[Resolved] sinowal and virtumonde
136 min read
S&D; log:
——————–\\ Lop S&D; 4.2.5-0 XP/Vista
Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Mobile Intel® Pentium® 4 CPU 3.06GHz )
BIOS : Phoenix FirstBIOS™ Notebook Pro Version 2.0 for IBM ThinkPad
USER : Paul A. Parone ( Administrator )
BOOT : Normal boot
Antivirus : Webroot AntiVirus with AntiSpyware 6.0.2.39 (Not Activated)
Firewall : Integrity Flex Firewall 6.0.116.000 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:33 Go (Free:18 Go)
D:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( Thu 01/01/2009| 6:48 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX
Deleted! - C:\DOCUME~1\PAULA~1.PAR\Cookies\[removed][2].txt
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
——————–\\ Listing folders in APPLIC~1
[08/09/2004|01:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[12/13/2008|08:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[10/07/2005|03:13] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Sonic
[10/07/2005|03:15] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Symantec
[10/21/2007|10:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[07/28/2007|03:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[03/31/2008|10:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Applications
[12/13/2008|08:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Avg7
[09/30/2007|10:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Avira
[11/01/2007|02:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ COMMON FILES
[12/19/2007|07:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Hewlett-Packard
[01/08/2008|02:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP
[12/19/2007|07:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP Product Assistant
[12/19/2007|07:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HPSSUPPLY
[10/07/2005|03:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ ibm
[11/03/2007|04:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intuit
[12/13/2008|08:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Kaspersky Lab Setup Files
[12/10/2008|07:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[12/17/2008|05:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[01/25/2008|09:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ McAfee
[11/13/2005|04:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[10/29/2005|05:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Motive
[11/12/2008|06:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ NOS
[01/24/2007|01:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ QuickTime
[08/09/2004|01:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[12/28/2008|07:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[12/10/2008|08:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SUPERAntiSpyware.com
[04/16/2008|09:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Symantec
[12/25/2008|10:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[08/23/2008|06:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Trend Micro
[03/20/2008|08:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Trymedia
[12/19/2007|07:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WEBREG
[12/14/2008|03:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Webroot
[05/16/2006|04:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[08/09/2004|01:03] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[12/01/2007|02:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[10/07/2005|03:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Sonic
[10/07/2005|03:15] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Symantec
[04/27/2006|01:59] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Adobe
[04/27/2006|01:59] C:\DOCUME~1\LOCALS~1\APPLIC~1\ AdobeUM
[01/25/2008|10:21] C:\DOCUME~1\LOCALS~1\APPLIC~1\ AVG7
[02/07/2008|11:29] C:\DOCUME~1\LOCALS~1\APPLIC~1\ HPAppData
[06/12/2006|08:44] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Macromedia
[12/13/2008|08:33] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[12/16/2008|04:52] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft
[10/05/2008|04:17] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Adobe
[10/21/2007|10:57] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ AdobeUM
[10/24/2007|03:30] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Apple Computer
[12/13/2008|08:34] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ AVG7
[11/22/2005|09:00] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Help
[01/08/2008|02:56] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ HP
[08/31/2008|12:23] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ HPAppData
[11/09/2005|02:44] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ IBM
[02/02/2008|09:43] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Identities
[11/13/2005|01:46] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Interact Commerce
[04/20/2006|06:07] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ InterVideo
[03/20/2006|07:39] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Lavasoft
[11/01/2005|02:46] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Macromedia
[12/17/2008|05:05] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Malwarebytes
[12/10/2008|02:22] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Microsoft
[01/21/2007|12:31] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Mozilla
[04/20/2008|05:07] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ MSNInstaller
[10/07/2005|03:13] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Sonic
[01/02/2008|06:19] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Sun
[12/10/2008|02:22] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ SUPERAntiSpyware.com
[02/07/2008|11:57] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Symantec
[01/21/2007|12:31] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Thunderbird
[03/07/2008|11:06] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ webex
[12/14/2008|02:51] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ Webroot
[10/06/2006|04:55] C:\DOCUME~1\PAULA~1.PAR\APPLIC~1\ yahoo!
——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks
[12/25/2008 10:21 AM][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[10/07/2005 03:32 PM][–a——] C:\WINDOWS\tasks\BMMTask.job
[01/01/2009 06:30 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 07:00 AM][-r-h-c—] C:\WINDOWS\tasks\desktop.ini
——————–\\ Listing Folders in C:\Program Files
[03/10/2006|01:02] C:\Program Files\ ACT
[11/11/2008|12:15] C:\Program Files\ Adobe
[12/11/2008|09:25] C:\Program Files\ Alwil Software
[10/07/2005|03:07] C:\Program Files\ Analog Devices
[07/28/2007|03:20] C:\Program Files\ Apple Software Update
[12/14/2008|02:51] C:\Program Files\ AskSBar
[12/01/2007|01:53] C:\Program Files\ AT&T; Network Client
[11/16/2006|02:40] C:\Program Files\ AT&T; Network Client Install
[12/04/2005|07:41] C:\Program Files\ Brio
[12/01/2007|10:40] C:\Program Files\ Canon
[10/31/2005|03:15] C:\Program Files\ CheckPoint
[01/01/2009|06:18] C:\Program Files\ Common Files
[08/09/2004|12:51] C:\Program Files\ ComPlus Applications
[10/07/2005|03:08] C:\Program Files\ CONEXANT
[03/31/2008|10:13] C:\Program Files\ DIFX
[10/07/2005|03:08] C:\Program Files\ Digital Line Detect
[04/29/2007|01:00] C:\Program Files\ Grisoft
[12/19/2007|07:04] C:\Program Files\ Hewlett-Packard
[12/19/2007|07:07] C:\Program Files\ HP
[12/04/2005|07:23] C:\Program Files\ IBM
[10/07/2005|03:13] C:\Program Files\ IBM DLA
[10/07/2005|03:12] C:\Program Files\ IBM RecordNow!
[12/01/2007|09:40] C:\Program Files\ InstallShield Installation Information
[12/14/2008|08:54] C:\Program Files\ Internet Explorer
[10/07/2005|03:14] C:\Program Files\ InterVideo
[11/01/2007|02:50] C:\Program Files\ Intuit
[11/28/2005|12:36] C:\Program Files\ Iomega
[12/31/2008|11:39] C:\Program Files\ Java
[12/13/2008|08:42] C:\Program Files\ Kaspersky Lab
[03/10/2006|06:06] C:\Program Files\ Kodak
[05/01/2008|04:09] C:\Program Files\ Lavasoft
[11/04/2006|12:04] C:\Program Files\ Lenovo
[10/31/2005|02:42] C:\Program Files\ lotus
[12/17/2008|05:05] C:\Program Files\ Malwarebytes' Anti-Malware
[08/24/2008|06:24] C:\Program Files\ Messenger
[11/13/2005|04:41] C:\Program Files\ Microsoft ActiveSync
[02/02/2008|08:46] C:\Program Files\ Microsoft CAPICOM 2.1.0.2
[08/09/2004|12:56] C:\Program Files\ microsoft frontpage
[03/31/2008|10:12] C:\Program Files\ Microsoft Office
[11/13/2005|04:39] C:\Program Files\ Microsoft.NET
[10/29/2005|05:38] C:\Program Files\ Motive
[08/23/2008|08:32] C:\Program Files\ Movie Maker
[08/26/2008|02:48] C:\Program Files\ Mozilla Thunderbird
[04/20/2008|05:07] C:\Program Files\ MSN
[08/09/2004|12:51] C:\Program Files\ MSN Gaming Zone
[11/18/2006|08:54] C:\Program Files\ MSXML 4.0
[08/23/2008|08:27] C:\Program Files\ NetMeeting
[10/07/2005|03:08] C:\Program Files\ NetWaiting
[10/31/2005|02:51] C:\Program Files\ nonav
[11/12/2008|06:41] C:\Program Files\ NOS
[08/09/2004|12:51] C:\Program Files\ Online Services
[08/23/2008|08:27] C:\Program Files\ Outlook Express
[10/07/2005|03:29] C:\Program Files\ PC-Doctor for Windows
[09/02/2006|02:48] C:\Program Files\ PCFriendly
[04/10/2007|02:34] C:\Program Files\ Personal Communications
[12/01/2007|11:14] C:\Program Files\ QuickTime
[10/31/2005|02:46] C:\Program Files\ SAV93TMP
[03/31/2008|10:55] C:\Program Files\ Sierra On-Line
[10/07/2005|03:12] C:\Program Files\ Sonic
[12/27/2008|06:48] C:\Program Files\ Spybot - Search & Destroy
[12/10/2008|02:22] C:\Program Files\ SUPERAntiSpyware
[10/07/2005|03:05] C:\Program Files\ ThinkPad
[12/27/2008|05:20] C:\Program Files\ Trend Micro
[08/09/2004|01:03] C:\Program Files\ Uninstall Information
[10/31/2005|01:13] C:\Program Files\ Verizon Online
[03/07/2008|11:06] C:\Program Files\ WebEx
[12/14/2008|02:51] C:\Program Files\ Webroot
[08/23/2008|08:33] C:\Program Files\ Windows Media Player
[08/23/2008|08:27] C:\Program Files\ Windows NT
[02/02/2008|08:34] C:\Program Files\ WindowsUpdate
[08/09/2004|12:56] C:\Program Files\ xerox
[10/06/2006|04:55] C:\Program Files\ Yahoo!
——————–\\ Listing Folders in C:\Program Files\Common Files
[11/09/2005|01:05] C:\Program Files\Common Files\ Adobe
[11/11/2008|12:14] C:\Program Files\Common Files\ Adobe AIR
[11/13/2005|04:40] C:\Program Files\Common Files\ DESIGNER
[12/19/2007|07:04] C:\Program Files\Common Files\ Hewlett-Packard
[12/19/2007|07:05] C:\Program Files\Common Files\ HP
[10/07/2005|03:04] C:\Program Files\Common Files\ InstallShield
[11/01/2007|02:52] C:\Program Files\Common Files\ Intuit
[01/02/2008|06:11] C:\Program Files\Common Files\ Java
[10/31/2005|02:42] C:\Program Files\Common Files\ Lotus
[03/31/2008|10:12] C:\Program Files\Common Files\ Microsoft Shared
[10/29/2005|05:38] C:\Program Files\Common Files\ Motive
[08/09/2004|12:53] C:\Program Files\Common Files\ MSSoap
[01/05/2007|11:02] C:\Program Files\Common Files\ Nullsoft
[08/09/2004|12:46] C:\Program Files\Common Files\ ODBC
[12/01/2007|11:13] C:\Program Files\Common Files\ Services
[10/07/2005|03:13] C:\Program Files\Common Files\ Sonic
[08/09/2004|12:46] C:\Program Files\Common Files\ SpeechEngines
[11/01/2007|03:03] C:\Program Files\Common Files\ supportsoft
[10/07/2005|03:12] C:\Program Files\Common Files\ SureThing Shared
[11/02/2007|12:57] C:\Program Files\Common Files\ SWF Studio
[08/23/2008|08:27] C:\Program Files\Common Files\ System
[10/29/2005|05:37] C:\Program Files\Common Files\ Verizon Online
——————–\\ Process
( 66 Processes )
… OK !
——————–\\ Searching with S_Lop
No Lop folder found !
——————–\\ Searching for Lop Files - Folders
No Lop folder found !
——————–\\ Searching within the Registry
….. OK !
——————–\\ Checking the Hosts file
Hosts file CLEAN
——————–\\ Searching for hidden files with Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-01 06:52:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0
——————–\\ Searching for other infections
No other infections found !
[F:1693][D:118]-> C:\DOCUME~1\PAULA~1.PAR\LOCALS~1\Temp
[F:20][D:0]-> C:\DOCUME~1\PAULA~1.PAR\Cookies
[F:628][D:5]-> C:\DOCUME~1\PAULA~1.PAR\LOCALS~1\TEMPOR~1\content.IE5
[F:2][D:0]-> C:\Recycled
1 - "C:\Lop SD\LopR_1.txt" - Thu 01/01/2009| 6:54 - Option : [2]
——————–\\ Scan completed at 6:54:20
RSIT log and RSIT info immediately below.
Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2009-01-01 07:17:15
Microsoft Windows XP Professional Service Pack 3
System drive C: has 19 GB (55%) free of 34 GB
Total RAM: 1014 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:17:26 AM, on 1/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
c:\sdwork\issimsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AT&TNE;~1\NetCfgSv.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\System32\drivers\trcboot.exe
C:\Program Files\Personal Communications\PCS_AGNT.EXE
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\WINDOWS\WRTService.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\tp4serv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spider.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Documents and Settings\Paul A. Parone\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Paul A. Parone.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [TrackPointSrv] "C:\WINDOWS\system32\tp4serv.exe"
O4 - HKLM\..\Run: [IgfxTray] "C:\WINDOWS\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [TPKMAPHELPER] "C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" -helper
O4 - HKLM\..\Run: [TPHOTKEY] "C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe"
O4 - HKLM\..\Run: [TP4EX] "C:\WINDOWS\system32\tp4ex.exe"
O4 - HKLM\..\Run: [EZEJMNAP] "C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe"
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] "C:\WINDOWS\system32\dla\tfswctrl.exe"
O4 - HKLM\..\Run: [IBMPRC] "C:\IBMTOOLS\UTILS\ibmprc.exe"
O4 - HKLM\..\Run: [QCWLICON] "C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE"
O4 - HKLM\..\Run: [BMMGAG] "C:\WINDOWS\system32\rundll32.exe" C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] "C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE"
O4 - HKLM\..\Run: [BMMMONWND] "C:\WINDOWS\system32\rundll32.exe" C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [Motive SmartBridge] "C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CheckPoint\Integrity Client\iclient.exe"
O4 - HKLM\..\Run: [Iomega Startup Options] "C:\Program Files\Iomega\Common\ImgStart.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] "C:\Program Files\Iomega\DriveIcons\ImgIcon.exe"
O4 - HKLM\..\Run: [ISSI EZUpdate Service] "c:\sdwork\issimsvc.exe"
O4 - HKLM\..\Run: [stgclean] "c:\sdwork\w32main2.exe" /cleanup
O4 - HKLM\..\Run: [QCTray] "C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ibmmessages] "C:\Program Files\IBM\Messages By IBM\ibmmessages.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Iomega Active Disk] "C:\Program Files\Iomega\AutoDisk\AD2KClient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1201959414343
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control) - https://www-1.ibm.com/sametime/stmeetingroo…STJNILoader.cab
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} (LNWebAssist Class) - http://w3.ibm.com/bluepages/scripts/lnwebassist.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://regatta.mcsgroup.com/dwa7W.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mlmeetings.webex.com/client/v_myweb…ent/ieatgpc.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Iomega Activity Disk2 - Iomega Corporation - C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
O23 - Service: ISSI EZUpdate (ISSIMon) - IBM Global Services - c:\sdwork\issimsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Program Files\lotus\notes\ntmulti.exe
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T; - C:\PROGRA~1\AT&TNE;~1\NetCfgSv.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TrcBoot - Unknown owner - C:\WINDOWS\System32\drivers\trcboot.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
O23 - Service: WRT Service (WRTService) - Unknown owner - C:\WINDOWS\WRTService.exe
–
End of file - 11949 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\BMMTask.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
Ask Search Assistant BHO - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL [2008-12-14 66912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D; IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
DriveLetterAccess - C:\WINDOWS\system32\dla\tfswshx.dll [2004-09-02 118842]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-31 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-31 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-31 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TrackPointSrv"=C:\WINDOWS\system32\tp4serv.exe [2003-11-13 94208]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2004-07-30 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2004-07-30 118784]
"TPKMAPHELPER"=C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe [2004-02-04 897024]
"TPHOTKEY"=C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe [2004-08-06 94208]
"TP4EX"=C:\WINDOWS\system32\tp4ex.exe [2002-09-04 53248]
"EZEJMNAP"=C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe [2003-12-25 208896]
"UC_Start"=C:\Program Files\IBM\Updater\\ucstartup.exe [2004-07-14 36864]
"UpdateManager"=C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe [2003-08-19 110592]
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe [2004-09-02 127035]
"IBMPRC"=C:\IBMTOOLS\UTILS\ibmprc.exe [2004-03-19 90112]
"QCWLICON"=C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE [2004-08-18 81920]
"BMMGAG"=C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll [2004-08-25 110592]
"BMMLREF"=C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE [2004-08-25 20480]
"BMMMONWND"=C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll [2004-08-25 395776]
"Motive SmartBridge"=C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe [2002-05-18 327680]
"Zone Labs Client"=C:\Program Files\CheckPoint\Integrity Client\iclient.exe [2005-05-10 931584]
"Iomega Startup Options"=C:\Program Files\Iomega\Common\ImgStart.exe [2001-01-17 45056]
"Iomega Drive Icons"=C:\Program Files\Iomega\DriveIcons\ImgIcon.exe [2001-09-12 61440]
"ISSI EZUpdate Service"=c:\sdwork\issimsvc.exe [2006-12-05 203264]
"stgclean"=c:\sdwork\w32main2.exe [2006-12-13 260608]
"QCTray"=C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe [2004-08-18 708608]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-31 136600]
"MSConfig"=C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE [2008-04-13 169984]
"SpySweeper"=C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 6273400]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ibmmessages"=C:\Program Files\IBM\Messages By IBM\ibmmessages.exe [2004-07-22 442368]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"Iomega Active Disk"=C:\Program Files\Iomega\AutoDisk\AD2KClient.exe [2001-09-13 45056]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
Verizon Online Support Center.lnk - C:\Program Files\Verizon Online\bin\matcli.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2004-07-30 344064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\QConGina]
C:\WINDOWS\system32\QConGina.dll [2004-08-18 258048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
pwdmon
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WebrootSpySweeperService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WRConsumerService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\AT&T; Network Client\NetClient.exe"="C:\Program Files\AT&T; Network Client\NetClient.exe:*:Enabled:Network access client"
"C:\sdwork\w32main2.exe"="C:\sdwork\w32main2.exe:*:Enabled:OSP Windows 32-bit ESD API"
"C:\WINDOWS\system32\ftp.exe"="C:\WINDOWS\system32\ftp.exe:*:Enabled:File Transfer Program"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\IBM\Updater\ucsmb.exe"="C:\Program Files\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector"
"C:\Program Files\IBM\Updater\jre\bin\javaw.exe"="C:\Program Files\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector"
"C:\Program Files\IBM\Updater\jre\bin\java.exe"="C:\Program Files\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector"
"C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe"="C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe:*:Enabled:QuickBooks 2008 Data Manager"
"C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe"="C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007"
"C:\Program Files\NetMeeting\conf.exe"="C:\Program Files\NetMeeting\conf.exe:*:Disabled:Windows® NetMeeting®"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe"="C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Disabled:TrueVector Service"
"C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\English\setup.exe"="C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\English\setup.exe:*:Enabled:Kaspersky Anti-Virus 2009 Setup"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\IBM\Updater\jre\bin\java.exe"="C:\Program Files\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector"
"C:\Program Files\IBM\Updater\jre\bin\javaw.exe"="C:\Program Files\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector"
"C:\Program Files\IBM\Updater\ucsmb.exe"="C:\Program Files\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe"="C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007"
======List of files/folders created in the last 3 months======
2009-01-01 07:17:15 —-D—- C:\rsit
2009-01-01 06:47:56 —-A—- C:\lopR.txt
2009-01-01 06:47:20 —-D—- C:\Lop SD
2008-12-31 11:40:29 —-A—- C:\WINDOWS\system32\javaws.exe
2008-12-31 11:40:29 —-A—- C:\WINDOWS\system32\javaw.exe
2008-12-31 11:40:29 —-A—- C:\WINDOWS\system32\java.exe
2008-12-31 11:40:29 —-A—- C:\WINDOWS\system32\deploytk.dll
2008-12-30 09:00:19 —-SHD—- C:\RECYCLER
2008-12-30 07:44:15 —-A—- C:\ComboFix.txt
2008-12-30 07:19:25 —-D—- C:\32788R22FWJFW
2008-12-29 20:09:34 —-D—- C:\WINDOWS\Internet Logs
2008-12-29 20:03:46 —-A—- C:\WINDOWS\NIRCMD.exe
2008-12-29 19:57:31 —-A—- C:\WINDOWS\zip.exe
2008-12-29 19:57:31 —-A—- C:\WINDOWS\VFIND.exe
2008-12-29 19:57:31 —-A—- C:\WINDOWS\SWXCACLS.exe
2008-12-29 19:57:31 —-A—- C:\WINDOWS\SWSC.exe
2008-12-29 19:57:31 —-A—- C:\WINDOWS\SWREG.exe
2008-12-29 19:57:31 —-A—- C:\WINDOWS\sed.exe
2008-12-29 19:57:31 —-A—- C:\WINDOWS\grep.exe
2008-12-29 19:57:31 —-A—- C:\WINDOWS\fdsv.exe
2008-12-29 19:57:22 —-D—- C:\Qoobox
2008-12-28 14:09:41 —-A—- C:\Boot.bak
2008-12-28 14:09:36 —-RASHD—- C:\cmdcons
2008-12-28 14:07:25 —-D—- C:\WINDOWS\ERDNT
2008-12-28 13:56:39 —-RA—- C:\Program Files\ComboFix.exe
2008-12-26 16:06:05 —-D—- C:\WINDOWS\pss
2008-12-23 17:51:47 —-A—- C:\WINDOWS\ntbtlog.txt
2008-12-17 17:05:41 —-D—- C:\Documents and Settings\Paul A. Parone\Application Data\Malwarebytes
2008-12-17 17:05:29 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-17 17:05:28 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-12-15 16:37:38 —-AD—- C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-14 14:51:47 —-D—- C:\Binaries
2008-12-14 14:51:04 —-A—- C:\WINDOWS\WRSetup.dll
2008-12-14 14:51:03 —-D—- C:\Program Files\Webroot
2008-12-14 14:51:03 —-D—- C:\Documents and Settings\Paul A. Parone\Application Data\Webroot
2008-12-14 14:51:03 —-D—- C:\Documents and Settings\All Users\Application Data\Webroot
2008-12-14 14:51:01 —-D—- C:\Program Files\AskSBar
2008-12-13 20:42:43 —-D—- C:\Program Files\Kaspersky Lab
2008-12-13 19:59:39 —-A—- C:\WINDOWS\sssTbarV2.ini
2008-12-13 18:19:22 —-D—- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-12-13 17:36:10 —-A—- C:\WINDOWS\st_affiliate.ini
2008-12-13 06:07:35 —-HDC—- C:\WINDOWS\$NtUninstallKB955839$
2008-12-13 06:02:48 —-HDC—- C:\WINDOWS\$NtUninstallKB952069_WM9$
2008-12-13 06:01:49 —-HDC—- C:\WINDOWS\$NtUninstallKB954600$
2008-12-13 06:01:33 —-HDC—- C:\WINDOWS\$NtUninstallKB956802$
2008-12-11 09:25:33 —-D—- C:\Program Files\Alwil Software
2008-12-10 14:29:30 —-D—- C:\Program Files\Spybot - Search & Destroy
2008-12-10 14:29:30 —-D—- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-10 08:14:03 —-D—- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-10 08:13:17 —-D—- C:\Program Files\SUPERAntiSpyware
2008-12-10 08:13:17 —-D—- C:\Documents and Settings\Paul A. Parone\Application Data\SUPERAntiSpyware.com
2008-12-07 21:35:36 —-HD—- C:\WINDOWS\PIF
2008-12-07 20:32:20 —-A—- C:\WINDOWS\system32\27187008-.txt
2008-11-12 17:26:10 —-HDC—- C:\WINDOWS\$NtUninstallKB957097$
2008-11-12 17:25:12 —-HDC—- C:\WINDOWS\$NtUninstallKB954459$
2008-11-12 17:24:31 —-HDC—- C:\WINDOWS\$NtUninstallKB955069$
2008-11-12 16:02:20 —-A—- C:\WINDOWS\system32\wrLZMA.dll
2008-11-12 16:02:12 —-A—- C:\WINDOWS\system32\SsiEfr.exe
2008-11-11 12:14:54 —-D—- C:\Program Files\Common Files\Adobe AIR
2008-11-11 12:12:43 —-D—- C:\Documents and Settings\All Users\Application Data\NOS
2008-11-11 12:12:41 —-D—- C:\Program Files\NOS
2008-10-25 18:47:50 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-10-18 22:14:48 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-10-18 22:14:40 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-18 22:14:32 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-10-18 22:12:38 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-10-18 22:12:24 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
======List of files/folders modified in the last 3 months======
2009-01-01 07:16:57 —-D—- C:\WINDOWS\Prefetch
2009-01-01 06:49:29 —-D—- C:\WINDOWS\Temp
2009-01-01 06:43:53 —-AD—- C:\Program Files
2009-01-01 06:43:27 —-AD—- C:\WINDOWS
2009-01-01 06:42:50 —-D—- C:\WINDOWS\system32\CatRoot2
2009-01-01 06:34:11 —-AD—- C:\WINDOWS\system32
2009-01-01 06:30:36 —-D—- C:\sdwork
2009-01-01 06:29:22 —-A—- C:\WINDOWS\SchedLgU.Txt
2009-01-01 06:18:18 —-D—- C:\Program Files\Common Files
2009-01-01 05:25:18 —-RASH—- C:\BOOT.INI
2009-01-01 05:25:18 —-A—- C:\WINDOWS\win.ini
2009-01-01 05:25:18 —-A—- C:\WINDOWS\system.ini
2008-12-31 11:40:43 —-SHD—- C:\WINDOWS\Installer
2008-12-31 11:39:03 —-D—- C:\Program Files\Java
2008-12-30 15:33:09 —-D—- C:\Talbots
2008-12-30 07:44:45 —-D—- C:\WINDOWS\system32\drivers
2008-12-30 07:29:44 —-D—- C:\WINDOWS\system32\config
2008-12-30 07:27:30 —-D—- C:\WINDOWS\AppPatch
2008-12-29 19:44:38 —-SHD—- C:\System Volume Information
2008-12-29 19:44:38 —-D—- C:\WINDOWS\system32\Restore
2008-12-29 15:46:33 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-12-28 14:11:23 —-SD—- C:\WINDOWS\Tasks
2008-12-27 17:20:06 —-D—- C:\Program Files\Trend Micro
2008-12-26 18:23:32 —-D—- C:\IBMSHARE
2008-12-26 16:15:55 —-A—- C:\WINDOWS\DUMP3170.tmp
2008-12-25 10:23:53 —-AC—- C:\WINDOWS\WinInit.ini
2008-12-22 14:59:32 —-D—- C:\TeamIT
2008-12-19 19:20:47 —-HD—- C:\WINDOWS\inf
2008-12-19 19:20:36 —-RSHD—- C:\WINDOWS\system32\dllcache
2008-12-19 19:18:39 —-HD—- C:\WINDOWS\$hf_mig$
2008-12-15 16:39:55 —-AC—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-12-14 14:07:50 —-D—- C:\WINDOWS\Minidump
2008-12-14 08:54:30 —-D—- C:\Program Files\Internet Explorer
2008-12-13 20:35:15 —-D—- C:\WINDOWS\system
2008-12-13 20:34:50 —-D—- C:\Documents and Settings\All Users\Application Data\Avg7
2008-12-13 20:34:41 —-D—- C:\Documents and Settings\Paul A. Parone\Application Data\AVG7
2008-12-13 18:10:55 —-D—- C:\WINDOWS\system32\ZoneLabs
2008-12-13 18:10:04 —-D—- C:\WINDOWS\WinSxS
2008-12-13 17:53:40 —-RSD—- C:\WINDOWS\assembly
2008-12-13 06:07:41 —-A—- C:\WINDOWS\imsins.BAK
2008-12-13 06:05:29 —-D—- C:\WINDOWS\ie7updates
2008-12-13 01:40:02 —-A—- C:\WINDOWS\system32\mshtml.dll
2008-12-12 09:39:18 —-D—- C:\WINDOWS\system32\wbem
2008-12-10 14:22:37 —-SD—- C:\Documents and Settings\Paul A. Parone\Application Data\Microsoft
2008-12-10 07:54:25 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-12-09 18:24:37 —-A—- C:\WINDOWS\system32\MRT.exe
2008-11-21 08:38:54 —-D—- C:\Dad
2008-11-21 07:42:53 —-D—- C:\WINDOWS\Help
2008-11-13 17:04:24 —-A—- C:\WINDOWS\system32\capicom.dll
2008-11-11 12:15:15 —-D—- C:\Program Files\Adobe
2008-11-07 16:45:32 —-A—- C:\WINDOWS\system32\WMVCore.dll
2008-10-23 07:36:14 —-A—- C:\WINDOWS\system32\gdi32.dll
2008-10-23 05:06:59 —-N—- C:\WINDOWS\system32\tzchange.exe
2008-10-16 15:38:40 —-A—- C:\WINDOWS\system32\wininet.dll
2008-10-16 15:38:39 —-A—- C:\WINDOWS\system32\webcheck.dll
2008-10-16 15:38:39 —-A—- C:\WINDOWS\system32\urlmon.dll
2008-10-16 15:38:39 —-A—- C:\WINDOWS\system32\url.dll
2008-10-16 15:38:39 —-A—- C:\WINDOWS\system32\pngfilt.dll
2008-10-16 15:38:39 —-A—- C:\WINDOWS\system32\occache.dll
2008-10-16 15:38:39 —-A—- C:\WINDOWS\system32\mstime.dll
2008-10-16 15:38:38 —-A—- C:\WINDOWS\system32\msrating.dll
2008-10-16 15:38:38 —-A—- C:\WINDOWS\system32\mshtmled.dll
2008-10-16 15:38:37 —-A—- C:\WINDOWS\system32\msfeedsbs.dll
2008-10-16 15:38:37 —-A—- C:\WINDOWS\system32\msfeeds.dll
2008-10-16 15:38:37 —-A—- C:\WINDOWS\system32\jsproxy.dll
2008-10-16 15:38:37 —-A—- C:\WINDOWS\system32\iertutil.dll
2008-10-16 15:38:37 —-A—- C:\WINDOWS\system32\iernonce.dll
2008-10-16 15:38:37 —-A—- C:\WINDOWS\system32\ieframe.dll
2008-10-16 15:38:35 —-A—- C:\WINDOWS\system32\iedkcs32.dll
2008-10-16 15:38:35 —-A—- C:\WINDOWS\system32\ieapfltr.dll
2008-10-16 15:38:35 —-A—- C:\WINDOWS\system32\ieaksie.dll
2008-10-16 15:38:35 —-A—- C:\WINDOWS\system32\ieakeng.dll
2008-10-16 15:38:35 —-A—- C:\WINDOWS\system32\icardie.dll
2008-10-16 15:38:35 —-A—- C:\WINDOWS\system32\extmgr.dll
2008-10-16 15:38:34 —-A—- C:\WINDOWS\system32\dxtrans.dll
2008-10-16 15:38:34 —-A—- C:\WINDOWS\system32\dxtmsft.dll
2008-10-16 15:38:34 —-A—- C:\WINDOWS\system32\advpack.dll
2008-10-16 14:13:40 —-A—- C:\WINDOWS\system32\wuweb.dll
2008-10-16 14:13:40 —-A—- C:\WINDOWS\system32\wuaueng.dll
2008-10-16 14:12:22 —-A—- C:\WINDOWS\system32\wucltui.dll
2008-10-16 14:12:20 —-A—- C:\WINDOWS\system32\wuapi.dll
2008-10-16 14:09:44 —-A—- C:\WINDOWS\system32\wups2.dll
2008-10-16 14:09:44 —-A—- C:\WINDOWS\system32\wuauclt.exe
2008-10-16 14:09:44 —-A—- C:\WINDOWS\system32\cdm.dll
2008-10-16 14:09:40 —-A—- C:\WINDOWS\system32\wucltui.dll.mui
2008-10-16 14:08:58 —-A—- C:\WINDOWS\system32\wups.dll
2008-10-16 14:07:44 —-A—- C:\WINDOWS\system32\wuapi.dll.mui
2008-10-16 14:07:14 —-A—- C:\WINDOWS\system32\wuaueng.dll.mui
2008-10-16 14:06:48 —-A—- C:\WINDOWS\system32\muweb.dll
2008-10-16 14:06:48 —-A—- C:\WINDOWS\system32\mucltui.dll.mui
2008-10-16 14:06:48 —-A—- C:\WINDOWS\system32\mucltui.dll
2008-10-16 08:11:09 —-A—- C:\WINDOWS\system32\ieudinit.exe
2008-10-16 08:11:09 —-A—- C:\WINDOWS\system32\ie4uinit.exe
2008-10-15 11:34:24 —-A—- C:\WINDOWS\system32\netapi32.dll
2008-10-15 02:04:53 —-A—- C:\WINDOWS\system32\ieakui.dll
2008-10-08 05:25:02 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-05 16:17:59 —-D—- C:\Documents and Settings\Paul A. Parone\Application Data\Adobe
2008-10-03 05:02:42 —-A—- C:\WINDOWS\system32\strmdll.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 ANC;ANC; C:\WINDOWS\System32\drivers\ANC.SYS [2004-08-18 11520]
R1 ASMBATT;ASMBATT; C:\WINDOWS\System32\drivers\ASMBATT.SYS [2004-07-16 4992]
R1 IBMTPCHK;IBMTPCHK; C:\WINDOWS\System32\drivers\IBMBLDID.SYS [2004-08-18 2432]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 Smapint;Smapint; C:\WINDOWS\System32\drivers\Smapint.sys [2004-07-29 14848]
R1 sscdbhk5;sscdbhk5; C:\WINDOWS\system32\drivers\sscdbhk5.sys [2004-07-14 5627]
R1 ssrtln;ssrtln; C:\WINDOWS\system32\drivers\ssrtln.sys [2004-07-14 23545]
R1 TDSMAPI;TDSMAPI; C:\WINDOWS\System32\drivers\TDSMAPI.SYS [2004-07-29 9341]
R1 TPHKDRV;TPHKDRV; C:\WINDOWS\system32\drivers\TPHKDRV.sys [2004-06-09 16340]
R1 TPPWR;TPPWR; C:\WINDOWS\System32\drivers\Tppwr.sys [2004-08-25 16384]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2005-05-10 280864]
R2 ATNT40K;ActiveTouch NT Appsharing Driver; C:\WINDOWS\SYSTEM32\DRIVERS\ATNT40K.SYS [2006-01-25 51392]
R2 drvnddm;drvnddm; C:\WINDOWS\system32\drivers\drvnddm.sys [2004-07-14 40448]
R2 EGATHDRV;IBM Access Support; \??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS []
R2 ibmfilter;ibmfilter; \??\C:\WINDOWS\system32\drivers\ibmfilter.sys []
R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.3.1.9; C:\WINDOWS\system32\DRIVERS\mdc8021x.sys [2005-10-07 15781]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-04-09 11043]
R2 NsTrcNT;NsTrcNT; C:\WINDOWS\System32\drivers\nstrcnt.sys [2000-12-13 10816]
R2 pcscoax;3270 Coax Driver; C:\WINDOWS\System32\drivers\pcscoax.sys [2000-12-13 30720]
R2 PMEM;PMEM; \??\C:\WINDOWS\SYSTEM32\Drivers\PMEMNT.SYS []
R2 tfsnboio;tfsnboio; C:\WINDOWS\system32\dla\tfsnboio.sys [2004-09-02 25723]
R2 tfsncofs;tfsncofs; C:\WINDOWS\system32\dla\tfsncofs.sys [2004-09-02 34843]
R2 tfsndrct;tfsndrct; C:\WINDOWS\system32\dla\tfsndrct.sys [2004-09-02 4123]
R2 tfsndres;tfsndres; C:\WINDOWS\system32\dla\tfsndres.sys [2004-09-02 2239]
R2 tfsnifs;tfsnifs; C:\WINDOWS\system32\dla\tfsnifs.sys [2004-09-02 86202]
R2 tfsnopio;tfsnopio; C:\WINDOWS\system32\dla\tfsnopio.sys [2004-09-02 14715]
R2 tfsnpool;tfsnpool; C:\WINDOWS\system32\dla\tfsnpool.sys [2004-09-02 6363]
R2 tfsnudf;tfsnudf; C:\WINDOWS\system32\dla\tfsnudf.sys [2004-09-02 98714]
R2 tfsnudfa;tfsnudfa; C:\WINDOWS\system32\dla\tfsnudfa.sys [2004-09-02 100603]
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R3 ABVPN2K;Net Firewall Miniport Interface; C:\WINDOWS\system32\DRIVERS\abvpn2k.sys [2004-06-03 164224]
R3 AR5211;Dual-band Wi-Fi Wireless Mini PCI Adapter; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2004-07-22 393408]
R3 avpnnic;AGN Virtual Network Adapter; C:\WINDOWS\system32\DRIVERS\avpnnic.sys [2003-04-04 13952]
R3 b57w2k;Broadcom NetXtreme Fast Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2004-06-19 190336]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2004-07-22 1041152]
R3 HSFHWICH;HSFHWICH; C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2004-07-22 197888]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-07-30 724989]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2004-02-26 11344]
R3 KLOGNT;KLOGNT; C:\WINDOWS\System32\drivers\klognt.sys [2000-12-13 22504]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-06-23 266880]
R3 Tp4Track;IBM PS/2 TrackPoint Driver; C:\WINDOWS\system32\DRIVERS\tp4track.sys [2003-11-13 13904]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2004-07-22 676096]
S3 ac97intc;Intel® 82801 Audio Driver Install Service (WDM); C:\WINDOWS\system32\drivers\ac97intc.sys [2001-08-17 96256]
S3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-03-07 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-03-07 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-03-07 21568]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
S3 psadd;IBM PSA Access Driver; \??\C:\WINDOWS\system32\Drivers\psadd.sys []
S3 QCNDISIF;QCNDISIF; C:\WINDOWS\System32\drivers\qcndisif.SYS [2004-08-18 12288]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-13 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 IBM Rapid Restore Ultra Service;IBM Rapid Restore Ultra Service; C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe [2004-03-19 339968]
R2 IBMPMSVC;IBM PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2004-02-26 57344]
R2 Iomega Activity Disk2;Iomega Activity Disk2; C:\PROGRA~1\Iomega\System32\ActivityDisk.exe [2001-09-20 61440]
R2 ISSIMon;ISSI EZUpdate; c:\sdwork\issimsvc.exe [2006-12-05 203264]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-31 152984]
R2 Multi-user Cleanup Service;Multi-user Cleanup Service; C:\Program Files\lotus\notes\ntmulti.exe [2005-08-15 53248]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
R2 NetCfgSvr;Network Configuration Service; C:\PROGRA~1\AT&TNE;~1\NetCfgSv.EXE [2004-03-01 94208]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
R2 QBCFMonitorService;QBCFMonitorService; C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2007-09-05 20480]
R2 QCONSVC;QCONSVC; C:\WINDOWS\System32\QCONSVC.EXE [2004-08-18 73728]
R2 TpKmpSVC;IBM KCU Service; C:\WINDOWS\system32\TpKmpSVC.exe [2003-07-11 32768]
R2 TrcBoot;TrcBoot; C:\WINDOWS\System32\drivers\trcboot.exe [2000-12-13 28672]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine; C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe [2008-11-12 3667312]
R2 WRConsumerService;Webroot Client Service; C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe [2008-11-13 1086840]
R2 WRTService;WRT Service; C:\WINDOWS\WRTService.exe [2006-09-29 77824]
R3 ACS;ACU Configuration Service; C:\WINDOWS\system32\acs.exe [2004-07-16 36864]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2005-05-10 1246968]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE []
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PsaSrv;IBM PSA Access Driver Control; C:\WINDOWS\system32\PsaSrv.exe []
S3 QBFCService;Intuit QuickBooks FCS; C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2007-05-24 61440]
—————–EOF—————–
info.txt logfile of random's system information tool 1.05 2009-01-01 07:17:29
======Uninstall list======
–>C:\PROGRA~1\VERIZO~1\Uninstall.exe Verizon
–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ibm\gsk4\gsk4BUI.isu"
–>C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
–>C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
–>C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
–>C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
–>MsiExec.exe /I{8ED4E82B-8CEA-40DE-826C-37AC7B941F81}
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00BF-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00C6-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00D1-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF03DA-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\SETUP.EXE"
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\SETUP.EXE" -l0x9 ControlPanelAnyText
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\SETUP.EXE"
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\SETUP.EXE"
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\SETUP.EXE" -l0x9 ControlPanel
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
32 Bit HP CIO Components Installer–>MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
Access IBM Message Center–>MsiExec.exe /X{F413B3A4-EE5D-457C-BAE5-6E58D9589ED5}
Access IBM–>MsiExec.exe /X{EC6AF20D-4376-4070-BEE4-D3A0DFF7E140}
Acrobat.com–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Active Disk–>C:\WINDOWS\unvise32.exe C:\Program Files\Iomega\AutoDisk\uninstal.log
Adobe AIR–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player 9 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
Apple Software Update–>MsiExec.exe /I{74EC78BC-B379-4E29-9006-8F161DCAABA6}
AT&T; Network Client–>C:\Program Files\AT&T; Network Client\NetUN.exe
Brio.Quickview–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Brio\Brio.Quickview\Uninst.isu"
Canon Camera Support Core Library–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{26BDE7D8-93F0-4A07-AD47-1707DB417941} /l1033
Canon Camera Window for ZoomBrowser EX–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{B34BE30D-A759-4EC2-B58F-19FE2DEBF651}
Canon MovieEdit Task for ZoomBrowser EX–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{DE286975-ACF1-45B8-9EF7-34E162B2C817}
Canon RAW Image Task for ZoomBrowser EX–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{68E7E8BD-2233-49BE-81D6-1A1FAF1B5196}
Canon RemoteCapture Task for ZoomBrowser EX–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{CF2C1A86-5A98-4862-A3AE-9992E3A6427D}
Canon Utilities PhotoStitch 3.1–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{EF4C7EB0-D71B-43A3-9552-8053DE4B0401}
Canon Utilities ZoomBrowser EX–>MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)–>"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hoyle Casino '98–>C:\WINDOWS\IsUninst.exe -fC:\SIERRA\Casino98\Uninst.isu
HP Customer Participation Program 9.0–>C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Deskjet All-In-One Software 9.0–>C:\Program Files\HP\Digital Imaging\{706BB40A-4102-4c89-8107-DC68C4EBD19B}\setup\hpzscr01.exe -datfile hposcr14.dat
HP Imaging Device Functions 9.0–>C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Essential 2.01–>C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
HP Smart Web Printing–>MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7}
HP Solution Center 9.0–>C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update–>MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
HPSSupply–>MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
Hyperion Intelligence Client–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D44D97D9-919B-4A6D-ABE8-C84B3DD757A9}\pluginsetup.exe" -l0x9 -uninst
IBM 32-bit Runtime Environment for Java 2, v1.4.1–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6C72E14A-C1F3-45E5-8810-83CE3C19ED63} /l1033
IBM Access Connections–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{22B71A00-4DED-11D4-A5E5-0004AC564F43}\SETUP.EXE" -l0x9 anything
IBM DLA–>MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
IBM Integrated 56K Modem–>C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV;_24C6&SUBSYS;_05591014\HXFSETUP.EXE -U -IVEN_8086&DEV;_24C6&SUBSYS;_05591014 -S -ISFG
IBM Personal Communications–>C:\WINDOWS\PCSUNIST.EXE C:\WINDOWS\unisthook.exe C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Personal Communications\DeIsL1.isu" -y
IBM RecordNow!–>MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
IBM Rescue and Recovery with Rapid Restore–>MsiExec.exe /X{11783F13-C3A9-44A8-929B-21A476F65272}
IBM Themes–>MsiExec.exe /I{6CE96A14-61E2-48CC-837E-22710A953ADE}
IBM ThinkPad Battery MaxiMiser and Power Management Features–>C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\Unbmm.isu -c"C:\Program Files\ThinkPad\Utilities\Tpinsbmm.dll"
IBM ThinkPad Configuration–>C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\UNTPUW.ISU -c"C:\Program Files\ThinkPad\Utilities\Tpinswin.dll"
IBM ThinkPad EasyEject Utility –>C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\Unezej.isu -c"C:\Program Files\ThinkPad\Utilities\Tpinsej.dll"
IBM ThinkPad Keyboard Customizer Utility–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2111B23F-7FDA-4A41-8309-E5A1663CA296}\SETUP.EXE" -l0x9 anything
IBM ThinkPad Power Management Driver–>RunDll32.exe tpinspm.dll,Uninstall
IBM ThinkVantage Technologies Welcome Message–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1007F41F-7D69-468E-8017-3849A5A973C2}\SETUP.EXE" -l0x9 anything
IBM TrackPoint Accessibility Features–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA664480-3844-11D5-8C25-444553540000}\SETUP.EXE"
IBM TrackPoint Support–>C:\WINDOWS\system32\tp4unins.exe
IBM Update Connector–>MsiExec.exe /X{8D815BF3-2399-459C-B121-49373FEFB9E8}
IBM Wireless LAN Adapters Software (11a/b, 11b/g, 11a/b/g) –>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}\SETUP.EXE" -l0x9 UNINSTALLFROMSYS
Intel® Extreme Graphics 2 Driver–>RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV;_3582
InterVideo WinDVD–>"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
Iomega App Services–>C:\WINDOWS\unvise32.exe C:\Program Files\Iomega\System32\uninstal.log
IomegaWare–>C:\WINDOWS\unvise32.exe C:\Program Files\Iomega\uninstal.log
J2SE Runtime Environment 5.0 Update 8–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150080}
Java™ 6 Update 11–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Lenovo Battery Program–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B214C3C8-FC16-42EC-B7BB-703A1BB9C790}\Setup.exe" -l0x9
LiveUpdate 3.2 (Symantec Corporation)–>"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Lotus Notes 7.0–>MsiExec.exe /I{628789DC-75F8-4302-A268-27EF628E6906}
Lotus NotesSQL 3.01 driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{113EECD6-9A04-11D4-811D-00805F923B86}\Setup.exe" -uninst
Lotus SmartSuite - English–>MsiExec.exe /I{536D6172-7453-7569-7465-392E38300409}
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Meeting Manager for Internet Explorer–>MsiExec.exe /I{F2AB2488-A0BF-4A9B-98A9-A88CF20FD2FF}
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Live Meeting 2007–>MsiExec.exe /I{7DB92914-0A00-48C6-8DBB-F8E9D02B78B1}
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Visio Professional 2003–>MsiExec.exe /I{90510409-6000-11D3-8CFE-0150048383C9}
Mozilla Thunderbird (1.5.0.12)–>C:\PROGRA~1\MOZILL~1\uninstall\uninstall.exe /ua "1.5.0.12 (en-US)"
MSXML 4.0 SP2 (KB927978)–>MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 and SOAP Toolkit 3.0–>MsiExec.exe /I{32343DB6-9A52-40C9-87E4-5E7C79791C87}
MSXML 4.0 SP2 Parser and SDK–>MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
PC-Doctor for Windows–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\SETUP.EXE"
PCFriendly–>C:\Program Files\PCFriendly\inuninst.exe
QuickBooks Simple Start 2008 (Plus Pack)–>msiexec.exe /I {8ED4E82B-8CEA-40DE-826C-37AC7B941F81} UNIQUE_NAME="atom" QBFULLNAME="QuickBooks Simple Start 2008 (Plus Pack)" ADDREMOVE=1
Sametime Client v3.1–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Lotus\Sametime Client\STCUnins.isu"
Security Update for CAPICOM (KB931906)–>MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)–>MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Step By Step Interactive Training (KB898458)–>"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723)–>"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB928090)–>"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)–>"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)–>"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)–>"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)–>"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)–>"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)–>"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)–>"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)–>"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)–>"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)–>"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB911565)–>"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB917734)–>"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)–>"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)–>"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Sierra Utilities–>C:\Program Files\Sierra On-Line\sutil32.exe uninstall
Sonic Update Manager–>MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
SoundMAX–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\SETUP.exe" -l0x9 -removeonly
Spy Sweeper Core–>MsiExec.exe /I{3F5B6210-0903-4DC6-8034-8F488AA3A782}
Spybot - Search & Destroy–>"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SupportSoft Assisted Service–>MsiExec.exe /I{5A3F6A80-7913-475E-8B96-477A952CFA43}
ThinkPad FullScreen Magnifier–>RunDll32 setupapi.dll,InstallHinfSection DefaultUninstall.NT 132 C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.inf
ThinkPad Software Installer–>_tpiu000.exe /U
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
VC 9.0 Runtime–>MsiExec.exe /I{A040AC77-C1AA-4CC9-8931-9F648AF178F6}
Verizon Online Support Center–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00A1-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
Verizon Online–>C:\WINDOWS\system32\VerizonUninstaller.exe
Wallpapers–>MsiExec.exe /I{F386C340-DF4B-4BBA-9503-420FB7EDB395}
WebEx–>C:\PROGRA~1\WebEx\atcliun.exe
Webroot AntiVirus with AntiSpyware–>"C:\Program Files\Webroot\WebrootSecurity\unins000.exe"
Windows Driver Package - Microsoft Corporation (usbvideo) Image (05/25/2007 1.0.3656.0)–>rundll32.exe C:\PROGRA~1\DIFX\7AA84A78695B31A503D9537A76801D74E0FD14BD\DIFxAppA.dll, DIFxARPUninstallDriverPackage C:\WINDOWS\system32\DRVSTORE\RoundTable_F29D632BDCC1844B9B7688A0A4B4DA9E716B76FF\RoundTable.inf
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Yahoo! Internet Mail–>C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
=====HijackThis Backups=====
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
======Security center information======
AV: Webroot AntiVirus with AntiSpyware (disabled)
FW: Webroot Internet Security Essentials (disabled)
FW: Integrity Flex Firewall (disabled)
System event log
Computer Name: IBM-546DEA067E3
Event Code: 4201
Message: The system detected that network adapter 11b/g…Mini PCI Adapter - Packet Scheduler Miniport was connected to the network,
and has initiated normal operation over the network adapter.
Record Number: 76665
Source Name: Tcpip
Time Written: 20081212143311.000000-300
Event Type: information
User:
Computer Name: IBM-546DEA067E3
Event Code: 7036
Message: The Windows Image Acquisition (WIA) service entered the running state.
Record Number: 76664
Source Name: Service Control Manager
Time Written: 20081212143307.000000-300
Event Type: information
User:
Computer Name: IBM-546DEA067E3
Event Code: 4201
Message: The system detected that network adapter 11b/g…Mini PCI Adapter - Packet Scheduler Miniport was connected to the network,
and has initiated normal operation over the network adapter.
Record Number: 76663
Source Name: Tcpip
Time Written: 20081212143306.000000-300
Event Type: information
User:
Computer Name: IBM-546DEA067E3
Event Code: 7036
Message: The Pml Driver HPZ12 service entered the running state.
Record Number: 76662
Source Name: Service Control Manager
Time Written: 20081212135559.000000-300
Event Type: information
User:
Computer Name: IBM-546DEA067E3
Event Code: 7035
Message: The Pml Driver HPZ12 service was successfully sent a start control.
Record Number: 76661
Source Name: Service Control Manager
Time Written: 20081212135558.000000-300
Event Type: information
User: IBM-546DEA067E3\Paul A. Parone
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\PROGRAM FILES\THINKPAD\UTILITIES;C:\WINDOWS\Downloaded Program Files;%SystemDrive%\IBMTOOLS\Python22;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\IBM\Trace Facility;C:\Program Files\Personal Communications;C:\Program Files\Common Files\Intuit\QBPOSSDKRuntime
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
"PROCESSOR_REVISION"=0401
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.pyo;.pyc;.py;.pyw
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"RRU"=C:\Program Files\IBM\IBM Rapid Restore Ultra\
"PYTHONPATH"=%SystemDrive%\IBMTOOLS\utils\support;%SystemDrive%\IBMTOOLS\utils\logger
"IBMSHARE"=%SystemDrive%\IBMSHARE
"TCL_LIBRARY"=%SystemDrive%\IBMTOOLS\Python22\tcl\tcl8.4
"TK_LIBRARY"=%SystemDrive%\IBMTOOLS\Python22\tcl\tk8.4
"PYTHONCASEOK"=1
"PCOMM_Root"=C:\Program Files\Personal Communications
"tvdebugflags"=0x260
"tvlogsessioncount"=5000
—————–EOF—————–
I think I got something here….
OTMoveIt3 by OldTimer
Please download the OTMoveIt3 by OldTimer.
- Save it to your desktop.
- Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
- Copy everything inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
:Files C:\WINDOWS\system32\wrLZMA.dll C:\WINDOWS\system32\SsiEfr.exe :Reg [-HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}] :Commands [purity] [emptytemp] - Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
- Click the red Moveit! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
- Close OTMoveIt3
===============================================
After that rerun Malwarebytes' Anti-Malware and post both logs. lets see what we have now
I was Recon in the Marine's, so I know a few Seal's as well
Download SDFix and save it to your Desktop.
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
- Instead of Windows loading as normal, the Advanced Options Menu should appear;
- Select the first option, to run Windows in Safe Mode, then press Enter.
- Choose your usual account.
- Open the extracted SDFix folder and double click RunThis.bat to start the script.
- Type Y to begin the cleanup process.
- It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
- Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum). - Finally paste the contents of the Report.txt back on the forum.
===============================================
Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
- Doubleclick the drweb-cureit.exe file and Allow to run the express scan
- This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
- Once the short scan has finished, mark the drives that you want to scan.
- Select all drives. A red dot shows which drives have been chosen.
- Click the green arrow at the right, and the scan will start.
- Click 'Yes to all' if it asks if you want to cure/move the file.
- When the scan has finished, in the menu, click file and choose save report list
- Save the report to your desktop. The report will be called DrWeb.csv
- Close Dr.Web Cureit.
===============================================
needed in your next reply:
SDFix log
DrWeb.csv log
Fresh RSIT log
And let me know how things are running now
I started on your action list last night, and while running SDFix my laptop suddenly shut down. It's happened before, making me wonder if these infections are self-healing and re-wire themselves when they sense a threat.
Upon running it again this morning I have the first of the three reports you want, SDFix report is below.
You said the Dr.Web scan would be fast. It is slow as a dog. I stopped it 2x thinking it was hung and not scanning. I'll post it up when it eventually completes.
BTW, excellent answer, seems you, Navy son and I are all cut from the same cloth.
paultpa
SDFix: Version 1.240
Run by [removed] on Mon 01/05/2009 at 07:41 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-05 07:49:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\AT&T; Network Client\\NetClient.exe"="C:\\Program Files\\AT&T; Network Client\\NetClient.exe:*:Enabled:Network access client"
"C:\\sdwork\\w32main2.exe"="C:\\sdwork\\w32main2.exe:*:Enabled:OSP Windows 32-bit ESD API"
"C:\\WINDOWS\\system32\\ftp.exe"="C:\\WINDOWS\\system32\\ftp.exe:*:Enabled:File Transfer Program"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\IBM\\Updater\\ucsmb.exe"="C:\\Program Files\\IBM\\Updater\\ucsmb.exe:*:Enabled:IBM Update Connector"
"C:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe"="C:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe:*:Enabled:IBM Update Connector"
"C:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe"="C:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe:*:Enabled:IBM Update Connector"
"C:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"="C:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe:*:Enabled:QuickBooks 2008 Data Manager"
"C:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"="C:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007"
"C:\\Program Files\\NetMeeting\\conf.exe"="C:\\Program Files\\NetMeeting\\conf.exe:*:Disabled:Windowsr NetMeetingr"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"="C:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe:*:Disabled:TrueVector Service"
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"="C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe:*:Enabled:Kaspersky Anti-Virus 2009 Setup"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe"="C:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe:*:Enabled:IBM Update Connector"
"C:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe"="C:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe:*:Enabled:IBM Update Connector"
"C:\\Program Files\\IBM\\Updater\\ucsmb.exe"="C:\\Program Files\\IBM\\Updater\\ucsmb.exe:*:Enabled:IBM Update Connector"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"="C:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007"
Remaining Files :
Files with Hidden Attributes :
Fri 28 Oct 2005 0 A..H. — "C:\config.bak"
Mon 6 Mar 2006 206,848 …H. — "C:\MSS\MIA accts\~WRL2984.tmp"
Wed 22 Oct 2008 949,072 A.SHR — "C:\Program Files\Spybot - Search & Destroy\advcheck.dll"
Wed 22 Oct 2008 962,896 A.SHR — "C:\Program Files\Spybot - Search & Destroy\Tools.dll"
Thu 21 Sep 2006 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS076A63CD-0E60-48BC-923F-6AE9B4542F1D.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS085B4A2E-7B1B-4764-BE8A-8A6AFA82C064.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS0D5DCCC7-5EC2-4DAB-9184-8F2529131B59.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS0E226E36-E1CF-46FA-8398-77E4037D67E0.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS0FE833D6-7147-4D3B-897F-7BE35FFC5B67.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS162343D2-6322-417B-86A8-BC4ACA9F1754.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS1A42302E-AFF8-49EF-B9DA-0A5FB869AB15.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS1A2A5DA7-D246-4C71-8B8F-785A372611B8.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS20674D4D-B8FB-4357-9E5E-B19C9363EABA.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS20BA323A-8D2A-4274-AA2C-751A5FD65DFB.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS21648073-DF5E-413A-987A-B575521AF647.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS22162D89-9E55-4260-AA6B-264018CD0881.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS2378A3AB-8988-49E5-9048-3F9B948AC373.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS25FDB643-DC3F-46A8-AC87-A7FBF460F5C5.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS276E4308-D73E-4BC0-97CC-91F1428290E4.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS284A6C3C-13E1-4BA1-B7CA-01516E1260C8.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS2EB40E61-C06C-4F79-BDC8-3AB43B867A04.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS2F4B9B8D-2D93-4B37-A331-2BFF9DB7521E.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS3DC1AA8B-77EC-48D7-BDB1-555CEC403695.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS3D663A59-EFFD-4B67-9ED9-672B14256216.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS4220D939-3AFC-446B-8072-D3C80BBC3B28.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS4379558D-5479-4AB3-B22F-77521CF22E38.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS43B66819-063D-4574-90BB-8551E88B7310.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS43EEEAFF-7F98-4018-BB13-90B011597B5C.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS44A63207-B814-4196-A54A-D59E36310DB9.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS442D1087-B7C3-4078-A774-3A95B7395EC6.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS4762C7B0-B3BF-4D38-9960-BF91319F51BF.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS4BF73AC1-87CD-4047-8A3D-C4C9573C901B.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS4C0B959B-014E-4A97-9E4B-C92CFF681C0F.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS4C10F254-BDE2-431B-BA70-7B9BC604F668.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS538C78ED-4863-45FF-9074-A73262817D92.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS5549F80D-1195-4698-B499-9D808011C662.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS57388FD8-D25E-4A4B-86A9-D513573615AF.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS59DE3232-27DC-4855-85FD-7AC7BF2AD094.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS5E168A6F-DE20-4CD4-9554-81D964E19273.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS5F2E224E-0EA7-4B12-BAEC-690A2BB1AD5D.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS63B7499C-8E5E-4E20-8AA9-D5B57CA49F24.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS6463D9C5-969A-4B86-9BD7-7CF40CA08043.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS68DAC726-8998-4E85-8ECB-16D98E6D3766.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS68BACA7D-548E-4604-A746-EA487B23CD08.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS68D4970D-8D44-40CE-AAC7-BF7B5360A020.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS6AD6CA8D-E88D-4355-B184-263044DA95BA.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS6B230D23-5A48-4FC7-90A6-854CC1D03EFB.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS6B65EBB4-4978-40F8-B469-54EFFE9A0772.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS6D079EF6-D1A0-41DD-BAFC-4344C488A77B.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS6E819741-911C-4778-9CF0-86F992FD3BBC.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS6E2F7C5E-90AC-4BF8-86B2-716A3C7DCD9F.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS6F66081C-FEA2-4825-9189-95705626521D.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS71375796-8D35-42F8-A62B-325F51F41927.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS715A7375-396E-49B8-8B7F-07D1902D6D7A.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS71E26AC9-25AF-466E-8DE0-829FDAA34EBA.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS770C7B41-5AF8-422C-8D22-89722D6C438F.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS8197D47D-25AD-410B-883D-9B01D5ED8577.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS8188115D-C844-40EB-BB1F-E6C20C1F2214.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS836A758D-9F38-46CD-BBA8-3C0C78684719.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS884DC3A3-DB8E-4273-8438-4CCAA725EFB7.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS8A162ECA-CD08-4ECB-A13D-684ED5FA1F37.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS8BB544A0-BE99-4560-B435-E9FCB32F68A1.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS8CDFB3C5-820C-4CFF-A396-3FC2FEAE98C2.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS8F995F4D-C33D-40B6-8970-D20207FE0EB8.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS93CEF95E-77D3-4A16-8071-57E8FDBC43E4.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS9659EA8F-1819-46DA-8C79-8B8AE003D3FE.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS96E51703-4F5B-49D7-812C-0BB824F56164.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS97B3F3F9-18D7-4269-9F1D-2893EE9E4468.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS97F50474-A85F-4B51-A013-5D1BDD3BB98B.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS99E6DBA9-AAF4-4E5D-9E7A-69AEA26ED8F1.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS9D32DF84-0E69-4B43-999C-BCCDD5170EF1.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMS9D2EB777-F00E-4F12-A0C1-5200D31A2E3D.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSA0799D15-1897-422B-A63E-5E3FF7C34B35.tmp"
Mon 5 Jan 2009 65,536 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSA1278170-9F5F-45E5-858B-01AF63D07788.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSA391FC5D-4DF2-470D-ADF0-E34CA2C64474.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSA7DF5BB7-0F6B-495E-8E52-2411DDA2CE05.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSAB5367F0-E284-4470-B75B-5D9CD5C5D74E.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSB0270B07-B7B9-4ABC-AB03-A9C4C815A3FA.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSB2AC688B-24C1-4072-A172-89AF0666FE71.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSB46A4B6E-21B8-430C-9B15-82B958832A8F.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSB9C5F944-96A8-45E2-87FA-E05ACB8D749B.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSC3F7ADDD-D99B-4DA6-BFB3-A2BD5FF21913.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSC5DBD72E-55E1-47E6-9DA0-E0E82E141538.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSC5FD33A2-1135-48E6-B7CE-98C19E87D6D0.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSC936820F-2873-4D1E-B49D-70EFCE6671B3.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSCA078ACF-06E6-4E8B-A4D9-ABA50E4DD277.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSD3D7F330-5437-4613-BA78-E8744F8F122B.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSDA0FF290-C1A3-4A7D-9B32-B02B6DA68099.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSDA77FB65-512F-4A08-921F-5C4CA74148AD.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSDBB73624-BD8A-42AA-AD56-928C512BFC6F.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSDDA06D0F-AA58-4D01-AEB8-112F96092EA0.tmp"
Mon 5 Jan 2009 65,536 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSDF227220-ABE5-438E-A05D-05B799E4A590.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSE1568469-6F17-46C2-A94C-864BC4C73A7C.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSE46587DD-4DBC-4823-A79F-778A4DC108A8.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSE579496C-1F4E-4E1E-A6A1-FCEF3FB5C1CC.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSE60E63C0-F3CF-4635-8BDE-8A832F845465.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSE8975102-E2AD-4DC9-96C3-40AABC031AA0.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSEAF3648E-6E09-4ECA-9A31-94782526316E.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSEBB93216-B7EC-4F3C-AA91-39462D6FEE3C.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSEC98CC9F-DA26-4BDF-858E-A405135EF90E.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSF0BEFE0F-0182-4197-82CC-648370DBDE02.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSF3320AF7-FC9D-442D-9633-4883D997E4F6.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSF7DE4AB9-E64A-4759-A740-72C7171E089F.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSF7A3F57F-74A5-4167-B1D1-91906CA85165.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSF88E12C5-528F-4B93-B3D9-F85416A1EA32.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSFA031EA1-8C6D-48B3-A89D-D900255425A3.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSFD8CE2F6-3E08-4BB0-8313-8B57F9C801F7.tmp"
Mon 5 Jan 2009 0 A..H. — "C:\WINDOWS\Temp\wrstemp\SSMSFE268B50-2803-4A26-9386-725E8BAB2F7D.tmp"
Finished!
DrWeb just finished after a 7 hour run. I "cured" some files, moved others and deleted the incurables. There may be some still lingering that need disposition.
The .csv log is below, note that it was saved in an .xls (excel) file format.
Below that are the two RSIT file logs.
Could this be the end of it?
paultpa
issimsvc.exe;c:\sdwork;Probably DLOADER.Trojan;Incurable.Moved.;
RegUBP2b-Paul A. Parone.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Deleted.;
SDFix.exe\SDFix\apps\Process.exe;C:\Documents and Settings\Paul A. Parone\Desktop\SDFix.exe;Tool.Prockill;;
SDFix.exe;C:\Documents and Settings\Paul A. Parone\Desktop;Archive contains infected objects;Moved.;
RTEditorcode_2[1].js;C:\Documents and Settings\Paul A. Parone\Local Settings\Temporary Internet Files\Content.IE5\041KR1TB;Probably SCRIPT.Virus;;
RTEditorcode_2[2].js;C:\Documents and Settings\Paul A. Parone\Local Settings\Temporary Internet Files\Content.IE5\041KR1TB;Probably SCRIPT.Virus;;
RTEditorcode_2[1].js;C:\Documents and Settings\Paul A. Parone\Local Settings\Temporary Internet Files\Content.IE5\70BHRNXC;Probably SCRIPT.Virus;;
RTEditorcode_2[1].js;C:\Documents and Settings\Paul A. Parone\Local Settings\Temporary Internet Files\Content.IE5\F3RDJPJ6;Probably SCRIPT.Virus;;
RTEditorcode_2[2].js;C:\Documents and Settings\Paul A. Parone\Local Settings\Temporary Internet Files\Content.IE5\F3RDJPJ6;Probably SCRIPT.Virus;;
RTEditorcode_2[1].js;C:\Documents and Settings\Paul A. Parone\Local Settings\Temporary Internet Files\Content.IE5\Q1PZ6WHP;Probably SCRIPT.Virus;;
RTEditorcode_2[2].js;C:\Documents and Settings\Paul A. Parone\Local Settings\Temporary Internet Files\Content.IE5\Q1PZ6WHP;Probably SCRIPT.Virus;;
data002\\issimsvc.exe;C:\IBM\ospw32.exe\data002\\ezuinst.exe\data002;Probably DLOADER.Trojan;;
data002;C:\IBM\ospw32.exe\data002\\ezuinst.exe;Archive contains infected objects;;
\ezuinst.exe;C:\IBM\ospw32.exe\data002\;Archive contains infected objects;;
data002;C:\IBM\ospw32.exe;Archive contains infected objects;;
ospw32.exe;C:\IBM;Archive contains infected objects;Moved.;
actdiag.exe;C:\Program Files\ACT;Probably WIN.SCRIPT.Virus;;
InstallHelper.exe;C:\Program Files\Common Files\Motive;Probably MULDROP.Trojan;;
pskill.exe;C:\Program Files\IBM\checker;Tool.Prockill;;
pslist.exe;C:\Program Files\IBM\checker;Program.PsList.127;;
Process.exe;C:\SDFix\apps;Tool.Prockill;;
checkerv2inst.exe\pskill.exe;C:\Siebel\checkerv2inst.exe;Tool.Prockill;;
checkerv2inst.exe\pslist.exe;C:\Siebel\checkerv2inst.exe;Program.PsList.127;;
checkerv2inst.exe;C:\Siebel;Archive contains infected objects;Moved.;
A0000368.EXE;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP5;Program.PsExec.170;;
A0001399.EXE;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP6;Program.PsExec.170;;
A0001595.reg;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP7;Trojan.StartPage.1505;Deleted.;
A0004881.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8;Tool.Prockill;;
A0006929.reg;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8;Trojan.StartPage.1505;Deleted.;
A0006950.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8;Probably DLOADER.Trojan;;
A0006951.exe\SDFix\apps\Process.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8\A0006951.exe;Tool.Prockill;;
A0006951.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8;Archive contains infected objects;Moved.;
data002\\issimsvc.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8\A0006952.exe\data002\\ezuinst.exe\data002;Probably DLOADER.Trojan;;
data002;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8\A0006952.exe\data002\\ezuinst.exe;Archive contains infected objects;;
\ezuinst.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8\A0006952.exe\data002\;Archive contains infected objects;;
data002;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8\A0006952.exe;Archive contains infected objects;;
A0006952.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8;Archive contains infected objects;Moved.;
A0006954.exe\pskill.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8\A0006954.exe;Tool.Prockill;;
A0006954.exe\pslist.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8\A0006954.exe;Program.PsList.127;;
A0006954.exe;C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP8;Archive contains infected objects;Moved.;
data002\\issimsvc.exe;C:\temp\ospw32.exe\data002\\ezuinst.exe\data002;Probably DLOADER.Trojan;;
data002;C:\temp\ospw32.exe\data002\\ezuinst.exe;Archive contains infected objects;;
\ezuinst.exe;C:\temp\ospw32.exe\data002\;Archive contains infected objects;;
data002;C:\temp\ospw32.exe;Archive contains infected objects;;
ospw32.exe;C:\temp;Archive contains infected objects;Moved.;
checkerv2inst250.exe\pskill.exe;C:\temp\Checker1141842822796\checkerv2inst250.exe;Tool.Prockill;;
checkerv2inst250.exe\pslist.exe;C:\temp\Checker1141842822796\checkerv2inst250.exe;Program.PsList.127;;
checkerv2inst250.exe;C:\temp\Checker1141842822796;Archive contains infected objects;Moved.;
checkerv2inst250.exe\pskill.exe;C:\temp\Checker1141842856781\checkerv2inst250.exe;Tool.Prockill;;
checkerv2inst250.exe\pslist.exe;C:\temp\Checker1141842856781\checkerv2inst250.exe;Program.PsList.127;;
checkerv2inst250.exe;C:\temp\Checker1141842856781;Archive contains infected objects;Moved.;
checkerv2inst250.exe\pskill.exe;C:\temp\Checker1141842880671\checkerv2inst250.exe;Tool.Prockill;;
checkerv2inst250.exe\pslist.exe;C:\temp\Checker1141842880671\checkerv2inst250.exe;Program.PsList.127;;
checkerv2inst250.exe;C:\temp\Checker1141842880671;Archive contains infected objects;Moved.;
checkerv2inst250.exe\pskill.exe;C:\temp\Checker1141842905140\checkerv2inst250.exe;Tool.Prockill;;
checkerv2inst250.exe\pslist.exe;C:\temp\Checker1141842905140\checkerv2inst250.exe;Program.PsList.127;;
checkerv2inst250.exe;C:\temp\Checker1141842905140;Archive contains infected objects;Moved.;
checkerv2inst270.exe\pskill.exe;C:\temp\Checker1161874666453\checkerv2inst270.exe;Tool.Prockill;;
checkerv2inst270.exe\pslist.exe;C:\temp\Checker1161874666453\checkerv2inst270.exe;Program.PsList.127;;
checkerv2inst270.exe;C:\temp\Checker1161874666453;Archive contains infected objects;Moved.;
issimsvc.exe;F:\sdwork;Probably DLOADER.Trojan;;
Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2009-01-05 16:18:27
Microsoft Windows XP Professional Service Pack 3
System drive C: has 19 GB (56%) free of 34 GB
Total RAM: 1014 MB (31% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:18:48 PM, on 1/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AT&TNE;~1\NetCfgSv.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\System32\drivers\trcboot.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Personal Communications\PCS_AGNT.EXE
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\WINDOWS\WRTService.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\tp4serv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\CheckPoint\Integrity Client\iclient.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Documents and Settings\Paul A. Parone\Desktop\drweb-cureit.exe
C:\DOCUME~1\PAULA~1.PAR\LOCALS~1\Temp\RarSFX3\_start.exe
C:\DOCUME~1\PAULA~1.PAR\LOCALS~1\Temp\RarSFX3\setup.exe
C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Documents and Settings\Paul A. Parone\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Paul A. Parone.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [TrackPointSrv] "C:\WINDOWS\system32\tp4serv.exe"
O4 - HKLM\..\Run: [IgfxTray] "C:\WINDOWS\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [TPKMAPHELPER] "C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" -helper
O4 - HKLM\..\Run: [TPHOTKEY] "C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe"
O4 - HKLM\..\Run: [TP4EX] "C:\WINDOWS\system32\tp4ex.exe"
O4 - HKLM\..\Run: [EZEJMNAP] "C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe"
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] "C:\WINDOWS\system32\dla\tfswctrl.exe"
O4 - HKLM\..\Run: [IBMPRC] "C:\IBMTOOLS\UTILS\ibmprc.exe"
O4 - HKLM\..\Run: [QCWLICON] "C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE"
O4 - HKLM\..\Run: [BMMGAG] "C:\WINDOWS\system32\rundll32.exe" C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] "C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE"
O4 - HKLM\..\Run: [BMMMONWND] "C:\WINDOWS\system32\rundll32.exe" C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [Motive SmartBridge] "C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CheckPoint\Integrity Client\iclient.exe"
O4 - HKLM\..\Run: [Iomega Startup Options] "C:\Program Files\Iomega\Common\ImgStart.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] "C:\Program Files\Iomega\DriveIcons\ImgIcon.exe"
O4 - HKLM\..\Run: [stgclean] "c:\sdwork\w32main2.exe" /cleanup
O4 - HKLM\..\Run: [QCTray] "C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ibmmessages] "C:\Program Files\IBM\Messages By IBM\ibmmessages.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Iomega Active Disk] "C:\Program Files\Iomega\AutoDisk\AD2KClient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1201959414343
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control) - https://www-1.ibm.com/sametime/stmeetingroo…STJNILoader.cab
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} (LNWebAssist Class) - http://w3.ibm.com/bluepages/scripts/lnwebassist.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://regatta.mcsgroup.com/dwa7W.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mlmeetings.webex.com/client/v_myweb…ent/ieatgpc.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Iomega Activity Disk2 - Iomega Corporation - C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Program Files\lotus\notes\ntmulti.exe
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T; - C:\PROGRA~1\AT&TNE;~1\NetCfgSv.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TrcBoot - Unknown owner - C:\WINDOWS\System32\drivers\trcboot.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
O23 - Service: WRT Service (WRTService) - Unknown owner - C:\WINDOWS\WRTService.exe
–
End of file - 12045 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\BMMTask.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
Ask Search Assistant BHO - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL [2008-12-14 66912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D; IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
DriveLetterAccess - C:\WINDOWS\system32\dla\tfswshx.dll [2004-09-02 118842]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-31 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-31 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-31 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TrackPointSrv"=C:\WINDOWS\system32\tp4serv.exe [2003-11-13 94208]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2004-07-30 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2004-07-30 118784]
"TPKMAPHELPER"=C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe [2004-02-04 897024]
"TPHOTKEY"=C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe [2004-08-06 94208]
"TP4EX"=C:\WINDOWS\system32\tp4ex.exe [2002-09-04 53248]
"EZEJMNAP"=C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe [2003-12-25 208896]
"UC_Start"=C:\Program Files\IBM\Updater\\ucstartup.exe [2004-07-14 36864]
"UpdateManager"=C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe [2003-08-19 110592]
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe [2004-09-02 127035]
"IBMPRC"=C:\IBMTOOLS\UTILS\ibmprc.exe [2004-03-19 90112]
"QCWLICON"=C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE [2004-08-18 81920]
"BMMGAG"=C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll [2004-08-25 110592]
"BMMLREF"=C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE [2004-08-25 20480]
"BMMMONWND"=C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll [2004-08-25 395776]
"Motive SmartBridge"=C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe [2002-05-18 327680]
"Zone Labs Client"=C:\Program Files\CheckPoint\Integrity Client\iclient.exe [2005-05-10 931584]
"Iomega Startup Options"=C:\Program Files\Iomega\Common\ImgStart.exe [2001-01-17 45056]
"Iomega Drive Icons"=C:\Program Files\Iomega\DriveIcons\ImgIcon.exe [2001-09-12 61440]
"stgclean"=c:\sdwork\w32main2.exe [2006-12-13 260608]
"QCTray"=C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe [2004-08-18 708608]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-31 136600]
"SpySweeper"=C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 6273400]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ibmmessages"=C:\Program Files\IBM\Messages By IBM\ibmmessages.exe [2004-07-22 442368]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"Iomega Active Disk"=C:\Program Files\Iomega\AutoDisk\AD2KClient.exe [2001-09-13 45056]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
Verizon Online Support Center.lnk - C:\Program Files\Verizon Online\bin\matcli.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2004-07-30 344064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\QConGina]
C:\WINDOWS\system32\QConGina.dll [2004-08-18 258048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
pwdmon
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WebrootSpySweeperService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WRConsumerService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\AT&T; Network Client\NetClient.exe"="C:\Program Files\AT&T; Network Client\NetClient.exe:*:Enabled:Network access client"
"C:\sdwork\w32main2.exe"="C:\sdwork\w32main2.exe:*:Enabled:OSP Windows 32-bit ESD API"
"C:\WINDOWS\system32\ftp.exe"="C:\WINDOWS\system32\ftp.exe:*:Enabled:File Transfer Program"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\IBM\Updater\ucsmb.exe"="C:\Program Files\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector"
"C:\Program Files\IBM\Updater\jre\bin\javaw.exe"="C:\Program Files\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector"
"C:\Program Files\IBM\Updater\jre\bin\java.exe"="C:\Program Files\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector"
"C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe"="C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe:*:Enabled:QuickBooks 2008 Data Manager"
"C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe"="C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007"
"C:\Program Files\NetMeeting\conf.exe"="C:\Program Files\NetMeeting\conf.exe:*:Disabled:Windows® NetMeeting®"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe"="C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Disabled:TrueVector Service"
"C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\English\setup.exe"="C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\English\setup.exe:*:Enabled:Kaspersky Anti-Virus 2009 Setup"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\IBM\Updater\jre\bin\java.exe"="C:\Program Files\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector"
"C:\Program Files\IBM\Updater\jre\bin\javaw.exe"="C:\Program Files\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector"
"C:\Program Files\IBM\Updater\ucsmb.exe"="C:\Program Files\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe"="C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007"
======List of files/folders created in the last 1 months======
2009-01-05 16:18:27 —-D—- C:\rsit
2009-01-04 21:50:43 —-D—- C:\WINDOWS\ERUNT
2009-01-04 21:36:49 —-D—- C:\SDFix
2008-12-31 11:40:29 —-A—- C:\WINDOWS\system32\javaws.exe
2008-12-31 11:40:29 —-A—- C:\WINDOWS\system32\javaw.exe
2008-12-31 11:40:29 —-A—- C:\WINDOWS\system32\java.exe
2008-12-31 11:40:29 —-A—- C:\WINDOWS\system32\deploytk.dll
2008-12-30 09:00:19 —-SHD—- C:\RECYCLER
2008-12-30 07:19:25 —-D—- C:\32788R22FWJFW
2008-12-29 20:09:34 —-D—- C:\WINDOWS\Internet Logs
2008-12-28 14:09:41 —-A—- C:\Boot.bak
2008-12-28 14:09:36 —-RASHD—- C:\cmdcons
2008-12-28 14:07:25 —-D—- C:\WINDOWS\ERDNT
2008-12-28 13:56:39 —-RA—- C:\Program Files\ComboFix.exe
2008-12-26 16:06:05 —-D—- C:\WINDOWS\pss
2008-12-23 17:51:47 —-A—- C:\WINDOWS\ntbtlog.txt
2008-12-17 17:05:41 —-D—- C:\Documents and Settings\Paul A. Parone\Application Data\Malwarebytes
2008-12-17 17:05:29 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-17 17:05:28 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-12-15 16:37:38 —-AD—- C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-14 14:51:47 —-D—- C:\Binaries
2008-12-14 14:51:04 —-A—- C:\WINDOWS\WRSetup.dll
2008-12-14 14:51:03 —-D—- C:\Program Files\Webroot
2008-12-14 14:51:03 —-D—- C:\Documents and Settings\Paul A. Parone\Application Data\Webroot
2008-12-14 14:51:03 —-D—- C:\Documents and Settings\All Users\Application Data\Webroot
2008-12-14 14:51:01 —-D—- C:\Program Files\AskSBar
2008-12-13 20:42:43 —-D—- C:\Program Files\Kaspersky Lab
2008-12-13 19:59:39 —-A—- C:\WINDOWS\sssTbarV2.ini
2008-12-13 18:19:22 —-D—- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-12-13 17:36:10 —-A—- C:\WINDOWS\st_affiliate.ini
2008-12-13 06:07:35 —-HDC—- C:\WINDOWS\$NtUninstallKB955839$
2008-12-13 06:02:48 —-HDC—- C:\WINDOWS\$NtUninstallKB952069_WM9$
2008-12-13 06:01:49 —-HDC—- C:\WINDOWS\$NtUninstallKB954600$
2008-12-13 06:01:33 —-HDC—- C:\WINDOWS\$NtUninstallKB956802$
2008-12-11 09:25:33 —-D—- C:\Program Files\Alwil Software
2008-12-10 14:29:30 —-D—- C:\Program Files\Spybot - Search & Destroy
2008-12-10 14:29:30 —-D—- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-10 08:14:03 —-D—- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-10 08:13:17 —-D—- C:\Program Files\SUPERAntiSpyware
2008-12-10 08:13:17 —-D—- C:\Documents and Settings\Paul A. Parone\Application Data\SUPERAntiSpyware.com
2008-12-07 21:35:36 —-HD—- C:\WINDOWS\PIF
2008-12-07 20:32:20 —-A—- C:\WINDOWS\system32\27187008-.txt
======List of files/folders modified in the last 1 months======
2009-01-05 16:18:35 —-D—- C:\WINDOWS\Temp
2009-01-05 16:18:34 —-D—- C:\WINDOWS\Prefetch
2009-01-05 14:33:56 —-D—- C:\temp
2009-01-05 14:05:35 —-D—- C:\Siebel
2009-01-05 12:30:29 —-D—- C:\IBM
2009-01-05 10:52:32 —-D—- C:\sdwork
2009-01-05 10:24:20 —-AD—- C:\WINDOWS\system32
2009-01-05 10:22:15 —-A—- C:\WINDOWS\SchedLgU.Txt
2009-01-05 07:40:03 —-RSHD—- C:\WINDOWS\system32\dllcache
2009-01-04 21:04:25 —-RASH—- C:\BOOT.INI
2009-01-04 21:04:23 —-A—- C:\WINDOWS\win.ini
2009-01-04 21:04:23 —-A—- C:\WINDOWS\system.ini
2009-01-04 12:06:22 —-AD—- C:\WINDOWS
2009-01-01 06:43:53 —-AD—- C:\Program Files
2009-01-01 06:42:50 —-D—- C:\WINDOWS\system32\CatRoot2
2009-01-01 06:18:18 —-D—- C:\Program Files\Common Files
2008-12-31 11:40:43 —-SHD—- C:\WINDOWS\Installer
2008-12-31 11:39:03 —-D—- C:\Program Files\Java
2008-12-30 15:33:09 —-D—- C:\Talbots
2008-12-30 07:44:45 —-D—- C:\WINDOWS\system32\drivers
2008-12-30 07:29:44 —-D—- C:\WINDOWS\system32\config
2008-12-30 07:27:30 —-D—- C:\WINDOWS\AppPatch
2008-12-29 19:44:38 —-SHD—- C:\System Volume Information
2008-12-29 19:44:38 —-D—- C:\WINDOWS\system32\Restore
2008-12-29 15:46:33 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-12-28 14:11:23 —-SD—- C:\WINDOWS\Tasks
2008-12-27 17:20:06 —-D—- C:\Program Files\Trend Micro
2008-12-26 18:23:32 —-D—- C:\IBMSHARE
2008-12-26 16:15:55 —-A—- C:\WINDOWS\DUMP3170.tmp
2008-12-25 10:23:53 —-AC—- C:\WINDOWS\WinInit.ini
2008-12-22 14:59:32 —-D—- C:\TeamIT
2008-12-19 19:20:47 —-HD—- C:\WINDOWS\inf
2008-12-19 19:18:39 —-HD—- C:\WINDOWS\$hf_mig$
2008-12-15 16:39:55 —-AC—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-12-14 14:07:50 —-D—- C:\WINDOWS\Minidump
2008-12-14 08:54:30 —-D—- C:\Program Files\Internet Explorer
2008-12-13 20:35:15 —-D—- C:\WINDOWS\system
2008-12-13 20:34:50 —-D—- C:\Documents and Settings\All Users\Application Data\Avg7
2008-12-13 20:34:41 —-D—- C:\Documents and Settings\Paul A. Parone\Application Data\AVG7
2008-12-13 18:10:55 —-D—- C:\WINDOWS\system32\ZoneLabs
2008-12-13 18:10:04 —-D—- C:\WINDOWS\WinSxS
2008-12-13 17:53:40 —-RSD—- C:\WINDOWS\assembly
2008-12-13 06:07:41 —-A—- C:\WINDOWS\imsins.BAK
2008-12-13 06:05:29 —-D—- C:\WINDOWS\ie7updates
2008-12-13 01:40:02 —-A—- C:\WINDOWS\system32\mshtml.dll
2008-12-12 09:39:18 —-D—- C:\WINDOWS\system32\wbem
2008-12-10 14:22:37 —-SD—- C:\Documents and Settings\Paul A. Parone\Application Data\Microsoft
2008-12-10 07:54:25 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-12-09 18:24:37 —-A—- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 ANC;ANC; C:\WINDOWS\System32\drivers\ANC.SYS [2004-08-18 11520]
R1 ASMBATT;ASMBATT; C:\WINDOWS\System32\drivers\ASMBATT.SYS [2004-07-16 4992]
R1 IBMTPCHK;IBMTPCHK; C:\WINDOWS\System32\drivers\IBMBLDID.SYS [2004-08-18 2432]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 Smapint;Smapint; C:\WINDOWS\System32\drivers\Smapint.sys [2004-07-29 14848]
R1 sscdbhk5;sscdbhk5; C:\WINDOWS\system32\drivers\sscdbhk5.sys [2004-07-14 5627]
R1 ssrtln;ssrtln; C:\WINDOWS\system32\drivers\ssrtln.sys [2004-07-14 23545]
R1 TDSMAPI;TDSMAPI; C:\WINDOWS\System32\drivers\TDSMAPI.SYS [2004-07-29 9341]
R1 TPHKDRV;TPHKDRV; C:\WINDOWS\system32\drivers\TPHKDRV.sys [2004-06-09 16340]
R1 TPPWR;TPPWR; C:\WINDOWS\System32\drivers\Tppwr.sys [2004-08-25 16384]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2005-05-10 280864]
R2 ATNT40K;ActiveTouch NT Appsharing Driver; C:\WINDOWS\SYSTEM32\DRIVERS\ATNT40K.SYS [2006-01-25 51392]
R2 drvnddm;drvnddm; C:\WINDOWS\system32\drivers\drvnddm.sys [2004-07-14 40448]
R2 EGATHDRV;IBM Access Support; \??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS []
R2 ibmfilter;ibmfilter; \??\C:\WINDOWS\system32\drivers\ibmfilter.sys []
R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.3.1.9; C:\WINDOWS\system32\DRIVERS\mdc8021x.sys [2005-10-07 15781]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-04-09 11043]
R2 NsTrcNT;NsTrcNT; C:\WINDOWS\System32\drivers\nstrcnt.sys [2000-12-13 10816]
R2 pcscoax;3270 Coax Driver; C:\WINDOWS\System32\drivers\pcscoax.sys [2000-12-13 30720]
R2 PMEM;PMEM; \??\C:\WINDOWS\SYSTEM32\Drivers\PMEMNT.SYS []
R2 tfsnboio;tfsnboio; C:\WINDOWS\system32\dla\tfsnboio.sys [2004-09-02 25723]
R2 tfsncofs;tfsncofs; C:\WINDOWS\system32\dla\tfsncofs.sys [2004-09-02 34843]
R2 tfsndrct;tfsndrct; C:\WINDOWS\system32\dla\tfsndrct.sys [2004-09-02 4123]
R2 tfsndres;tfsndres; C:\WINDOWS\system32\dla\tfsndres.sys [2004-09-02 2239]
R2 tfsnifs;tfsnifs; C:\WINDOWS\system32\dla\tfsnifs.sys [2004-09-02 86202]
R2 tfsnopio;tfsnopio; C:\WINDOWS\system32\dla\tfsnopio.sys [2004-09-02 14715]
R2 tfsnpool;tfsnpool; C:\WINDOWS\system32\dla\tfsnpool.sys [2004-09-02 6363]
R2 tfsnudf;tfsnudf; C:\WINDOWS\system32\dla\tfsnudf.sys [2004-09-02 98714]
R2 tfsnudfa;tfsnudfa; C:\WINDOWS\system32\dla\tfsnudfa.sys [2004-09-02 100603]
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R3 ABVPN2K;Net Firewall Miniport Interface; C:\WINDOWS\system32\DRIVERS\abvpn2k.sys [2004-06-03 164224]
R3 AR5211;Dual-band Wi-Fi Wireless Mini PCI Adapter; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2004-07-22 393408]
R3 avpnnic;AGN Virtual Network Adapter; C:\WINDOWS\system32\DRIVERS\avpnnic.sys [2003-04-04 13952]
R3 b57w2k;Broadcom NetXtreme Fast Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2004-06-19 190336]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2004-07-22 1041152]
R3 HSFHWICH;HSFHWICH; C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2004-07-22 197888]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-07-30 724989]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2004-02-26 11344]
R3 KLOGNT;KLOGNT; C:\WINDOWS\System32\drivers\klognt.sys [2000-12-13 22504]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-06-23 266880]
R3 Tp4Track;IBM PS/2 TrackPoint Driver; C:\WINDOWS\system32\DRIVERS\tp4track.sys [2003-11-13 13904]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2004-07-22 676096]
S3 ac97intc;Intel® 82801 Audio Driver Install Service (WDM); C:\WINDOWS\system32\drivers\ac97intc.sys [2001-08-17 96256]
S3 catchme;catchme; \??\C:\DOCUME~1\PAULA~1.PAR\LOCALS~1\Temp\catchme.sys []
S3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-03-07 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-03-07 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-03-07 21568]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
S3 psadd;IBM PSA Access Driver; \??\C:\WINDOWS\system32\Drivers\psadd.sys []
S3 QCNDISIF;QCNDISIF; C:\WINDOWS\System32\drivers\qcndisif.SYS [2004-08-18 12288]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-13 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 IBM Rapid Restore Ultra Service;IBM Rapid Restore Ultra Service; C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe [2004-03-19 339968]
R2 IBMPMSVC;IBM PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2004-02-26 57344]
R2 Iomega Activity Disk2;Iomega Activity Disk2; C:\PROGRA~1\Iomega\System32\ActivityDisk.exe [2001-09-20 61440]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-31 152984]
R2 Multi-user Cleanup Service;Multi-user Cleanup Service; C:\Program Files\lotus\notes\ntmulti.exe [2005-08-15 53248]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
R2 NetCfgSvr;Network Configuration Service; C:\PROGRA~1\AT&TNE;~1\NetCfgSv.EXE [2004-03-01 94208]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
R2 QBCFMonitorService;QBCFMonitorService; C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2007-09-05 20480]
R2 QCONSVC;QCONSVC; C:\WINDOWS\System32\QCONSVC.EXE [2004-08-18 73728]
R2 TpKmpSVC;IBM KCU Service; C:\WINDOWS\system32\TpKmpSVC.exe [2003-07-11 32768]
R2 TrcBoot;TrcBoot; C:\WINDOWS\System32\drivers\trcboot.exe [2000-12-13 28672]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2005-05-10 1246968]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine; C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe [2008-11-12 3667312]
R2 WRConsumerService;Webroot Client Service; C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe [2008-11-13 1086840]
R2 WRTService;WRT Service; C:\WINDOWS\WRTService.exe [2006-09-29 77824]
R3 ACS;ACU Configuration Service; C:\WINDOWS\system32\acs.exe [2004-07-16 36864]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE []
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PsaSrv;IBM PSA Access Driver Control; C:\WINDOWS\system32\PsaSrv.exe []
S3 QBFCService;Intuit QuickBooks FCS; C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2007-05-24 61440]
—————–EOF—————–
info.txt logfile of random's system information tool 1.05 2009-01-05 16:18:52
======Uninstall list======
–>C:\PROGRA~1\VERIZO~1\Uninstall.exe Verizon
–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ibm\gsk4\gsk4BUI.isu"
–>C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
–>C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
–>C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
–>C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
–>MsiExec.exe /I{8ED4E82B-8CEA-40DE-826C-37AC7B941F81}
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00BF-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00C6-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00D1-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF03DA-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\SETUP.EXE"
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\SETUP.EXE" -l0x9 ControlPanelAnyText
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\SETUP.EXE"
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\SETUP.EXE"
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\SETUP.EXE" -l0x9 ControlPanel
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
32 Bit HP CIO Components Installer–>MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
Access IBM Message Center–>MsiExec.exe /X{F413B3A4-EE5D-457C-BAE5-6E58D9589ED5}
Access IBM–>MsiExec.exe /X{EC6AF20D-4376-4070-BEE4-D3A0DFF7E140}
Acrobat.com–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Active Disk–>C:\WINDOWS\unvise32.exe C:\Program Files\Iomega\AutoDisk\uninstal.log
Adobe AIR–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player 9 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
Apple Software Update–>MsiExec.exe /I{74EC78BC-B379-4E29-9006-8F161DCAABA6}
AT&T; Network Client–>C:\Program Files\AT&T; Network Client\NetUN.exe
Brio.Quickview–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Brio\Brio.Quickview\Uninst.isu"
Canon Camera Support Core Library–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{26BDE7D8-93F0-4A07-AD47-1707DB417941} /l1033
Canon Camera Window for ZoomBrowser EX–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{B34BE30D-A759-4EC2-B58F-19FE2DEBF651}
Canon MovieEdit Task for ZoomBrowser EX–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{DE286975-ACF1-45B8-9EF7-34E162B2C817}
Canon RAW Image Task for ZoomBrowser EX–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{68E7E8BD-2233-49BE-81D6-1A1FAF1B5196}
Canon RemoteCapture Task for ZoomBrowser EX–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{CF2C1A86-5A98-4862-A3AE-9992E3A6427D}
Canon Utilities PhotoStitch 3.1–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{EF4C7EB0-D71B-43A3-9552-8053DE4B0401}
Canon Utilities ZoomBrowser EX–>MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)–>"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hoyle Casino '98–>C:\WINDOWS\IsUninst.exe -fC:\SIERRA\Casino98\Uninst.isu
HP Customer Participation Program 9.0–>C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Deskjet All-In-One Software 9.0–>C:\Program Files\HP\Digital Imaging\{706BB40A-4102-4c89-8107-DC68C4EBD19B}\setup\hpzscr01.exe -datfile hposcr14.dat
HP Imaging Device Functions 9.0–>C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Essential 2.01–>C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
HP Smart Web Printing–>MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7}
HP Solution Center 9.0–>C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update–>MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
HPSSupply–>MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
Hyperion Intelligence Client–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D44D97D9-919B-4A6D-ABE8-C84B3DD757A9}\pluginsetup.exe" -l0x9 -uninst
IBM 32-bit Runtime Environment for Java 2, v1.4.1–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6C72E14A-C1F3-45E5-8810-83CE3C19ED63} /l1033
IBM Access Connections–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{22B71A00-4DED-11D4-A5E5-0004AC564F43}\SETUP.EXE" -l0x9 anything
IBM DLA–>MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
IBM Integrated 56K Modem–>C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV;_24C6&SUBSYS;_05591014\HXFSETUP.EXE -U -IVEN_8086&DEV;_24C6&SUBSYS;_05591014 -S -ISFG
IBM Personal Communications–>C:\WINDOWS\PCSUNIST.EXE C:\WINDOWS\unisthook.exe C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Personal Communications\DeIsL1.isu" -y
IBM RecordNow!–>MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
IBM Rescue and Recovery with Rapid Restore–>MsiExec.exe /X{11783F13-C3A9-44A8-929B-21A476F65272}
IBM Themes–>MsiExec.exe /I{6CE96A14-61E2-48CC-837E-22710A953ADE}
IBM ThinkPad Battery MaxiMiser and Power Management Features–>C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\Unbmm.isu -c"C:\Program Files\ThinkPad\Utilities\Tpinsbmm.dll"
IBM ThinkPad Configuration–>C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\UNTPUW.ISU -c"C:\Program Files\ThinkPad\Utilities\Tpinswin.dll"
IBM ThinkPad EasyEject Utility –>C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\Unezej.isu -c"C:\Program Files\ThinkPad\Utilities\Tpinsej.dll"
IBM ThinkPad Keyboard Customizer Utility–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2111B23F-7FDA-4A41-8309-E5A1663CA296}\SETUP.EXE" -l0x9 anything
IBM ThinkPad Power Management Driver–>RunDll32.exe tpinspm.dll,Uninstall
IBM ThinkVantage Technologies Welcome Message–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1007F41F-7D69-468E-8017-3849A5A973C2}\SETUP.EXE" -l0x9 anything
IBM TrackPoint Accessibility Features–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA664480-3844-11D5-8C25-444553540000}\SETUP.EXE"
IBM TrackPoint Support–>C:\WINDOWS\system32\tp4unins.exe
IBM Update Connector–>MsiExec.exe /X{8D815BF3-2399-459C-B121-49373FEFB9E8}
IBM Wireless LAN Adapters Software (11a/b, 11b/g, 11a/b/g) –>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}\SETUP.EXE" -l0x9 UNINSTALLFROMSYS
Intel® Extreme Graphics 2 Driver–>RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV;_3582
InterVideo WinDVD–>"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
Iomega App Services–>C:\WINDOWS\unvise32.exe C:\Program Files\Iomega\System32\uninstal.log
IomegaWare–>C:\WINDOWS\unvise32.exe C:\Program Files\Iomega\uninstal.log
J2SE Runtime Environment 5.0 Update 8–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150080}
Java™ 6 Update 11–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Lenovo Battery Program–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B214C3C8-FC16-42EC-B7BB-703A1BB9C790}\Setup.exe" -l0x9
LiveUpdate 3.2 (Symantec Corporation)–>"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Lotus Notes 7.0–>MsiExec.exe /I{628789DC-75F8-4302-A268-27EF628E6906}
Lotus NotesSQL 3.01 driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{113EECD6-9A04-11D4-811D-00805F923B86}\Setup.exe" -uninst
Lotus SmartSuite - English–>MsiExec.exe /I{536D6172-7453-7569-7465-392E38300409}
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Meeting Manager for Internet Explorer–>MsiExec.exe /I{F2AB2488-A0BF-4A9B-98A9-A88CF20FD2FF}
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Live Meeting 2007–>MsiExec.exe /I{7DB92914-0A00-48C6-8DBB-F8E9D02B78B1}
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Visio Professional 2003–>MsiExec.exe /I{90510409-6000-11D3-8CFE-0150048383C9}
Mozilla Thunderbird (1.5.0.12)–>C:\PROGRA~1\MOZILL~1\uninstall\uninstall.exe /ua "1.5.0.12 (en-US)"
MSXML 4.0 SP2 (KB927978)–>MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 and SOAP Toolkit 3.0–>MsiExec.exe /I{32343DB6-9A52-40C9-87E4-5E7C79791C87}
MSXML 4.0 SP2 Parser and SDK–>MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
PC-Doctor for Windows–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\SETUP.EXE"
PCFriendly–>C:\Program Files\PCFriendly\inuninst.exe
QuickBooks Simple Start 2008 (Plus Pack)–>msiexec.exe /I {8ED4E82B-8CEA-40DE-826C-37AC7B941F81} UNIQUE_NAME="atom" QBFULLNAME="QuickBooks Simple Start 2008 (Plus Pack)" ADDREMOVE=1
Sametime Client v3.1–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Lotus\Sametime Client\STCUnins.isu"
Security Update for CAPICOM (KB931906)–>MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)–>MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Step By Step Interactive Training (KB898458)–>"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723)–>"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB928090)–>"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)–>"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)–>"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)–>"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)–>"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)–>"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)–>"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)–>"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)–>"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)–>"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)–>"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB911565)–>"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB917734)–>"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)–>"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)–>"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Sierra Utilities–>C:\Program Files\Sierra On-Line\sutil32.exe uninstall
Sonic Update Manager–>MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
SoundMAX–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\SETUP.exe" -l0x9 -removeonly
Spy Sweeper Core–>MsiExec.exe /I{3F5B6210-0903-4DC6-8034-8F488AA3A782}
Spybot - Search & Destroy–>"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SupportSoft Assisted Service–>MsiExec.exe /I{5A3F6A80-7913-475E-8B96-477A952CFA43}
ThinkPad FullScreen Magnifier–>RunDll32 setupapi.dll,InstallHinfSection DefaultUninstall.NT 132 C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.inf
ThinkPad Software Installer–>_tpiu000.exe /U
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
VC 9.0 Runtime–>MsiExec.exe /I{A040AC77-C1AA-4CC9-8931-9F648AF178F6}
Verizon Online Support Center–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00A1-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
Verizon Online–>C:\WINDOWS\system32\VerizonUninstaller.exe
Wallpapers–>MsiExec.exe /I{F386C340-DF4B-4BBA-9503-420FB7EDB395}
WebEx–>C:\PROGRA~1\WebEx\atcliun.exe
Webroot AntiVirus with AntiSpyware–>"C:\Program Files\Webroot\WebrootSecurity\unins000.exe"
Windows Driver Package - Microsoft Corporation (usbvideo) Image (05/25/2007 1.0.3656.0)–>rundll32.exe C:\PROGRA~1\DIFX\7AA84A78695B31A503D9537A76801D74E0FD14BD\DIFxAppA.dll, DIFxARPUninstallDriverPackage C:\WINDOWS\system32\DRVSTORE\RoundTable_F29D632BDCC1844B9B7688A0A4B4DA9E716B76FF\RoundTable.inf
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Yahoo! Internet Mail–>C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
=====HijackThis Backups=====
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
======Hosts File======
127.0.0.1 localhost
======Security center information======
AV: Webroot AntiVirus with AntiSpyware
FW: Webroot Internet Security Essentials (disabled)
FW: Integrity Flex Firewall
System event log
Computer Name: IBM-546DEA067E3
Event Code: 7035
Message: The ACU Configuration Service service was successfully sent a start control.
Record Number: 77273
Source Name: Service Control Manager
Time Written: 20081217065453.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM
Computer Name: IBM-546DEA067E3
Event Code: 7036
Message: The ACU Configuration Service service entered the running state.
Record Number: 77272
Source Name: Service Control Manager
Time Written: 20081217065453.000000-300
Event Type: information
User:
Computer Name: IBM-546DEA067E3
Event Code: 7036
Message: The hpqcxs08 service entered the running state.
Record Number: 77271
Source Name: Service Control Manager
Time Written: 20081217065451.000000-300
Event Type: information
User:
Computer Name: IBM-546DEA067E3
Event Code: 7035
Message: The hpqcxs08 service was successfully sent a start control.
Record Number: 77270
Source Name: Service Control Manager
Time Written: 20081217065451.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM
Computer Name: IBM-546DEA067E3
Event Code: 4
Message: Broadcom NetXtreme Fast Ethernet: The network link is down. Check to make sure the network cable is properly connected.
Record Number: 77269
Source Name: b57w2k
Time Written: 20081217065439.000000-300
Event Type: warning
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\PROGRAM FILES\THINKPAD\UTILITIES;C:\WINDOWS\Downloaded Program Files;%SystemDrive%\IBMTOOLS\Python22;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\IBM\Trace Facility;C:\Program Files\Personal Communications;C:\Program Files\Common Files\Intuit\QBPOSSDKRuntime
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
"PROCESSOR_REVISION"=0401
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.pyo;.pyc;.py;.pyw
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"RRU"=C:\Program Files\IBM\IBM Rapid Restore Ultra\
"PYTHONPATH"=%SystemDrive%\IBMTOOLS\utils\support;%SystemDrive%\IBMTOOLS\utils\logger
"IBMSHARE"=%SystemDrive%\IBMSHARE
"TCL_LIBRARY"=%SystemDrive%\IBMTOOLS\Python22\tcl\tcl8.4
"TK_LIBRARY"=%SystemDrive%\IBMTOOLS\Python22\tcl\tk8.4
"PYTHONCASEOK"=1
"PCOMM_Root"=C:\Program Files\Personal Communications
"tvdebugflags"=0x260
"tvlogsessioncount"=5000
—————–EOF—————–
After an all day series of scans I posted up some results yesterday. I did a Malewarebytes scan last night, as well as a Spybot run.
Malewarebytes saw nothing. Another scan this morning around 0730 repeated that no threats were found. Log below.
- However, Spybot's scan saw 2 threats labeled the usual MyWay.MyWebSearch.xxx, with 2 entries below. When I hit the clean button Spybot checked one of them. The other is still on. Unfortunately I do NOT see a log file for Spybot, otherwise I would show you that info.
- This morning I opened in Safe Mode and attempted to run Malewarebytes again in the hopes of getting anything. Twice it shut everything down (application and PC) in mid run. I opened in Windows (in the modified safe mode) and ran the scans I described above.
- new info . . . I referred to a log file I discovered back in Nov. 2006 which I believe started my troubles, called
msxml(small L)4-KB927978-enu.log . This morning I was going through my directory, folders and files and stumbled upon that file. Since that is in notepad I am posting that below, as it may give you an idea what it is and what started it. It is massively long.
- in addition, there is one file that will not delete that I uncovered. It is in the AskSBar directory, SrchAstt folder, 1.bin subfolder and called A2SRCHAS.DLL. (66K) I often back door into my temporary internet files folder, and manually delete everything. The file titled B1[1] always re-creates itself, and attaches that re-creation to others, often called pixel[1] and others.
This is the one I suspect we need to kill. Attempts at deleting the file and folders via Windows all fail.
- I also deleted CyberDefender to my Recycle Bin. Please let me know if I need to restore that.
The 2006 file should be good intel. Lock and load, BHowett Happy hunting and Semper Fi.
paultpa
Malwarebytes' Anti-Malware 1.32
Database version: 1620
Windows 5.1.2600 Service Pack 3
1/6/2009 7:46:21 AM
mbam-log-2009-01-06 (07-46-21).txt
Scan type: Quick Scan
Objects scanned: 59578
Time elapsed: 12 minute(s), 6 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
=== Verbose logging started: 11/18/2006 20:54:28 Build type: SHIP UNICODE 3.01.4000.2435 Calling process: C:\WINDOWS\system32\msiexec.exe ===
MSI © (58:14) [20:54:28:140]: Resetting cached policy values
MSI © (58:14) [20:54:28:140]: Machine policy value 'Debug' is 0
MSI © (58:14) [20:54:28:140]: ******* RunEngine:
******* Product: c:\f543835665da81c0d6df901ff022\msxml.msi
******* Action:
******* CommandLine: **********
MSI © (58:14) [20:54:28:140]: Client-side and UI is none or basic: Running entire install on the server.
MSI © (58:14) [20:54:28:140]: Grabbed execution mutex.
MSI © (58:14) [20:54:28:312]: Cloaking enabled.
MSI © (58:14) [20:54:28:312]: Attempting to enable all disabled priveleges before calling Install on Server
MSI © (58:14) [20:54:28:312]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (EC:38) [20:54:28:328]: Grabbed execution mutex.
MSI (s) (EC:14) [20:54:28:343]: Resetting cached policy values
MSI (s) (EC:14) [20:54:28:343]: Machine policy value 'Debug' is 0
MSI (s) (EC:14) [20:54:28:343]: ******* RunEngine:
******* Product: c:\f543835665da81c0d6df901ff022\msxml.msi
******* Action:
******* CommandLine: **********
MSI (s) (EC:14) [20:54:28:375]: Machine policy value 'DisableUserInstalls' is 0
MSI (s) (EC:14) [20:54:28:406]: File will have security applied from OpCode.
MSI (s) (EC:14) [20:54:28:484]: SOFTWARE RESTRICTION POLICY: Verifying package –> 'c:\f543835665da81c0d6df901ff022\msxml.msi' against software restriction policy
MSI (s) (EC:14) [20:54:28:484]: SOFTWARE RESTRICTION POLICY: c:\f543835665da81c0d6df901ff022\msxml.msi has a digital signature
MSI (s) (EC:14) [20:54:29:468]: SOFTWARE RESTRICTION POLICY: c:\f543835665da81c0d6df901ff022\msxml.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (EC:14) [20:54:29:500]: End dialog not enabled
MSI (s) (EC:14) [20:54:29:515]: Original package ==> c:\f543835665da81c0d6df901ff022\msxml.msi
MSI (s) (EC:14) [20:54:29:515]: Package we're running from ==> c:\WINDOWS\Installer\3c2210d.msi
MSI (s) (EC:14) [20:54:29:562]: APPCOMPAT: looking for appcompat database entry with ProductCode '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (EC:14) [20:54:29:593]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (EC:14) [20:54:29:609]: MSCOREE not loaded loading copy from system32
MSI (s) (EC:14) [20:54:29:921]: Machine policy value 'TransformsSecure' is 0
MSI (s) (EC:14) [20:54:29:921]: User policy value 'TransformsAtSource' is 0
MSI (s) (EC:14) [20:54:29:953]: Machine policy value 'DisablePatch' is 0
MSI (s) (EC:14) [20:54:29:953]: Machine policy value 'AllowLockdownPatch' is 0
MSI (s) (EC:14) [20:54:29:953]: Machine policy value 'DisableLUAPatching' is 0
MSI (s) (EC:14) [20:54:29:953]: Machine policy value 'DisableFlyWeightPatching' is 0
MSI (s) (EC:14) [20:54:29:953]: APPCOMPAT: looking for appcompat database entry with ProductCode '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (EC:14) [20:54:29:953]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (EC:14) [20:54:29:953]: Transforms are not secure.
MSI (s) (EC:14) [20:54:29:953]: Command Line: REBOOT=ReallySuppress CURRENTDIRECTORY=c:\f543835665da81c0d6df901ff022 CLIENTUILEVEL=3 CLIENTPROCESSID=2136
MSI (s) (EC:14) [20:54:29:953]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{2B27DCD9-53FA-4885-B6CD-698623819F4C}'.
MSI (s) (EC:14) [20:54:29:953]: Product Code passed to Engine.Initialize: ''
MSI (s) (EC:14) [20:54:29:953]: Product Code from property table before transforms: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (EC:14) [20:54:29:953]: Product Code from property table after transforms: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (EC:14) [20:54:29:953]: Product not registered: beginning first-time install
MSI (s) (EC:14) [20:54:29:953]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.
MSI (s) (EC:14) [20:54:29:953]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (EC:14) [20:54:29:953]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (EC:14) [20:54:29:968]: Adding new sources is allowed.
MSI (s) (EC:14) [20:54:29:968]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.
MSI (s) (EC:14) [20:54:29:968]: Package name extracted from package path: 'msxml.msi'
MSI (s) (EC:14) [20:54:29:968]: Package to be registered: 'msxml.msi'
MSI (s) (EC:14) [20:54:29:968]: Note: 1: 2729
MSI (s) (EC:14) [20:54:30:000]: Note: 1: 2729
MSI (s) (EC:14) [20:54:30:000]: Note: 1: 2262 2: AdminProperties 3: -2147287038
MSI (s) (EC:14) [20:54:30:000]: Machine policy value 'DisableMsi' is 0
MSI (s) (EC:14) [20:54:30:000]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (EC:14) [20:54:30:000]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (EC:14) [20:54:30:000]: Product installation will be elevated because user is admin and product is being installed per-machine.
MSI (s) (EC:14) [20:54:30:000]: Running product '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}' with elevated privileges: Product is assigned.
MSI (s) (EC:14) [20:54:30:000]: PROPERTY CHANGE: Adding REBOOT property. Its value is 'ReallySuppress'.
MSI (s) (EC:14) [20:54:30:000]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'c:\f543835665da81c0d6df901ff022'.
MSI (s) (EC:14) [20:54:30:000]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.
MSI (s) (EC:14) [20:54:30:000]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '2136'.
MSI (s) (EC:14) [20:54:30:000]: TRANSFORMS property is now:
MSI (s) (EC:14) [20:54:30:000]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '200'.
MSI (s) (EC:14) [20:54:30:000]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Application Data
MSI (s) (EC:14) [20:54:30:000]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Favorites
MSI (s) (EC:14) [20:54:30:000]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\NetHood
MSI (s) (EC:14) [20:54:30:000]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\My Documents
MSI (s) (EC:14) [20:54:30:000]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\PrintHood
MSI (s) (EC:14) [20:54:30:015]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Recent
MSI (s) (EC:14) [20:54:30:015]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\SendTo
MSI (s) (EC:14) [20:54:30:015]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Templates
MSI (s) (EC:14) [20:54:30:015]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Application Data
MSI (s) (EC:14) [20:54:30:015]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data
MSI (s) (EC:14) [20:54:30:015]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures
MSI (s) (EC:14) [20:54:30:015]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
MSI (s) (EC:14) [20:54:30:015]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs\Startup
MSI (s) (EC:14) [20:54:30:031]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs
MSI (s) (EC:14) [20:54:30:031]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu
MSI (s) (EC:14) [20:54:30:031]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Desktop
MSI (s) (EC:14) [20:54:30:031]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Administrative Tools
MSI (s) (EC:14) [20:54:30:031]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup
MSI (s) (EC:14) [20:54:30:031]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs
MSI (s) (EC:14) [20:54:30:031]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu
MSI (s) (EC:14) [20:54:30:031]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Desktop
MSI (s) (EC:14) [20:54:30:031]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Templates
MSI (s) (EC:14) [20:54:30:031]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\Fonts
MSI (s) (EC:14) [20:54:30:046]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16
MSI (s) (EC:14) [20:54:30:062]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
MSI (s) (EC:14) [20:54:30:062]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (EC:14) [20:54:30:062]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'Paul A. Parone'.
MSI (s) (EC:14) [20:54:30:062]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (EC:14) [20:54:30:062]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'c:\WINDOWS\Installer\3c2210d.msi'.
MSI (s) (EC:14) [20:54:30:062]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'c:\f543835665da81c0d6df901ff022\msxml.msi'.
MSI (s) (EC:14) [20:54:30:062]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (EC:14) [20:54:30:062]: Machine policy value 'DisableRollback' is 0
MSI (s) (EC:14) [20:54:30:062]: User policy value 'DisableRollback' is 0
MSI (s) (EC:14) [20:54:30:062]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.
=== Logging started: 11/18/2006 20:54:30 ===
MSI (s) (EC:14) [20:54:30:062]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
MSI (s) (EC:14) [20:54:30:062]: Doing action: INSTALL
MSI (s) (EC:14) [20:54:30:078]: Running ExecuteSequence
MSI (s) (EC:14) [20:54:30:078]: Doing action: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901
Action start 20:54:30: INSTALL.
MSI (s) (EC:14) [20:54:30:078]: PROPERTY CHANGE: Adding DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Desktop\'.
Action start 20:54:30: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901.
MSI (s) (EC:14) [20:54:30:078]: Doing action: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901
Action ended 20:54:30: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901. Return value 1.
MSI (s) (EC:14) [20:54:30:078]: PROPERTY CHANGE: Adding ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Start Menu\Programs\'.
Action start 20:54:30: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901.
MSI (s) (EC:14) [20:54:30:078]: Doing action: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
Action ended 20:54:30: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901. Return value 1.
MSI (s) (EC:14) [20:54:30:078]: PROPERTY CHANGE: Adding WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 20:54:30: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537.
MSI (s) (EC:14) [20:54:30:078]: Doing action: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
Action ended 20:54:30: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (EC:14) [20:54:30:078]: PROPERTY CHANGE: Adding SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 20:54:30: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537.
MSI (s) (EC:14) [20:54:30:078]: Doing action: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537
Action ended 20:54:30: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (EC:14) [20:54:30:078]: PROPERTY CHANGE: Adding WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 20:54:30: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537.
MSI (s) (EC:14) [20:54:30:078]: Doing action: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537
Action ended 20:54:30: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (EC:14) [20:54:30:078]: PROPERTY CHANGE: Adding SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 20:54:30: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537.
MSI (s) (EC:14) [20:54:30:078]: Doing action: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
Action ended 20:54:30: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (EC:14) [20:54:30:078]: PROPERTY CHANGE: Adding WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 20:54:30: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537.
MSI (s) (EC:14) [20:54:30:078]: Doing action: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
Action ended 20:54:30: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (EC:14) [20:54:30:093]: PROPERTY CHANGE: Adding SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 20:54:30: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537.
MSI (s) (EC:14) [20:54:30:093]: Doing action: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB
Action ended 20:54:30: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (EC:14) [20:54:30:093]: PROPERTY CHANGE: Adding SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB property. Its value is 'C:\WINDOWS\system32\'.
Action start 20:54:30: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB.
MSI (s) (EC:14) [20:54:30:093]: Doing action: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1
Action ended 20:54:30: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB. Return value 1.
MSI (s) (EC:14) [20:54:30:093]: PROPERTY CHANGE: Adding SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 property. Its value is 'C:\WINDOWS\system32\'.
Action start 20:54:30: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1.
MSI (s) (EC:14) [20:54:30:093]: Doing action: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7
Action ended 20:54:30: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1. Return value 1.
MSI (s) (EC:14) [20:54:30:093]: PROPERTY CHANGE: Adding SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its value is 'C:\WINDOWS\system32\'.
Action start 20:54:30: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7.
MSI (s) (EC:14) [20:54:30:093]: Doing action: LaunchConditions
Action ended 20:54:30: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7. Return value 1.
Action start 20:54:30: LaunchConditions.
MSI (s) (EC:14) [20:54:30:093]: Doing action: FindRelatedProducts
Action ended 20:54:30: LaunchConditions. Return value 1.
Action start 20:54:30: FindRelatedProducts.
MSI (s) (EC:14) [20:54:30:093]: Doing action: AppSearch
Action ended 20:54:30: FindRelatedProducts. Return value 1.
Action start 20:54:30: AppSearch.
MSI (s) (EC:14) [20:54:30:093]: Note: 1: 2262 2: Signature 3: -2147287038
MSI (s) (EC:14) [20:54:30:093]: PROPERTY CHANGE: Adding WINHTTP_51 property. Its value is 'WinHttpRequest Component version 5.1'.
MSI (s) (EC:14) [20:54:30:093]: Skipping action: CCPSearch (condition is false)
MSI (s) (EC:14) [20:54:30:093]: Skipping action: RMCCPSearch (condition is false)
MSI (s) (EC:14) [20:54:30:093]: Doing action: ValidateProductID
Action ended 20:54:30: AppSearch. Return value 1.
Action start 20:54:30: ValidateProductID.
MSI (s) (EC:14) [20:54:30:093]: Doing action: CostInitialize
Action ended 20:54:30: ValidateProductID. Return value 1.
MSI (s) (EC:14) [20:54:30:093]: Machine policy value 'MaxPatchCacheSize' is 10
Action start 20:54:30: CostInitialize.
MSI (s) (EC:14) [20:54:30:125]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'c:\'.
MSI (s) (EC:14) [20:54:30:125]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.
MSI (s) (EC:14) [20:54:30:125]: Note: 1: 2205 2: 3: Patch
MSI (s) (EC:14) [20:54:30:125]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (EC:14) [20:54:30:125]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (EC:14) [20:54:30:125]: Note: 1: 2205 2: 3: __MsiPatchFileList
MSI (s) (EC:14) [20:54:30:125]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (EC:14) [20:54:30:125]: Note: 1: 2228 2: 3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId`
MSI (s) (EC:14) [20:54:30:125]: Doing action: FileCost
Action ended 20:54:30: CostInitialize. Return value 1.
MSI (s) (EC:14) [20:54:30:125]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 20:54:30: FileCost.
MSI (s) (EC:14) [20:54:30:125]: Doing action: CostFinalize
Action ended 20:54:30: FileCost. Return value 1.
MSI (s) (EC:14) [20:54:30:125]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.
MSI (s) (EC:14) [20:54:30:125]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.
MSI (s) (EC:14) [20:54:30:125]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.
MSI (s) (EC:14) [20:54:30:125]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.
MSI (s) (EC:14) [20:54:30:125]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.
MSI (s) (EC:14) [20:54:30:125]: Note: 1: 2205 2: 3: Patch
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'c:\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying WindowsFolder property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying CommonFilesFolder property. Its current value is 'C:\Program Files\Common Files\'. Its new value: 'c:\Program Files\Common Files\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 property. Its value is 'c:\Program Files\Common Files\Microsoft Shared\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 property. Its value is 'c:\Program Files\Common Files\Microsoft Shared\MSDN\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa692
0e9f98fc\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying DesktopFolder property. Its current value is 'C:\Documents and Settings\All Users\Desktop\'. Its new value: 'c:\Documents and Settings\All Users\Desktop\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying ProgramFilesFolder property. Its current value is 'C:\Program Files\'. Its new value: 'c:\Program Files\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding MSXML property. Its value is 'c:\Program Files\MSXML 4.0\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding INC.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\inc\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding LIB.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\lib\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding DOC.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\doc\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its current value is 'C:\Documents and Settings\All Users\Start Menu\Programs\'. Its new value: 'c:\Documents and Settings\All Users\Start Menu\Programs\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Adding MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\'.
MSI (s) (EC:14) [20:54:30:140]: PROPERTY CHANGE: Modifying DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its current value is 'C:\Documents and Settings\All Users\Desktop\'. Its new value: 'c:\Documents and Settings\All Users\Desktop\'.
MSI (s) (EC:14) [20:54:30:140]: Target path resolution complete. Dumping Directory table…
MSI (s) (EC:14) [20:54:30:140]: Note: target paths subject to change (via custom actions or browsing)
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: TARGETDIR , Object: c:\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WindowsFolder , Object: c:\WINDOWS\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: CommonFilesFolder , Object: c:\Program Files\Common Files\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\Program Files\Common Files\Microsoft Shared\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\Program Files\Common Files\Microsoft Shared\MSDN\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa692
0e9f98fc\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB , Object: c:\WINDOWS\system32\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 , Object: c:\WINDOWS\system32\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 , Object: c:\WINDOWS\system32\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: DesktopFolder , Object: c:\Documents and Settings\All Users\Desktop\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: ProgramFilesFolder , Object: c:\Program Files\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: MSXML , Object: c:\Program Files\MSXML 4.0\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: INC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\inc\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: LIB.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\lib\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: DOC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\doc\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Start Menu\Programs\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\
MSI (s) (EC:14) [20:54:30:140]: Dir (target): Key: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Desktop\
Action start 20:54:30: CostFinalize.
MSI (s) (EC:14) [20:54:30:156]: Doing action: SetODBCFolders
Action ended 20:54:30: CostFinalize. Return value 1.
MSI (s) (EC:14) [20:54:30:156]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (EC:14) [20:54:30:156]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `ComponentId`,`Description`,`Directory_`, `ActionRequest`, `Installed`, `Attributes` FROM `ODBCDriver`, `Component` WHERE `ODBCDriver`.`Component_` = `Component` AND (`ActionRequest` = 1 OR `ActionRequest` = 2)
MSI (s) (EC:14) [20:54:30:156]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (EC:14) [20:54:30:156]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `ComponentId`,`Description`,`Directory_`, `ActionRequest`, `Installed`, `Attributes` FROM `ODBCTranslator`, `Component` WHERE `ODBCTranslator`.`Component_` = `Component` AND (`ActionRequest` = 1 OR `ActionRequest` = 2)
Action start 20:54:30: SetODBCFolders.
MSI (s) (EC:14) [20:54:30:171]: Doing action: MigrateFeatureStates
Action ended 20:54:30: SetODBCFolders. Return value 0.
Action start 20:54:30: MigrateFeatureStates.
MSI (s) (EC:14) [20:54:30:171]: Doing action: InstallValidate
Action ended 20:54:30: MigrateFeatureStates. Return value 0.
MSI (s) (EC:14) [20:54:30:171]: Feature: MSXML; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Feature: MSXMLSYS; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Feature: MSXMLSUPP; Installed: Absent; Request: Null; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Feature: MSXMLSUPP2; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Feature: MSXMLSXS; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Feature: XMLSDK; Installed: Absent; Request: Null; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: RememberInstallFolder; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: QKBKEY; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: MSXML4_System.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: MSXML4_SystemRes.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: MSXML4_ANSI.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: WINHTTP50_COMPONENT.781A0624_31FF_4712_BFFD_31C829FFDBF1; Installed: Absent; Request: Null; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: PROXYCFG_COMPONENT.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB; Installed: Absent; Request: Local; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: uplevel.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: downlevel_manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: downlevel_payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: uplevel.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: downlevel_manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: downlevel_payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: uplevel.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: downlevel_manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: XMLSDK_Docs.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: XMLSDK_LIB.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: XMLSDK_INC.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: CookDoc_dll.3FB7DAB3_19E7_40A0_8730_4482CE77AC59; Installed: Absent; Request: Null; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: __uplevel.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: __uplevel.DA6654F6_456F_3658_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: __uplevel.0E9F98FC_A692_A6DF_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: __QKBKEY65; Installed: Null; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: __MSXML4_System.246EB7AD_459A_4FA8_83D1_4165; Installed: Null; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: __downlevel_payload.7B2FCEFF_0F22_B7E1_FF665; Installed: Null; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: __downlevel_manifest.7B2FCEFF_0F22_B7E1_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: __downlevel_payload.DA6654F6_456F_3658_FF665; Installed: Null; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: __downlevel_manifest.DA6654F6_456F_3658_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: __downlevel_manifest.0E9F98FC_A692_A6DF_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (EC:14) [20:54:30:171]: Component: __CookDoc_dll.3FB7DAB3_19E7_40A0_8730_448265; Installed: Null; Request: Null; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Component: __XMLSDK_Docs.4576A2F1_959E_4BCA_94A9_596565; Installed: Null; Request: Null; Action: Null
MSI (s) (EC:14) [20:54:30:171]: Note: 1: 2205 2: 3: BindImage
MSI (s) (EC:14) [20:54:30:171]: Note: 1: 2262 2: PublishComponent 3: -2147287038
MSI (s) (EC:14) [20:54:30:171]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (EC:14) [20:54:30:171]: Note: 1: 2205 2: 3: Font
Action start 20:54:30: InstallValidate.
MSI (s) (EC:14) [20:54:30:171]: Note: 1: 2205 2: 3: _RemoveFilePath
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (EC:14) [20:54:30:281]: PROPERTY CHANGE: Modifying CostingComplete property. Its current value is '0'. Its new value: '1'.
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2205 2: 3: BindImage
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2262 2: PublishComponent 3: -2147287038
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2205 2: 3: Font
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2727 2:
MSI (s) (EC:14) [20:54:30:281]: Note: 1: 2727 2:
MSI (s) (EC:14) [20:54:30:281]: Doing action: InstallInitialize
Action ended 20:54:30: InstallValidate. Return value 1.
MSI (s) (EC:14) [20:54:30:281]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (EC:14) [20:54:30:296]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (EC:14) [20:54:30:296]: BeginTransaction: Locking Server
MSI (s) (EC:14) [20:54:30:296]: SRSetRestorePoint skipped for this transaction.
MSI (s) (EC:14) [20:54:30:296]: Server not locked: locking for product {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
Action start 20:54:30: InstallInitialize.
MSI (s) (EC:14) [20:54:31:500]: Doing action: SxsInstallCA
Action ended 20:54:31: InstallInitialize. Return value 1.
MSI (s) (EC:B0) [20:54:31:578]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI100.tmp, Entrypoint: CustomAction_SxsMsmInstall
MSI (s) (EC:A4) [20:54:31:578]: Generating random cookie.
MSI (s) (EC:A4) [20:54:31:593]: Created Custom Action Server with PID 2668 (0xA6C).
MSI (s) (EC:AC) [20:54:31:703]: Running as a service.
MSI (s) (EC:AC) [20:54:31:703]: Hello, I'm your 32bit Elevated custom action server.
Action start 20:54:31: SxsInstallCA.
1: sxsdelca 2: traceop 3: 1256 4: 0
1: sxsdelca 2: traceop 3: 1257 4: 0
1: sxsdelca 2: traceop 3: 1258 4: 0
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 1306 4: 0
1: sxsdelca 2: traceop 3: 1307 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 0
1: sxsdelca 2: traceop 3: 1288 4: 0
1: sxsdelca 2: traceop 3: 1289 4: 0
1: sxsdelca 2: traceop 3: 1290 4: 0
1: sxsdelca 2: traceop 3: 1292 4: 0
1: sxsdelca 2: traceop 3: 796 4: 0
1: sxsdelca 2: traceop 3: 801 4: 0
1: sxsdelca 2: traceop 3: 802 4: 0
1: sxsdelca 2: traceop 3: 803 4: 0
1: sxsdelca 2: traceop 3: 805 4: 0
1: sxsdelca 2: traceop 3: 812 4: 0
1: sxsdelca 2: traceop 3: 813 4: 0
1: sxsdelca 2: traceop 3: 814 4: 0
1: sxsdelca 2: traceop 3: 819 4: 0
1: sxsdelca 2: traceop 3: 820 4: 0
1: sxsdelca 2: traceop 3: 821 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 0
1: sxsdelca 2: traceop 3: 831 4: 0
1: sxsdelca 2: traceop 3: 827 4: 259
1: sxsdelca 2: traceop 3: 1311 4: 0
1: sxsdelca 2: traceop 3: 1312 4: 0
1: sxsdelca 2: traceop 3: 1077 4: 0
1: sxsdelca 2: traceop 3: 1081 4: 0
1: sxsdelca 2: traceop 3: 1083 4: 0
1: sxsdelca 2: traceop 3: 1087 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1097 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1101 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1105 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1109 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1113 4: 0
1: sxsdelca 2: traceop 3: 1093 4: 0
1: sxsdelca 2: traceop 3: 1117 4: 0
1: sxsdelca 2: traceop 3: 1121 4: 0
1: sxsdelca 2: traceop 3: 1313 4: 0
1: sxsdelca 2: traceop 3: 1314 4: 0
1: sxsdelca: Added reg value for 2: downlevel_manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
1: sxsdelca 2: traceop 3: 1284 4: 259
1: sxsdelca 2: SxsMsmInstall completed 3: 0 4: 0
MSI (s) (EC:14) [20:54:31:890]: Doing action: AllocateRegistrySpace
Action ended 20:54:31: SxsInstallCA. Return value 1.
Action start 20:54:31: AllocateRegistrySpace.
MSI (s) (EC:14) [20:54:31:906]: Doing action: ProcessComponents
Action ended 20:54:31: AllocateRegistrySpace. Return value 1.
MSI (s) (EC:14) [20:54:31:906]: Note: 1: 2205 2: 3: MsiPatchCertificate
MSI (s) (EC:14) [20:54:31:906]: LUA patching is disabled: missing MsiPatchCertificate table
MSI (s) (EC:14) [20:54:31:906]: Resolving source.
MSI (s) (EC:14) [20:54:31:906]: Resolving source to launched-from source.
MSI (s) (EC:14) [20:54:31:906]: Setting launched-from source as last-used.
MSI (s) (EC:14) [20:54:31:906]: PROPERTY CHANGE: Adding SourceDir property. Its value is 'c:\f543835665da81c0d6df901ff022\'.
MSI (s) (EC:14) [20:54:31:906]: PROPERTY CHANGE: Adding SOURCEDIR property. Its value is 'c:\f543835665da81c0d6df901ff022\'.
MSI (s) (EC:14) [20:54:31:906]: PROPERTY CHANGE: Adding SourcedirProduct property. Its value is '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (EC:14) [20:54:31:906]: SOURCEDIR ==> c:\f543835665da81c0d6df901ff022\
MSI (s) (EC:14) [20:54:31:906]: SOURCEDIR product ==> {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSI (s) (EC:14) [20:54:31:906]: Determining source type
MSI (s) (EC:14) [20:54:31:906]: Source type from package 'msxml.msi': 2
Action start 20:54:31: ProcessComponents.
MSI (s) (EC:14) [20:54:31:906]: Source path resolution complete. Dumping Directory table…
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: TARGETDIR , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WindowsFolder , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: CommonFilesFolder , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Microsoft Shared\ , ShortSubPath: MICROS~1\
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Microsoft Shared\MSDN\ , ShortSubPath: MICROS~1\MSDN\
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\system32\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\k0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\h0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\Manifests\ , ShortSubPath: Windows\winsxs\manifest\
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\Policies\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\Policies\i0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\j0r1wg7y.dqe\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\system32\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\8n0mtfut.k85\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\Policies\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\Policies\6n0mtfut.k85\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\Manifests\ , ShortSubPath: Windows\winsxs\manifest\
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\5n0mtfut.k85\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\7n0mtfut.k85\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\system32\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\wl34x2va.rt8\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\Policies\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\Policies\ul34x2va.rt8\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\Manifests\ , ShortSubPath: Windows\winsxs\manifest\
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\tl34x2va.rt8\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: Windows\winsxs\vl34x2va.rt8\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: System\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: DesktopFolder , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: ProgramFilesFolder , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: MSXML , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: redist\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: INC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: redist\inc\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: LIB.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: redist\lib\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: DOC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: redist\doc\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: redist\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: redist\MSXML 4.0\ , ShortSubPath: redist\MSXML4\
MSI (s) (EC:14) [20:54:31:906]: Dir (source): Key: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\f543835665da81c0d6df901ff022\ , LongSubPath: redist\ , ShortSubPath:
MSI (s) (EC:14) [20:54:31:921]: Doing action: UnpublishComponents
Action ended 20:54:31: ProcessComponents. Return value 1.
MSI (s) (EC:14) [20:54:31:921]: Note: 1: 2262 2: PublishComponent 3: -2147287038
Action start 20:54:31: UnpublishComponents.
MSI (s) (EC:14) [20:54:31:921]: Doing action: MsiUnpublishAssemblies
Action ended 20:54:31: UnpublishComponents. Return value 1.
Action start 20:54:31: MsiUnpublishAssemblies.
MSI (s) (EC:14) [20:54:31:921]: Doing action: UnpublishFeatures
Action ended 20:54:31: MsiUnpublishAssemblies. Return value 1.
Action start 20:54:31: UnpublishFeatures.
MSI (s) (EC:14) [20:54:31:921]: Doing action: StopServices
Action ended 20:54:31: UnpublishFeatures. Return value 1.
MSI (s) (EC:14) [20:54:31:921]: Note: 1: 2205 2: 3: ServiceControl
MSI (s) (EC:14) [20:54:31:921]: Note: 1: 2228 2: 3: ServiceControl 4: SELECT `Name`,`Wait`,`Arguments`,`Event`, `Action` FROM `ServiceControl`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 2)
Action start 20:54:31: StopServices.
MSI (s) (EC:14) [20:54:31:921]: Doing action: DeleteServices
Action ended 20:54:31: StopServices. Return value 1.
MSI (s) (EC:14) [20:54:31:921]: Note: 1: 2205 2: 3: ServiceControl
MSI (s) (EC:14) [20:54:31:921]: Note: 1: 2228 2: 3: ServiceControl 4: SELECT `Name`,`Wait`,`Arguments`,`Event`, `Action` FROM `ServiceControl`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 2)
Action start 20:54:31: DeleteServices.
MSI (s) (EC:14) [20:54:31:937]: Doing action: UnregisterComPlus
Action ended 20:54:31: DeleteServices. Return value 1.
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2205 2: 3: Complus
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2228 2: 3: Complus 4: SELECT `ComponentId`, `FileName`, `Component`.`Directory_`, `ExpType`, `Component`.`Action`, `Component`.`Installed` FROM `Complus`, `Component`, `File` WHERE `Complus`.`Component_` = `Component` AND `Component`.`KeyPath` = `File`.`File` AND `Action` = 0
Action start 20:54:31: UnregisterComPlus.
MSI (s) (EC:14) [20:54:31:937]: Doing action: SelfUnregModules
Action ended 20:54:31: UnregisterComPlus. Return value 0.
Action start 20:54:31: SelfUnregModules.
MSI (s) (EC:14) [20:54:31:937]: Doing action: UnregisterTypeLibraries
Action ended 20:54:31: SelfUnregModules. Return value 1.
Action start 20:54:31: UnregisterTypeLibraries.
MSI (s) (EC:14) [20:54:31:937]: Doing action: RemoveODBC
Action ended 20:54:31: UnregisterTypeLibraries. Return value 1.
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND `Component`.`Action` = 0 AND `BinaryType` = ?
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND `Component`.`Action` = 0 AND `BinaryType` = ?
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCTranslator`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCTranslator`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCDriver`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`, `RuntimeFlags`, `Component`.`Attributes` FROM `ODBCDriver`, `Component` WHERE `Component_` = `Component` AND `Component`.`ActionRequest` = 0 AND `BinaryType` = ?
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2711 2: ODBCDriverManager
Action start 20:54:31: RemoveODBC.
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2711 2: ODBCDriverManager64
MSI (s) (EC:14) [20:54:31:937]: Doing action: UnregisterFonts
Action ended 20:54:31: RemoveODBC. Return value 1.
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2205 2: 3: Font
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2228 2: 3: Font 4: SELECT `FontTitle`, `FileName`, `Directory_`, `Installed`From `Font`, `FileAction` Where `Font`.`File_` = `FileAction`.`File` And `FileAction`.`Action` = 0 ORDER BY `FileAction`.`Directory_`
Action start 20:54:31: UnregisterFonts.
MSI (s) (EC:14) [20:54:31:937]: Doing action: RemoveRegistryValues
Action ended 20:54:31: UnregisterFonts. Return value 1.
Action start 20:54:31: RemoveRegistryValues.
MSI (s) (EC:14) [20:54:31:937]: Doing action: UnregisterClassInfo
Action ended 20:54:31: RemoveRegistryValues. Return value 1.
Action start 20:54:31: UnregisterClassInfo.
MSI (s) (EC:14) [20:54:31:937]: Doing action: UnregisterExtensionInfo
Action ended 20:54:31: UnregisterClassInfo. Return value 1.
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 20:54:31: UnregisterExtensionInfo.
MSI (s) (EC:14) [20:54:31:937]: Doing action: UnregisterProgIdInfo
Action ended 20:54:31: UnregisterExtensionInfo. Return value 1.
MSI (s) (EC:14) [20:54:31:937]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 20:54:31: UnregisterProgIdInfo.
MSI (s) (EC:14) [20:54:31:937]: Doing action: UnregisterMIMEInfo
Action ended 20:54:31: UnregisterProgIdInfo. Return value 1.
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2262 2: MIME 3: -2147287038
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 20:54:31: UnregisterMIMEInfo.
MSI (s) (EC:14) [20:54:31:953]: Doing action: RemoveIniValues
Action ended 20:54:31: UnregisterMIMEInfo. Return value 1.
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2205 2: 3: IniFile
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2228 2: 3: IniFile 4: SELECT `FileName`,`IniFile`.`DirProperty`,`Section`,`IniFile`.`Key`,`IniFile`.`Value`,`IniFile`.`Action` FROM `IniFile`, `Component` WHERE `Component`=`Component_` AND `Component`.`Action`=0 ORDER BY `FileName`,`Section`
Action start 20:54:31: RemoveIniValues.
MSI (s) (EC:14) [20:54:31:953]: Doing action: RemoveShortcuts
Action ended 20:54:31: RemoveIniValues. Return value 1.
Action start 20:54:31: RemoveShortcuts.
MSI (s) (EC:14) [20:54:31:953]: Doing action: RemoveEnvironmentStrings
Action ended 20:54:31: RemoveShortcuts. Return value 1.
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2205 2: 3: Environment
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2228 2: 3: Environment 4: SELECT `Name`,`Value` FROM `Environment`,`Component` WHERE `Component_`=`Component` AND (`Component`.`Action` = 0)
Action start 20:54:31: RemoveEnvironmentStrings.
MSI (s) (EC:14) [20:54:31:953]: Doing action: RemoveDuplicateFiles
Action ended 20:54:31: RemoveEnvironmentStrings. Return value 1.
Action start 20:54:31: RemoveDuplicateFiles.
MSI (s) (EC:14) [20:54:31:953]: Doing action: RemoveFiles
Action ended 20:54:31: RemoveDuplicateFiles. Return value 1.
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2205 2: 3: RemoveFile
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2205 2: 3: RemoveFile
Action start 20:54:31: RemoveFiles.
MSI (s) (EC:14) [20:54:31:953]: Doing action: RemoveFolders
Action ended 20:54:31: RemoveFiles. Return value 0.
Action start 20:54:31: RemoveFolders.
MSI (s) (EC:14) [20:54:31:953]: Doing action: CreateFolders
Action ended 20:54:31: RemoveFolders. Return value 1.
Action start 20:54:31: CreateFolders.
MSI (s) (EC:14) [20:54:31:953]: Doing action: MoveFiles
Action ended 20:54:31: CreateFolders. Return value 1.
Action start 20:54:31: MoveFiles.
MSI (s) (EC:14) [20:54:31:953]: Doing action: InstallFiles
Action ended 20:54:31: MoveFiles. Return value 1.
Action start 20:54:31: InstallFiles.
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2205 2: 3: Patch
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2228 2: 3: Patch 4: SELECT `Patch`.`File_`, `Patch`.`Header`, `Patch`.`Attributes`, `Patch`.`Sequence`, `Patch`.`StreamRef_` FROM `Patch` WHERE `Patch`.`File_` = ? AND `Patch`.`#_MsiActive`=? ORDER BY `Patch`.`Sequence`
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2228 2: 3: MsiPatchHeaders 4: SELECT `Header` FROM `MsiPatchHeaders` WHERE `StreamRef` = ?
MSI (s) (EC:14) [20:54:31:953]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (EC:14) [20:54:31:968]: Doing action: PatchFiles
Action ended 20:54:31: InstallFiles. Return value 1.
MSI (s) (EC:14) [20:54:31:968]: Note: 1: 2205 2: 3: Patch
MSI (s) (EC:14) [20:54:31:968]: Note: 1: 2228 2: 3: Patch 4: SELECT `File`,`FileName`,`FileSize`,`Directory_`,`PatchSize`,`File`.`Attributes`,`Patch`.`Attributes`,`Patch`.`Sequence`,`Component`.`Component`,`Component`.`ComponentId` FROM `File`,`Component`,`Patch` WHERE `Patch`.`#_MsiActive`=? AND `File`=`File_` AND `Component`=`Component_` ORDER BY `Patch`.`Sequence`
Action start 20:54:31: PatchFiles.
MSI (s) (EC:14) [20:54:31:968]: Doing action: DuplicateFiles
Action ended 20:54:31: PatchFiles. Return value 0.
Action start 20:54:31: DuplicateFiles.
MSI (s) (EC:14) [20:54:31:968]: Doing action: BindImage
Action ended 20:54:31: DuplicateFiles. Return value 1.
Action start 20:54:31: BindImage.
MSI (s) (EC:14) [20:54:31:968]: Doing action: CreateShortcuts
Action ended 20:54:31: BindImage. Return value 1.
Action start 20:54:31: CreateShortcuts.
MSI (s) (EC:14) [20:54:31:968]: Doing action: RegisterClassInfo
Action ended 20:54:31: CreateShortcuts. Return value 1.
Action start 20:54:31: RegisterClassInfo.
MSI (s) (EC:14) [20:54:31:968]: Doing action: RegisterExtensionInfo
Action ended 20:54:31: RegisterClassInfo. Return value 1.
MSI (s) (EC:14) [20:54:31:968]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 20:54:31: RegisterExtensionInfo.
MSI (s) (EC:14) [20:54:31:984]: Doing action: RegisterProgIdInfo
Action ended 20:54:31: RegisterExtensionInfo. Return value 1.
MSI (s) (EC:14) [20:54:31:984]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 20:54:31: RegisterProgIdInfo.
MSI (s) (EC:14) [20:54:31:984]: Doing action: RegisterMIMEInfo
Action ended 20:54:31: RegisterProgIdInfo. Return value 1.
MSI (s) (EC:14) [20:54:31:984]: Note: 1: 2262 2: MIME 3: -2147287038
MSI (s) (EC:14) [20:54:31:984]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 20:54:31: RegisterMIMEInfo.
MSI (s) (EC:14) [20:54:31:984]: Doing action: WriteRegistryValues
Action ended 20:54:31: RegisterMIMEInfo. Return value 1.
Action start 20:54:31: WriteRegistryValues.
MSI (s) (EC:14) [20:54:32:015]: Doing action: WriteIniValues
Action ended 20:54:32: WriteRegistryValues. Return value 1.
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2205 2: 3: IniFile
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2228 2: 3: IniFile 4: SELECT `FileName`,`IniFile`.`DirProperty`,`Section`,`IniFile`.`Key`,`IniFile`.`Value`,`IniFile`.`Action` FROM `IniFile`, `Component` WHERE `Component`=`Component_` AND (`Component`.`Action`=1 OR `Component`.`Action`=2) ORDER BY `FileName`,`Section`
Action start 20:54:32: WriteIniValues.
MSI (s) (EC:14) [20:54:32:015]: Doing action: WriteEnvironmentStrings
Action ended 20:54:32: WriteIniValues. Return value 1.
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2205 2: 3: Environment
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2228 2: 3: Environment 4: SELECT `Name`,`Value` FROM `Environment`,`Component` WHERE `Component_`=`Component` AND (`Component`.`Action` = 1 OR `Component`.`Action` = 2)
Action start 20:54:32: WriteEnvironmentStrings.
MSI (s) (EC:14) [20:54:32:015]: Doing action: RegisterFonts
Action ended 20:54:32: WriteEnvironmentStrings. Return value 1.
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2205 2: 3: Font
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2228 2: 3: Font 4: SELECT `FontTitle`, `FileName`, `Directory_`, `Action` From `Font`, `FileAction` Where `Font`.`File_` = `FileAction`.`File` And (`FileAction`.`Action` = 1 Or `FileAction`.`Action` = 2) ORDER BY `FileAction`.`Directory_`
Action start 20:54:32: RegisterFonts.
MSI (s) (EC:14) [20:54:32:015]: Doing action: InstallODBC
Action ended 20:54:32: RegisterFonts. Return value 1.
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2711 2: ODBCDriverManager
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2711 2: ODBCDriverManager64
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCDriver`, `File`, `Component` WHERE `File_` = `File` AND `ODBCDriver`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `Driver`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCDriver`, `File`, `Component` WHERE `File_` = `File` AND `ODBCDriver`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCTranslator`, `File`, `Component` WHERE `File_` = `File` AND `ODBCTranslator`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `Translator`,`ComponentId`,`Description`,`RuntimeFlags`,`Directory_`,`FileName`,`File_Setup`,`Action` FROM `ODBCTranslator`, `File`, `Component` WHERE `File_` = `File` AND `ODBCTranslator`.`Component_` = `Component` AND (`Component`.`ActionRequest` = 1 OR `Component`.`ActionRequest` = 2) AND `BinaryType` = ?
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND (`Component`.`Action` = 1 OR `Component`.`Action` = 2) AND `BinaryType` = ?
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2205 2: 3: ODBCDataSource
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2228 2: 3: ODBCDataSource 4: SELECT `DataSource`,`ComponentId`,`DriverDescription`,`Description`,`Registration` FROM `ODBCDataSource`, `Component` WHERE `Component_` = `Component` AND (`Component`.`Action` = 1 OR `Component`.`Action` = 2) AND `BinaryType` = ?
Action start 20:54:32: InstallODBC.
MSI (s) (EC:14) [20:54:32:015]: Doing action: RegisterTypeLibraries
Action ended 20:54:32: InstallODBC. Return value 0.
Action start 20:54:32: RegisterTypeLibraries.
MSI (s) (EC:14) [20:54:32:015]: Doing action: SelfRegModules
Action ended 20:54:32: RegisterTypeLibraries. Return value 1.
Action start 20:54:32: SelfRegModules.
MSI (s) (EC:14) [20:54:32:015]: Doing action: RegisterComPlus
Action ended 20:54:32: SelfRegModules. Return value 1.
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2205 2: 3: Complus
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2228 2: 3: Complus 4: SELECT `ComponentId`, `FileName`, `Component`.`Directory_`, `ExpType`, `Component`.`Action`, `Component`.`Installed` FROM `Complus`, `Component`, `File` WHERE `Complus`.`Component_` = `Component` AND `Component`.`KeyPath` = `File`.`File` AND (`Action` = 1 OR `Action` = 2)
Action start 20:54:32: RegisterComPlus.
MSI (s) (EC:14) [20:54:32:015]: Doing action: InstallServices
Action ended 20:54:32: RegisterComPlus. Return value 0.
MSI (s) (EC:14) [20:54:32:015]: Detected older ServiceInstall table schema
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2205 2: 3: ServiceInstall
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2228 2: 3: ServiceInstall 4: SELECT `Name`,`DisplayName`,`ServiceType`,`StartType`,`ErrorControl`,`LoadOrderGroup`,`Dependencies`,`StartName`,`Password`,`ComponentId`,`Directory_`,`FileName`,`Arguments` FROM `ServiceInstall`, `Component`, `File` WHERE `ServiceInstall`.`Component_` = `Component`.`Component` AND (`Component`.`KeyPath` = `File`.`File`) AND (`Action` = 1 OR `Action` = 2)
Action start 20:54:32: InstallServices.
MSI (s) (EC:14) [20:54:32:015]: Doing action: StartServices
Action ended 20:54:32: InstallServices. Return value 1.
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2205 2: 3: ServiceControl
MSI (s) (EC:14) [20:54:32:015]: Note: 1: 2228 2: 3: ServiceControl 4: SELECT `Name`,`Wait`,`Arguments`,`Event`, `Action` FROM `ServiceControl`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 2)
Action start 20:54:32: StartServices.
MSI (s) (EC:14) [20:54:32:015]: Doing action: RegisterUser
Action ended 20:54:32: StartServices. Return value 1.
Action start 20:54:32: RegisterUser.
MSI (s) (EC:14) [20:54:32:015]: Doing action: RegisterProduct
Action ended 20:54:32: RegisterUser. Return value 1.
Action start 20:54:32: RegisterProduct.
MSI (s) (EC:14) [20:54:32:031]: PROPERTY CHANGE: Adding ProductToBeRegistered property. Its value is '1'.
MSI (s) (EC:14) [20:54:32:031]: Doing action: PublishComponents
Action ended 20:54:32: RegisterProduct. Return value 1.
MSI (s) (EC:14) [20:54:32:031]: Note: 1: 2262 2: PublishComponent 3: -2147287038
Action start 20:54:32: PublishComponents.
MSI (s) (EC:14) [20:54:32:031]: Doing action: MsiPublishAssemblies
Action ended 20:54:32: PublishComponents. Return value 1.
Action start 20:54:32: MsiPublishAssemblies.
MSI (s) (EC:14) [20:54:32:031]: Doing action: PublishFeatures
Action ended 20:54:32: MsiPublishAssemblies. Return value 1.
Action start 20:54:32: PublishFeatures.
MSI (s) (EC:14) [20:54:32:031]: Doing action: PublishProduct
Action ended 20:54:32: PublishFeatures. Return value 1.
Action start 20:54:32: PublishProduct.
MSI (s) (EC:14) [20:54:32:031]: Doing action: InstallFinalize
Action ended 20:54:32: PublishProduct. Return value 1.
MSI (s) (EC:14) [20:54:32:031]: Running Script: C:\WINDOWS\Installer\MSI101.tmp
MSI (s) (EC:14) [20:54:32:031]: PROPERTY CHANGE: Adding UpdateStarted property. Its value is '1'.
MSI (s) (EC:14) [20:54:32:046]: Machine policy value 'DisableRollback' is 0
MSI (s) (EC:14) [20:54:32:046]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (EC:14) [20:54:32:062]: Executing op: Header(Signature=1397708873,Version=301,Timestamp=896706256,LangId=1033,Platform
=0,ScriptType=1,ScriptMajorVersion=21,ScriptMinorVersion=4,ScriptAttributes=1)
Action start 20:54:32: InstallFinalize.
MSI (s) (EC:14) [20:54:32:062]: Executing op: ProductInfo(ProductKey={37477865-A3F1-4772-AD43-AAFC6BCFF99F},ProductName=MSXML 4.0 SP2 (KB927978),PackageName=msxml.msi,Language=1033,Version=68429425,Assignment=1,Obs
oleteArg=0,,,PackageCode={2B27DCD9-53FA-4885-B6CD-698623819F4C},,,InstanceType=0,LUASetting=0,RemoteURTInstalls=0)
MSI (s) (EC:14) [20:54:32:078]: Executing op: DialogInfo(Type=0,Argument=1033)
MSI (s) (EC:14) [20:54:32:078]: Executing op: DialogInfo(Type=1,Argument=MSXML 4.0 SP2 (KB927978))
MSI (s) (EC:14) [20:54:32:078]: Executing op: RollbackInfo(,RollbackAction=Rollback,RollbackDescription=Rolling back action:,RollbackTemplate=[1],CleanupAction=RollbackCleanup,CleanupDescription=Re
moving backup files,CleanupTemplate=File: [1])
MSI (s) (EC:14) [20:54:32:078]: Executing op: SetBaseline(Baseline=0,)
MSI (s) (EC:14) [20:54:32:078]: Executing op: SetBaseline(Baseline=1,)
MSI (s) (EC:14) [20:54:32:078]: Executing op: ActionStart(Name=ProcessComponents,Description=Updating component registration,)
MSI (s) (EC:14) [20:54:32:078]: Executing op: ProgressTotal(Total=5,Type=1,ByteEquivalent=24000)
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentUnregister(ComponentId={E9BC82F6-AC0E-407C-8666-619D6D60DF2B},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (EC:14) [20:54:32:078]: Note: 1: 1402 2: UNKNOWN\Components\6F28CB9EE0CAC704686616D9D606FDB2 3: 2
MSI (s) (EC:14) [20:54:32:078]: Note: 1: 1402 2: UNKNOWN\Components\6F28CB9EE0CAC704686616D9D606FDB2 3: 2
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentUnregister(ComponentId={81754FFD-DA2B-49C6-9447-E1C1E1733BB6},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (EC:14) [20:54:32:078]: Note: 1: 1402 2: UNKNOWN\Components\DFF45718B2AD6C9449741E1C1E37B36B 3: 2
MSI (s) (EC:14) [20:54:32:078]: Note: 1: 1402 2: UNKNOWN\Components\DFF45718B2AD6C9449741E1C1E37B36B 3: 2
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentUnregister(ComponentId={5E6714E1-EA46-4B0F-B479-06D87058DC74},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (EC:14) [20:54:32:078]: Note: 1: 1402 2: UNKNOWN\Components\1E4176E564AEF0B44B97608D0785CD47 3: 2
MSI (s) (EC:14) [20:54:32:078]: Note: 1: 1402 2: UNKNOWN\Components\1E4176E564AEF0B44B97608D0785CD47 3: 2
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentUnregister(ComponentId={57E0F99D-E884-4BD0-B8CB-803CF9EA2066},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (EC:14) [20:54:32:078]: Note: 1: 1402 2: UNKNOWN\Components\D99F0E75488E0DB48BBC08C39FAE0266 3: 2
MSI (s) (EC:14) [20:54:32:078]: Note: 1: 1402 2: UNKNOWN\Components\D99F0E75488E0DB48BBC08C39FAE0266 3: 2
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentUnregister(ComponentId={C763CD13-6E1E-4166-8C78-D274B266E9B6},,BinaryType=0,PreviouslyPinned=1)
MSI (s) (EC:14) [20:54:32:078]: Note: 1: 1402 2: UNKNOWN\Components\31DC367CE1E66614C8872D472B669E6B 3: 2
MSI (s) (EC:14) [20:54:32:078]: Note: 1: 1402 2: UNKNOWN\Components\31DC367CE1E66614C8872D472B669E6B 3: 2
MSI (s) (EC:14) [20:54:32:078]: Executing op: ProgressTotal(Total=14,Type=1,ByteEquivalent=24000)
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentRegister(ComponentId={4075CDF6-D88F-4F57-AF1A-29A124755695},KeyPath=c:\Program Files\MSXML 4.0\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentRegister(ComponentId={D21D9CCD-C3FA-4D72-982F-C29A2DE361EC},KeyPath=02:\Software\Microsoft\Updates\MSXML4SP2\Q927978\Description,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentRegister(ComponentId={4B1F71A7-50C6-44B7-A3AD-B6C3574BB896},KeyPath=c:\WINDOWS\system32\msxml4.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentRegister(ComponentId={62846705-2671-4547-AB45-854DCC93B3C7},KeyPath=c:\WINDOWS\system32\msxml4r.dll,State=3,,Disk=1,SharedDllRefCount=1,BinaryType=0)
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentRegister(ComponentId={3AAE95CD-F592-46E7-89A1-9B56717C4413},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentRegister(ComponentId={CCF8B6EF-5FB9-4DE1-A276-683008BA3485},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentRegister(ComponentId={7B2FCEFF-0F22-B7E1-A06B-D6B9ABF34537},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (EC:14) [20:54:32:078]: Executing op: ComponentRegister(ComponentId={7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\downlevel_manifest\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ComponentRegister(ComponentId={7B2FCEFF-0F22-B7E1-B06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\downlevel_payload\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ComponentRegister(ComponentId={DA6654F6-456F-3658-A06B-D6B9ABF34537},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ComponentRegister(ComponentId={DA6654F6-456F-3658-C06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\downlevel_manifest\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ComponentRegister(ComponentId={DA6654F6-456F-3658-B06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\downlevel_payload\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ComponentRegister(ComponentId={0E9F98FC-A692-A6DF-A06B-D6B9ABF34537},,State=-7,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ComponentRegister(ComponentId={0E9F98FC-A692-A6DF-C06B-D6B9ABF34537},KeyPath=02:\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\downlevel_manifest\,State=3,,Disk=1,SharedDllRefCount=0,BinaryType=0)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (EC:14) [20:54:32:093]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ProgressTick()
MSI (s) (EC:14) [20:54:32:093]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)
MSI (s) (EC:14) [20:54:32:093]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ProgressTick()
MSI (s) (EC:14) [20:54:32:093]: Executing op: ActionStart(Name=RemoveODBC,Description=Removing ODBC components,)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ODBCDriverManager(,BinaryType=0)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ODBCDriverManager(,BinaryType=1)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ActionStart(Name=CreateFolders,Description=Creating folders,Template=Folder: [1])
MSI (s) (EC:14) [20:54:32:093]: Executing op: FolderCreate(Folder=c:\Program Files\MSXML 4.0\,Foreign=0,)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ActionStart(Name=InstallFiles,Description=Copying new files,Template=File: [1], Directory: [9], Size: [6])
MSI (s) (EC:14) [20:54:32:093]: Executing op: ProgressTotal(Total=2521072,Type=0,ByteEquivalent=1)
MSI (s) (EC:14) [20:54:32:093]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\system32\)
MSI (s) (EC:14) [20:54:32:093]: Executing op: SetSourceFolder(Folder=1\System\)
MSI (s) (EC:14) [20:54:32:093]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,MediaCabinet=XML_Core.cab,BytesPerTick=32768,CopierType=2,ModuleFileName=c:\WINDOWS\Installer\3c2210d.msi,,,,,IsFirstPhysicalMedia=1)
MSI (s) (EC:14) [20:54:32:093]: Executing op: FileCopy(SourceName=msxml4.dll,SourceCabKey=msxml4.dll.246EB7AD_459A_4FA8_83D1_4
1A46D7634B7,DestName=msxml4.dll,Attributes=512,FileSize=1245696,PerTick=32768,,Ve
rifyMedia=1,,,,,CheckCRC=0,Version=4.20.9841.0,Language=0,InstallMode=58982400,,,
,,,,)
MSI (s) (EC:14) [20:54:32:093]: File: c:\WINDOWS\system32\msxml4.dll; Overwrite; Won't patch; Existing file is a lower version
MSI (s) (EC:14) [20:54:32:093]: Source for file 'msxml4.dll.246EB7AD_459A_4FA8_83D1_41A46D7634B7' is compressed
MSI (s) (EC:14) [20:54:32:093]: Re-applying security from existing file.
MSI (s) (EC:14) [20:54:32:109]: Verifying accessibility of file: msxml4.dll
MSI (s) (EC:14) [20:54:32:125]: SOFTWARE RESTRICTION POLICY: Verifying object –> 'c:\WINDOWS\Installer\3c2210d.msi' against software restriction policy
MSI (s) (EC:14) [20:54:32:125]: SOFTWARE RESTRICTION POLICY: c:\WINDOWS\Installer\3c2210d.msi has a digital signature
MSI (s) (EC:14) [20:54:32:171]: SOFTWARE RESTRICTION POLICY: c:\WINDOWS\Installer\3c2210d.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (EC:14) [20:54:32:171]: Note: 1: 2318 2: c:\WINDOWS\system32\msxml4.dll
MSI (s) (EC:14) [20:54:32:171]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:187]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:203]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:218]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:218]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:218]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:218]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:218]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:218]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:218]: Executing op: FileCopy(SourceName=msxml4r.dll,SourceCabKey=msxml4r.dll.246EB7AD_459A_4FA8_83D1
_41A46D7634B7,DestName=msxml4r.dll,Attributes=512,FileSize=82432,PerTick=32768,,V
erifyMedia=1,,,,,CheckCRC=0,Version=4.10.9404.0,Language=1033,InstallMode=5898240
0,,,,,,,)
MSI (s) (EC:14) [20:54:32:218]: File: c:\WINDOWS\system32\msxml4r.dll; Won't Overwrite; Won't patch; Existing file is of an equal version
MSI (s) (EC:14) [20:54:32:218]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\Manifests\)
MSI (s) (EC:14) [20:54:32:218]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\manifest\|Windows\winsxs\Manifests\)
MSI (s) (EC:14) [20:54:32:218]: Executing op: FileCopy(SourceName=xl34x2va.rt8|x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841
.0_x-ww_18171213.manifest,SourceCabKey=manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537,
DestName=x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest,,FileSize=3973,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,
,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-85909274,HashPart2=-393638470,HashPart3=495071453,HashPart4=945762879,,)
MSI (s) (EC:14) [20:54:32:218]: File: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest; To be installed; Won't patch; No existing file
MSI (s) (EC:14) [20:54:32:218]: Source for file 'manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537' is compressed
MSI (s) (EC:14) [20:54:32:234]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest
MSI (s) (EC:14) [20:54:32:234]: Executing op: FileCopy(SourceName=yl34x2va.rt8|x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841
.0_x-ww_18171213.cat,SourceCabKey=catalog.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537,DestNa
me=x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat,,FileSize=8347,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,,,Ch
eckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1679697816,HashPart2=1808584787,HashPart3=1425912084,HashPart4=629236904,,)
MSI (s) (EC:14) [20:54:32:234]: File: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat; To be installed; Won't patch; No existing file
MSI (s) (EC:14) [20:54:32:234]: Source for file 'catalog.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537' is compressed
MSI (s) (EC:14) [20:54:32:234]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat
MSI (s) (EC:14) [20:54:32:234]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\)
MSI (s) (EC:14) [20:54:32:234]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\tl34x2va.rt8\)
MSI (s) (EC:14) [20:54:32:234]: Executing op: FileCopy(SourceName=1m34x2va.rt8|msxml4.dll,SourceCabKey=msxml4.dll.7B2FCEFF_0F2
2_B7E1_FF6B_D6B9ABF34537,DestName=msxml4.dll,,FileSize=1245696,PerTick=32768,,Ver
ifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,Version=4.20.9841.0,Language=0,InstallMod
e=58982400,,,,,,,)
MSI (s) (EC:14) [20:54:32:234]: File: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\msxml4.dll; To be installed; Won't patch; No existing file
MSI (s) (EC:14) [20:54:32:234]: Source for file 'msxml4.dll.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537' is compressed
MSI (s) (EC:14) [20:54:32:250]: Note: 1: 2318 2: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\msxml4.dll
MSI (s) (EC:14) [20:54:32:250]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:250]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:250]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:250]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:250]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:250]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:250]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:250]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:250]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:250]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:250]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:265]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:281]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:281]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:281]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:281]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:281]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:281]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:281]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:281]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:281]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:281]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:281]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:281]: Note: 1: 2360
MSI (s) (EC:14) [20:54:32:296]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\Manifests\)
MSI (s) (EC:14) [20:54:32:296]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\manifest\|Windows\winsxs\Manifests\)
MSI (s) (EC:14) [20:54:32:296]: Executing op: FileCopy(SourceName=9n0mtfut.k85|x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_
x-ww_29c3ad6a.manifest,SourceCabKey=manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537,
DestName=x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.manifest,,FileSize=500,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,
,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-707213148,HashPart2=1938794768,HashPart3=-933075776,HashPart4=-843550219,,)
MSI (s) (EC:14) [20:54:32:296]: File: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.manifest; Won't Overwrite; Won't patch; Existing file is unversioned and unmodified - hash matches source file
MSI (s) (EC:14) [20:54:32:296]: Executing op: FileCopy(SourceName=an0mtfut.k85|x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_
x-ww_29c3ad6a.cat,SourceCabKey=catalog.DA6654F6_456F_3658_FF6B_D6B9ABF34537,DestNa
me=x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat,,FileSize=8349,PerTick=32768,,VerifyMedia=1,ElevateFlags=4,,,,Ch
eckCRC=0,,,InstallMode=58982400,HashOptions=0,HashPart1=-1336197992,HashPart2=-627824155,HashPart3=82633343,HashPart4=1105156543,,)
MSI (s) (EC:14) [20:54:32:296]: File: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat; Overwrite; Won't patch; Existing file is unversioned and unmodified - hash doesn't match source file
MSI (s) (EC:14) [20:54:32:296]: Source for file 'catalog.DA6654F6_456F_3658_FF6B_D6B9ABF34537' is compressed
MSI (s) (EC:14) [20:54:32:296]: Re-applying security from existing file.
MSI (s) (EC:14) [20:54:32:484]: Verifying accessibility of file: x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat
MSI (s) (EC:14) [20:54:32:484]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Manifests\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat
MSI (s) (EC:14) [20:54:32:515]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\)
MSI (s) (EC:14) [20:54:32:515]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\5n0mtfut.k85\)
MSI (s) (EC:14) [20:54:32:515]: Executing op: FileCopy(SourceName=dn0mtfut.k85|msxml4r.dll,SourceCabKey=msxml4r.dll.DA6654F6_4
56F_3658_FF6B_D6B9ABF34537,DestName=msxml4r.dll,,FileSize=82432,PerTick=32768,,Ve
rifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,Version=4.10.9404.0,Language=1033,Instal
lMode=58982400,,,,,,,)
MSI (s) (EC:14) [20:54:32:515]: File: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\msxml4r.dll; Won't Overwrite; Won't patch; Existing file is of an equal version
MSI (s) (EC:14) [20:54:32:515]: Executing op: SetTargetFolder(Folder=c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\)
MSI (s) (EC:14) [20:54:32:515]: Executing op: SetSourceFolder(Folder=1\Windows\winsxs\Policies\i0r1wg7y.dqe\)
MSI (s) (EC:14) [20:54:32:515]: Executing op: FileCopy(SourceName=l0r1wg7y.dqe|4.20.9841.0.policy,SourceCabKey=manifest.0E9F98
FC_A692_A6DF_FF6B_D6B9ABF34537,DestName=4.20.9841.0.policy,,FileSize=652,PerTick=
32768,,VerifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,,,InstallMode=58982400,HashOpti
ons=0,HashPart1=49613189,HashPart2=1139053242,HashPart3=-1699064514,HashPart4=-854272932,,)
MSI (s) (EC:14) [20:54:32:515]: File: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.policy; To be installed; Won't patch; No existing file
MSI (s) (EC:14) [20:54:32:515]: Source for file 'manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537' is compressed
MSI (s) (EC:14) [20:54:32:515]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.policy
MSI (s) (EC:14) [20:54:32:531]: Executing op: FileCopy(SourceName=m0r1wg7y.dqe|4.20.9841.0.cat,SourceCabKey=catalog.0E9F98FC_A
692_A6DF_FF6B_D6B9ABF34537,DestName=4.20.9841.0.cat,,FileSize=8359,PerTick=32768,
,VerifyMedia=1,ElevateFlags=4,,,,CheckCRC=0,,,InstallMode=58982400,HashOptions=0,
HashPart1=-861819424,HashPart2=1423527147,HashPart3=-1146259424,HashPart4=2040409349,,)
MSI (s) (EC:14) [20:54:32:531]: File: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.cat; To be installed; Won't patch; No existing file
MSI (s) (EC:14) [20:54:32:531]: Source for file 'catalog.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537' is compressed
MSI (s) (EC:14) [20:54:32:531]: Note: 1: 2318 2: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.cat
MSI (s) (EC:14) [20:54:32:531]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,MediaCabinet=XML_SDK.cab,BytesPerTick=32768,CopierType=2,ModuleFileName=c:\WINDOWS\Installer\3c2210d.msi,,,,,IsFirstPhysicalMedia=1)
MSI (s) (EC:14) [20:54:32:531]: Executing op: CacheSizeFlush(,)
MSI (s) (EC:14) [20:54:32:531]: Executing op: InstallProtectedFiles(AllowUI=0)
MSI (s) (EC:14) [20:54:32:531]: Executing op: ActionStart(Name=WriteRegistryValues,Description=Writing system registry values,Template=Key: [1], Name: [2], Value: [3])
MSI (s) (EC:14) [20:54:32:531]: Executing op: ProgressTotal(Total=112,Type=1,ByteEquivalent=13200)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegAddValue(,Value=XML DOM Document 4.0,)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegOpenKey(,Key=Msxml2.DOMDocument.4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegAddValue(,Value=XML DOM Document 4.0,)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegAddValue(,Value=Msxml2.DOMDocument.4.0,)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegOpenKey(,Key=CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegOpenKey(,Key=Msxml2.DOMDocument.4.0\CLSID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:531]: Executing op: RegAddValue(,Value={88D969C0-F192-11D4-A65F-0040963251E5},)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=Free Threaded XML DOM Document 4.0,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=Msxml2.FreeThreadedDOMDocument.4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=Free Threaded XML DOM Document 4.0,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=Msxml2.FreeThreadedDOMDocument.4.0,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=Msxml2.FreeThreadedDOMDocument.4.0\CLSID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value={88D969C1-F192-11D4-A65F-0040963251E5},)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=XML Data Source Object 4.0,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(Name=ThreadingModel,Value=Apartment,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=Msxml2.DSOControl.4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=XML Data Source Object 4.0,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=Msxml2.DSOControl.4.0,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=Msxml2.DSOControl.4.0\CLSID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value={88D969C4-F192-11D4-A65F-0040963251E5},)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=XML HTTP 4.0,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(Name=ThreadingModel,Value=Apartment,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=Msxml2.XMLHTTP.4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=XML HTTP 4.0,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=Msxml2.XMLHTTP.4.0,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegOpenKey(,Key=CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:546]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=Msxml2.XMLHTTP.4.0\CLSID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value={88D969C5-F192-11D4-A65F-0040963251E5},)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=Server XML HTTP 4.0,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(Name=ThreadingModel,Value=Apartment,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=Msxml2.ServerXMLHTTP.4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=Server XML HTTP 4.0,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=Msxml2.ServerXMLHTTP.4.0,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\TypeLib,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value={F5078F18-C551-11D3-89B9-0000F81FE221},)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=Msxml2.ServerXMLHTTP.4.0\CLSID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value={88D969C6-F192-11D4-A65F-0040963251E5},)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C2-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=XML Schema Cache 4.0,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=Msxml2.XMLSchemaCache.4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=XML Schema Cache 4.0,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=Msxml2.XMLSchemaCache.4.0,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=Msxml2.XMLSchemaCache.4.0\CLSID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value={88D969C2-F192-11D4-A65F-0040963251E5},)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C3-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=XSL Template 4.0,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=Msxml2.XSLTemplate.4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=XSL Template 4.0,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=Msxml2.XSLTemplate.4.0,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegOpenKey(,Key=Msxml2.XSLTemplate.4.0\CLSID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:562]: Executing op: RegAddValue(,Value={88D969C3-F192-11D4-A65F-0040963251E5},)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=SAX XML Reader 4.0,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=Msxml2.SAXXMLReader.4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=SAX XML Reader 4.0,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\ProgID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=Msxml2.SAXXMLReader.4.0,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\Version,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=Msxml2.SAXXMLReader.4.0\CLSID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value={7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F},)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=MX XML Reader 4.0,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{88D969C8-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=MXXMLWriter 4.0,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=Msxml2.MXXMLWriter.4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=MXXMLWriter 4.0,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=Msxml2.MXXMLWriter.4.0,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=Msxml2.MXXMLWriter.4.0\CLSID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value={88D969C8-F192-11D4-A65F-0040963251E5},)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{88D969C9-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=MXHTMLWriter 4.0,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=Msxml2.MXHTMLWriter.4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=MXHTMLWriter 4.0,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=Msxml2.MXHTMLWriter.4.0,)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegOpenKey(,Key=CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:578]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=Msxml2.MXHTMLWriter.4.0\CLSID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value={88D969C9-F192-11D4-A65F-0040963251E5},)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=CLSID\{88D969CA-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value=SAXAttributes 4.0,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=Msxml2.SAXAttributes.4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value=SAXAttributes 4.0,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value=Msxml2.SAXAttributes.4.0,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=Msxml2.SAXAttributes.4.0\CLSID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value={88D969CA-F192-11D4-A65F-0040963251E5},)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=CLSID\{88D969D6-F192-11D4-A65F-0040963251E5},,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value=MXNamespaceManager 4.0,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\InProcServer32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(Name=ThreadingModel,Value=Both,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=Msxml2.MXNamespaceManager.4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value=MXNamespaceManager 4.0,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\ProgID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value=Msxml2.MXNamespaceManager.4.0,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\Version,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value=4.0,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(,Key=Msxml2.MXNamespaceManager.4.0\CLSID,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value={88D969D6-F192-11D4-A65F-0040963251E5},)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Updates\MSXML4SP2\Q927978,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(Name=Description,Value=FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(Name=InstalledDate,Value=11/18/2006,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(Name=InstalledBy,Value=Paul A. Parone,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(Name=IsInstalled,Value=#1,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(Name=ServicePack,Value=#1,)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:593]: Executing op: RegAddValue(,Value=Microsoft XML, v4.0,)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\0,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(,,)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\0\win32,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(,Value=c:\WINDOWS\system32\msxml4.dll,)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\FLAGS,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(,Value=0,)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Classes\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\HELPDIR,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(,,)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\downlevel_payload,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(,,)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\downlevel_manifest,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(,,)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\downlevel_payload,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(,,)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\downlevel_manifest,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(,,)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\downlevel_manifest,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(,,)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\SideBySide\PatchedComponents,,BinaryType=0)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(Name={7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\Manifests\\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest[~]{7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Manifests\\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat[~]{7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Manifests\[~]{7B2FCEFF-0F22-B7E1-C06B-D6B9ABF34537},)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(Name={7B2FCEFF-0F22-B7E1-B06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\\msxml4.dll[~]{7B2FCEFF-0F22-B7E1-B06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\[~]{7B2FCEFF-0F22-B7E1-B06B-D6B9ABF34537},)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(Name={DA6654F6-456F-3658-C06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\Manifests\\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.manifest[~]{DA6654F6-456F-3658-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Manifests\\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat[~]{DA6654F6-456F-3658-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Manifests\[~]{DA6654F6-456F-3658-C06B-D6B9ABF34537},)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(Name={DA6654F6-456F-3658-B06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\\msxml4r.dll[~]{DA6654F6-456F-3658-B06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\[~]{DA6654F6-456F-3658-B06B-D6B9ABF34537},)
MSI (s) (EC:14) [20:54:32:609]: Executing op: RegAddValue(Name={0E9F98FC-A692-A6DF-C06B-D6B9ABF34537},Value=c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\\4.20.9841.0.policy[~]{0E9F98FC-A692-A6DF-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\\4.20.9841.0.cat[~]{0E9F98FC-A692-A6DF-C06B-D6B9ABF34537}[~]c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\[~]{0E9F98FC-A692-A6DF-C06B-D6B9ABF34537},)
MSI (s) (EC:14) [20:54:32:609]: Executing op: ActionStart(Name=RegisterTypeLibraries,Description=Registering type libraries,Template=LibID: [1])
MSI (s) (EC:14) [20:54:32:609]: Executing op: TypeLibraryRegister(,,FilePath=c:\WINDOWS\system32\msxml4.dll,LibID={F5078F18-C551-11D3-89B9-0000F81FE221},Version=1024,,Language=0,,BinaryType=0,IgnoreRegistrationFailure=0
)
MSI (s) (EC:14) [20:54:32:625]: QueryPathOfRegTypeLib returned 0 in local context. Path is 'c:\WINDOWS\system32\msxml4.dll'
MSI (s) (EC:14) [20:54:32:625]: Note: 1: 1402 2: UNKNOWN\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\400.0\0\win32 3: 2
MSI (s) (EC:14) [20:54:32:625]: CMsiServices::ProcessTypeLibrary runs in local context, not impersonated.
MSI (s) (EC:14) [20:54:32:953]: ProcessTypeLibraryCore returns: 0. (0 means OK)
MSI (s) (EC:14) [20:54:32:953]: CMsiServices::ProcessTypeLibrary runs in local context, not impersonated.
MSI (s) (EC:14) [20:54:32:984]: ProcessTypeLibraryCore returns: 0. (0 means OK)
MSI (s) (EC:14) [20:54:32:984]: Executing op: ActionStart(Name=RegisterUser,Description=Registering user,Template=[1])
MSI (s) (EC:14) [20:54:32:984]: Executing op: UserRegister(Owner=Paul A. Parone,,ProductId=none)
MSI (s) (EC:14) [20:54:32:984]: Executing op: ActionStart(Name=RegisterProduct,Description=Registering product,Template=[1])
MSI (s) (EC:14) [20:54:33:000]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,MediaCabinet=XML_Core.cab,BytesPerTick=0,CopierType=2,ModuleFileName=c:\WINDOWS\Installer\3c2210d.msi,,,,,IsFirstPhysicalMedia=1)
MSI (s) (EC:14) [20:54:33:000]: Executing op: DatabaseCopy(DatabasePath=c:\WINDOWS\Installer\3c2210d.msi,ProductCode={37477865-A3F1-4772-AD43-AAFC6BCFF99F},CabinetStreams=XML_Core.cab;XML_SDK.cab,,)
MSI (s) (EC:14) [20:54:33:203]: Executing op: ProductRegister(UpgradeCode={7CE723E3-E56B-432C-9F24-78C0606045A5},VersionString=4.20.9841.0,HelpLink=http://support.microsoft.com/kb/927978,,,InstallSource=c:\f543835665da81c0d6df901ff022\,Publisher=Microsoft Corporation,,,,,,,,,,,,EstimatedSize=2625)
MSI (s) (EC:14) [20:54:33:218]: Executing op: ProductCPDisplayInfoRegister()
MSI (s) (EC:14) [20:54:33:218]: Executing op: ActionStart(Name=PublishFeatures,Description=Publishing Product Features,Template=Feature: [1])
MSI (s) (EC:14) [20:54:33:234]: Executing op: FeaturePublish(Feature=MSXML,,Absent=2,Component=MF}e835XRAhvfl[X%h~W(s-UlQ2mt@MgogY-xd{t)
MSI (s) (EC:14) [20:54:33:234]: Executing op: FeaturePublish(Feature=MSXMLSYS,Parent=MSXML,Absent=2,Component=V2?0@7$9*=IdbugpYRMX}GHaGLdZ==A&kv@Y~]3iui-r60O)l=Em%pCn7G4))
MSI (s) (EC:14) [20:54:33:234]: Executing op: FeaturePublish(Feature=MSXMLSUPP2,Parent=MSXML,Absent=2,Component=?`ZsjqO[%A*`NW3OG&nR)
MSI (s) (EC:14) [20:54:33:234]: Executing op: FeaturePublish(Feature=MSXMLSXS,Parent=MSXML,Absent=2,Component=LdCZOHqG+dpWsfdD
E!j5LdCZOHqG+d6XsfdDE!j5LdCZOHqG+d%XsfdDE!j5`DM4olJ_O5pWsfdDE!j5`DM4olJ_O56XsfdDE!j5`DM4olJ_O5%XsfdDE!j5l0Rd'9?m^^pWsfdDE!j5l0Rd'9?m^^6XsfdDE!j5)
MSI (s) (EC:14) [20:54:33:234]: Executing op: FeaturePublish(Feature=XMLSDK,,Absent=3,Component=mk`[Q=PRe?RvYBgpXHXc5~{DF_B]-@1_XLnB~RWMMvh8D]u5G@j^sM7=J&oH0G,*i]!a$9uKNVM3Kykc)
MSI (s) (EC:14) [20:54:33:234]: Executing op: ActionStart(Name=PublishProduct,Description=Publishing product information,)
MSI (s) (EC:14) [20:54:33:234]: Executing op: IconCreate(Icon=icon.exe,Data=BinaryData)
MSI (s) (EC:14) [20:54:33:250]: Executing op: CleanupConfigData()
MSI (s) (EC:14) [20:54:33:250]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\568774731F3A2774DA34AACFB6FC9FF9\Patches 3: 2
MSI (s) (EC:14) [20:54:33:250]: Executing op: RegisterPatchOrder(Continue=0,SequenceType=1,Remove=0)
MSI (s) (EC:14) [20:54:33:250]: Note: 1: 1402 2: UNKNOWN\Products\568774731F3A2774DA34AACFB6FC9FF9\Patches 3: 2
MSI (s) (EC:14) [20:54:33:250]: Executing op: ProductPublish(PackageKey={2B27DCD9-53FA-4885-B6CD-698623819F4C})
MSI (s) (EC:14) [20:54:33:250]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (EC:14) [20:54:33:250]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (EC:14) [20:54:33:250]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (EC:14) [20:54:33:250]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (EC:14) [20:54:33:250]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (EC:14) [20:54:33:250]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (EC:14) [20:54:33:250]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (EC:14) [20:54:33:250]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (EC:14) [20:54:33:250]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (EC:14) [20:54:33:250]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9 3: 2
MSI (s) (EC:14) [20:54:33:265]: Executing op: UpgradeCodePublish(UpgradeCode={7CE723E3-E56B-432C-9F24-78C0606045A5})
MSI (s) (EC:14) [20:54:33:265]: Executing op: SourceListPublish(,,,,NumberOfDisks=2)
MSI (s) (EC:14) [20:54:33:265]: Note: 1: 1402 2: UNKNOWN\Installer\Products\568774731F3A2774DA34AACFB6FC9FF9\SourceList 3: 2
MSI (s) (EC:14) [20:54:33:265]: Executing op: ProductPublishClient(,,)
MSI (s) (EC:14) [20:54:33:265]: Executing op: SourceListRegisterLastUsed(SourceProduct={37477865-A3F1-4772-AD43-AAFC6BCFF99F},LastUsedSource=c:\f543835665da81c0d6df901ff022\)
MSI (s) (EC:14) [20:54:33:265]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (EC:14) [20:54:33:265]: Specifed source is already in a list.
MSI (s) (EC:14) [20:54:33:265]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (EC:14) [20:54:33:265]: Machine policy value 'DisableBrowse' is 0
MSI (s) (EC:14) [20:54:33:265]: Machine policy value 'AllowLockdownBrowse' is 0
MSI (s) (EC:14) [20:54:33:265]: Adding new sources is allowed.
MSI (s) (EC:14) [20:54:33:265]: Set LastUsedSource to: c:\f543835665da81c0d6df901ff022\.
MSI (s) (EC:14) [20:54:33:265]: Set LastUsedType to: n.
MSI (s) (EC:14) [20:54:33:265]: Set LastUsedIndex to: 1.
MSI (s) (EC:14) [20:54:33:265]: Executing op: End(Checksum=0,ProgressTotalHDWord=0,ProgressTotalLDWord=4481872)
MSI (s) (EC:14) [20:54:33:265]: User policy value 'DisableRollback' is 0
MSI (s) (EC:14) [20:54:33:265]: Machine policy value 'DisableRollback' is 0
MSI (s) (EC:14) [20:54:33:343]: No System Restore sequence number for this installation.
MSI (s) (EC:14) [20:54:33:343]: Unlocking Server
MSI (s) (EC:14) [20:54:33:343]: PROPERTY CHANGE: Deleting UpdateStarted property. Its current value is '1'.
MSI (s) (EC:14) [20:54:33:359]: Skipping action: SxsUninstallCA (condition is false)
MSI (s) (EC:14) [20:54:33:359]: Doing action: RemoveExistingProducts
Action ended 20:54:33: InstallFinalize. Return value 1.
Action start 20:54:33: RemoveExistingProducts.
Action ended 20:54:33: RemoveExistingProducts. Return value 1.
Action ended 20:54:33: INSTALL. Return value 1.
Property(S): ProductName = MSXML 4.0 SP2 (KB927978)
Property(S): ProductCode = {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
Property(S): Manufacturer = Microsoft Corporation
Property(S): ProductVersion = 4.20.9841.0
Property(S): ProductLanguage = 1033
Property(S): BannerBitmap = bannrbmp
Property(S): IAgree = No
Property(S): ProductID = none
Property(S): ARPHELPLINK = http://support.microsoft.com/kb/927978
Property(S): ButtonText_Back = < &Back
Property(S): ButtonText_Browse = Br&owse
Property(S): ButtonText_Cancel = Cancel
Property(S): ButtonText_Exit = &Exit
Property(S): ButtonText_Finish = &Finish
Property(S): ButtonText_Ignore = &Ignore
Property(S): ButtonText_Install = &Install
Property(S): ButtonText_InstallNow = &Install Now
Property(S): ButtonText_Next = &Next >
Property(S): ButtonText_No = &No
Property(S): ButtonText_OK = OK
Property(S): ButtonText_Remove = &Remove
Property(S): ButtonText_Reset = &Reset
Property(S): ButtonText_Resume = &Resume
Property(S): ButtonText_Retry = &Retry
Property(S): ButtonText_Return = &Return
Property(S): ButtonText_Yes = &Yes
Property(S): CompleteSetupIcon = completi
Property(S): CustomSetupIcon = custicon
Property(S): DialogBitmap = dlgbmp
Property(S): DlgTitleFont = {&DlgFontBold8}
Property(S): ExclamationIcon = exclamic
Property(S): InfoIcon = info
Property(S): InstallerIcon = insticon
Property(S): INSTALLLEVEL = 3
Property(S): InstallModeTxt_1 = Custom
Property(S): InstallModeVal = InstallModeTxt_1
Property(S): InstallModeTxt_2 = Complete
Property(S): InstallModeTxt_3 = Server Image
Property(S): InstallModeTxt_4 = Change
Property(S): InstallModeTxt_5 = Repair
Property(S): InstallModeTxt_6 = Remove
Property(S): PIDTemplate = 12345<###-%%%%%%%>@@@@@
Property(S): Progress1Txt_1 = Installing
Property(S): Progress1 = Progress1Txt_1
Property(S): Progress2Txt_1 = installs
Property(S): Progress2 = Progress2Txt_1
Property(S): Progress1Txt_2 = Changing
Property(S): Progress2Txt_2 = changes
Property(S): Progress1Txt_3 = Repairing
Property(S): Progress2Txt_3 = repairs
Property(S): Progress1Txt_4 = Removing
Property(S): Progress2Txt_4 = removes
Property(S): PROMPTROLLBACKCOST = P
Property(S): RemoveIcon = removico
Property(S): RepairIcon = repairic
Property(S): Setup = Setup
Property(S): Wizard = Setup Wizard
Property(S): DefaultUIFont = DlgFont8
Property(S): ErrorDialog = ErrorDlg
Property(S): TARGETDIR = c:\
Property(S): USERNAME = Paul A. Parone
Property(S): APPS_TEST = 1
Property(S): VersionNT = 501
Property(S): SecureCustomProperties = MSXML4SP2
Property(S): UpgradeCode = {7CE723E3-E56B-432C-9F24-78C0606045A5}
Property(S): ALLUSERS = 1
Property(S): WINHTTP_51 = WinHttpRequest Component version 5.1
Property(S): MSXML = c:\Program Files\MSXML 4.0\
Property(S): SourceDir = c:\f543835665da81c0d6df901ff022\
Property(S): DesktopFolder = c:\Documents and Settings\All Users\Desktop\
Property(S): ProgramFilesFolder = c:\Program Files\
Property(S): ProductState = -1
Property(S): PackageCode = {2B27DCD9-53FA-4885-B6CD-698623819F4C}
Property(S): SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 = c:\WINDOWS\system32\
Property(S): SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 = c:\WINDOWS\system32\
Property(S): SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB = c:\WINDOWS\system32\
Property(S): WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\
Property(S): payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\
Property(S): payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
Property(S): WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Manifests\
Property(S): WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\
Property(S): SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\system32\
Property(S): WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\
Property(S): policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\
Property(S): policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
Property(S): WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\
Property(S): payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\
Property(S): payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
Property(S): WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Manifests\
Property(S): WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\
Property(S): SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\system32\
Property(S): WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\
Property(S): policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\
Property(S): policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
Property(S): WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\
Property(S): payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa692
0e9f98fc\
Property(S): WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\
Property(S): policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\
Property(S): WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\
Property(S): SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\system32\
Property(S): WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\Manifests\
Property(S): payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
Property(S): policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 = c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
Property(S): DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Documents and Settings\All Users\Desktop\
Property(S): ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Documents and Settings\All Users\Start Menu\Programs\
Property(S): MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\
Property(S): DOC.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Program Files\MSXML 4.0\doc\
Property(S): LIB.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Program Files\MSXML 4.0\lib\
Property(S): INC.4576A2F1_959E_4BCA_94A9_596523761901 = c:\Program Files\MSXML 4.0\inc\
Property(S): CommonFilesFolder = c:\Program Files\Common Files\
Property(S): MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 = c:\Program Files\Common Files\Microsoft Shared\
Property(S): MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 = c:\Program Files\Common Files\Microsoft Shared\MSDN\
Property(S): Date = 11/18/2006
Property(S): PackagecodeChanging = 1
Property(S): REBOOT = ReallySuppress
Property(S): CURRENTDIRECTORY = c:\f543835665da81c0d6df901ff022
Property(S): CLIENTUILEVEL = 3
Property(S): CLIENTPROCESSID = 2136
Property(S): VersionDatabase = 200
Property(S): VersionMsi = 3.01
Property(S): WindowsBuild = 2600
Property(S): ServicePackLevel = 2
Property(S): ServicePackLevelMinor = 0
Property(S): MsiNTProductType = 1
Property(S): WindowsFolder = c:\WINDOWS\
Property(S): WindowsVolume = c:\
Property(S): SystemFolder = C:\WINDOWS\system32\
Property(S): System16Folder = C:\WINDOWS\system\
Property(S): RemoteAdminTS = 1
Property(S): TempFolder = C:\WINDOWS\TEMP\
Property(S): AppDataFolder = C:\WINDOWS\system32\config\systemprofile\Application Data\
Property(S): FavoritesFolder = C:\WINDOWS\system32\config\systemprofile\Favorites\
Property(S): NetHoodFolder = C:\WINDOWS\system32\config\systemprofile\NetHood\
Property(S): PersonalFolder = C:\WINDOWS\system32\config\systemprofile\My Documents\
Property(S): PrintHoodFolder = C:\WINDOWS\system32\config\systemprofile\PrintHood\
Property(S): RecentFolder = C:\WINDOWS\system32\config\systemprofile\Recent\
Property(S): SendToFolder = C:\WINDOWS\system32\config\systemprofile\SendTo\
Property(S): TemplateFolder = C:\Documents and Settings\All Users\Templates\
Property(S): CommonAppDataFolder = C:\Documents and Settings\All Users\Application Data\
Property(S): LocalAppDataFolder = C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\
Property(S): MyPicturesFolder = C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures\
Property(S): AdminToolsFolder = C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\
Property(S): StartupFolder = C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Property(S): ProgramMenuFolder = C:\Documents and Settings\All Users\Start Menu\Programs\
Property(S): StartMenuFolder = C:\Documents and Settings\All Users\Start Menu\
Property(S): FontsFolder = C:\WINDOWS\Fonts\
Property(S): GPTSupport = 1
Property(S): OLEAdvtSupport = 1
Property(S): ShellAdvtSupport = 1
Property(S): Intel = 15
Property(S): PhysicalMemory = 1015
Property(S): VirtualMemory = 2159
Property(S): AdminUser = 1
Property(S): LogonUser = SYSTEM
Property(S): UserSID = S-1-5-18
Property(S): UserLanguageID = 1033
Property(S): ComputerName = IBM-546DEA067E3
Property(S): SystemLanguageID = 1033
Property(S): ScreenX = 1024
Property(S): ScreenY = 768
Property(S): CaptionHeight = 26
Property(S): BorderTop = 1
Property(S): BorderSide = 1
Property(S): TextHeight = 16
Property(S): ColorBits = 16
Property(S): TTCSupport = 1
Property(S): Time = 20:54:33
Property(S): MsiNetAssemblySupport = 1.1.4322.573
Property(S): MsiWin32AssemblySupport = 5.1.2600.2180
Property(S): RedirectedDllSupport = 2
Property(S): Privileged = 1
Property(S): DATABASE = c:\WINDOWS\Installer\3c2210d.msi
Property(S): OriginalDatabase = c:\f543835665da81c0d6df901ff022\msxml.msi
Property(S): UILevel = 2
Property(S): ACTION = INSTALL
Property(S): ROOTDRIVE = c:\
Property(S): CostingComplete = 1
Property(S): OutOfDiskSpace = 0
Property(S): OutOfNoRbDiskSpace = 0
Property(S): PrimaryVolumeSpaceAvailable = 0
Property(S): PrimaryVolumeSpaceRequired = 0
Property(S): PrimaryVolumeSpaceRemaining = 0
Property(S): SOURCEDIR = c:\f543835665da81c0d6df901ff022\
Property(S): SourcedirProduct = {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
Property(S): ProductToBeRegistered = 1
MSI (s) (EC:14) [20:54:33:437]: Note: 1: 1707
MSI (s) (EC:14) [20:54:33:437]: Product: MSXML 4.0 SP2 (KB927978) – Installation completed successfully.
MSI (s) (EC:14) [20:54:33:453]: Cleaning up uninstalled install packages, if any exist
MSI (s) (EC:14) [20:54:33:468]: MainEngineThread is returning 0
MSI (s) (EC:38) [20:54:33:578]: Destroying RemoteAPI object.
MSI (s) (EC:A4) [20:54:33:578]: Custom Action Manager thread ending.
=== Logging stopped: 11/18/2006 20:54:33 ===
MSI © (58:14) [20:54:33:578]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1
MSI © (58:14) [20:54:33:578]: MainEngineThread is returning 0
=== Verbose logging stopped: 11/18/2006 20:54:33 ===
BHowett,
After an all day series of scans I posted up some results yesterday. I did a Malewarebytes scan last night, as well as a Spybot run.
Malewarebytes saw nothing.
thats what we wanted
that could be cookies, with out the file path I can't tell but Malewarebytes targets MyWebSearch so its not a threat or it would of showed up in the log.However, Spybot's scan saw 2 threats labeled the usual MyWay.MyWebSearch.xxx, with 2 entries below. When I hit the clean button Spybot checked one of them. The other is still on. Unfortunately I do NOT see a log file for Spybot, otherwise I would show you that info.
This file is created by the Microsoft Security update on 11/18/2006 and it not harmful, you can delete if if you like.new info . . . I referred to a log file I discovered back in Nov. 2006 which I believe started my troubles, called
msxml(small L)4-KB927978-enu.log . This morning I was going through my directory, folders and files and stumbled upon that file. Since that is in notepad I am posting that below, as it may give you an idea what it is and what started it. It is massively long.
AskSBar can be removed through add/remove programs. I was going to advise removing it anyway because its a junk program.in addition, there is one file that will not delete that I uncovered. It is in the AskSBar directory, SrchAstt folder, 1.bin subfolder and called A2SRCHAS.DLL. (66K) I often back door into my temporary internet files folder, and manually delete everything. The file titled B1[1] always re-creates itself, and attaches that re-creation to others, often called pixel[1] and others.
This is the one I suspect we need to kill. Attempts at deleting the file and folders via Windows all fail.
looks like we got everything… now time for some clean up
ComboFix Removal
Follow these steps to uninstall Combofix and tools used in the removal of malware
- Click START then RUN
- Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
[external image: Posted Image]
OTCleanIt
Download OTCleanit
Save it to your Desktop.
- Double-click on OTCleanIt.exe to run
- Click on the CleanUp! button
- Click Yes to begin the Cleanup process and remove these components, including this application.
- You may be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
===============================================
and just to make sure we are good to go, please post a fresh Malewarebytes & HijackThis log
Fresh Malwarebytes and Hijack This logfiles below. Notes:
- spybot still sees two infections with MyWay.MyWebSearch:
- a registry file titled SBI $AF599DF9
- a file titled SBI $BCCFFOB2
I cannot delete the directory or file in Windows Explorer.
- AskSBar does not appear in my add/delete programs lineup.
- I still cannot see the "temporary internet files" folder for the folder with my name in Local Settings.
- it seemed like ComboFix /u removed none of the apps I used.
- after completing the OTCleanit step I received a flood of popups for Access Violations with the same four addresses. The reply button was empty, I clicked the "x" in the upper right and re-booted to do these scans.
- finally, I found more Symantec traces in my directory and removed all the files.
Question:
- suggestions on what AV/spyware app to keep or delete?
- leave modified safe mode upon startup and return to normal windows?
- OK to defrag?
thx,
paultpa
Malwarebytes' Anti-Malware 1.32
Database version: 1620
Windows 5.1.2600 Service Pack 3
1/6/2009 2:29:59 PM
mbam-log-2009-01-06 (14-29-59).txt
Scan type: Full Scan (C:\|F:\|)
Objects scanned: 123227
Time elapsed: 1 hour(s), 3 minute(s), 27 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:31:14 PM, on 1/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\System32\drivers\trcboot.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Personal Communications\PCS_AGNT.EXE
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\WINDOWS\WRTService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\tp4serv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\CheckPoint\Integrity Client\iclient.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [TrackPointSrv] "C:\WINDOWS\system32\tp4serv.exe"
O4 - HKLM\..\Run: [IgfxTray] "C:\WINDOWS\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [TPKMAPHELPER] "C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" -helper
O4 - HKLM\..\Run: [TPHOTKEY] "C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe"
O4 - HKLM\..\Run: [TP4EX] "C:\WINDOWS\system32\tp4ex.exe"
O4 - HKLM\..\Run: [EZEJMNAP] "C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe"
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] "C:\WINDOWS\system32\dla\tfswctrl.exe"
O4 - HKLM\..\Run: [IBMPRC] "C:\IBMTOOLS\UTILS\ibmprc.exe"
O4 - HKLM\..\Run: [QCWLICON] "C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE"
O4 - HKLM\..\Run: [BMMGAG] "C:\WINDOWS\system32\rundll32.exe" C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] "C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE"
O4 - HKLM\..\Run: [BMMMONWND] "C:\WINDOWS\system32\rundll32.exe" C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [Motive SmartBridge] "C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CheckPoint\Integrity Client\iclient.exe"
O4 - HKLM\..\Run: [Iomega Startup Options] "C:\Program Files\Iomega\Common\ImgStart.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] "C:\Program Files\Iomega\DriveIcons\ImgIcon.exe"
O4 - HKLM\..\Run: [stgclean] "c:\sdwork\w32main2.exe" /cleanup
O4 - HKLM\..\Run: [QCTray] "C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ISSI EZUpdate Service] "c:\sdwork\issimsvc.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Iomega Active Disk] "C:\Program Files\Iomega\AutoDisk\AD2KClient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1201959414343
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control) - https://www-1.ibm.com/sametime/stmeetingroo…STJNILoader.cab
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} (LNWebAssist Class) - http://w3.ibm.com/bluepages/scripts/lnwebassist.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://regatta.mcsgroup.com/dwa7W.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mlmeetings.webex.com/client/v_myweb…ent/ieatgpc.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Iomega Activity Disk2 - Iomega Corporation - C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Program Files\lotus\notes\ntmulti.exe
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TrcBoot - Unknown owner - C:\WINDOWS\System32\drivers\trcboot.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
O23 - Service: WRT Service (WRTService) - Unknown owner - C:\WINDOWS\WRTService.exe
–
End of file - 11950 bytes
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI