I'd appreciate another set of eyes on my HJT log.
Logfile of HijackThis v1.99.1
Scan saved at 6:00:00 AM, on 11/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\MICROS~4\OFFICE11\OUTLOOK.EXE
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.mywa...idebar.jsp?p=DE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://office.micros...te/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://soccernet.espn.go.com
O15 - Trusted Zone: http://www.majorgeeks.com
O15 - Trusted Zone: http://portal.partners.org
O15 - Trusted Zone: www.zonelabs.com
O16 - DPF: {225781F3-B27C-4182-83F1-CBF79247D36B} (PHSVPNPortal.VPNPortalCtl) - http://portal.partne...HSVPNPortal.CAB
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://vpnclients.partners.org/dana-cached...oterisSetup.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1158801254296
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion...canner37670.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
2nd pair of eyes on HJT log
Started by ajd24, Nov 20 2006 05:10 PM
6 replies to this topic
#1 OFFLINE
Posted 20 November 2006 - 05:10 PM
#2 OFFLINE
Posted 20 November 2006 - 09:14 PM
Run the following online scan: Panda ActiveScan.
Copy and paste the result of the above scan into your next reply along with a fresh HJT log AND a description of how your PC is running.
Also, run HJT:
- Please note that IE is required to run this scan.
- You will need to fill in the "Country, region, email address" information before you can download and install the ActiveX components necessary to run the scan.
- When you are asked to "Select a device to scan...", click on "My Computer".
Copy and paste the result of the above scan into your next reply along with a fresh HJT log AND a description of how your PC is running.
Also, run HJT:
- Click Open the Misc Tools section.
- Click Open Uninstall Manager...
- Click Save list... and save it to your Desktop.
- Copy and paste the file uninstall_list.txt into your next reply.
Team Numpty - Poking a finger in the eye of malware since a week last Thursday!
#3 OFFLINE
Posted 21 November 2006 - 03:33 PM
Thanks Novicate. Below I show the log files for all the things you suggested I do.
==============================================
1) Panda ActiveScan.txt
Incident Status Location
Potentially unwanted tool:Application/MyWay Not disinfected
===============================================
2) Hijack This Uninstall_list.txt
Ad-Aware SE Personal
Adobe Reader 7.0
AOLIcon
Apple Software Update
Business Objects Planning
Cache Cleaner
CCleaner (remove only)
Cisco
Citrix Web Client
Conexant D110 MDC V.9x Modem
Corel Photo Album 6
Dell Driver Reset Tool
Dell Media Experience
Dell Support 3.1
Dell Wireless WLAN Card
Digital Content Portal
Digital Line Detect
DMX Update
EducateU
Eraser
GdiplusUpgrade
Get High Speed Internet!
HDCleaner
HijackThis 1.99.1
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
HP Extended Capabilities 4.7
HP Image Zone 4.7
HP PSC & OfficeJet 4.7
HP Software Update
Intel® Graphics Media Accelerator Driver for Mobile
Intel® PRO Network Adapters and Drivers
Intel® PROSet for Wired Connections
Internal Network Card Power Management
Internet Explorer Default Page
iTunes
Java 2 Runtime Environment, SE v1.4.2_03
Learn2 Player (Uninstall Only)
Macromedia Flash Player
Macromedia Flash Player 8
McAfee SecurityCenter
McAfee VirusScan
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Modem Helper
Mozilla Firefox (1.5.0.8)
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
Musicmatch® Jukebox
MyWay Search Assistant
NetWaiting
Panda ActiveScan
Photo Click
PowerDVD 5.5
Qualxserve Service Agreement
QuickBooks Simple Start Special Edition
QuickSet
QuickTime
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB925486)
Sonic Audio module
Sonic DLA
Sonic MyDVD LE
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spybot - Search & Destroy 1.4
SpywareBlaster v3.5.1
SpywareGuard v2.2
Synaptics Pointing Device Driver
TweakNow RegCleaner Standard
Update for Windows XP (KB904942)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
URGE
Viewpoint Media Player
VPN Client
WebCyberCoach 3.2 Dell
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player 11
ZoneAlarm
=======================================
3) Hijack This log file after running Panda Active scan, & then Spybot Search & Destroy
Logfile of HijackThis v1.99.1
Scan saved at 7:51:23 AM, on 11/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\HijackThis\HijackThis.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.mywa...idebar.jsp?p=DE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://office.micros...te/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://soccernet.espn.go.com
O15 - Trusted Zone: http://www.majorgeeks.com
O15 - Trusted Zone: http://portal.partners.org
O15 - Trusted Zone: www.zonelabs.com
O16 - DPF: {225781F3-B27C-4182-83F1-CBF79247D36B} (PHSVPNPortal.VPNPortalCtl) - http://portal.partne...HSVPNPortal.CAB
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://vpnclients.partners.org/dana-cached...oterisSetup.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1158801254296
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion...canner37670.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
=======================================
How's my computer running? It seems fine. What bad signs should I be looking for? Its a year old Dell Inspiron 2200 laptop. I connect to the internet through a Netgear wireless router. I use Firefox as my browser with NoScript & Mcafee SiteAdvisor added in. My firewall is ZoneAlarm. McAfee is my anti-virus. I run Spybot S&D & Ad-aware SE Personal a couple of times a week each.
Thanks in advance for you advice.
==============================================
1) Panda ActiveScan.txt
Incident Status Location
Potentially unwanted tool:Application/MyWay Not disinfected
===============================================
2) Hijack This Uninstall_list.txt
Ad-Aware SE Personal
Adobe Reader 7.0
AOLIcon
Apple Software Update
Business Objects Planning
Cache Cleaner
CCleaner (remove only)
Cisco
Citrix Web Client
Conexant D110 MDC V.9x Modem
Corel Photo Album 6
Dell Driver Reset Tool
Dell Media Experience
Dell Support 3.1
Dell Wireless WLAN Card
Digital Content Portal
Digital Line Detect
DMX Update
EducateU
Eraser
GdiplusUpgrade
Get High Speed Internet!
HDCleaner
HijackThis 1.99.1
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
HP Extended Capabilities 4.7
HP Image Zone 4.7
HP PSC & OfficeJet 4.7
HP Software Update
Intel® Graphics Media Accelerator Driver for Mobile
Intel® PRO Network Adapters and Drivers
Intel® PROSet for Wired Connections
Internal Network Card Power Management
Internet Explorer Default Page
iTunes
Java 2 Runtime Environment, SE v1.4.2_03
Learn2 Player (Uninstall Only)
Macromedia Flash Player
Macromedia Flash Player 8
McAfee SecurityCenter
McAfee VirusScan
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Modem Helper
Mozilla Firefox (1.5.0.8)
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
Musicmatch® Jukebox
MyWay Search Assistant
NetWaiting
Panda ActiveScan
Photo Click
PowerDVD 5.5
Qualxserve Service Agreement
QuickBooks Simple Start Special Edition
QuickSet
QuickTime
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB925486)
Sonic Audio module
Sonic DLA
Sonic MyDVD LE
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spybot - Search & Destroy 1.4
SpywareBlaster v3.5.1
SpywareGuard v2.2
Synaptics Pointing Device Driver
TweakNow RegCleaner Standard
Update for Windows XP (KB904942)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
URGE
Viewpoint Media Player
VPN Client
WebCyberCoach 3.2 Dell
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player 11
ZoneAlarm
=======================================
3) Hijack This log file after running Panda Active scan, & then Spybot Search & Destroy
Logfile of HijackThis v1.99.1
Scan saved at 7:51:23 AM, on 11/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\HijackThis\HijackThis.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.mywa...idebar.jsp?p=DE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://office.micros...te/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://soccernet.espn.go.com
O15 - Trusted Zone: http://www.majorgeeks.com
O15 - Trusted Zone: http://portal.partners.org
O15 - Trusted Zone: www.zonelabs.com
O16 - DPF: {225781F3-B27C-4182-83F1-CBF79247D36B} (PHSVPNPortal.VPNPortalCtl) - http://portal.partne...HSVPNPortal.CAB
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://vpnclients.partners.org/dana-cached...oterisSetup.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1158801254296
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion...canner37670.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
=======================================
How's my computer running? It seems fine. What bad signs should I be looking for? Its a year old Dell Inspiron 2200 laptop. I connect to the internet through a Netgear wireless router. I use Firefox as my browser with NoScript & Mcafee SiteAdvisor added in. My firewall is ZoneAlarm. McAfee is my anti-virus. I run Spybot S&D & Ad-aware SE Personal a couple of times a week each.
Thanks in advance for you advice.
#4 OFFLINE
Posted 21 November 2006 - 07:53 PM
The log looks OK to me, but this little post should give you a double check:
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.
Preparation
1) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.
If you already have this program installed, skip to Updating AVG Anti-Spyware: below.
* Please note that this program was formerly known as Ewido anti-spyware 4.0. Taken from the Ewido website:
Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.
AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.
2) You will need to know how to boot into Safe Mode.
Instructions can be found here.
3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **
4) Log off from the internet and disconnect your modem cable for the duration of the fix.
Removal
1) Boot into Safe Mode.
2) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.
3) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.
4) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files...
Check the box to the left of 'Delete all offline content' and then click on OK.
5) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
6) Boot into Normal Mode.
Post a new HJT log (run in Normal Mode), the AVG A-S log AND a description of how your PC is running.
I don't expect to see anything of real interest, but post it anyway.
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.
Preparation
1) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.
If you already have this program installed, skip to Updating AVG Anti-Spyware: below.
* Please note that this program was formerly known as Ewido anti-spyware 4.0. Taken from the Ewido website:
Quote
ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:
Highly improved cleaning
Lower resource usage
Additional languages supported
All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.
Highly improved cleaning
Lower resource usage
Additional languages supported
All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.
When the program has been installed, and you click the Finish button, AVG A-S will open.
- Updating AVG Anti-Spyware:
- Click the Update icon at the top and under "Manual Update" - click the Start update button.
- Either AVG A-S will update or inform you that no update was available.
- If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
Once you have installed AVG A-S, double click avgas-signatures-full-current.exe to update it.
Disabling the Resident Shield:
- By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
(When the PC has been cleaned you can activate the shield again, if you wish.) - Click the Shield icon at the top and under "Resident shield is..." - click active.
- This should now change to inactive.
Changing Recommended Actions
- Click the Scanner icon at the top and then click the Settings Tab.
- Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.
2) You will need to know how to boot into Safe Mode.
Instructions can be found here.
3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **
4) Log off from the internet and disconnect your modem cable for the duration of the fix.
Removal
1) Boot into Safe Mode.
2) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.
3) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.
4) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files...
Check the box to the left of 'Delete all offline content' and then click on OK.
5) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
- If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
- Click "Complete System Scan"
- While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
- When the scan has completed, any threats that AVG A-S has detected will be displayed.
- Click the Apply all actions button at the bottom.
- When AVG A-S has finished, it will display the message "All actions have been applied".
Saving a report:
- Click the Save Report button at the bottom left and the "Reports" window will open.
- The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
- You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
6) Boot into Normal Mode.
Post a new HJT log (run in Normal Mode), the AVG A-S log AND a description of how your PC is running.
I don't expect to see anything of real interest, but post it anyway.
Team Numpty - Poking a finger in the eye of malware since a week last Thursday!
#5 OFFLINE
Posted 24 November 2006 - 02:13 AM
Hi. I just discovered this log file from a program I don't recognize. This is from a back up desktop I use running Windows XP (and not the laptop you've helped me with up to now). Just wanted to know if you recognize it. Or where I could go to find out. McAfee doesn't have a virus call MSIEXEC.EXEC listed.
The whole log is too long so I'm just posting the start.
=========================
=== Verbose logging started: 11/14/2006 22:30:02 Build type: SHIP UNICODE 3.01.4000.2435 Calling process: C:\WINDOWS\system32\msiexec.exe ===
MSI © (54:98) [22:30:02:472]: Resetting cached policy values
MSI © (54:98) [22:30:02:472]: Machine policy value 'Debug' is 0
MSI © (54:98) [22:30:02:472]: ******* RunEngine:
******* Product: c:\02541f7b9bb8ce8de456aa\msxml.msi
******* Action:
******* CommandLine: **********
MSI © (54:98) [22:30:02:472]: Client-side and UI is none or basic: Running entire install on the server.
MSI © (54:98) [22:30:02:472]: Grabbed execution mutex.
MSI © (54:98) [22:30:02:502]: Cloaking enabled.
MSI © (54:98) [22:30:02:502]: Attempting to enable all disabled priveleges before calling Install on Server
MSI © (54:98) [22:30:02:532]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (84:1C) [22:30:02:552]: Grabbed execution mutex.
MSI (s) (84:24) [22:30:02:552]: Resetting cached policy values
MSI (s) (84:24) [22:30:02:552]: Machine policy value 'Debug' is 0
MSI (s) (84:24) [22:30:02:552]: ******* RunEngine:
******* Product: c:\02541f7b9bb8ce8de456aa\msxml.msi
******* Action:
******* CommandLine: **********
MSI (s) (84:24) [22:30:02:552]: Machine policy value 'DisableUserInstalls' is 0
MSI (s) (84:24) [22:30:02:592]: File will have security applied from OpCode.
MSI (s) (84:24) [22:30:02:752]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'c:\02541f7b9bb8ce8de456aa\msxml.msi' against software restriction policy
MSI (s) (84:24) [22:30:02:752]: SOFTWARE RESTRICTION POLICY: c:\02541f7b9bb8ce8de456aa\msxml.msi has a digital signature
MSI (s) (84:24) [22:30:04:685]: SOFTWARE RESTRICTION POLICY: c:\02541f7b9bb8ce8de456aa\msxml.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (84:24) [22:30:04:705]: End dialog not enabled
MSI (s) (84:24) [22:30:04:705]: Original package ==> c:\02541f7b9bb8ce8de456aa\msxml.msi
MSI (s) (84:24) [22:30:04:705]: Package we're running from ==> c:\WINDOWS\Installer\54c669.msi
MSI (s) (84:24) [22:30:04:735]: APPCOMPAT: looking for appcompat database entry with ProductCode '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (84:24) [22:30:04:735]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (84:24) [22:30:04:765]: MSCOREE not loaded loading copy from system32
MSI (s) (84:24) [22:30:04:956]: Machine policy value 'TransformsSecure' is 0
MSI (s) (84:24) [22:30:04:956]: User policy value 'TransformsAtSource' is 0
MSI (s) (84:24) [22:30:04:956]: Machine policy value 'DisablePatch' is 0
MSI (s) (84:24) [22:30:04:956]: Machine policy value 'AllowLockdownPatch' is 0
MSI (s) (84:24) [22:30:04:956]: Machine policy value 'DisableLUAPatching' is 0
MSI (s) (84:24) [22:30:04:956]: Machine policy value 'DisableFlyWeightPatching' is 0
MSI (s) (84:24) [22:30:04:956]: APPCOMPAT: looking for appcompat database entry with ProductCode '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (84:24) [22:30:04:966]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (84:24) [22:30:04:966]: Transforms are not secure.
MSI (s) (84:24) [22:30:04:966]: Command Line: REBOOT=ReallySuppress CURRENTDIRECTORY=c:\02541f7b9bb8ce8de456aa CLIENTUILEVEL=3 CLIENTPROCESSID=1364
MSI (s) (84:24) [22:30:04:966]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{2B27DCD9-53FA-4885-B6CD-698623819F4C}'.
MSI (s) (84:24) [22:30:04:966]: Product Code passed to Engine.Initialize: ''
MSI (s) (84:24) [22:30:04:966]: Product Code from property table before transforms: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (84:24) [22:30:04:966]: Product Code from property table after transforms: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (84:24) [22:30:05:066]: Product not registered: beginning first-time install
MSI (s) (84:24) [22:30:05:066]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.
MSI (s) (84:24) [22:30:05:066]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (84:24) [22:30:05:066]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (84:24) [22:30:05:066]: Adding new sources is allowed.
MSI (s) (84:24) [22:30:05:066]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.
MSI (s) (84:24) [22:30:05:066]: Package name extracted from package path: 'msxml.msi'
MSI (s) (84:24) [22:30:05:066]: Package to be registered: 'msxml.msi'
MSI (s) (84:24) [22:30:05:066]: Note: 1: 2729
MSI (s) (84:24) [22:30:05:086]: Note: 1: 2729
MSI (s) (84:24) [22:30:05:096]: Note: 1: 2262 2: AdminProperties 3: -2147287038
MSI (s) (84:24) [22:30:05:096]: Machine policy value 'DisableMsi' is 0
MSI (s) (84:24) [22:30:05:096]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (84:24) [22:30:05:096]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (84:24) [22:30:05:096]: Product installation will be elevated because user is admin and product is being installed per-machine.
MSI (s) (84:24) [22:30:05:096]: Running product '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}' with elevated privileges: Product is assigned.
MSI (s) (84:24) [22:30:05:096]: PROPERTY CHANGE: Adding REBOOT property. Its value is 'ReallySuppress'.
MSI (s) (84:24) [22:30:05:096]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'c:\02541f7b9bb8ce8de456aa'.
MSI (s) (84:24) [22:30:05:096]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.
MSI (s) (84:24) [22:30:05:096]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '1364'.
MSI (s) (84:24) [22:30:05:096]: TRANSFORMS property is now:
MSI (s) (84:24) [22:30:05:096]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '200'.
MSI (s) (84:24) [22:30:05:106]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Application Data
MSI (s) (84:24) [22:30:05:116]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Favorites
MSI (s) (84:24) [22:30:05:126]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\NetHood
MSI (s) (84:24) [22:30:05:126]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\My Documents
MSI (s) (84:24) [22:30:05:136]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\PrintHood
MSI (s) (84:24) [22:30:05:146]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Recent
MSI (s) (84:24) [22:30:05:146]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\SendTo
MSI (s) (84:24) [22:30:05:156]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Templates
MSI (s) (84:24) [22:30:05:166]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Application Data
MSI (s) (84:24) [22:30:05:166]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data
MSI (s) (84:24) [22:30:05:176]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures
MSI (s) (84:24) [22:30:05:176]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
MSI (s) (84:24) [22:30:05:186]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs\Startup
MSI (s) (84:24) [22:30:05:196]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs
MSI (s) (84:24) [22:30:05:196]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu
MSI (s) (84:24) [22:30:05:206]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Desktop
MSI (s) (84:24) [22:30:05:206]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Administrative Tools
MSI (s) (84:24) [22:30:05:236]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup
MSI (s) (84:24) [22:30:05:236]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs
MSI (s) (84:24) [22:30:05:246]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu
MSI (s) (84:24) [22:30:05:256]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Desktop
MSI (s) (84:24) [22:30:05:256]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Templates
MSI (s) (84:24) [22:30:05:256]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\Fonts
MSI (s) (84:24) [22:30:05:256]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16
MSI (s) (84:24) [22:30:05:266]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
MSI (s) (84:24) [22:30:05:266]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (84:24) [22:30:05:266]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'Ellen Davidson'.
MSI (s) (84:24) [22:30:05:266]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (84:24) [22:30:05:266]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'c:\WINDOWS\Installer\54c669.msi'.
MSI (s) (84:24) [22:30:05:266]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'c:\02541f7b9bb8ce8de456aa\msxml.msi'.
MSI (s) (84:24) [22:30:05:266]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (84:24) [22:30:05:266]: Machine policy value 'DisableRollback' is 0
MSI (s) (84:24) [22:30:05:266]: User policy value 'DisableRollback' is 0
MSI (s) (84:24) [22:30:05:266]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.
=== Logging started: 11/14/2006 22:30:05 ===
MSI (s) (84:24) [22:30:05:266]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
MSI (s) (84:24) [22:30:05:266]: Doing action: INSTALL
MSI (s) (84:24) [22:30:05:276]: Running ExecuteSequence
MSI (s) (84:24) [22:30:05:276]: Doing action: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901
Action start 22:30:05: INSTALL.
MSI (s) (84:24) [22:30:05:276]: PROPERTY CHANGE: Adding DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Desktop\'.
Action start 22:30:05: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901.
MSI (s) (84:24) [22:30:05:276]: Doing action: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901
Action ended 22:30:05: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901. Return value 1.
MSI (s) (84:24) [22:30:05:286]: PROPERTY CHANGE: Adding ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Start Menu\Programs\'.
Action start 22:30:05: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901.
MSI (s) (84:24) [22:30:05:286]: Doing action: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
Action ended 22:30:05: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901. Return value 1.
MSI (s) (84:24) [22:30:05:286]: PROPERTY CHANGE: Adding WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 22:30:05: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537.
MSI (s) (84:24) [22:30:05:286]: Doing action: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
Action ended 22:30:05: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (84:24) [22:30:05:296]: PROPERTY CHANGE: Adding SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:30:05: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537.
MSI (s) (84:24) [22:30:05:296]: Doing action: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537
Action ended 22:30:05: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (84:24) [22:30:05:296]: PROPERTY CHANGE: Adding WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 22:30:05: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537.
MSI (s) (84:24) [22:30:05:296]: Doing action: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537
Action ended 22:30:05: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (84:24) [22:30:05:306]: PROPERTY CHANGE: Adding SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:30:05: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537.
MSI (s) (84:24) [22:30:05:306]: Doing action: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
Action ended 22:30:05: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (84:24) [22:30:05:306]: PROPERTY CHANGE: Adding WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 22:30:05: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537.
MSI (s) (84:24) [22:30:05:316]: Doing action: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
Action ended 22:30:05: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (84:24) [22:30:05:316]: PROPERTY CHANGE: Adding SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:30:05: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537.
MSI (s) (84:24) [22:30:05:316]: Doing action: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB
Action ended 22:30:05: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (84:24) [22:30:05:316]: PROPERTY CHANGE: Adding SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:30:05: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB.
MSI (s) (84:24) [22:30:05:326]: Doing action: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1
Action ended 22:30:05: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB. Return value 1.
MSI (s) (84:24) [22:30:05:326]: PROPERTY CHANGE: Adding SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:30:05: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1.
MSI (s) (84:24) [22:30:05:326]: Doing action: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7
Action ended 22:30:05: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1. Return value 1.
MSI (s) (84:24) [22:30:05:336]: PROPERTY CHANGE: Adding SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:30:05: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7.
MSI (s) (84:24) [22:30:05:336]: Doing action: LaunchConditions
Action ended 22:30:05: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7. Return value 1.
Action start 22:30:05: LaunchConditions.
MSI (s) (84:24) [22:30:05:336]: Doing action: FindRelatedProducts
Action ended 22:30:05: LaunchConditions. Return value 1.
Action start 22:30:05: FindRelatedProducts.
MSI (s) (84:24) [22:30:05:366]: Doing action: AppSearch
Action ended 22:30:05: FindRelatedProducts. Return value 1.
Action start 22:30:05: AppSearch.
MSI (s) (84:24) [22:30:05:366]: Note: 1: 2262 2: Signature 3: -2147287038
MSI (s) (84:24) [22:30:05:366]: PROPERTY CHANGE: Adding WINHTTP_51 property. Its value is 'WinHttpRequest Component version 5.1'.
MSI (s) (84:24) [22:30:05:366]: Skipping action: CCPSearch (condition is false)
MSI (s) (84:24) [22:30:05:366]: Skipping action: RMCCPSearch (condition is false)
MSI (s) (84:24) [22:30:05:366]: Doing action: ValidateProductID
Action ended 22:30:05: AppSearch. Return value 1.
Action start 22:30:05: ValidateProductID.
MSI (s) (84:24) [22:30:05:376]: Doing action: CostInitialize
Action ended 22:30:05: ValidateProductID. Return value 1.
MSI (s) (84:24) [22:30:05:376]: Machine policy value 'MaxPatchCacheSize' is 10
Action start 22:30:05: CostInitialize.
MSI (s) (84:24) [22:30:05:386]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'c:\'.
MSI (s) (84:24) [22:30:05:386]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.
MSI (s) (84:24) [22:30:05:386]: Note: 1: 2205 2: 3: Patch
MSI (s) (84:24) [22:30:05:386]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (84:24) [22:30:05:386]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (84:24) [22:30:05:386]: Note: 1: 2205 2: 3: __MsiPatchFileList
MSI (s) (84:24) [22:30:05:386]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (84:24) [22:30:05:386]: Note: 1: 2228 2: 3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId`
MSI (s) (84:24) [22:30:05:386]: Doing action: FileCost
Action ended 22:30:05: CostInitialize. Return value 1.
MSI (s) (84:24) [22:30:05:396]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:30:05: FileCost.
MSI (s) (84:24) [22:30:05:396]: Doing action: CostFinalize
Action ended 22:30:05: FileCost. Return value 1.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.
MSI (s) (84:24) [22:30:05:396]: Note: 1: 2205 2: 3: Patch
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'c:\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Modifying WindowsFolder property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Modifying CommonFilesFolder property. Its current value is 'C:\Program Files\Common Files\'. Its new value: 'c:\Program Files\Common Files\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 property. Its value is 'c:\Program Files\Common Files\Microsoft Shared\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 property. Its value is 'c:\Program Files\Common Files\Microsoft Shared\MSDN\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Modifying WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Modifying SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa6920e9f98fc\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying DesktopFolder property. Its current value is 'C:\Documents and Settings\All Users\Desktop\'. Its new value: 'c:\Documents and Settings\All Users\Desktop\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying ProgramFilesFolder property. Its current value is 'C:\Program Files\'. Its new value: 'c:\Program Files\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding MSXML property. Its value is 'c:\Program Files\MSXML 4.0\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding INC.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\inc\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding LIB.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\lib\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding DOC.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\doc\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its current value is 'C:\Documents and Settings\All Users\Start Menu\Programs\'. Its new value: 'c:\Documents and Settings\All Users\Start Menu\Programs\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its current value is 'C:\Documents and Settings\All Users\Desktop\'. Its new value: 'c:\Documents and Settings\All Users\Desktop\'.
MSI (s) (84:24) [22:30:05:406]: Target path resolution complete. Dumping Directory table...
MSI (s) (84:24) [22:30:05:406]: Note: target paths subject to change (via custom actions or browsing)
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: TARGETDIR , Object: c:\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: WindowsFolder , Object: c:\WINDOWS\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: CommonFilesFolder , Object: c:\Program Files\Common Files\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\Program Files\Common Files\Microsoft Shared\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\Program Files\Common Files\Microsoft Shared\MSDN\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa6920e9f98fc\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB , Object: c:\WINDOWS\system32\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 , Object: c:\WINDOWS\system32\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 , Object: c:\WINDOWS\system32\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: DesktopFolder , Object: c:\Documents and Settings\All Users\Desktop\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: ProgramFilesFolder , Object: c:\Program Files\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: MSXML , Object: c:\Program Files\MSXML 4.0\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: INC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\inc\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: LIB.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\lib\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: DOC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\doc\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Start Menu\Programs\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Desktop\
Action start 22:30:05: CostFinalize.
MSI (s) (84:24) [22:30:05:466]: Doing action: SetODBCFolders
Action ended 22:30:05: CostFinalize. Return value 1.
MSI (s) (84:24) [22:30:05:476]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (84:24) [22:30:05:476]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `ComponentId`,`Description`,`Directory_`, `ActionRequest`, `Installed`, `Attributes` FROM `ODBCDriver`, `Component` WHERE `ODBCDriver`.`Component_` = `Component` AND (`ActionRequest` = 1 OR `ActionRequest` = 2)
MSI (s) (84:24) [22:30:05:476]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (84:24) [22:30:05:476]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `ComponentId`,`Description`,`Directory_`, `ActionRequest`, `Installed`, `Attributes` FROM `ODBCTranslator`, `Component` WHERE `ODBCTranslator`.`Component_` = `Component` AND (`ActionRequest` = 1 OR `ActionRequest` = 2)
Action start 22:30:05: SetODBCFolders.
MSI (s) (84:24) [22:30:05:476]: Doing action: MigrateFeatureStates
Action ended 22:30:05: SetODBCFolders. Return value 0.
Action start 22:30:05: MigrateFeatureStates.
MSI (s) (84:24) [22:30:05:476]: Doing action: InstallValidate
Action ended 22:30:05: MigrateFeatureStates. Return value 0.
MSI (s) (84:24) [22:30:05:476]: Feature: MSXML; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Feature: MSXMLSYS; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Feature: MSXMLSUPP; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:476]: Feature: MSXMLSUPP2; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Feature: MSXMLSXS; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Feature: XMLSDK; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:476]: Component: RememberInstallFolder; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Component: QKBKEY; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Component: MSXML4_System.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Component: MSXML4_SystemRes.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Component: MSXML4_ANSI.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:476]: Component: WINHTTP50_COMPONENT.781A0624_31FF_4712_BFFD_31C829FFDBF1; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:476]: Component: PROXYCFG_COMPONENT.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB; Installed: Absent; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:476]: Component: uplevel.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:476]: Component: downlevel_manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Component: downlevel_payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: uplevel.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: downlevel_manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: downlevel_payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: uplevel.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: downlevel_manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: XMLSDK_Docs.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: XMLSDK_LIB.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: XMLSDK_INC.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: CookDoc_dll.3FB7DAB3_19E7_40A0_8730_4482CE77AC59; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: __uplevel.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: __uplevel.DA6654F6_456F_3658_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: __uplevel.0E9F98FC_A692_A6DF_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: __QKBKEY65; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __MSXML4_System.246EB7AD_459A_4FA8_83D1_4165; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __downlevel_payload.7B2FCEFF_0F22_B7E1_FF665; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __downlevel_manifest.7B2FCEFF_0F22_B7E1_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __downlevel_payload.DA6654F6_456F_3658_FF665; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __downlevel_manifest.DA6654F6_456F_3658_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __downlevel_manifest.0E9F98FC_A692_A6DF_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __CookDoc_dll.3FB7DAB3_19E7_40A0_8730_448265; Installed: Null; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: __XMLSDK_Docs.4576A2F1_959E_4BCA_94A9_596565; Installed: Null; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:486]: Note: 1: 2205 2: 3: BindImage
MSI (s) (84:24) [22:30:05:486]: Note: 1: 2262 2: PublishComponent 3: -2147287038
MSI (s) (84:24) [22:30:05:486]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:486]: Note: 1: 2205 2: 3: Font
Action start 22:30:05: InstallValidate.
MSI (s) (84:24) [22:30:05:486]: Note: 1: 2205 2: 3: _RemoveFilePath
MSI (s) (84:24) [22:30:05:687]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:697]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:697]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:697]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:707]: PROPERTY CHANGE: Modifying CostingComplete property. Its current value is '0'. Its new value: '1'.
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2205 2: 3: BindImage
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2262 2: PublishComponent 3: -2147287038
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2205 2: 3: Font
MSI (s) (84:24) [22:30:05:717]: Note: 1: 2727 2:
MSI (s) (84:24) [22:30:05:717]: Note: 1: 2727 2:
MSI (s) (84:24) [22:30:05:717]: Doing action: InstallInitialize
Action ended 22:30:05: InstallValidate. Return value 1.
MSI (s) (84:24) [22:30:05:717]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (84:24) [22:30:05:727]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (84:24) [22:30:05:727]: BeginTransaction: Locking Server
MSI (s) (84:24) [22:30:05:727]: SRSetRestorePoint skipped for this transaction.
MSI (s) (84:24) [22:30:05:727]: Server not locked: locking for product {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
Action start 22:30:05: InstallInitialize.
MSI (s) (84:24) [22:30:07:019]: Doing action: SxsInstallCA
Action ended 22:30:07: InstallInitialize. Return value 1.
MSI (s) (84:E4) [22:30:07:079]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSIA7.tmp, Entrypoint: CustomAction_SxsMsmInstall
MSI (s) (84:68) [22:30:07:079]: Generating random cookie.
MSI (s) (84:68) [22:30:07:109]: Created Custom Action Server with PID 3676 (0xE5C).
MSI (s) (84:40) [22:30:07:359]: Running as a service.
MSI (s) (84:04) [22:30:07:369]: Hello, I'm your 32bit Elevated custom action server.
Action start 22:30:07: SxsInstallCA.
The whole log is too long so I'm just posting the start.
=========================
=== Verbose logging started: 11/14/2006 22:30:02 Build type: SHIP UNICODE 3.01.4000.2435 Calling process: C:\WINDOWS\system32\msiexec.exe ===
MSI © (54:98) [22:30:02:472]: Resetting cached policy values
MSI © (54:98) [22:30:02:472]: Machine policy value 'Debug' is 0
MSI © (54:98) [22:30:02:472]: ******* RunEngine:
******* Product: c:\02541f7b9bb8ce8de456aa\msxml.msi
******* Action:
******* CommandLine: **********
MSI © (54:98) [22:30:02:472]: Client-side and UI is none or basic: Running entire install on the server.
MSI © (54:98) [22:30:02:472]: Grabbed execution mutex.
MSI © (54:98) [22:30:02:502]: Cloaking enabled.
MSI © (54:98) [22:30:02:502]: Attempting to enable all disabled priveleges before calling Install on Server
MSI © (54:98) [22:30:02:532]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (84:1C) [22:30:02:552]: Grabbed execution mutex.
MSI (s) (84:24) [22:30:02:552]: Resetting cached policy values
MSI (s) (84:24) [22:30:02:552]: Machine policy value 'Debug' is 0
MSI (s) (84:24) [22:30:02:552]: ******* RunEngine:
******* Product: c:\02541f7b9bb8ce8de456aa\msxml.msi
******* Action:
******* CommandLine: **********
MSI (s) (84:24) [22:30:02:552]: Machine policy value 'DisableUserInstalls' is 0
MSI (s) (84:24) [22:30:02:592]: File will have security applied from OpCode.
MSI (s) (84:24) [22:30:02:752]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'c:\02541f7b9bb8ce8de456aa\msxml.msi' against software restriction policy
MSI (s) (84:24) [22:30:02:752]: SOFTWARE RESTRICTION POLICY: c:\02541f7b9bb8ce8de456aa\msxml.msi has a digital signature
MSI (s) (84:24) [22:30:04:685]: SOFTWARE RESTRICTION POLICY: c:\02541f7b9bb8ce8de456aa\msxml.msi is permitted to run at the 'unrestricted' authorization level.
MSI (s) (84:24) [22:30:04:705]: End dialog not enabled
MSI (s) (84:24) [22:30:04:705]: Original package ==> c:\02541f7b9bb8ce8de456aa\msxml.msi
MSI (s) (84:24) [22:30:04:705]: Package we're running from ==> c:\WINDOWS\Installer\54c669.msi
MSI (s) (84:24) [22:30:04:735]: APPCOMPAT: looking for appcompat database entry with ProductCode '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (84:24) [22:30:04:735]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (84:24) [22:30:04:765]: MSCOREE not loaded loading copy from system32
MSI (s) (84:24) [22:30:04:956]: Machine policy value 'TransformsSecure' is 0
MSI (s) (84:24) [22:30:04:956]: User policy value 'TransformsAtSource' is 0
MSI (s) (84:24) [22:30:04:956]: Machine policy value 'DisablePatch' is 0
MSI (s) (84:24) [22:30:04:956]: Machine policy value 'AllowLockdownPatch' is 0
MSI (s) (84:24) [22:30:04:956]: Machine policy value 'DisableLUAPatching' is 0
MSI (s) (84:24) [22:30:04:956]: Machine policy value 'DisableFlyWeightPatching' is 0
MSI (s) (84:24) [22:30:04:956]: APPCOMPAT: looking for appcompat database entry with ProductCode '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'.
MSI (s) (84:24) [22:30:04:966]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (84:24) [22:30:04:966]: Transforms are not secure.
MSI (s) (84:24) [22:30:04:966]: Command Line: REBOOT=ReallySuppress CURRENTDIRECTORY=c:\02541f7b9bb8ce8de456aa CLIENTUILEVEL=3 CLIENTPROCESSID=1364
MSI (s) (84:24) [22:30:04:966]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{2B27DCD9-53FA-4885-B6CD-698623819F4C}'.
MSI (s) (84:24) [22:30:04:966]: Product Code passed to Engine.Initialize: ''
MSI (s) (84:24) [22:30:04:966]: Product Code from property table before transforms: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (84:24) [22:30:04:966]: Product Code from property table after transforms: '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}'
MSI (s) (84:24) [22:30:05:066]: Product not registered: beginning first-time install
MSI (s) (84:24) [22:30:05:066]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.
MSI (s) (84:24) [22:30:05:066]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (84:24) [22:30:05:066]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (84:24) [22:30:05:066]: Adding new sources is allowed.
MSI (s) (84:24) [22:30:05:066]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.
MSI (s) (84:24) [22:30:05:066]: Package name extracted from package path: 'msxml.msi'
MSI (s) (84:24) [22:30:05:066]: Package to be registered: 'msxml.msi'
MSI (s) (84:24) [22:30:05:066]: Note: 1: 2729
MSI (s) (84:24) [22:30:05:086]: Note: 1: 2729
MSI (s) (84:24) [22:30:05:096]: Note: 1: 2262 2: AdminProperties 3: -2147287038
MSI (s) (84:24) [22:30:05:096]: Machine policy value 'DisableMsi' is 0
MSI (s) (84:24) [22:30:05:096]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (84:24) [22:30:05:096]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (84:24) [22:30:05:096]: Product installation will be elevated because user is admin and product is being installed per-machine.
MSI (s) (84:24) [22:30:05:096]: Running product '{37477865-A3F1-4772-AD43-AAFC6BCFF99F}' with elevated privileges: Product is assigned.
MSI (s) (84:24) [22:30:05:096]: PROPERTY CHANGE: Adding REBOOT property. Its value is 'ReallySuppress'.
MSI (s) (84:24) [22:30:05:096]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'c:\02541f7b9bb8ce8de456aa'.
MSI (s) (84:24) [22:30:05:096]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.
MSI (s) (84:24) [22:30:05:096]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '1364'.
MSI (s) (84:24) [22:30:05:096]: TRANSFORMS property is now:
MSI (s) (84:24) [22:30:05:096]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '200'.
MSI (s) (84:24) [22:30:05:106]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Application Data
MSI (s) (84:24) [22:30:05:116]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Favorites
MSI (s) (84:24) [22:30:05:126]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\NetHood
MSI (s) (84:24) [22:30:05:126]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\My Documents
MSI (s) (84:24) [22:30:05:136]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\PrintHood
MSI (s) (84:24) [22:30:05:146]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Recent
MSI (s) (84:24) [22:30:05:146]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\SendTo
MSI (s) (84:24) [22:30:05:156]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Templates
MSI (s) (84:24) [22:30:05:166]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Application Data
MSI (s) (84:24) [22:30:05:166]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data
MSI (s) (84:24) [22:30:05:176]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures
MSI (s) (84:24) [22:30:05:176]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
MSI (s) (84:24) [22:30:05:186]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs\Startup
MSI (s) (84:24) [22:30:05:196]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu\Programs
MSI (s) (84:24) [22:30:05:196]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Start Menu
MSI (s) (84:24) [22:30:05:206]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Desktop
MSI (s) (84:24) [22:30:05:206]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Administrative Tools
MSI (s) (84:24) [22:30:05:236]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup
MSI (s) (84:24) [22:30:05:236]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs
MSI (s) (84:24) [22:30:05:246]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Start Menu
MSI (s) (84:24) [22:30:05:256]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\Desktop
MSI (s) (84:24) [22:30:05:256]: SHELL32::SHGetFolderPath returned: C:\Documents and Settings\All Users\Templates
MSI (s) (84:24) [22:30:05:256]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\Fonts
MSI (s) (84:24) [22:30:05:256]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16
MSI (s) (84:24) [22:30:05:266]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
MSI (s) (84:24) [22:30:05:266]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (84:24) [22:30:05:266]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'Ellen Davidson'.
MSI (s) (84:24) [22:30:05:266]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (s) (84:24) [22:30:05:266]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'c:\WINDOWS\Installer\54c669.msi'.
MSI (s) (84:24) [22:30:05:266]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'c:\02541f7b9bb8ce8de456aa\msxml.msi'.
MSI (s) (84:24) [22:30:05:266]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (84:24) [22:30:05:266]: Machine policy value 'DisableRollback' is 0
MSI (s) (84:24) [22:30:05:266]: User policy value 'DisableRollback' is 0
MSI (s) (84:24) [22:30:05:266]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.
=== Logging started: 11/14/2006 22:30:05 ===
MSI (s) (84:24) [22:30:05:266]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
MSI (s) (84:24) [22:30:05:266]: Doing action: INSTALL
MSI (s) (84:24) [22:30:05:276]: Running ExecuteSequence
MSI (s) (84:24) [22:30:05:276]: Doing action: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901
Action start 22:30:05: INSTALL.
MSI (s) (84:24) [22:30:05:276]: PROPERTY CHANGE: Adding DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Desktop\'.
Action start 22:30:05: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901.
MSI (s) (84:24) [22:30:05:276]: Doing action: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901
Action ended 22:30:05: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901. Return value 1.
MSI (s) (84:24) [22:30:05:286]: PROPERTY CHANGE: Adding ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'C:\Documents and Settings\All Users\Start Menu\Programs\'.
Action start 22:30:05: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901.
MSI (s) (84:24) [22:30:05:286]: Doing action: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
Action ended 22:30:05: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901. Return value 1.
MSI (s) (84:24) [22:30:05:286]: PROPERTY CHANGE: Adding WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 22:30:05: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537.
MSI (s) (84:24) [22:30:05:286]: Doing action: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537
Action ended 22:30:05: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (84:24) [22:30:05:296]: PROPERTY CHANGE: Adding SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:30:05: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537.
MSI (s) (84:24) [22:30:05:296]: Doing action: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537
Action ended 22:30:05: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (84:24) [22:30:05:296]: PROPERTY CHANGE: Adding WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 22:30:05: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537.
MSI (s) (84:24) [22:30:05:296]: Doing action: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537
Action ended 22:30:05: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (84:24) [22:30:05:306]: PROPERTY CHANGE: Adding SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:30:05: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537.
MSI (s) (84:24) [22:30:05:306]: Doing action: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
Action ended 22:30:05: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (84:24) [22:30:05:306]: PROPERTY CHANGE: Adding WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\'.
Action start 22:30:05: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537.
MSI (s) (84:24) [22:30:05:316]: Doing action: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537
Action ended 22:30:05: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (84:24) [22:30:05:316]: PROPERTY CHANGE: Adding SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:30:05: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537.
MSI (s) (84:24) [22:30:05:316]: Doing action: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB
Action ended 22:30:05: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537. Return value 1.
MSI (s) (84:24) [22:30:05:316]: PROPERTY CHANGE: Adding SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:30:05: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB.
MSI (s) (84:24) [22:30:05:326]: Doing action: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1
Action ended 22:30:05: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB. Return value 1.
MSI (s) (84:24) [22:30:05:326]: PROPERTY CHANGE: Adding SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:30:05: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1.
MSI (s) (84:24) [22:30:05:326]: Doing action: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7
Action ended 22:30:05: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1. Return value 1.
MSI (s) (84:24) [22:30:05:336]: PROPERTY CHANGE: Adding SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its value is 'C:\WINDOWS\system32\'.
Action start 22:30:05: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7.
MSI (s) (84:24) [22:30:05:336]: Doing action: LaunchConditions
Action ended 22:30:05: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7. Return value 1.
Action start 22:30:05: LaunchConditions.
MSI (s) (84:24) [22:30:05:336]: Doing action: FindRelatedProducts
Action ended 22:30:05: LaunchConditions. Return value 1.
Action start 22:30:05: FindRelatedProducts.
MSI (s) (84:24) [22:30:05:366]: Doing action: AppSearch
Action ended 22:30:05: FindRelatedProducts. Return value 1.
Action start 22:30:05: AppSearch.
MSI (s) (84:24) [22:30:05:366]: Note: 1: 2262 2: Signature 3: -2147287038
MSI (s) (84:24) [22:30:05:366]: PROPERTY CHANGE: Adding WINHTTP_51 property. Its value is 'WinHttpRequest Component version 5.1'.
MSI (s) (84:24) [22:30:05:366]: Skipping action: CCPSearch (condition is false)
MSI (s) (84:24) [22:30:05:366]: Skipping action: RMCCPSearch (condition is false)
MSI (s) (84:24) [22:30:05:366]: Doing action: ValidateProductID
Action ended 22:30:05: AppSearch. Return value 1.
Action start 22:30:05: ValidateProductID.
MSI (s) (84:24) [22:30:05:376]: Doing action: CostInitialize
Action ended 22:30:05: ValidateProductID. Return value 1.
MSI (s) (84:24) [22:30:05:376]: Machine policy value 'MaxPatchCacheSize' is 10
Action start 22:30:05: CostInitialize.
MSI (s) (84:24) [22:30:05:386]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'c:\'.
MSI (s) (84:24) [22:30:05:386]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.
MSI (s) (84:24) [22:30:05:386]: Note: 1: 2205 2: 3: Patch
MSI (s) (84:24) [22:30:05:386]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (84:24) [22:30:05:386]: Note: 1: 2205 2: 3: MsiPatchHeaders
MSI (s) (84:24) [22:30:05:386]: Note: 1: 2205 2: 3: __MsiPatchFileList
MSI (s) (84:24) [22:30:05:386]: Note: 1: 2205 2: 3: PatchPackage
MSI (s) (84:24) [22:30:05:386]: Note: 1: 2228 2: 3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId`
MSI (s) (84:24) [22:30:05:386]: Doing action: FileCost
Action ended 22:30:05: CostInitialize. Return value 1.
MSI (s) (84:24) [22:30:05:396]: Note: 1: 2262 2: Extension 3: -2147287038
Action start 22:30:05: FileCost.
MSI (s) (84:24) [22:30:05:396]: Doing action: CostFinalize
Action ended 22:30:05: FileCost. Return value 1.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.
MSI (s) (84:24) [22:30:05:396]: Note: 1: 2205 2: 3: Patch
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'c:\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Modifying WindowsFolder property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Modifying CommonFilesFolder property. Its current value is 'C:\Program Files\Common Files\'. Its new value: 'c:\Program Files\Common Files\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 property. Its value is 'c:\Program Files\Common Files\Microsoft Shared\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 property. Its value is 'c:\Program Files\Common Files\Microsoft Shared\MSDN\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Modifying WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Modifying SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\'.
MSI (s) (84:24) [22:30:05:396]: PROPERTY CHANGE: Adding payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa6920e9f98fc\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\'. Its new value: 'c:\WINDOWS\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\Manifests\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 property. Its value is 'c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'c:\WINDOWS\system32\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying DesktopFolder property. Its current value is 'C:\Documents and Settings\All Users\Desktop\'. Its new value: 'c:\Documents and Settings\All Users\Desktop\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying ProgramFilesFolder property. Its current value is 'C:\Program Files\'. Its new value: 'c:\Program Files\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding MSXML property. Its value is 'c:\Program Files\MSXML 4.0\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding INC.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\inc\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding LIB.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\lib\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding DOC.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Program Files\MSXML 4.0\doc\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its current value is 'C:\Documents and Settings\All Users\Start Menu\Programs\'. Its new value: 'c:\Documents and Settings\All Users\Start Menu\Programs\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Adding MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 property. Its value is 'c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\'.
MSI (s) (84:24) [22:30:05:406]: PROPERTY CHANGE: Modifying DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 property. Its current value is 'C:\Documents and Settings\All Users\Desktop\'. Its new value: 'c:\Documents and Settings\All Users\Desktop\'.
MSI (s) (84:24) [22:30:05:406]: Target path resolution complete. Dumping Directory table...
MSI (s) (84:24) [22:30:05:406]: Note: target paths subject to change (via custom actions or browsing)
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: TARGETDIR , Object: c:\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: WindowsFolder , Object: c:\WINDOWS\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: CommonFilesFolder , Object: c:\Program Files\Common Files\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: MicrosoftShared.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\Program Files\Common Files\Microsoft Shared\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: MSDN.3FB7DAB3_19E7_40A0_8730_4482CE77AC59 , Object: c:\Program Files\Common Files\Microsoft Shared\MSDN\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: WindowsFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: SystemFolder.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: WinSxsDirectory.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (84:24) [22:30:05:406]: Dir (target): Key: policydir_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: payload.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_ff05e224\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsManifests.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsPolicies.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: policydir.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: payload_ul.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa6920e9f98fc\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WindowsFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: SystemFolder.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsDirectory.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: policydir_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsPolicies.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: policydir.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2R_6bd6b9abf345378f_x-ww_f529d679\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsManifests.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: payload_ul.DA6654F6_456F_3658_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WindowsFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: SystemFolder.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\system32\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsDirectory.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: policydir_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsPolicies.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: policydir.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Policies\x86_Microsoft.MSXML2_6bd6b9abf345378f_x-ww_b261cf09\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: WinSxsManifests.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\Manifests\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: payload_ul.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537 , Object: c:\WINDOWS\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: SystemFolder.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB , Object: c:\WINDOWS\system32\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: SystemFolder.781A0624_31FF_4712_BFFD_31C829FFDBF1 , Object: c:\WINDOWS\system32\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: SystemFolder.246EB7AD_459A_4FA8_83D1_41A46D7634B7 , Object: c:\WINDOWS\system32\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: DesktopFolder , Object: c:\Documents and Settings\All Users\Desktop\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: ProgramFilesFolder , Object: c:\Program Files\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: MSXML , Object: c:\Program Files\MSXML 4.0\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: INC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\inc\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: LIB.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\lib\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: DOC.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Program Files\MSXML 4.0\doc\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: ProgramMenuFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Start Menu\Programs\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: MenuMSXML.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Start Menu\Programs\MSXML 4.0\
MSI (s) (84:24) [22:30:05:416]: Dir (target): Key: DesktopFolder.4576A2F1_959E_4BCA_94A9_596523761901 , Object: c:\Documents and Settings\All Users\Desktop\
Action start 22:30:05: CostFinalize.
MSI (s) (84:24) [22:30:05:466]: Doing action: SetODBCFolders
Action ended 22:30:05: CostFinalize. Return value 1.
MSI (s) (84:24) [22:30:05:476]: Note: 1: 2205 2: 3: ODBCDriver
MSI (s) (84:24) [22:30:05:476]: Note: 1: 2228 2: 3: ODBCDriver 4: SELECT `ComponentId`,`Description`,`Directory_`, `ActionRequest`, `Installed`, `Attributes` FROM `ODBCDriver`, `Component` WHERE `ODBCDriver`.`Component_` = `Component` AND (`ActionRequest` = 1 OR `ActionRequest` = 2)
MSI (s) (84:24) [22:30:05:476]: Note: 1: 2205 2: 3: ODBCTranslator
MSI (s) (84:24) [22:30:05:476]: Note: 1: 2228 2: 3: ODBCTranslator 4: SELECT `ComponentId`,`Description`,`Directory_`, `ActionRequest`, `Installed`, `Attributes` FROM `ODBCTranslator`, `Component` WHERE `ODBCTranslator`.`Component_` = `Component` AND (`ActionRequest` = 1 OR `ActionRequest` = 2)
Action start 22:30:05: SetODBCFolders.
MSI (s) (84:24) [22:30:05:476]: Doing action: MigrateFeatureStates
Action ended 22:30:05: SetODBCFolders. Return value 0.
Action start 22:30:05: MigrateFeatureStates.
MSI (s) (84:24) [22:30:05:476]: Doing action: InstallValidate
Action ended 22:30:05: MigrateFeatureStates. Return value 0.
MSI (s) (84:24) [22:30:05:476]: Feature: MSXML; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Feature: MSXMLSYS; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Feature: MSXMLSUPP; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:476]: Feature: MSXMLSUPP2; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Feature: MSXMLSXS; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Feature: XMLSDK; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:476]: Component: RememberInstallFolder; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Component: QKBKEY; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Component: MSXML4_System.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Component: MSXML4_SystemRes.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Component: MSXML4_ANSI.246EB7AD_459A_4FA8_83D1_41A46D7634B7; Installed: Absent; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:476]: Component: WINHTTP50_COMPONENT.781A0624_31FF_4712_BFFD_31C829FFDBF1; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:476]: Component: PROXYCFG_COMPONENT.FA0F135B_0C6B_485B_9A27_5A4A5044D5AB; Installed: Absent; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:476]: Component: uplevel.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:476]: Component: downlevel_manifest.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:476]: Component: downlevel_payload.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: uplevel.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: downlevel_manifest.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: downlevel_payload.DA6654F6_456F_3658_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: uplevel.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: downlevel_manifest.0E9F98FC_A692_A6DF_FF6B_D6B9ABF34537; Installed: Absent; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: XMLSDK_Docs.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: XMLSDK_LIB.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: XMLSDK_INC.4576A2F1_959E_4BCA_94A9_596523761901; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: CookDoc_dll.3FB7DAB3_19E7_40A0_8730_4482CE77AC59; Installed: Absent; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: __uplevel.7B2FCEFF_0F22_B7E1_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: __uplevel.DA6654F6_456F_3658_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: __uplevel.0E9F98FC_A692_A6DF_FF6B_D6B9ABF365; Installed: Null; Request: Local; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: __QKBKEY65; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __MSXML4_System.246EB7AD_459A_4FA8_83D1_4165; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __downlevel_payload.7B2FCEFF_0F22_B7E1_FF665; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __downlevel_manifest.7B2FCEFF_0F22_B7E1_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __downlevel_payload.DA6654F6_456F_3658_FF665; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __downlevel_manifest.DA6654F6_456F_3658_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __downlevel_manifest.0E9F98FC_A692_A6DF_FF65; Installed: Null; Request: Local; Action: Local
MSI (s) (84:24) [22:30:05:486]: Component: __CookDoc_dll.3FB7DAB3_19E7_40A0_8730_448265; Installed: Null; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:486]: Component: __XMLSDK_Docs.4576A2F1_959E_4BCA_94A9_596565; Installed: Null; Request: Null; Action: Null
MSI (s) (84:24) [22:30:05:486]: Note: 1: 2205 2: 3: BindImage
MSI (s) (84:24) [22:30:05:486]: Note: 1: 2262 2: PublishComponent 3: -2147287038
MSI (s) (84:24) [22:30:05:486]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:486]: Note: 1: 2205 2: 3: Font
Action start 22:30:05: InstallValidate.
MSI (s) (84:24) [22:30:05:486]: Note: 1: 2205 2: 3: _RemoveFilePath
MSI (s) (84:24) [22:30:05:687]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:697]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:697]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:697]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:707]: PROPERTY CHANGE: Modifying CostingComplete property. Its current value is '0'. Its new value: '1'.
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2205 2: 3: BindImage
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2262 2: PublishComponent 3: -2147287038
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2262 2: Extension 3: -2147287038
MSI (s) (84:24) [22:30:05:707]: Note: 1: 2205 2: 3: Font
MSI (s) (84:24) [22:30:05:717]: Note: 1: 2727 2:
MSI (s) (84:24) [22:30:05:717]: Note: 1: 2727 2:
MSI (s) (84:24) [22:30:05:717]: Doing action: InstallInitialize
Action ended 22:30:05: InstallValidate. Return value 1.
MSI (s) (84:24) [22:30:05:717]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (84:24) [22:30:05:727]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (84:24) [22:30:05:727]: BeginTransaction: Locking Server
MSI (s) (84:24) [22:30:05:727]: SRSetRestorePoint skipped for this transaction.
MSI (s) (84:24) [22:30:05:727]: Server not locked: locking for product {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
Action start 22:30:05: InstallInitialize.
MSI (s) (84:24) [22:30:07:019]: Doing action: SxsInstallCA
Action ended 22:30:07: InstallInitialize. Return value 1.
MSI (s) (84:E4) [22:30:07:079]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSIA7.tmp, Entrypoint: CustomAction_SxsMsmInstall
MSI (s) (84:68) [22:30:07:079]: Generating random cookie.
MSI (s) (84:68) [22:30:07:109]: Created Custom Action Server with PID 3676 (0xE5C).
MSI (s) (84:40) [22:30:07:359]: Running as a service.
MSI (s) (84:04) [22:30:07:369]: Hello, I'm your 32bit Elevated custom action server.
Action start 22:30:07: SxsInstallCA.
#6 OFFLINE
Posted 24 November 2006 - 07:34 PM
MSIEXEC.EXE is the Windows Installer - I would guess that you installed some M$ updates on 11/14/2006.
Team Numpty - Poking a finger in the eye of malware since a week last Thursday!
#7 OFFLINE
Posted 27 November 2006 - 07:09 PM
Thanks again for all your help. No need to post a reponse.











