This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help clean install

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 11:02:20 AM, on 12/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MSMPSVC.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Documents and Settings\Rhonda\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.windowsonecare.com/install/defa…px?pc=FreeTrial
O4 - HKLM\..\Run: [SMC] C:\SMC\SMC.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/…nSSWebAgent.CAB
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1165117050921
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15027/CTPID.cab
O23 - Service: MSMPSVC - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MSMPSVC.exe" -n 4 (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Sorry running macafee antivirus now. The problems im having are the mouse jumps around alot, pages scroll for no reason, very slow windows startup and slow internet. I used MBSA to check my system and it says the sql driver update isnt installed, didnt get much info about this from microsoft, though I am a newbie.
I also dont have alot of commands under cmd, like sfc /scannow. It starts to open, I have to put in windows cd, and it cant copy alot of the files. I am running windows xp SP2 home edition and it keeps asking for proffesional version. Also I am not connected to a network that I know of, this is a stand alone PC. Also when I log off any changes I have made to anything seem to disappear and it goes back to before I changed it example nwiz I take it out of the start menu under msconfig and it gets greyed out to where I cant take it out. As I said im not on a network and have no need for it. I will repost a new logfile Please I hope you can help and thank you in advance.. sorry so long

Logfile of HijackThis v1.99.1
Scan saved at 8:11:17 AM, on 12/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [System Sentry] C:\PROGRA~1\EASYDE~1\NTSYST~1\Protect.exe protect
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://download.mcafee.com/molbin/Shared/C…22/ComCtl32.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1165117050921
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/dd/instal…edsolutions.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…912/mcfscan.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15027/CTPID.cab
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\RpcSandraSrv.exe
I don't see anything bad in your log.

nwiz is part of your video card driver.

Associated with the newer versions of nVidia graphics cards drivers. Allows you to immensely improve desktop layouts by setting preferences and optimizations. However, this isn't necessary for the operation of your system



We can try this:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download AVG Anti-Spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select ""Quarantine".".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the
    results of the AVG Anti-Spyware report scan along with a new HijackThis log.
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 7:09:03 PM 12/9/2006

+ Scan result:



C:\Documents and Settings\Rhonda\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken.


::Report end

AVG report
ogfile of HijackThis v1.99.1
Scan saved at 7:16:47 PM, on 12/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis(2)\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://download.mcafee.com/molbin/Shared/C…22/ComCtl32.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1165117050921
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15027/CTPID.cab
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\RpcSandraSrv.exe

AVG found one tracker, I am concerned about missing entries in the registry. What would cause them to be missing?..And is there a program to see if I am connected to a network when I know im not? Thanks again for you help

I am concerned about missing entries in the registry. What would cause them to be missing?

What missing entries?

..

And is there a program to see if I am connected to a network when I know im not?

If your using DSL or Cable, you're always connected.
I know this isnt a hijack this log but was hoping you could look into it to see if something is loading to allow remote access. When I go into the registry to try to block remote access I come across missing entries like HKLM/software/microsoft/windows/currentversion/……there is no registered owner. Also in MSconfig services I get an access denied error while attempting to change a service, and I was logged in as administrator. Also I use Macafee and I keep getting events like this: A computer at bas3-london14-1096788177.dsl.bell.ca has attempted to access one of your system ports (TCP port 1433). If you want to allow this traffic, you should either Trust the IP address or open the port in the System Services Tool. TCP port 1433 is commonly used by the "Microsoft-SQL-Server" service or program. This port is used by the popular Microsoft SQL server database server. SQL server has several well known vulnerabilities and worms associated with it. The firewall has blocked access to this port. However, if you are using SQL server and it is not functioning properly, you may need to open this port. Only open this port after making certain you are using the latest service pack, have assigned a strong pass code to the SA account and followed other industry guidelines to secure this server from threats…… Please help [UpdSpAPI Log] OS Version = 5.1.2600 Service Pack 2 Platform ID = 2 (NT) Service Pack = 2.0 Suite = 0x0300 Product Type = 1 Architecture = x86 [2006/12/01 21:20:07 488.5] #-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\dc3b8fb011c281dea1cb7a45f880da78\update\update.exe" with command line: update\update.exe -q -z -er /ParentInfo:200d02c945e9384e941f9323cb99b394 #-336 Copying file "c:\windows\softwaredistribution\download\dc3b8fb011c281dea1cb7a45f880da78\SP2GDR\winsrv.dll" to "C:\WINDOWS\system32\winsrv.dll" via temporary file "C:\WINDOWS\system32\SET7.tmp". #W190 File "C:\WINDOWS\system32\SET7.tmp" marked to be moved to "C:\WINDOWS\system32\winsrv.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\dc3b8fb011c281dea1cb7a45f880da78\SP2GDR\user32.dll" to "C:\WINDOWS\system32\user32.dll" via temporary file "C:\WINDOWS\system32\SET8.tmp". #W190 File "C:\WINDOWS\system32\SET8.tmp" marked to be moved to "C:\WINDOWS\system32\user32.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\dc3b8fb011c281dea1cb7a45f880da78\SP2GDR\authz.dll" to "C:\WINDOWS\system32\authz.dll" via temporary file "C:\WINDOWS\system32\SET9.tmp". #W190 File "C:\WINDOWS\system32\SET9.tmp" marked to be moved to "C:\WINDOWS\system32\authz.dll" on next reboot. [2006/12/01 21:20:19 2016.7] #-336 Copying file "c:\windows\softwaredistribution\download\b29e2a9f14df0d88f5323f96793e432b\SP2GDR\rasadhlp.dll" to "C:\WINDOWS\system32\rasadhlp.dll" via temporary file "C:\WINDOWS\system32\SET23.tmp". #W190 File "C:\WINDOWS\system32\SET23.tmp" marked to be moved to "C:\WINDOWS\system32\rasadhlp.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\b29e2a9f14df0d88f5323f96793e432b\SP2GDR\dnsapi.dll" to "C:\WINDOWS\system32\dnsapi.dll" via temporary file "C:\WINDOWS\system32\SET24.tmp". #W190 File "C:\WINDOWS\system32\SET24.tmp" marked to be moved to "C:\WINDOWS\system32\dnsapi.dll" on next reboot. [2006/12/01 21:20:26 1944.5] #-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\7fc28d97b1595fa7b9dce8dd43cee6b0\update\update.exe" with command line: update\update.exe -q -z -er /ParentInfo:c0bd180572fb1a4a89bc32168e20c6e0 #-336 Copying file "c:\windows\softwaredistribution\download\7fc28d97b1595fa7b9dce8dd43cee6b0\SP2GDR\rpcss.dll" to "C:\WINDOWS\system32\rpcss.dll" via temporary file "C:\WINDOWS\system32\SET32.tmp". #W190 File "C:\WINDOWS\system32\SET32.tmp" marked to be moved to "C:\WINDOWS\system32\rpcss.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\7fc28d97b1595fa7b9dce8dd43cee6b0\SP2GDR\olecli32.dll" to "C:\WINDOWS\system32\olecli32.dll" via temporary file "C:\WINDOWS\system32\SET33.tmp". #W190 File "C:\WINDOWS\system32\SET33.tmp" marked to be moved to "C:\WINDOWS\system32\olecli32.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\7fc28d97b1595fa7b9dce8dd43cee6b0\SP2GDR\ole32.dll" to "C:\WINDOWS\system32\ole32.dll" via temporary file "C:\WINDOWS\system32\SET34.tmp". #W190 File "C:\WINDOWS\system32\SET34.tmp" marked to be moved to "C:\WINDOWS\system32\ole32.dll" on next reboot. [2006/12/01 21:20:36 364.7] #-336 Copying file "c:\windows\softwaredistribution\download\82a44777d56c8f1e0182cf5a94f8b14a\SP2GDR\wininet.dll" to "C:\WINDOWS\system32\wininet.dll" via temporary file "C:\WINDOWS\system32\SET4B.tmp". #W190 File "C:\WINDOWS\system32\SET4B.tmp" marked to be moved to "C:\WINDOWS\system32\wininet.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\82a44777d56c8f1e0182cf5a94f8b14a\SP2GDR\urlmon.dll" to "C:\WINDOWS\system32\urlmon.dll" via temporary file "C:\WINDOWS\system32\SET4C.tmp". #W190 File "C:\WINDOWS\system32\SET4C.tmp" marked to be moved to "C:\WINDOWS\system32\urlmon.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\82a44777d56c8f1e0182cf5a94f8b14a\SP2GDR\shlwapi.dll" to "C:\WINDOWS\system32\shlwapi.dll" via temporary file "C:\WINDOWS\system32\SET4D.tmp". #W190 File "C:\WINDOWS\system32\SET4D.tmp" marked to be moved to "C:\WINDOWS\system32\shlwapi.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\82a44777d56c8f1e0182cf5a94f8b14a\SP2GDR\shdocvw.dll" to "C:\WINDOWS\system32\shdocvw.dll" via temporary file "C:\WINDOWS\system32\SET4E.tmp". #W190 File "C:\WINDOWS\system32\SET4E.tmp" marked to be moved to "C:\WINDOWS\system32\shdocvw.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\82a44777d56c8f1e0182cf5a94f8b14a\SP2GDR\mshtml.dll" to "C:\WINDOWS\system32\mshtml.dll" via temporary file "C:\WINDOWS\system32\SET53.tmp". #W190 File "C:\WINDOWS\system32\SET53.tmp" marked to be moved to "C:\WINDOWS\system32\mshtml.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\82a44777d56c8f1e0182cf5a94f8b14a\SP2GDR\browseui.dll" to "C:\WINDOWS\system32\browseui.dll" via temporary file "C:\WINDOWS\system32\SET5B.tmp". #W190 File "C:\WINDOWS\system32\SET5B.tmp" marked to be moved to "C:\WINDOWS\system32\browseui.dll" on next reboot. [2006/12/01 21:20:50 176.7] #-336 Copying file "c:\windows\softwaredistribution\download\4185df9bd0b35509f908e14df73d4fab\SP2GDR\mtxclu.dll" to "C:\WINDOWS\system32\mtxclu.dll" via temporary file "C:\WINDOWS\system32\SET8D.tmp". #W190 File "C:\WINDOWS\system32\SET8D.tmp" marked to be moved to "C:\WINDOWS\system32\mtxclu.dll" on next reboot. [2006/12/01 21:20:55 1528.5] #-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\843953281f8497f8e20b19c4e3fe3e01\update\update.exe" with command line: update\update.exe -q -z -er /ParentInfo:47eda6f41726034f94f8d86809a8b111 #-336 Copying file "c:\windows\softwaredistribution\download\843953281f8497f8e20b19c4e3fe3e01\SP2GDR\umpnpmgr.dll" to "C:\WINDOWS\system32\umpnpmgr.dll" via temporary file "C:\WINDOWS\system32\SET9E.tmp". #W190 File "C:\WINDOWS\system32\SET9E.tmp" marked to be moved to "C:\WINDOWS\system32\umpnpmgr.dll" on next reboot. [2006/12/01 21:20:59 1204.7] #-336 Copying file "c:\windows\softwaredistribution\download\cb2769f3b1daf367a31ed046299a3790\SP2GDR\shell32.dll" to "C:\WINDOWS\system32\shell32.dll" via temporary file "C:\WINDOWS\system32\SETA2.tmp". #W190 File "C:\WINDOWS\system32\SETA2.tmp" marked to be moved to "C:\WINDOWS\system32\shell32.dll" on next reboot. [2006/12/01 21:21:15 1544.7] #-336 Copying file "c:\windows\softwaredistribution\download\7e9c3219e54b43a6d50fc3202fbc3a2b\SP2GDR\gdi32.dll" to "C:\WINDOWS\system32\gdi32.dll" via temporary file "C:\WINDOWS\system32\SETB6.tmp". #W190 File "C:\WINDOWS\system32\SETB6.tmp" marked to be moved to "C:\WINDOWS\system32\gdi32.dll" on next reboot. [2006/12/01 21:21:18 184.7] #-336 Copying file "c:\windows\softwaredistribution\download\b15b843ee2a6cbca76875f1244f36866\SP2GDR\agentdpv.dll" to "C:\WINDOWS\msagent\agentdpv.dll" via temporary file "C:\WINDOWS\msagent\SETBB.tmp". #W190 File "C:\WINDOWS\msagent\SETBB.tmp" marked to be moved to "C:\WINDOWS\msagent\agentdpv.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\b15b843ee2a6cbca76875f1244f36866\SP2GDR\xpsp3res.dll" to "C:\WINDOWS\system32\xpsp3res.dll" via temporary file "C:\WINDOWS\system32\SETBD.tmp". #W190 File "C:\WINDOWS\system32\SETBD.tmp" marked to be moved to "C:\WINDOWS\system32\xpsp3res.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\b15b843ee2a6cbca76875f1244f36866\SP2GDR\agentdpv.dll" to "C:\WINDOWS\system32\DllCache\agentdpv.dll" via temporary file "C:\WINDOWS\system32\DllCache\SETBF.tmp". #W190 File "C:\WINDOWS\system32\DllCache\SETBF.tmp" marked to be moved to "C:\WINDOWS\system32\DllCache\agentdpv.dll" on next reboot. [2006/12/01 21:21:26 1240.5] #-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\0ad26524c298df9a41026d3b49a38936\update\update.exe" with command line: update\update.exe -q -z -er /ParentInfo:764a1a0d130090438e41dda170c7b441 #-336 Copying file "c:\windows\softwaredistribution\download\0ad26524c298df9a41026d3b49a38936\SP2GDR\winsrv.dll" to "C:\WINDOWS\system32\winsrv.dll" via temporary file "C:\WINDOWS\system32\SETCA.tmp". #W190 File "C:\WINDOWS\system32\SETCA.tmp" marked to be moved to "C:\WINDOWS\system32\winsrv.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\0ad26524c298df9a41026d3b49a38936\SP2GDR\linkinfo.dll" to "C:\WINDOWS\system32\linkinfo.dll" via temporary file "C:\WINDOWS\system32\SETCB.tmp". #W190 File "C:\WINDOWS\system32\SETCB.tmp" marked to be moved to "C:\WINDOWS\system32\linkinfo.dll" on next reboot. [2006/12/01 21:21:47 948.6] #-336 Copying file "c:\a424378ce1a7a8c3499af02a1d\SP2GDR\fltmc.exe" to "C:\WINDOWS\system32\fltmc.exe" via temporary file "C:\WINDOWS\system32\SETDA.tmp". #W190 File "C:\WINDOWS\system32\SETDA.tmp" marked to be moved to "C:\WINDOWS\system32\fltmc.exe" on next reboot. #-336 Copying file "c:\a424378ce1a7a8c3499af02a1d\SP2GDR\fltlib.dll" to "C:\WINDOWS\system32\fltlib.dll" via temporary file "C:\WINDOWS\system32\SETDB.tmp". #W190 File "C:\WINDOWS\system32\SETDB.tmp" marked to be moved to "C:\WINDOWS\system32\fltlib.dll" on next reboot. #-336 Copying file "c:\a424378ce1a7a8c3499af02a1d\SP2GDR\fltmgr.sys" to "C:\WINDOWS\system32\DllCache\fltmgr.sys" via temporary file "C:\WINDOWS\system32\DllCache\SETDC.tmp". #W190 File "C:\WINDOWS\system32\DllCache\SETDC.tmp" marked to be moved to "C:\WINDOWS\system32\DllCache\fltmgr.sys" on next reboot. #-336 Copying file "c:\a424378ce1a7a8c3499af02a1d\SP2GDR\fltmc.exe" to "C:\WINDOWS\system32\DllCache\fltmc.exe" via temporary file "C:\WINDOWS\system32\DllCache\SETDD.tmp". #W190 File "C:\WINDOWS\system32\DllCache\SETDD.tmp" marked to be moved to "C:\WINDOWS\system32\DllCache\fltmc.exe" on next reboot. #-336 Copying file "c:\a424378ce1a7a8c3499af02a1d\SP2GDR\fltlib.dll" to "C:\WINDOWS\system32\DllCache\fltlib.dll" via temporary file "C:\WINDOWS\system32\DllCache\SETDE.tmp". #W190 File "C:\WINDOWS\system32\DllCache\SETDE.tmp" marked to be moved to "C:\WINDOWS\system32\DllCache\fltlib.dll" on next reboot. [2006/12/01 21:22:06 1468.5] #-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\f7a4b3723a3aad7955ede9785b307e88\update\update.exe" with command line: update\update.exe -q -z -er /ParentInfo:2b90b43d771ed444a270ad25d3e5a923 #-336 Copying file "c:\windows\softwaredistribution\download\f7a4b3723a3aad7955ede9785b307e88\SP2GDR\netman.dll" to "C:\WINDOWS\system32\netman.dll" via temporary file "C:\WINDOWS\system32\SETF5.tmp". #W190 File "C:\WINDOWS\system32\SETF5.tmp" marked to be moved to "C:\WINDOWS\system32\netman.dll" on next reboot. [2006/12/01 21:22:13 1936.7] #-336 Copying file "c:\windows\softwaredistribution\download\7d6100e060a1f93df520847b1cd9dc71\SP2GDR\iphlpapi.dll" to "C:\WINDOWS\system32\iphlpapi.dll" via temporary file "C:\WINDOWS\system32\SETFE.tmp". #W190 File "C:\WINDOWS\system32\SETFE.tmp" marked to be moved to "C:\WINDOWS\system32\iphlpapi.dll" on next reboot. [2006/12/01 21:22:25 428.5] #-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\dca9d8a1ecbaf4bd0e18d083156f30c9\update\update.exe" with command line: update\update.exe -q -z -er /ParentInfo:99d877f4f5c7dc45a2bb0a9fc2038e11 #-336 Copying file "c:\windows\softwaredistribution\download\dca9d8a1ecbaf4bd0e18d083156f30c9\SP2GDR\rpcss.dll" to "C:\WINDOWS\system32\rpcss.dll" via temporary file "C:\WINDOWS\system32\SET118.tmp". #W190 File "C:\WINDOWS\system32\SET118.tmp" marked to be moved to "C:\WINDOWS\system32\rpcss.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\dca9d8a1ecbaf4bd0e18d083156f30c9\SP2GDR\olecli32.dll" to "C:\WINDOWS\system32\olecli32.dll" via temporary file "C:\WINDOWS\system32\SET119.tmp". #W190 File "C:\WINDOWS\system32\SET119.tmp" marked to be moved to "C:\WINDOWS\system32\olecli32.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\dca9d8a1ecbaf4bd0e18d083156f30c9\SP2GDR\ole32.dll" to "C:\WINDOWS\system32\ole32.dll" via temporary file "C:\WINDOWS\system32\SET11A.tmp". #W190 File "C:\WINDOWS\system32\SET11A.tmp" marked to be moved to "C:\WINDOWS\system32\ole32.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\dca9d8a1ecbaf4bd0e18d083156f30c9\SP2GDR\es.dll" to "C:\WINDOWS\system32\es.dll" via temporary file "C:\WINDOWS\system32\SET11B.tmp". #W190 File "C:\WINDOWS\system32\SET11B.tmp" marked to be moved to "C:\WINDOWS\system32\es.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\dca9d8a1ecbaf4bd0e18d083156f30c9\SP2GDR\comsvcs.dll" to "C:\WINDOWS\system32\comsvcs.dll" via temporary file "C:\WINDOWS\system32\SET11D.tmp". #W190 File "C:\WINDOWS\system32\SET11D.tmp" marked to be moved to "C:\WINDOWS\system32\comsvcs.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\dca9d8a1ecbaf4bd0e18d083156f30c9\SP2GDR\colbact.dll" to "C:\WINDOWS\system32\colbact.dll" via temporary file "C:\WINDOWS\system32\SET11F.tmp". #W190 File "C:\WINDOWS\system32\SET11F.tmp" marked to be moved to "C:\WINDOWS\system32\colbact.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\dca9d8a1ecbaf4bd0e18d083156f30c9\SP2GDR\clbcatq.dll" to "C:\WINDOWS\system32\clbcatq.dll" via temporary file "C:\WINDOWS\system32\SET120.tmp". #W190 File "C:\WINDOWS\system32\SET120.tmp" marked to be moved to "C:\WINDOWS\system32\clbcatq.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\dca9d8a1ecbaf4bd0e18d083156f30c9\SP2GDR\catsrvut.dll" to "C:\WINDOWS\system32\catsrvut.dll" via temporary file "C:\WINDOWS\system32\SET122.tmp". #W190 File "C:\WINDOWS\system32\SET122.tmp" marked to be moved to "C:\WINDOWS\system32\catsrvut.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\dca9d8a1ecbaf4bd0e18d083156f30c9\SP2GDR\catsrv.dll" to "C:\WINDOWS\system32\catsrv.dll" via temporary file "C:\WINDOWS\system32\SET123.tmp". #W190 File "C:\WINDOWS\system32\SET123.tmp" marked to be moved to "C:\WINDOWS\system32\catsrv.dll" on next reboot. [2006/12/01 21:22:54 1776.6] #-336 Copying file "c:\windows\softwaredistribution\download\f14f8865dd08e4d95c38a2ae4cb1096f\SP2GDR\esent.dll" to "C:\WINDOWS\system32\esent.dll" via temporary file "C:\WINDOWS\system32\SET15E.tmp". #W190 File "C:\WINDOWS\system32\SET15E.tmp" marked to be moved to "C:\WINDOWS\system32\esent.dll" on next reboot. [2006/12/01 21:23:06 1576.7] #-336 Copying file "c:\windows\softwaredistribution\download\25d72ef1acc6d7256eb94ad3d6a21e9b\SP2GDR\shell32.dll" to "C:\WINDOWS\system32\shell32.dll" via temporary file "C:\WINDOWS\system32\SET174.tmp". #W190 File "C:\WINDOWS\system32\SET174.tmp" marked to be moved to "C:\WINDOWS\system32\shell32.dll" on next reboot. [2006/12/01 21:23:12 400.7] #-336 Copying file "c:\windows\softwaredistribution\download\6ebd16cfa495accd1804cd7de17cee70\SP2GDR\shdocvw.dll" to "C:\WINDOWS\system32\shdocvw.dll" via temporary file "C:\WINDOWS\system32\SET179.tmp". #W190 File "C:\WINDOWS\system32\SET179.tmp" marked to be moved to "C:\WINDOWS\system32\shdocvw.dll" on next reboot. [2006/12/01 21:23:20 1872.7] #-336 Copying file "c:\windows\softwaredistribution\download\2a8c07aaf8ec0a2dbcb5ab11c4e40d88\SP2GDR\netapi32.dll" to "C:\WINDOWS\system32\netapi32.dll" via temporary file "C:\WINDOWS\system32\SET181.tmp". #W190 File "C:\WINDOWS\system32\SET181.tmp" marked to be moved to "C:\WINDOWS\system32\netapi32.dll" on next reboot. [2006/12/01 21:23:29 1640.5] #-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\update\update.exe" with command line: update\update.exe -q -z -er /ParentInfo:7395d520ee530847a670ff548503c9dc #-336 Copying file "c:\windows\softwaredistribution\download\0fd33c77398fa2b50df56456525ef5c3\SP2GDR\spoolsv.exe" to "C:\WINDOWS\system32\spoolsv.exe" via temporary file "C:\WINDOWS\system32\SET18D.tmp". #W190 File "C:\WINDOWS\system32\SET18D.tmp" marked to be moved to "C:\WINDOWS\system32\spoolsv.exe" on next reboot. [2006/12/01 21:23:32 908.7] #-336 Copying file "c:\windows\softwaredistribution\download\94993dc41f085fded913ffe873108208\SP2GDR\msadco.dll" to "C:\Program Files\Common Files\System\MSADC\msadco.dll" via temporary file "C:\Program Files\Common Files\System\MSADC\SET192.tmp". #W190 File "C:\Program Files\Common Files\System\MSADC\SET192.tmp" marked to be moved to "C:\Program Files\Common Files\System\MSADC\msadco.dll" on next reboot. [2006/12/01 21:23:36 336.7] #-336 Copying file "c:\windows\softwaredistribution\download\dfb1b328cf19d4352aeb86f82e39c295\SP2GDR\rasmans.dll" to "C:\WINDOWS\system32\rasmans.dll" via temporary file "C:\WINDOWS\system32\SET195.tmp". #W190 File "C:\WINDOWS\system32\SET195.tmp" marked to be moved to "C:\WINDOWS\system32\rasmans.dll" on next reboot. [2006/12/01 21:23:44 416.5] #-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\c97484bc3f0a909669b5abb5a1bd9a86\update\update.exe" with command line: update\update.exe -q -z -er /ParentInfo:162c9a88f915af4cbf5cbf180fdffe25 #-336 Copying file "c:\windows\softwaredistribution\download\c97484bc3f0a909669b5abb5a1bd9a86\SP2GDR\tapisrv.dll" to "C:\WINDOWS\system32\tapisrv.dll" via temporary file "C:\WINDOWS\system32\SET1A0.tmp". #W190 File "C:\WINDOWS\system32\SET1A0.tmp" marked to be moved to "C:\WINDOWS\system32\tapisrv.dll" on next reboot. [2006/12/01 21:24:07 1440.7] #-336 Copying file "c:\windows\softwaredistribution\download\ff8044f26e091ff4d09b3860932ee4eb\SP2GDR\webclnt.dll" to "C:\WINDOWS\system32\webclnt.dll" via temporary file "C:\WINDOWS\system32\SET1BF.tmp". #W190 File "C:\WINDOWS\system32\SET1BF.tmp" marked to be moved to "C:\WINDOWS\system32\webclnt.dll" on next reboot. [2006/12/01 21:24:32 1140.7] #-336 Copying file "c:\windows\softwaredistribution\download\fde4a5af73d5aee9b5faba71cbff1d6c\SP2GDR\6to4svc.dll" to "C:\WINDOWS\system32\6to4svc.dll" via temporary file "C:\WINDOWS\system32\SET1DB.tmp". #W190 File "C:\WINDOWS\system32\SET1DB.tmp" marked to be moved to "C:\WINDOWS\system32\6to4svc.dll" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\fde4a5af73d5aee9b5faba71cbff1d6c\SP2GDR\tcpip6.sys" to "C:\WINDOWS\system32\DllCache\tcpip6.sys" via temporary file "C:\WINDOWS\system32\DllCache\SET1DC.tmp". #W190 File "C:\WINDOWS\system32\DllCache\SET1DC.tmp" marked to be moved to "C:\WINDOWS\system32\DllCache\tcpip6.sys" on next reboot. #-336 Copying file "c:\windows\softwaredistribution\download\fde4a5af73d5aee9b5faba71cbff1d6c\SP2GDR\6to4svc.dll" to "C:\WINDOWS\system32\DllCache\6to4svc.dll" via temporary file "C:\WINDOWS\system32\DllCache\SET1DD.tmp". #W190 File "C:\WINDOWS\system32\DllCache\SET1DD.tmp" marked to be moved to "C:\WINDOWS\system32\DllCache\6to4svc.dll" on next reboot. [2006/12/01 21:24:36 1944.7] #-336 Copying file "c:\windows\softwaredistribution\download\187d2ab765f3595de795d17271e0496c\SP2GDR\msxml3.dll" to "C:\WINDOWS\system32\msxml3.dll" via temporary file "C:\WINDOWS\system32\SET1E1.tmp". #W190 File "C:\WINDOWS\system32\SET1E1.tmp" marked to be moved to "C:\WINDOWS\system32\msxml3.dll" on next reboot. [2006/12/01 21:24:40 424.5] #-199 Executing "C:\WINDOWS\SoftwareDistribution\Download\660425732726e9b33577f4657b36117d\update\update.exe" with command line: update\update.exe -q -z -er /ParentInfo:c29dcd082853854fb877bfbdb4430deb #-336 Copying file "c:\windows\softwaredistribution\download\660425732726e9b33577f4657b36117d\SP2GDR\kerberos.dll" to "C:\WINDOWS\system32\kerberos.dll" via temporary file "C:\WINDOWS\system32\SET1E5.tmp". #W190 File "C:\WINDOWS\system32\SET1E5.tmp" marked to be moved to "C:\WINDOWS\system32\kerberos.dll" on next reboot.
All I'm seeing are updates and temp files that will be removed on next reboot. If you have questions about your McAfee firewall I'd contact them via their web site.
All I'm seeing are updates and temp files that will be removed on next reboot. Sorry for being a newbie but why would updates and temp files wont to remove themselves on next reboot? Is this some sort of script or something?…sorry again this is all confusing and thank you for your help
They look like windows updates. When updates download they go into a temp area first. After the updates, update, the temp files aren't needed anymore so they get deleted when the reboot happens.
LDTate Thank you for all your help. And I hope for more :)….My computer is acting strange, very slow bootup before the welcome screen I get a box containing a 1 and an ok button have to click ok to get to logon screen. I have internet access but in network connections it is empty..IE is also acting strange, I getting script errors with no numbers just that it is a script error. I tried to reinstall windows but it wont, I never figured out the sfc /scannow, Windows wouldnt copy and now I go to the windows site to validate the product and it says it cant any suggestions please
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI