) [18:17:08:953]: CMsiServices::ProcessTypeLibrary runs in local context, not impersonated.
MSI (s) (F8:64) [18:17:09:265]: ProcessTypeLibraryCore returns: 0. (0 means OK)
MSI (s) (F8:64) [18:17:09:265]: CMsiServices::ProcessTypeLibrary runs in local context, not impersonated.
MSI (s) (F8:64) [18:17:09:281]: ProcessTypeLibraryCore returns: 0. (0 means OK)
MSI (s) (F8:64) [18:17:09:281]: Executing op: ActionStart(Name=RegisterUser,Description=Registering user,Template=[1])
MSI (s) (F8:64) [18:17:09:281]: Executing op: UserRegister(Owner=Nancy,,ProductId=none)
MSI (s) (F8:64) [18:17:09:281]: Executing op: ActionStart(Name=RegisterProduct,Description=Registering product,Template=[1])
MSI (s) (F8:64) [18:17:09:296]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,MediaCabinet=XML_Core.cab,BytesPerTick=0,CopierType=2,ModuleFileName=c:\WINDOWS\Installer\9dff401.msi,,,,,IsFirstPhysicalMedia=1)
MSI (s) (F8:64) [18:17:09:296]: Executing op: DatabaseCopy(DatabasePath=c:\WINDOWS\Installer\9dff401.msi,ProductCode={37477865-A3F1-4772-AD43-AAFC6BCFF99F},CabinetStreams=XML_Core.cab;XML_SDK.cab,,)
MSI (s) (F8:64) [18:17:09:500]: Executing op: ProductRegister(UpgradeCode={7CE723E3-E56B-432C-9F24-78C0606045A5},VersionString=4.20.9841.0,HelpLink=http://support.microsoft.com/kb/927978,,,InstallSource=c:\5a78a614ae0728d014fcdf\,Publisher=Microsoft Corporation,,,,,,,,,,,,EstimatedSize=2625)
MSI (s) (F8:64) [18:17:09:531]: Executing op: ProductCPDisplayInfoRegister()
MSI (s) (F8:64) [18:17:09:531]: Executing op: ActionStart(Name=PublishFeatures,Description=Publishing Product Features,Template=Feature: [1])
MSI (s) (F8:64) [18:17:09:531]: Executing op: FeaturePublish(Feature=MSXML,,Absent=2,Component=MF}e835XRAhvfl[X%h~W(s-UlQ2mt@MgogY-xd{t)
MSI (s) (F8:64) [18:17:09:546]: Executing op: FeaturePublish(Feature=MSXMLSYS,Parent=MSXML,Absent=2,Component=V2?0@7$9*=IdbugpYRMX}GHaGLdZ==A&kv@Y~]3iui-r60O)l=Em%pCn7G4))
MSI (s) (F8:64) [18:17:09:546]: Executing op: FeaturePublish(Feature=MSXMLSUPP2,Parent=MSXML,Absent=2,Component=?`ZsjqO[%A*`NW3OG&nR)
MSI (s) (F8:64) [18:17:09:546]: Executing op: FeaturePublish(Feature=MSXMLSXS,Parent=MSXML,Absent=2,Component=LdCZOHqG+dpWsfdD
E!j5LdCZOHqG+d6XsfdDE!j5LdCZOHqG+d%XsfdDE!j5`DM4olJ_O5pWsfdDE!j5`DM4olJ_O56XsfdDE!j5`DM4olJ_O5%XsfdDE!j5l0Rd'9?m^^pWsfdDE!j5l0Rd'9?m^^6XsfdDE!j5)
MSI (s) (F8:64) [18:17:09:546]: Executing op: FeaturePublish(Feature=XMLSDK,,Absent=3,Component=mk`[Q=PRe?RvYBgpXHXc5~{DF_B]-@1_XLnB~RWMMvh8D]u5G@j^sM7=J&oH0G,*i]!a$9uKNVM3Kykc)
MSI (s) (F8:64) [18:17:09:562]: Executing op: ActionStart(Name=PublishProduct,Description=Publishing product information,)
MSI (s) (F8:64) [18:17:09:562]: Executing op: IconCreate(Icon=icon.exe,Data=BinaryData)
MSI (s) (F8:64) [18:17:09:562]: Executing op: CleanupConfigData()
MSI (s) (F8:64) [18:17:09:562]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\568774731F3A2774DA34AACFB6FC9FF9\Patches 3: 2
MSI (s) (F8:64) [18:17:09:562]: Executing op: RegisterPatchOrder(Continue=0,SequenceType=1,Remove=0)
MSI (s) (F8:64) [18:17:09:562]: Note: 1: 1402 2: UNKNOWN\Products\568774731F3A2774DA34AACFB6FC9FF9\Patches 3: 2
MSI (s) (F8:64) [18:17:09:578]: Executing op: ProductPublish(PackageKey={2B27DCD9-53FA-4885-B6CD-698623819F4C})
MSI (s) (F8:64) [18:17:09:578]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F8:64) [18:17:09:578]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F8:64) [18:17:09:578]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F8:64) [18:17:09:578]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F8:64) [18:17:09:578]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F8:64) [18:17:09:578]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F8:64) [18:17:09:578]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F8:64) [18:17:09:578]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F8:64) [18:17:09:578]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F8:64) [18:17:09:578]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (F8:64) [18:17:09:578]: Executing op: UpgradeCodePublish(UpgradeCode={7CE723E3-E56B-432C-9F24-78C0606045A5})
MSI (s) (F8:64) [18:17:09:578]: Executing op: SourceListPublish(,,,,NumberOfDisks=2)
MSI (s) (F8:64) [18:17:09:578]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9\SourceList 3: 2
MSI (s) (F8:64) [18:17:09:593]: Executing op: ProductPublishClient(,,)
MSI (s) (F8:64) [18:17:09:593]: Executing op: SourceListRegisterLastUsed(SourceProduct={37477865-A3F1-4772-AD43-AAFC6BCFF99F},LastUsedSource=c:\5a78a614ae0728d014fcdf\)
MSI (s) (F8:64) [18:17:09:593]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (F8:64) [18:17:09:593]: Specifed source is already in a list.
MSI (s) (F8:64) [18:17:09:593]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (F8:64) [18:17:09:593]: Machine policy value 'DisableBrowse' is 0
MSI (s) (F8:64) [18:17:09:593]: Machine policy value 'AllowLockdownBrowse' is 0
MSI (s) (F8:64) [18:17:09:593]: Adding new sources is allowed.
MSI (s) (F8:64) [18:17:09:593]: Set LastUsedSource to: c:\5a78a614ae0728d014fcdf\.
MSI (s) (F8:64) [18:17:09:593]: Set LastUsedType to: n.
MSI (s) (F8:64) [18:17:09:593]: Set LastUsedIndex to: 1.
MSI (s) (F8:64) [18:17:09:593]: Executing op: End(Checksum=0,ProgressTotalHDWord=0,ProgressTotalLDWord=4481872)
MSI (s) (F8:64) [18:17:09:593]: User policy value 'DisableRollback' is 0
MSI (s) (F8:64) [18:17:09:593]: Machine policy value 'DisableRollback' is 0
MSI (s) (F8:64) [18:17:09:703]: No System Restore sequence number for this installation.
MSI (s) (F8:64) [18:17:09:703]: Unlocking Server
MSI (s) (F8:64) [18:17:09:703]: PROPERTY CHANGE: Deleting UpdateStarted property. Its current value is '1'.
MSI (s) (F8:64) [18:17:09:718]: Skipping action: SxsUninstallCA (condition is false)
MSI (s) (F8:64) [18:17:09:718]: Doing action: RemoveExistingProducts
Action ended 18:17:09: InstallFinalize. Return value 1.
Action start 18:17:09: RemoveExistingProducts.
Action ended 18:17:09: RemoveExistingProducts. Return value 1.
Action ended 18:17:09: INSTALL. Return value 1.
Property(S): ProductName = MSXML 4.0 SP2 (KB927978)
Property(S): ProductCode = {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
Property(S): Manufacturer = Microsoft Corporation
Property(S): ProductVersion = 4.20.9841.0
Property(S): ProductLanguage = 1033
Property(S): BannerBitmap = bannrbmp
Property(S): IAgree = No
Property(S): ProductID = none
Property(S): ARPHELPLINK = http://support.microsoft.com/kb/927978
Property(S): ButtonText_Back = < &Back
Property(S): ButtonText_Browse = Br&owse
Property(S): ButtonText_Cancel = Cancel
Property(S): ButtonText_Exit = &Exit
Property(S): ButtonText_Finish = &Finish
Property(S): ButtonText_Ignore = &Ignore
Property(S): ButtonText_Install = &Install
Property(S): ButtonText_InstallNow = &Install Now
Property(S): ButtonText_Next = &Next >
Property(S): ButtonText_No = &No
Property(S): ButtonText_OK = OK
Property(S): ButtonText_Remove = &Remove
Property(S): ButtonText_Reset = &Reset
Property(S): ButtonText_Resume = &Resume
Property(S): ButtonText_Retry = &Retry
Property(S): ButtonText_Return = &Return
Property(S): ButtonText_Yes = &Yes
Property(S): CompleteSetupIcon = completi
Property(S): CustomSetupIcon = custicon
Property(S): DialogBitmap = dlgbmp
Property(S): DlgTitleFont = {&DlgFontBold8}
Property(S): ExclamationIcon = exclamic
Property(S): InfoIcon = info
Property(S): InstallerIcon = insticon
Property(S): INSTALLLEVEL = 3
Property(S): InstallModeTxt_1 = Custom
Property(S): InstallModeVal = InstallModeTxt_1
Property(S): InstallModeTxt_2 = Complete
Property(S): InstallModeTxt_3 = Server Image
Property(S): InstallModeTxt_4 = Change
Property(S): InstallModeTxt_5 = Repair
Property(S): InstallModeTxt_6 = Remove
Property(S): PIDTemplate = 12345<###-%%%%%%%>@@@@@
Property(S): Progress1Txt_1 = Installing
Property(S): Progress1 = Progress1Txt_1
Property(S): Progress2Txt_1 = installs
Property(S): Progress2 = Progress2Txt_1
Property(S): Progress1Txt_2 = Changing
Property(S): Progress2Txt_2 = changes
Property(S): Progress1Txt_3 = Repairing
Property(S): Progress2Txt_3 = repairs
Property(S): Progress1Txt_4 = Removing
Property(S): Progress2Txt_4 = removes
Property(S): PROMPTROLLBACKCOST = P
Property(S): RemoveIcon = removico
Property(S): RepairIcon = repairic
Property(S): Setup = Setup
Property(S): Wizard = Setup Wizard
Property(S): DefaultUIFont = DlgFont8
Property(S): ErrorDialog = ErrorDlg
Property(S): TARGETDIR = c:\
Property(S): USERNAME = Nancy
Property(S): APPS_TEST = 1
Property(S): VersionNT = 501
Property(S): SecureCustomProperties = MSXML4SP2
Property(S): UpgradeCode = {7CE723E3-E56B-432C-9F24-78C0606045A5}
Property(S): ALLUSERS = 1
Property(S): WINHTTP_51 = WinHttpRequest Component version 5.1
Property(S): MSXML = c:\Program Files\MSXML 4.0\
Property(S): SourceDir = c:\5a78a614ae0728d014fcdf\
Property(S): DesktopFolder = c:\Documents and Settings\All Users\Desktop\
Property(S): ProgramFilesFolder = c:\Program Files\
Property(S): ProductState = -1
Property(S): PackageCode = {2B27DCD9-53FA-4885-B6CD-698623819F4C}
Property(S): SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 = c:\WINDOWS\system32\
Property(S): SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 = c:\WINDOWS\system32\
Property(S): SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB = c:\WINDOWS\system32\
Property(S): WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\
Property(S): payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\
Property(S): payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
Property(S): WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Manifests\
Property(S): WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\
Property(S): SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\system32\
Property(S): WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\
Property(S): policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\
Property(S): policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
Property(S): WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\
Property(S): payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\
Property(S): payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
Property(S): WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Manifests\
Property(S): WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\
Property(S): SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\system32\
Property(S): WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\
Property(S): policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\
Property(S): policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
Property(S): WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\
Property(S): payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa692
0e9f98fc\
Property(S): WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\
Property(S): policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\
Property(S): WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\
Property(S): SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\system32\
Property(S): WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Manifests\
Property(S): payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
Property(S): policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
Property(S): DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Documents and Settings\All Users\Desktop\
Property(S): ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Documents and Settings\All Users\Start Menu\Programs\
Property(S): MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\
Property(S): DOC.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Program Files\MSXML 4.0\doc\
Property(S): LIB.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Program Files\MSXML 4.0\lib\
Property(S): INC.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Program Files\MSXML 4.0\inc\
Property(S): CommonFilesFolder = c:\Program Files\Common Files\
Property(S): MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 = c:\Program Files\Common Files\Microsoft Shared\
Property(S): MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 = c:\Program Files\Common Files\Microsoft Shared\MSDN\
Property(S): Date = 11/17/2006
Property(S): PackagecodeChanging = 1
Property(S): REBOOT = ReallySuppress
Property(S): CURRENTDIRECTORY = c:\5a78a614ae0728d014fcdf
Property(S): CLIENTUILEVEL = 3
Property(S): CLIENTPROCESSID = 3780
Property(S): VersionDatabase = 200
Property(S): VersionMsi = 3.01
Property(S): WindowsBuild = 2600
Property(S): ServicePackLevel = 2
Property(S): ServicePackLevelMinor = 0
Property(S): MsiNTProductType = 1
Property(S): MsiNTSuitePersonal = 1
Property(S): WindowsFolder = c:\WINDOWS\
Property(S): WindowsVolume = c:\
Property(S): SystemFolder = C:\WINDOWS\system32\
Property(S): System16Folder = C:\WINDOWS\system\
Property(S): RemoteAdminTS = 1
Property(S): TempFolder = C:\WINDOWS\TEMP\
Property(S): AppDataFolder = C:\WINDOWS\system32\config\systemprofile\Application Data\
Property(S): FavoritesFolder = C:\WINDOWS\system32\config\systemprofile\Favorites\
Property(S): NetHoodFolder = C:\WINDOWS\system32\config\systemprofile\NetHood\
Property(S): PersonalFolder = C:\WINDOWS\system32\config\systemprofile\My Documents\
Property(S): PrintHoodFolder = C:\WINDOWS\system32\config\systemprofile\PrintHood\
Property(S): RecentFolder = C:\WINDOWS\system32\config\systemprofile\Recent\
Property(S): SendToFolder = C:\WINDOWS\system32\config\systemprofile\SendTo\
Property(S): TemplateFolder = C:\Documents and Settings\All Users\Templates\
Property(S): CommonAppDataFolder = C:\Documents and Settings\All Users\Application Data\
Property(S): LocalAppDataFolder = C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\
Property(S): MyPicturesFolder = C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures\
Property(S): AdminToolsFolder = C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\
Property(S): StartupFolder = C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Property(S): ProgramMenuFolder = C:\Documents and Settings\All Users\Start Menu\Programs\
Property(S): StartMenuFolder = C:\Documents and Settings\All Users\Start Menu\
Property(S): FontsFolder = C:\WINDOWS\Fonts\
Property(S): GPTSupport = 1
Property(S): OLEAdvtSupport = 1
Property(S): ShellAdvtSupport = 1
Property(S): Intel = 15
Property(S): PhysicalMemory = 383
Property(S): VirtualMemory = 592
Property(S): AdminUser = 1
Property(S): LogonUser = SYSTEM
Property(S): UserSID = S-1-5-18
Property(S): UserLanguageID = 1033
Property(S): ComputerName = NOTEBOOK
Property(S): SystemLanguageID = 1033
Property(S): ScreenX = 1280
Property(S): ScreenY = 768
Property(S): CaptionHeight = 26
Property(S): BorderTop = 1
Property(S): BorderSide = 1
Property(S): TextHeight = 16
Property(S): ColorBits = 32
Property(S): TTCSupport = 1
Property(S): Time = 18:17:09
Property(S): MsiNetAssemblySupport = 1.1.4322.2032
Property(S): MsiWin32AssemblySupport = 5.1.2600.2180
Property(S): RedirectedDllSupport = 2
Property(S): Privileged = 1
Property(S): DATABASE = c:\WINDOWS\Installer\9dff401.msi
Property(S): OriginalDatabase = c:\5a78a614ae0728d014fcdf\msxml.msi
Property(S): UILevel = 2
Property(S): ACTION = INSTALL
Property(S): ROOTDRIVE = c:\
Property(S): CostingComplete = 1
Property(S): OutOfDiskSpace = 0
Property(S): OutOfNoRbDiskSpace = 0
Property(S): PrimaryVolumeSpaceAvailable = 0
Property(S): PrimaryVolumeSpaceRequired = 0
Property(S): PrimaryVolumeSpaceRemaining = 0
Property(S): SOURCEDIR = c:\5a78a614ae0728d014fcdf\
Property(S): SourcedirProduct = {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
Property(S): ProductToBeRegistered = 1
MSI (s) (F8:64) [18:17:09:781]: Note: 1: 1707
MSI (s) (F8:64) [18:17:09:781]: Product: MSXML 4.0 SP2 (KB927978) – Installation completed successfully.

MSI (s) (F8:64) [18:17:09:812]: Cleaning up uninstalled install packages, if any exist
MSI (s) (F8:64) [18:17:09:812]: MainEngineThread is returning 0
MSI (s) (F8:C4) [18:17:09:953]: Destroying RemoteAPI object.
MSI (s) (F8:C4) [18:17:09:953]: Custom Action Manager thread ending.
=== Logging stopped: 11/17/2006 18:17:09 ===
MSI © (C4:5C) [18:17:09:953]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1
MSI © (C4:5C) [18:17:09:953]: MainEngineThread is returning 0
=== Verbose logging stopped: 11/17/2006 18:17:09 ===
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi Catbyte & THANK YOU for your help…I am losing my mind over this virus!. I downloaded & ran the DDS program & saved the text files. That was pretty much the extent of my success. The redirecting blocked me from downloading a zip utility so I could not zip the ATTACH file. I plan to attach it as is. I hope it is not a problem. I downloaded, extracted & ran the GMER program as instructed. It took about 2 hours then just quit running. It gave me no prompt to save a file. I ran it again with the same results. It is 2 A.M. & I have to keep telling myself "There's no crying over computer problems!" I searched my C drive for any GMER files & found only the application files. Below is my DDS report: DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 20:06:14.46 on Tue 08/04/2009 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.382.100 [GMT -5:00] AV: Anti-Virus - SBC Yahoo! Online Protection *On-access scanning enabled* (Outdated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Yahoo!\Antivirus\ISafe.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe C:\Program Files\Yahoo!\Antivirus\CAVTray.exe C:\Program Files\Yahoo!\Antivirus\CAVRID.exe C:\PROGRA~1\Yahoo!\YOP\yop.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\bcmntray.exe C:\Program Files\BroadJump\Client Foundation\CFD.exe C:\WINDOWS\system32\braviax.exe C:\Program Files\HomeAntivirus2010\HomeAntivirus2010.exe C:\Program Files\Yahoo!\Antivirus\VetMsg.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Logitech\MouseWare\system\em_exec.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe C:\Program Files\LG Electronics\LG PC Sync\LGSyncManager.exe C:\PROGRA~1\Yahoo!\browser\ycommon.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\system32\freecell.exe C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Nancy\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mDefault_Search_URL = hxxp://www.google.com/ie mSearch Page = hxxp://www.google.com mStart Page = hxxp://www.google.com uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=laptop uInternet Settings,ProxyOverride = uInternet Settings,ProxyServer = uSearchURL,(Default) = hxxp://www.google.com/keyword/%s mSearchAssistant = hxxp://www.google.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: PayPal Plug-In: {dc0f2f93-27fa-4f84-acaa-9416f90b9511} - c:\program files\paypal\paypal plug-in\OToolbar.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [braviax] c:\windows\system32\braviax.exe mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_01\bin\jusched.exe" mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe mRun: [CaAvTray] "c:\program files\yahoo!\antivirus\CAVTray.exe" mRun: [CAVRID] "c:\program files\yahoo!\antivirus\CAVRID.exe" mRun: [YOP] c:\progra~1\yahoo!\yop\yop.exe /autostart mRun: [GhostSurfDelSatellite] "c:\program files\ghostsurf 2006 platinum\DeleteSatellite.exe" mRun: [Logitech Utility] Logi_MwX.Exe mRun: [] mRun: [HP Software Update] c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Broadcom Wireless Manager UI] c:\windows\system32\bcmntray mRun: [BJCFD] c:\program files\broadjump\client foundation\CFD.exe mRun: [braviax] c:\windows\system32\braviax.exe mRun: [Home Antivirus 2010] "c:\program files\homeantivirus2010\HomeAntivirus2010.exe" /hide StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\lgsync~1.lnk - c:\program files\lg electronics\lg pc sync\LGSyncManager.exe uPolicies-explorer: ForceClassicControlPanel = 1 (0x1) uPolicies-system: EnableProfileQuota = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\ssv.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL LSP: c:\windows\system32\VetRedir.dll DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {238F6F83-B8B4-11CF-8771-00A024531EE0} - hxxps://www.external.net/webclients/setup.exe DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\Vet-Filt.sys [2005-12-27 21031] R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\Vet-Rec.sys [2005-12-27 15478] R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\VetEFile.sys [2005-12-27 879832] R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\VetFDDNT.sys [2005-12-27 15735] R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2006-7-31 26787] R2 CAISafe;CAISafe;c:\program files\yahoo!\antivirus\iSafe.exe [2005-12-27 259184] R2 VETMSGNT;VET Message Service;c:\program files\yahoo!\antivirus\VetMsg.exe [2005-12-27 201840] R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2005-12-30 200192] R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\VetEBoot.sys [2005-12-27 108360] =============== Created Last 30 ================ 2009-08-04 19:51 –d—– c:\windows\system32\CatRoot 2009-08-01 12:57 –d—– c:\program files\Trend Micro 2009-07-30 21:47 –d—– c:\docume~1\nancy\applic~1\Malwarebytes 2009-07-30 21:47 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-30 21:46 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-30 21:46 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-30 21:46 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-28 17:58 19,179 a——- c:\windows\system32\avefun.scr 2009-07-28 17:58 18,681 a——- c:\windows\system32\evojuzyx.dl 2009-07-28 17:58 17,012 a——- c:\docume~1\nancy\applic~1\wopy.bat 2009-07-28 17:58 16,014 a——- c:\windows\azyjyl._dl 2009-07-28 17:58 14,266 a——- c:\windows\system32\irufa._sy 2009-07-28 17:58 13,743 a——- c:\program files\common files\wohocez.bat 2009-07-28 17:58 10,514 a——- c:\windows\mitef.sys 2009-07-28 17:58 19,348 a——- c:\windows\system32\fati.scr 2009-07-28 17:58 17,539 a——- c:\windows\system32\ihypawoda.scr 2009-07-28 17:58 16,388 a——- c:\docume~1\nancy\applic~1\ecilyta.dat 2009-07-28 17:58 14,366 a——- c:\windows\elon._sy 2009-07-28 17:58 13,394 a——- c:\docume~1\nancy\applic~1\silocaxunu.dll 2009-07-28 17:58 13,061 a——- c:\docume~1\alluse~1\applic~1\foxaj.scr 2009-07-28 17:58 10,630 a——- c:\windows\yroduxiwi.ban 2009-07-27 21:42 –d—– c:\program files\HomeAntivirus2010 2009-07-25 20:25 15,764 a——- c:\docume~1\nancy\applic~1\upyxojakar.sys 2009-07-25 20:25 13,772 a——- c:\windows\ygufifa.ban 2009-07-25 20:25 19,657 a——- c:\docume~1\alluse~1\applic~1\epar.bat 2009-07-25 20:25 13,806 a——- c:\windows\jopum.scr 2009-07-25 20:25 18,404 a——- c:\windows\koqawudo.sys 2009-07-25 20:25 18,160 a——- c:\docume~1\alluse~1\applic~1\vupe.bin 2009-07-25 20:25 18,044 a——- c:\windows\system32\osutyqaj.lib 2009-07-25 20:25 15,626 a——- c:\windows\qiby.exe 2009-07-25 20:25 15,483 a——- c:\windows\rerywamyr.sys 2009-07-25 20:25 14,051 a——- c:\windows\system32\gizocyhov._dl 2009-07-25 20:25 10,061 a——- c:\program files\common files\vumycizyso.dat 2009-07-25 20:19 345,699 a——- c:\windows\system32\_scui.cpl 2009-07-25 20:19 181,488 a——- c:\windows\system32\wisdstr.exe 2009-07-25 16:37 43,008 a——- C:\ynee.exe 2009-07-25 16:37 22,016 a——- C:\dfncp.exe 2009-07-25 16:37 21,504 a——- C:\srgaupnr.exe 2009-07-25 16:37 11,264 a——- C:\alurm.exe 2009-07-25 16:35 11,264 a——- c:\windows\system32\braviax.exe ==================== Find3M ==================== 2009-07-28 17:58 15,110 a——- c:\program files\common files\nazekom.lib 2009-07-25 20:25 13,651 a——- c:\program files\common files\ifavowa.ban 2009-07-25 20:25 17,390 a——- c:\program files\common files\efel._sy 2009-07-19 08:33 3,597,824 a——- c:\windows\system32\dllcache\mshtml.dll 2009-07-19 08:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll 2009-06-29 06:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-06-29 06:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-06-29 03:35 634,632 ——– c:\windows\system32\dllcache\iexplore.exe 2009-06-29 03:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat 2009-06-29 03:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2009-06-16 09:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 09:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-16 09:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll 2009-06-16 09:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll 2009-06-03 14:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-06-03 14:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll 2009-05-07 10:32 345,600 a——- c:\windows\system32\localspl.dll 2009-05-07 10:32 345,600 ——– c:\windows\system32\dllcache\localspl.dll 2009-02-04 18:05 0 a——- c:\program files\temp01 ============= FINISH: 20:07:05.98 ===============

Attachments:

Hi,

One or more of the identified infections is a backdoor trojan/rootkit.

This type of infection allows hackers to remotely control your computer, steal critical system information and download and execute files without your knowledge.
If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Please read this: How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?

NEXT


Please try running GMER in safe mode, try renaming it to REMG.exe first.

If it still will not run, please run this program:

Please download Sysprot Antirootkit from HERE

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select all items.
  • Look near the bottom left, and Check "Hidden Objects Only"
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to.
  • Open the text file and copy/paste the log here.


NEXT


Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–


Note: If ComboFix will not run renamed to Combo-Fix.exe the please rename it to Combofix.com
Hi I attempted to run GMER in safe mode. Access was denied for both running & renaming. I download Combo-fix as instructed but it would not run. It appeared to begin to run. There was a small box with Combofix at the top with a green status bar running below it. It ran for a few seconds & then simply stopped without any prompts. I disabled the antivirus with my AT&T Yahoo security but the Home Antivirus 2010 that snuck in with the virus is still there. It does not even show up in my list of programs to remove in Control Panel. I was able to run Sysprot & the log is below. SysProt AntiRootkit v1.0.1.0 by swatkat ******************************************************************************** ********** ******************************************************************************** ********** No Hidden Processes found ******************************************************************************** ********** ******************************************************************************** ********** Kernel Modules: Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys Service Name: — Module Base: EE851000 Module End: EE869000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS Service Name: — Module Base: F7A82000 Module End: F7A84000 Hidden: Yes Module Name: \systemroot\win32k.sys:1 Service Name: — Module Base: F7834000 Module End: F7839000 Hidden: Yes Module Name: \systemroot\win32k.sys:2 Service Name: — Module Base: EE8D9000 Module End: EE8E8000 Hidden: Yes ******************************************************************************** ********** ******************************************************************************** ********** No SSDT Hooks found ******************************************************************************** ********** ******************************************************************************** ********** No Kernel Hooks found ******************************************************************************** ********** ******************************************************************************** ********** No IRP Hooks found ******************************************************************************** ********** ******************************************************************************** ********** Ports: Local Address: NOTEBOOK.GATEWAY.2WIRE.NET:1121 Remote Address: IW-IN-F137.GOOGLE.COM:HTTP Type: TCP Process: C:\Program Files\Internet Explorer\iexplore.exe State: CLOSE_WAIT Local Address: NOTEBOOK.GATEWAY.2WIRE.NET:1120 Remote Address: IY-IN-F113.GOOGLE.COM:HTTP Type: TCP Process: C:\Program Files\Internet Explorer\iexplore.exe State: CLOSE_WAIT Local Address: NOTEBOOK.GATEWAY.2WIRE.NET:NETBIOS-SSN Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: NOTEBOOK:27015 Remote Address: LOCALHOST:1035 Type: TCP Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe State: ESTABLISHED Local Address: NOTEBOOK:27015 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe State: LISTENING Local Address: NOTEBOOK:1147 Remote Address: LOCALHOST:1025 Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: NOTEBOOK:1146 Remote Address: LOCALHOST:1025 Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: NOTEBOOK:1144 Remote Address: LOCALHOST:1025 Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: NOTEBOOK:1035 Remote Address: LOCALHOST:27015 Type: TCP Process: C:\Program Files\iTunes\iTunesHelper.exe State: ESTABLISHED Local Address: NOTEBOOK:1030 Remote Address: LOCALHOST:1027 Type: TCP Process: C:\Program Files\Yahoo!\Antivirus\CAVTray.exe State: ESTABLISHED Local Address: NOTEBOOK:1029 Remote Address: LOCALHOST:1027 Type: TCP Process: C:\Program Files\Yahoo!\Antivirus\VetMsg.exe State: ESTABLISHED Local Address: NOTEBOOK:1028 Remote Address: LOCALHOST:1025 Type: TCP Process: C:\Program Files\Yahoo!\Antivirus\VetMsg.exe State: ESTABLISHED Local Address: NOTEBOOK:1027 Remote Address: LOCALHOST:1030 Type: TCP Process: C:\Program Files\Yahoo!\Antivirus\iSafe.exe State: ESTABLISHED Local Address: NOTEBOOK:1027 Remote Address: LOCALHOST:1029 Type: TCP Process: C:\Program Files\Yahoo!\Antivirus\iSafe.exe State: ESTABLISHED Local Address: NOTEBOOK:1027 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Yahoo!\Antivirus\iSafe.exe State: LISTENING Local Address: NOTEBOOK:1026 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Yahoo!\Antivirus\iSafe.exe State: LISTENING Local Address: NOTEBOOK:1025 Remote Address: LOCALHOST:1028 Type: TCP Process: C:\Program Files\Yahoo!\Antivirus\iSafe.exe State: ESTABLISHED Local Address: NOTEBOOK:1025 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Yahoo!\Antivirus\iSafe.exe State: LISTENING Local Address: NOTEBOOK:MICROSOFT-DS Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: NOTEBOOK:EPMAP Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\svchost.exe State: LISTENING Local Address: NOTEBOOK.GATEWAY.2WIRE.NET:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: NOTEBOOK.GATEWAY.2WIRE.NET:138 Remote Address: NA Type: UDP Process: System State: NA Local Address: NOTEBOOK.GATEWAY.2WIRE.NET:NETBIOS-NS Remote Address: NA Type: UDP Process: System State: NA Local Address: NOTEBOOK.GATEWAY.2WIRE.NET:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: NOTEBOOK:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: NOTEBOOK:1069 Remote Address: NA Type: UDP Process: C:\Program Files\Internet Explorer\iexplore.exe State: NA Local Address: NOTEBOOK:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: NOTEBOOK:4500 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\lsass.exe State: NA Local Address: NOTEBOOK:500 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\lsass.exe State: NA Local Address: NOTEBOOK:MICROSOFT-DS Remote Address: NA Type: UDP Process: System State: NA ******************************************************************************** ********** ******************************************************************************** ********** Hidden files/folders: Object: C:\System Volume Information\MountPointManagerRemoteDatabase Status: Access denied Object: C:\System Volume Information\tracking.log Status: Access denied Object: C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B} Status: Access denied
Hi,

Delete the copy of ComboFix that you have from your desktop.

Download a fresh copy from one of the links previously provided.

Make sure you rename it to ComboFix.COM before saving it to your desktop.

tap into safe mode then run Combofix.com

Make sure all your security programs are disabled
I deleted combofix, reinstalled it naming it Combofix.com during the download. I disabled my antivirus & deleted malwarebytes. I was able to deltee the Home Antivirus 2010 program. I rebooted in safe mode & tried to run combofix. It had the same results as earlier. I even did it all over again and named it combo-fix.exe with the same results. Am I hopeless?
No, not at all, some infections intentionally disable our tools.

Please do the following:

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
I had no luck with the OTL scan either. It stopped running without opening any windows with text files. I searched the C drive & there were no text files created. All of the scans & other programs create a file in the windows/prefetch directory. It ends with .pf. Is this normal? Should I have run it in safe mode? Your instructions did not specify.
try it in safe mode.

If it will not run, try this program

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two text files will open - log.txt (<info.txt (<
  • Make sure Format->Word Wrap is unchecked
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of log.txt andinfo.txt in your reply, you won't need to produce a new HijackThis log as RSIT produces one for you.
I ran rsit in safe mod & had similar results as before. It ran after the disclaimer screen then just stopped.. It did create an rsit folder in the c drive with the log.txt file in it. I could not find an info.txt file. I noticed the log entry HijackThis download failed. I will go back into safe mode & try to run another hijack log. I will add it to another reply if it is successful. Logfile of random's system information tool 1.06 (written by random/random) Run by [removed] at 2009-08-06 20:20:13 Microsoft Windows XP Home Edition Service Pack 3 System drive C: has 80 GB (84%) free of 95 GB Total RAM: 382 MB (64% free) HijackThis download failed ======Scheduled tasks folder====== C:\WINDOWS\tasks\AppleSoftwareUpdate.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2006-09-29 440384] {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - PayPal Plug-In - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll [2008-09-29 3146240] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-04-11 339968] "SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe [2007-03-14 83608] "SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2005-02-02 102492] "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-02-02 692316] "eabconfg.cpl"=C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe [2004-12-03 290816] "Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2005-02-17 233534] "LSBWatcher"=c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe [2004-10-14 253952] "CaAvTray"=C:\Program Files\Yahoo!\Antivirus\CAVTray.exe [2005-12-27 230512] "CAVRID"=C:\Program Files\Yahoo!\Antivirus\CAVRID.exe [2005-12-27 185456] "YOP"=C:\PROGRA~1\Yahoo!\YOP\yop.exe [2006-07-21 407032] "GhostSurfDelSatellite"=C:\Program Files\GhostSurf 2006 Platinum\DeleteSatellite.exe [] "Logitech Utility"=C:\WINDOWS\Logi_MwX.Exe [2003-11-07 19968] ""= [] "HP Software Update"=C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [2006-12-10 49152] "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2007-11-15 286720] "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2007-11-15 267048] "Broadcom Wireless Manager UI"=C:\WINDOWS\system32\bcmntray [] "BJCFD"=C:\Program Files\BroadJump\Client Foundation\CFD.exe [2002-09-10 368706] "braviax"=C:\WINDOWS\system32\braviax.exe [2009-07-25 11264] "Home Antivirus 2010"=C:\Program Files\HomeAntivirus2010\HomeAntivirus2010.exe /hide [] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360] "braviax"=C:\WINDOWS\system32\braviax.exe [2009-07-25 11264] C:\Documents and Settings\All Users\Start Menu\Programs\Startup HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe LG SyncManager.lnk - C:\Program Files\LG Electronics\LG PC Sync\LGSyncManager.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent] C:\WINDOWS\system32\Ati2evxx.dll [2005-04-11 46080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] C:\WINDOWS\system32\WgaLogon.dll [2007-02-15 236928] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "EnableProfileQuota"=1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 "ForceClassicControlPanel"=1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "HonorAutoRunSetting"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe"="C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Disabled:Earthlink" "C:\WINDOWS\Network Diagnostic\xpnetdiag.exe"="C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000" "C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019" "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Disabled:iTunes" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" ======List of files/folders created in the last 1 months====== 2009-08-06 20:20:13 —-D—- C:\rsit 2009-08-06 12:30:19 —-A—- C:\WINDOWS\system32\rymoxija.dll 2009-08-06 12:30:19 —-A—- C:\Documents and Settings\All Users\Application Data\vivapocopa.bat 2009-08-06 12:30:19 —-A—- C:\Documents and Settings\All Users\Application Data\ijuwy.com 2009-08-06 12:30:19 —-A—- C:\Documents and Settings\All Users\Application Data\fohul.exe 2009-08-06 12:16:26 —-D—- C:\32788R22FWJFW 2009-08-06 12:10:49 —-D—- C:\Program Files\HomeAntivirus2010 2009-08-05 22:24:37 —-HD—- C:\WINDOWS\PIF 2009-08-04 19:51:11 —-D—- C:\WINDOWS\system32\CatRoot 2009-08-01 12:57:19 —-D—- C:\Program Files\Trend Micro 2009-07-30 21:47:12 —-D—- C:\Documents and Settings\Nancy\Application Data\Malwarebytes 2009-07-30 21:46:56 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2009-07-28 17:58:33 —-A—- C:\Program Files\Common Files\wohocez.bat 2009-07-28 17:58:33 —-A—- C:\Documents and Settings\Nancy\Application Data\wopy.bat 2009-07-28 17:58:32 —-A—- C:\Documents and Settings\Nancy\Application Data\silocaxunu.dll 2009-07-25 20:25:06 —-A—- C:\Documents and Settings\All Users\Application Data\epar.bat 2009-07-25 20:25:05 —-A—- C:\WINDOWS\qiby.exe 2009-07-25 20:19:12 —-A—- C:\WINDOWS\system32\wisdstr.exe 2009-07-25 16:37:19 —-A—- C:\ynee.exe 2009-07-25 16:37:14 —-A—- C:\srgaupnr.exe 2009-07-25 16:37:14 —-A—- C:\dfncp.exe 2009-07-25 16:37:11 —-A—- C:\alurm.exe 2009-07-25 16:35:18 —-A—- C:\WINDOWS\system32\braviax.exe 2009-07-17 23:55:36 —-HDC—- C:\WINDOWS\$NtUninstallKB973346$ 2009-07-17 23:54:51 —-HDC—- C:\WINDOWS\$NtUninstallKB971633$ 2009-07-17 23:50:04 —-HDC—- C:\WINDOWS\$NtUninstallKB961371$ ======List of files/folders modified in the last 1 months====== 2009-08-06 20:20:17 —-AC—- C:\WINDOWS\ntbtlog.txt 2009-08-06 20:17:23 —-D—- C:\WINDOWS 2009-08-06 20:15:43 —-A—- C:\WINDOWS\SchedLgU.Txt 2009-08-06 20:11:56 —-D—- C:\WINDOWS\Prefetch 2009-08-06 17:14:33 —-A—- C:\WINDOWS\system.ini 2009-08-06 12:30:19 —-D—- C:\WINDOWS\system32 2009-08-06 12:30:19 —-D—- C:\Program Files\Common Files 2009-08-06 12:24:54 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI 2009-08-06 12:23:19 —-D—- C:\WINDOWS\system32\CatRoot2 2009-08-06 12:21:23 —-D—- C:\WINDOWS\Temp 2009-08-06 12:10:49 —-RD—- C:\Program Files 2009-08-06 12:04:20 —-D—- C:\WINDOWS\system32\config 2009-08-05 23:57:28 —-D—- C:\WINDOWS\system32\drivers 2009-08-05 02:49:29 —-HD—- C:\Program Files\InstallShield Installation Information 2009-08-05 02:41:46 —-D—- C:\Program Files\JoWood 2009-08-01 13:03:46 —-D—- C:\
Hi

Please do the following:

Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Services

:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Home Antivirus 2010"=-
"braviax"=-
""=- 
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"braviax"=-

:Files
C:\Program Files\HomeAntivirus2010\HomeAntivirus2010.exe
C:\WINDOWS\system32\rymoxija.dll
C:\Documents and Settings\All Users\Application Data\vivapocopa.bat
C:\Documents and Settings\All Users\Application Data\ijuwy.com
C:\Documents and Settings\All Users\Application Data\fohul.exe
C:\32788R22FWJFW
C:\Program Files\HomeAntivirus2010
C:\Program Files\Common Files\wohocez.bat
C:\Documents and Settings\Nancy\Application Data\wopy.bat
C:\Documents and Settings\Nancy\Application Data\silocaxunu.dll
C:\Documents and Settings\All Users\Application Data\epar.bat
C:\WINDOWS\qiby.exe
C:\WINDOWS\system32\wisdstr.exe
C:\ynee.exe
C:\srgaupnr.exe
C:\dfncp.exe
C:\alurm.exe
C:\WINDOWS\system32\braviax.exe

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Finally…a program that actually ran on the first try! I hope this means I am on my way to viruslessness. Is that a word? ————————————– All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Home Antivirus 2010 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\braviax deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\braviax deleted successfully. ========== FILES ========== File/Folder C:\Program Files\HomeAntivirus2010\HomeAntivirus2010.exe not found. LoadLibrary failed for C:\WINDOWS\system32\rymoxija.dll C:\WINDOWS\system32\rymoxija.dll NOT unregistered. C:\WINDOWS\system32\rymoxija.dll moved successfully. C:\Documents and Settings\All Users\Application Data\vivapocopa.bat moved successfully. C:\Documents and Settings\All Users\Application Data\ijuwy.com moved successfully. C:\Documents and Settings\All Users\Application Data\fohul.exe moved successfully. C:\32788R22FWJFW\License moved successfully. C:\32788R22FWJFW moved successfully. C:\Program Files\HomeAntivirus2010 moved successfully. C:\Program Files\Common Files\wohocez.bat moved successfully. C:\Documents and Settings\Nancy\Application Data\wopy.bat moved successfully. LoadLibrary failed for C:\Documents and Settings\Nancy\Application Data\silocaxunu.dll C:\Documents and Settings\Nancy\Application Data\silocaxunu.dll NOT unregistered. C:\Documents and Settings\Nancy\Application Data\silocaxunu.dll moved successfully. C:\Documents and Settings\All Users\Application Data\epar.bat moved successfully. C:\WINDOWS\qiby.exe moved successfully. C:\WINDOWS\system32\wisdstr.exe moved successfully. C:\ynee.exe moved successfully. C:\srgaupnr.exe moved successfully. C:\dfncp.exe moved successfully. C:\alurm.exe moved successfully. C:\WINDOWS\system32\braviax.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 82239 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32768 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes User: Nancy ->Temp folder emptied: 43258404 bytes ->Temporary Internet Files folder emptied: 312653301 bytes ->Java cache emptied: 11041135 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 953256 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 2577 bytes Windows Temp folder emptied: 22171456 bytes RecycleBin emptied: 327157047 bytes Total Files Cleaned = 684.17 mb OTM by OldTimer - Version 3.0.0.6 log created on 08072009_223337
Can you see if Combo Fix will run now.

Delete the copy of ComboFix from your desktop then do the following:

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI